Skip to main content
Free template · Updated September 2026

Software Development RFP Template

A complete request for proposal you can fill in and send to vendors — scope, non-functional requirements, 20 vendor questions, a weighted scoring table and the commercial terms that avoid disputes later. Copy it, download it as Markdown or save it as a PDF.

The RFP template

Replace every grey italic hint with your own answer. Delete sections that genuinely do not apply, but keep the headings for requirements you have not decided yet and write “To be confirmed” — vendors price uncertainty, so saying so openly gets you more honest quotes.

It is one of several planning resources in our free tools library.

1. Company background

ItemYour answer
Company name and websiteLegal entity name, website, head office country
What you doTwo or three sentences: products or services, customers, size (employees, revenue band if you are comfortable sharing)
Why this project, why nowThe business trigger: a failing legacy system, a new market, a regulator, a growth ceiling
Current systemsThe tools and platforms this project replaces or touches (e.g. spreadsheets, an in-house PHP app, Salesforce)
Internal teamWho you have in-house: product owner, designers, developers, IT/ops — and how many hours a week they can give this project

2. Project goals and success measures

State outcomes, not features. Each goal should have a measure you can check after launch.

GoalHow we will measure itBaseline todayTarget and by when
e.g. Cut manual order entrye.g. Orders keyed by hand per weeke.g. ~600e.g. Under 100 within 3 months of launch
Goal 2MeasureBaselineTarget
Goal 3MeasureBaselineTarget

3. Scope and features (MoSCoW)

Must = launch is pointless without it. Should = important, but a workaround exists for launch. Could = nice to have if budget allows. List Won't (this phase) explicitly so vendors do not quote for it.

IDFeature / user storyPriorityNotes and acceptance hints
F-01As a customer, I can create an account with email or Google sign-inMuste.g. Email verification required; password rules per security policy
F-02As an admin, I can export orders to CSVShouldFilters by date and status
F-03FeatureMust / Should / CouldNotes
F-04FeatureMust / Should / CouldNotes
ItemYour answer
Won't (this phase)Features you are deliberately excluding, e.g. native mobile apps, multi-currency, marketplace payouts
Existing designs or prototypesLinks to wireframes, Figma files, screenshots of competitor flows you like — or “none, design is in scope”

4. Users and roles

RoleWho they areApprox. number of usersKey permissions
e.g. CustomerExternal buyers on desktop and mobilee.g. 20,000 registered, 1,500 daily activePlace and track own orders
e.g. Operations staffInternal, office-basede.g. 25Edit orders, issue refunds up to a limit
e.g. Super adminIT leade.g. 2Manage users, roles, settings

5. Integrations

SystemDirectionMethod (if known)Data exchangedOwner / access available?
e.g. SAP Business OneIn / Out / BothREST API, SFTP file, webhook, database viewProducts, stock levels, invoicesName; sandbox available yes/no
e.g. StripeBothAPI + webhooksPayments, refundsFinance team
SystemDirectionMethodDataOwner

6. Non-functional requirements

These drive architecture and cost as much as features do. If you do not know a number, give a range or write “vendor to recommend”.

Performance and scale

ItemYour answer
Page / screen response timee.g. 95% of pages interactive in under 2.5 s on a mid-range phone over 4G
API response timee.g. p95 under 500 ms for read endpoints at expected peak
Peak concurrent usersExpected at launch and in 24 months; note seasonal spikes (sales, exam results, month-end)
Data volumesRecords today, growth per month, file/image storage estimates
Availability targete.g. 99.5% or 99.9% monthly, planned maintenance windows allowed?

Security

ItemYour answer
AuthenticationSSO (SAML / OIDC) with your identity provider? MFA required for which roles?
AuthorisationRole-based access, record-level rules, audit log of admin actions
Data protectionEncryption in transit and at rest, secrets management, PII fields that need masking
TestingIs an independent penetration test required before go-live? Who pays for it?
Security standard to align withe.g. OWASP ASVS level 2, your internal security policy (attach it)

Compliance and data residency

ItemYour answer
Regulations that applye.g. GDPR, India DPDP Act, HIPAA, PCI DSS, sector rules — or “unsure, vendor to advise”
Data residencyCountries or cloud regions where data must be stored and processed
Audit expectationse.g. customer security questionnaires, SOC 2 evidence you will need the vendor to support

Accessibility, browsers and devices

ItemYour answer
Accessibility levele.g. WCAG 2.2 AA for all customer-facing screens
Browsers and devicese.g. last two versions of Chrome, Safari, Edge, Firefox; iOS 16+ and Android 10+
Languages and localesUI languages, right-to-left support, currencies, date and number formats

7. Technical constraints and preferences

ItemYour answer
HostingYour AWS / Azure / GCP account, on-premise, or vendor-recommended; who owns the cloud account
Preferred or mandated stacke.g. .NET 8 and SQL Server because your team maintains them — or “open, justify your choice”
Constraints to respecte.g. must run behind corporate VPN, no open-source licences with copyleft terms, existing API gateway
Handover and maintenanceWill your team take over the code? What documentation and training do they need?

8. Data migration

SourceData setsVolumeQuality notesCut-over expectation
e.g. Legacy MySQL databaseCustomers, orders since 2018e.g. 1.2 M rowsDuplicates, free-text addressesBig-bang weekend / phased / parallel run
e.g. Excel sheetsPrice listsVolumeQualityExpectation

Who is responsible for cleansing data: your team, the vendor, or shared — say which.

9. Deliverables

  • Discovery output: validated scope, user flows, architecture outline, refined estimate
  • UX/UI design: wireframes, clickable prototype, design system in Figma
  • Working software: web app, admin panel, APIs, mobile apps — list each
  • Source code in your Git organisation from day one, with commit history
  • Automated tests and CI/CD pipeline configuration
  • Infrastructure as code for all environments (dev, staging, production)
  • Documentation: architecture, API reference, runbook, admin guide
  • Knowledge transfer: number of sessions, recorded walkthroughs

10. Timeline and milestones

MilestoneTarget dateFixed or flexible?Exit criteria
Vendor selecteddateFixedContract signed
Discovery completedateFlexibleScope, design direction and estimate approved
MVP / first release to usersdateFixed / Flexible — and whyMust-have features accepted in UAT
Full launchdateFlexiblePerformance and security tests passed
Warranty period endsdateFixedNo open severity 1–2 defects

Hard external deadlines (events, contract renewals, regulatory dates): list them and what happens if missed.

11. Budget range

ItemYour answer
Indicative budget rangee.g. USD 40k–70k for build; separate budget for hosting and support
Preferred engagement modelFixed price per phase / time and materials with a cap / dedicated team per month
What the budget must coverDiscovery, design, build, QA, deployment, warranty — tick what applies
Ongoing costs you expectHosting, third-party licences, support retainer — rough monthly ceiling

Sharing a range is not a weakness. Without one, vendors guess your ambition and you receive proposals that are impossible to compare.

12. Questions vendors must answer

Ask every vendor the same questions, in the same order, so answers can be compared side by side.

#QuestionVendor answer
Q1Describe two projects similar in scope or domain. What was your role, team size and duration? Can we speak to those clients?answer
Q2Who exactly will work on our project (roles, seniority, location, time allocation)? Can we interview the lead engineer?answer
Q3How do you run discovery, and what do we receive at the end of it?answer
Q4Which parts of our scope do you see as highest risk, and how would you reduce that risk early?answer
Q5What architecture and technology stack do you propose, and why is it right for our constraints?answer
Q6How do you estimate? Show the breakdown behind your price and the assumptions it depends on.answer
Q7How do you handle change requests, and how are they priced?answer
Q8What is your sprint cadence, and what will we see in each demo?answer
Q9How do you test: unit, integration, end-to-end, performance, accessibility? What coverage do you target?answer
Q10Describe your CI/CD pipeline and release process, including rollback.answer
Q11How do you secure code, secrets, environments and developer access to our data?answer
Q12Which compliance requirements have you delivered against before (e.g. GDPR, HIPAA), and what evidence can you provide?answer
Q13How will you document the system and hand it over to our team or another vendor?answer
Q14What does your warranty cover, for how long, and what are the response times?answer
Q15What post-launch support and maintenance options do you offer, and at what rates?answer
Q16How do you communicate day to day — tools, time-zone overlap, escalation path?answer
Q17Which third-party services, licences or open-source components will we need to pay for or accept?answer
Q18Do you use subcontractors or AI coding tools on client code? Under what controls?answer
Q19What would you need from us (people, access, decisions) to hit the timeline?answer
Q20What in this RFP is unclear, missing or, in your view, a bad idea?answer

13. Evaluation criteria and weighting

Score each vendor 1–5 per criterion, multiply by the weight, and add up. Agree the weights internally before proposals arrive.

CriterionWeightVendor A score (1–5)Vendor A weightedVendor B score (1–5)Vendor B weighted
Understanding of our problem and goals20%score × weight
Relevant experience and references15%
Proposed team quality and continuity15%
Technical approach and architecture15%
Delivery process, QA and risk management10%
Security and compliance10%
Total cost of ownership (build + 2 years run)15%
Total100%sumsum

14. Commercial terms

ItemYour answer
Intellectual propertyAll custom code, designs and documentation assigned to us on payment; vendor lists any pre-existing components and their licence
Source code and accountsCode in our repository; cloud, domain and third-party accounts registered to us
Warrantye.g. 60–90 days after go-live; defects against accepted requirements fixed at no charge
Support SLAsResponse and resolution targets by severity (see table below)
Payment milestonese.g. 10% on signing, 20% after discovery, 50% across sprint/milestone acceptance, 20% after go-live and warranty
AcceptanceWho signs off, how many days for UAT, what counts as a blocking defect
Confidentiality and dataNDA, data processing agreement, deletion of our data at contract end
Termination and exitNotice period, handover obligations, payment for work completed
Liability and insuranceLiability cap, professional indemnity cover required
SeverityExampleResponse timeResolution / workaround target
1 — CriticalProduction down, data loss, security breache.g. 1 hour, 24×7e.g. 4–8 hours
2 — HighKey feature broken, no workarounde.g. 4 business hourse.g. 2 business days
3 — MediumFeature impaired, workaround existse.g. 1 business daye.g. next release
4 — LowCosmetic issue, questione.g. 2 business dayse.g. backlog, prioritised with us

15. Submission instructions

ItemYour answer
Questions deadlineDate by which vendors can send clarifying questions; answers shared with all vendors
Proposal deadlineDate, time and time zone
FormatPDF, max ~20 pages plus appendices; answer Q1–Q20 in order; itemised price breakdown in a spreadsheet
Send toName, email; one contact only
Selection timelineShortlist date, vendor presentations, final decision date, target start date
Rights reservede.g. We may accept none of the proposals; costs of responding are borne by vendors

How to use this template

1Fill inProduct owner drafts; finance, IT and ops add their parts
2ShortlistSend to 3–5 vendors, not 15
3ClarifyOne Q&A round, answers shared with all
4ScoreWeighted table, each scorer independently
5DecidePresentations, references, then contract

This RFP works best when one person owns it — usually the product owner or project sponsor — but several people contribute. Draft the background, goals and scope first. Then hand the non-functional requirements to IT or security, the integrations table to whoever owns those systems, and the budget and commercial terms to finance or legal. Expect two to five working days of effort spread over one or two weeks.

Keep the scope table honest. It is tempting to mark everything as “Must”; if more than about half of your features are Musts, vendors cannot tell what the real launch is, and their quotes will drift apart. If you are unsure what a minimal first release looks like, fill in our MVP requirements template first (or read how MVP development engagements are usually scoped) and paste the result into section 3.

Send the RFP to a short list of three to five vendors whose work you have already checked. Give them two to three weeks to respond and one round of clarifying questions — and share every answer with all bidders so the comparison stays fair. When proposals arrive, score them independently using the weighting table before discussing them as a group; this stops the most persuasive person in the room from setting the result.

If you are comparing an agency with a dedicated team model, ask both to price the same scope so the comparison is like-for-like. Our pages on custom software development and hiring dedicated developers explain how those two engagement models differ in practice.

Tips from our delivery team

  • Ask for a paid discovery phase. For anything larger than a small MVP, a 2–4 week discovery (typically $3k–$8k) turns a guess into an estimate. Before discovery, a rough figure from our app development cost calculator helps you set a realistic range. Vendors who quote a large fixed price with no discovery are pricing in risk you cannot see.
  • Price total cost of ownership, not build cost. Ask for two years of hosting, licences and support alongside the build price. A cheaper build on an expensive or unusual stack can cost more over time.
  • Insist on meeting the delivery team. The people in the sales pitch are often not the people who write your code. Question 2 exists for this reason; interview the lead engineer.
  • Put IP and account ownership in writing. Code in your repository and cloud accounts in your name from day one make it far easier to change vendor if you ever need to.
  • Read the answer to question 20 closely. A vendor that pushes back on a requirement with a clear reason is usually more valuable than one that agrees to everything.
  • Look at how the vendor works, not just what it builds. Sprint demos, acceptance criteria and release discipline matter more than a portfolio. Our how we work page shows the kind of process detail worth asking every bidder for.

Frequently asked questions

What should a software development RFP include?

At minimum: company background, business goals with measures, prioritised scope, users and roles, integrations, non-functional requirements (performance, security, compliance, accessibility), technical constraints, data migration, deliverables, timeline, budget range, standard vendor questions, weighted evaluation criteria, commercial terms and submission instructions. This template covers all of them.

Should I include a budget in my RFP?

Yes, as a range. Without a range, vendors guess your ambition and proposals vary by several times in price and scope, which makes them impossible to compare. A range also lets vendors tell you early what is realistic for the money.

How many vendors should receive the RFP?

Three to five pre-screened vendors is usually right. Fewer gives you little comparison; more creates evaluation work your team will not have time to do properly, and good vendors are less likely to invest in a detailed response when they know the field is very large.

How long should vendors have to respond?

Two to three weeks for a mid-sized project, with a clarifying-questions deadline about one week in. Very short deadlines favour vendors who reuse generic proposals rather than those who think about your problem.

Fixed price or time and materials — which should I ask for?

Fixed price suits well-defined scope, such as a phase that follows a discovery. Time and materials with a cap suits evolving products where you expect to learn and change priorities. Many teams combine them: a fixed-price discovery followed by time-and-materials or dedicated-team delivery.

Want us to review your completed template? — free

Send us your filled-in RFP and one of our solution architects will flag gaps, unclear requirements and cost risks before you send it to vendors. No obligation to work with us.

Request a free review
© Next Olive Technologies · nextolive.com · sales@nextolive.com