Request for Proposal (RFP)

A procurement document issued to invite qualified vendors to submit detailed plans, approaches, and pricing for delivering specified goods or services. In some industries, the term may be used with a more narrowly defined meaning.

Key Points

  • Used when the buyer seeks vendor solutions and approaches, not just a price quote.
  • Typically includes scope or requirements, evaluation criteria, and submission instructions.
  • Proposals are assessed against predefined, often weighted, technical and cost criteria.
  • Differs from an RFQ or IFB, which are used when requirements are well defined and price is the primary factor.

Example

A company planning a new customer support platform issues an RFP detailing business requirements and desired outcomes. Vendors submit proposals describing their technical solution, implementation plan, team qualifications, schedule, and pricing. The buyer scores each proposal using published criteria and shortlists the top two for negotiations.

PMP Example Question

Which document should a project manager issue to obtain detailed solution approaches and pricing from potential sellers when the scope allows for multiple technical options?

  1. Request for Quotation (RFQ)
  2. Request for Proposal (RFP)
  3. Purchase Order (PO)
  4. Change Request

Correct Answer: B — Request for Proposal (RFP)

Explanation: An RFP solicits comprehensive proposals, including technical approach and cost, whereas an RFQ focuses mainly on pricing for well-defined specifications.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course