Vendor demos are designed to answer the questions the vendor likes. A requirements list flips that around. It makes every product answer the same questions in the same format, so a sales engineer’s enthusiasm counts for less than a “yes / no / roadmap” in a table. We built this checklist from the questions we ask when we review monitoring tools for this site. Copy it into your RFP, delete what does not apply, and mark each line Must, Should or Nice.
How to use the checklist
- Fill in the context block first. Vendors cannot quote accurately without device counts, sites and growth.
- Mark priorities before you send it. If everything is a Must, nothing is.
- Ask for evidence, not adjectives. For each Must, request a documentation link or a demo step.
- Keep the answer format fixed: Yes (included) / Yes (add-on, cost) / Roadmap (date) / No.
- Verify the Musts in a trial. Our 14-day trial plan is built around that.
Context block (send this with every RFP)
| Item | Your answer |
|---|---|
| Sites and locations | e.g. 1 HQ + 4 branches |
| Network devices (switches, routers, firewalls, APs) | |
| Servers (physical / virtual) | |
| Other devices (printers, UPS, cameras, IoT) | |
| Cloud services to watch (AWS, Azure, Microsoft 365) | |
| Expected growth over 3 years | |
| Monitoring team size and skills | |
| Hosting preference: SaaS, self-hosted, either | |
| Budget model preference: annual subscription, perpetual, monthly |
1. Coverage
| Requirement | Priority | Vendor answer |
|---|---|---|
| SNMP v1/v2c/v3 polling of switches, routers, firewalls | ||
| Vendor-specific health (fans, PSUs, temperature) for our hardware brands | ||
| Interface traffic, errors and discards per port | ||
| Flow analysis (NetFlow, sFlow, IPFIX) | ||
| Windows server monitoring (WMI/WinRM) | ||
| Linux server monitoring (SSH/agent/SNMP) | ||
| Hypervisor monitoring (VMware, Hyper-V, Proxmox) | ||
| Wireless controller and AP monitoring | ||
| HTTP(S), DNS and certificate-expiry checks | ||
| Cloud and SaaS service checks | ||
| Syslog and SNMP trap reception |
2. Discovery and mapping
- Scheduled auto-discovery by IP range, with exclusions
- Device identification by make, model and role
- Layer 2 / Layer 3 topology maps drawn from real neighbor data (LLDP/CDP)
- Custom dashboards and maps that can be shared read-only
- Configuration backup and change detection for network devices (included or add-on?)
3. Alerting
- Thresholds per device, per group and per template
- Dependencies, so a failed uplink suppresses downstream alerts
- Maintenance windows and scheduled suppression
- Escalation after X minutes unacknowledged
- Channels: email, SMS, Teams, Slack, webhook, PagerDuty-style on-call tools
- Ticketing integration (ServiceNow, Jira, ConnectWise, Autotask, other)
- Alert history with acknowledgement notes
4. Reporting
- Availability / SLA reports per service and per site
- Bandwidth and top-talker reports
- Scheduled reports by email as PDF or CSV
- Data retention: raw resolution kept for __ days, aggregated for __ months
- Export or API access to historical data
5. Deployment and architecture
| Requirement | Priority | Vendor answer |
|---|---|---|
| SaaS option; data residency region | ||
| Self-hosted option; OS and database requirements | ||
| Remote probe or collector per site; is it charged separately? | ||
| High availability or failover for the core | ||
| Tested scale (devices or sensors per server / per collector) | ||
| Time from signup to first useful alert in our environment |
6. Security and access
- Single sign-on (SAML/OIDC) and MFA for all users
- Role-based access, including per-site or per-customer restrictions
- Audit log of user actions
- Credential storage method (encrypted vault, integration with a secrets manager)
- Least-privilege credentials documented (read-only SNMP, no domain admin requirement)
- Vendor security attestations (SOC 2 report, ISO 27001) and a published vulnerability disclosure process
- Software supply-chain practices: signed updates, release notes, patch cadence
7. Licensing and total cost
These questions stop the year-two surprise:
| Question | Vendor answer |
|---|---|
| What is the license unit (sensor, device, node, element, endpoint)? | |
| How is our environment counted in that unit? Show the arithmetic. | |
| Price for current size, and at +50% growth | |
| What happens when we exceed the licensed count? | |
| Which features require a higher edition or add-on module? | |
| Renewal price protection for years 2–3 | |
| Server, OS and database licenses we must supply ourselves | |
| Trial length and whether it is full-featured |
If the answers use different units, convert them with our pricing models guide. For sensor-based products, run the PRTG sensor estimate before accepting a tier.
8. Support and vendor
- Support hours and channels; response time targets per severity
- Named contact or partner in our region
- Documentation quality and public knowledge base
- Release frequency and upgrade process (in place, downtime required?)
- Exit terms: data export format when the contract ends
Common mistakes with RFP checklists
- Copying a 300-line template. Vendors answer “Yes” to everything on long lists. Twenty sharp questions beat three hundred vague ones.
- Skipping the context block. Without counts, quotes are not comparable.
- Leaving out the do-it-yourself option. Score Zabbix or LibreNMS against the same list, with staff hours as the cost, so the paid options have to beat a real baseline.
Shortlist candidates
Products we have reviewed against these criteria include PRTG, SolarWinds NPM, ManageEngine OpManager, Auvik, NinjaOne and Checkmk. Browse them by size in small business, enterprise and cloud-managed monitoring, and see our methodology for how we score them.