Procurement toolkit

Vendor selection templates for Singapore tech buyers.

Scope projects, compare vendors, and demand the right Singapore-specific proof — across private and public-sector buying — before you request quotes.

General information, not legal advice. Rules change — verify against the live agency source (linked throughout) before relying on any figure or date. Facts current as of 2026.

Free Singapore RFQ builder

Build a procurement-ready RFQ.

Choose the project category, tailor the evidence you need, then download the RFQ or share it with up to three category-matching vendors already in your comparison shortlist.

1 Project brief
2 Requirements

Recommended baseline requirements are selected. Choosing a category adds the relevant Singapore licences, certifications, and delivery checks.

3 Send to your shortlist

Your comparison shortlist is stored only in this browser. We resolve and validate every selected company on the server before creating an enquiry.

Add vendors with the Compare button in the company directory, then return here.

We retain the submitted lead for 18 months, then erase the buyer details and RFQ content from the procurement and vendor-inbox records.

The core templates

Project RFQ brief

Clarify outcomes, current stack, constraints, timeline, budget, and the regimes that bind the project.

  • Business outcome: what should change after this project ships?
  • Current environment: systems, vendors, network, users, locations — and flag any personal data (the PDPA applies).
  • Scope boundary: what is in scope, out of scope, and optional.
  • Delivery constraints: deadline, blackout windows, compliance needs (PDPA, sector rules), and your procurement process.
  • Budget range and buying stage — and any grant you plan to use (PSG today, EDGE from 2H 2026): apply before you commit to a purchase.
  • Regulatory context: which regimes bind this project — PDPA always; Cybersecurity Act, MAS TRM, IMDA licensing, or AI governance as relevant.

Vendor scorecard

Compare capability, Singapore fit, proof, commercial clarity, and delivery risk on one sheet.

CriterionWeightWhat to verify
Relevant capability25%Similar Singapore projects, category-specific services, technical depth.
Singapore fit20%Local office, UEN, response coverage, and the relevant IMDA/CSA licence for the service.
Proof and references20%Case studies, reachable references, reviews, and verifiable certifications (ISO 27001, Cyber Essentials/Trust, MTCS).
Commercial clarity15%Pricing model, assumptions, exclusions, renewal terms — with GST (9%) shown separately.
Delivery and support risk20%Governance, SLA, escalation, incident-notification fit with your 3-calendar-day PDPA clock, and a handover/exit plan.

SLA checklist

Pressure-test uptime, support, measurement, exclusions, credits, and exit.

  • Availability target and exactly how it is measured.
  • Support hours, response time, restoration time, and escalation tiers.
  • Maintenance windows, exclusions, and customer responsibilities.
  • Service credits, reporting cadence, and the evidence required to claim credits.
  • Change management, incident postmortems, and incident-notification timelines that fit your 3-calendar-day PDPA breach clock.
  • Termination assistance, data export, and a documented handover.

Security diligence

Ask for PDPA posture, licensing, access control, and audit evidence.

  • PDPA handling: the 11 obligations, a named Data Protection Officer (DPO), and a breach plan that reaches you fast enough for your 3-calendar-day PDPC notification.
  • Licensing: a current CSA licence (via CSRO) for any penetration testing or managed-SOC work — the only two licensable service types.
  • Access control: MFA, privileged-access management, and a joiner-mover-leaver process.
  • Infrastructure security: patching, vulnerability scans, endpoint controls, and tested backups.
  • Certifications as signals, not proof: ISO/IEC 27001, Cyber Essentials, Cyber Trust (2025) — verify them.
  • Subprocessors and data residency: cloud regions, third parties, audit rights, and where personal data goes.

Category-specific diligence

Every category carries its own licences, certifications, and red flags. Jump to the cluster that fits your project.

Telecom & Connectivity

What to demand

  • Local network delivery proof — installed base, coverage, and response times in Singapore.
  • Link and uptime SLA with clear measurement, plus a PSTN-to-SIP or number-portability migration plan where relevant.
  • Spectrum and coverage evidence for any wireless or IoT service, and equipment that meets IMDA registration rules.

Licences & certifications to verify

  • Which IMDA licence covers the service: FBO (owns/operates facilities) vs SBO (resells), and Individual vs Class.
  • IMDA-registered/approved equipment for anything imported or deployed.
  • For a public IoT network in licensed spectrum, the vendor’s FBO or Class-licence position.

Red flags

  • Cannot state which IMDA licence class covers what they sell.
  • Reselling telco lines with no SBO position, or deploying facilities with no FBO position.
  • Coverage or uptime claims with no measurement or evidence.

Cybersecurity & Surveillance

What to demand

  • Clear scope of assessment, remediation support, and a retest after fixes.
  • Incident-response support that fits your own 3-calendar-day PDPA breach clock.
  • For video surveillance, a footage-handling policy (retention, access, deletion).

Licences & certifications to verify

  • A current CSA licence for penetration testing or managed-SOC monitoring (via CSRO) — the only two licensable service types.
  • Cyber Essentials mark, Cyber Trust (2025 / SS 712), or ISO/IEC 27001 as maturity signals.
  • That CCTV/VMS footage is treated as personal data under the PDPA.

Red flags

  • Offers penetration testing or managed SOC without a current CSA licence.
  • Treats surveillance footage as non-personal-data.
  • Certifications claimed but not verifiable.

Regulated & Fintech (MAS)

What to demand

  • A clear fit with the MAS Technology Risk Management (TRM) Guidelines.
  • Material-outsourcing terms: register entry, annual review, audit rights, and MAS supervisory access.
  • Incident-notification SLAs and written data-location/access rights.

Licences & certifications to verify

  • Alignment with MAS TRM and the Outsourcing / proposed Third-Party Risk Management Guidelines (6 Mar 2026).
  • For a payment institution, Payment Services Act duties — notify MAS within 1 hour of a customer-affecting outage, annual penetration testing.
  • ISO/IEC 27001 or MTCS where cloud is involved.

Red flags

  • Will not grant audit rights or MAS supervisory access under a material-outsourcing arrangement.
  • Cannot meet the 1-hour outage-notification expectation for payment services.
  • Assumes outsourcing to a hyperscaler transfers your MAS compliance.

AI, Analytics & Data

What to demand

  • Governance mapped to the Model AI Governance Frameworks, with humans meaningfully accountable.
  • For agents: approval gates, action logging, and human-override-rate monitoring.
  • Data provenance, IP position, and evaluation/testing evidence.

Licences & certifications to verify

  • Alignment with the Model AI Governance Framework — Generative AI (May 2024) and Agentic AI (Jan 2026, rev 20 May 2026).
  • AI Verify / testing evidence (an open-source toolkit, not a certification) and ISO/IEC 42001 where claimed.
  • A PDPA basis for any personal data used in training or inference — where the real liability sits.

Red flags

  • “Fully autonomous, no human oversight” with no controls, logging, or approval gates.
  • Training or fine-tuning on personal data with no PDPA basis.
  • Dismisses the voluntary frameworks as irrelevant — large buyers write them into contracts.

Cloud, SaaS & Data Centre

What to demand

  • Written data residency and a tested data-export / exit plan (no lock-in).
  • Uptime SLA with defined measurement, exclusions, and service credits.
  • A clear shared-responsibility matrix; sustainability evidence for data centres.

Licences & certifications to verify

  • MTCS SS 584 tier — Tier 3 for regulated or high-impact data; ISO/IEC 27001 or SOC 2.
  • For data centres, BCA-IMDA Green Mark for Data Centres (Platinum / GoldPLUS / Gold) and PUE.
  • Who owns which control in the shared-responsibility model.

Red flags

  • No data-export or exit path (vendor lock-in).
  • Vague on data location and access rights.
  • An SLA with no measurement, exclusions, or credits; a data centre with no efficiency evidence.

Digital Marketing, MarTech & CRM

What to demand

  • PDPA-compliant data handling with genuine consent capture and purpose limitation.
  • Do Not Call (DNC) Registry screening before any telemarketing.
  • Unsubscribe and sender-ID handling for bulk email/SMS, and data export on exit.

Licences & certifications to verify

  • How consent is captured, recorded, and honoured under the PDPA.
  • DNC Registry screening and Spam Control Act compliance for email/SMS campaigns.
  • Transfer safeguards where personal data leaves Singapore, and data portability on termination.

Red flags

  • Uses purchased contact lists with no consent basis.
  • No DNC screening, or bulk messaging with no unsubscribe/sender ID.
  • A CRM with no data-export path when you leave.

System Integration, Software & Tech Vendors

What to demand

  • A local delivery track record with comparable, reachable references.
  • Project governance, milestone sign-off, and a documented handover/exit plan.
  • Secure SDLC for custom software, with clear IP ownership and source-code escrow.

Licences & certifications to verify

  • Relevant vendor/partner certifications (Cisco, HPE, Microsoft, AWS, etc.).
  • ISO/IEC 27001, ISO 9001, or ISO/IEC 20000, and secure-development evidence.
  • PDPA-by-design and written IP and escrow terms.

Red flags

  • No comparable Singapore references you can actually call.
  • Unclear IP ownership on a custom build, or no handover/exit plan.
  • “Certified partner” claims that cannot be verified.

Buying as (or for) the public sector — GeBIZ

Selling to Singapore government runs through GeBIZ (run by AGD, under the Ministry of Finance). The mechanics differ from private-sector buying — here is the track.

ModeTypical valueWhat to know
Small Value Purchase (SVP)Up to ~S$6,000Direct purchase; minimal bid effort.
Invitation to Quote (ITQ)~S$6,000–90,000Open quotation on GeBIZ (or a Limited Quotation to selected suppliers). Price-led, but the lowest quote does not automatically win.
Tender Lite~S$90,000–1,000,000Simplified tender conditions; covers ICT goods and services from end April 2026.
Invitation to Tender (ITT)Above ~S$90,000Detailed spec; often two-envelope / price-quality method. Selective tenders pre-qualify via an EOI first.
Period ContractMulti-yearStanding contract for repeated drawdowns.
Request for Information (RFI)Pre-procurementShapes the eventual tender; no award.

From registration to payment

  • Register as a GeBIZ Trading Partner (free) with your UEN and CorpPass.
  • Complete every mandatory declaration (anti-bribery, conflict of interest, debarment) — they are pass/fail gates.
  • Use the agency’s price schedule format exactly, and raise problems during clarifications — silence on the Conditions of Contract counts as acceptance.
  • Never vary the Conditions of Contract in place. Submit a compliant base offer, then put any proposed change in a separate alternative offer — an in-place deviation reads as non-compliance.
  • Mind the mechanics: 35 MB per uploaded file, no amendments or extra information after closing, and late bids are simply not accepted.
  • After award: Letter of Acceptance, then Purchase Order — quote the PO number on everything; any scope change needs a Variation Order.
  • Invoice through InvoiceNow (Peppol), now the default government channel, with Vendors@Gov being phased out; the default payment term is 30 days unless your contract agrees otherwise.
  • Protect your standing: poor delivery or missed SLAs can lead to debarment from future government procurement.

Grants & licensing quick-reference

What to tap and what to verify. Dates and rates move between budget cycles — confirm on the official page before you rely on them.

Scheme / licenceWhat it isWhat to verifyLearn more
PSG — Productivity Solutions Grant Up to 50% of qualifying cost against pre-approved digital solutions (EnterpriseSG). That the solution is on the pre-approved list, and that you apply before committing to purchase. PSG explained
Verify: enterprisesg.gov.sg/psg
EDG — Enterprise Development Grant Co-funding for consultancy and capability projects (EnterpriseSG). Eligibility and project scope before engaging a consultant. IT & digital grants
Verify: enterprisesg.gov.sg
EDGE — unified grant (from 2H 2026) Replaces PSG, EDG and MRA; up to S$100,000/year; extended to non-SMEs. Launch status — PSG/EDG/MRA remain live until EDGE launches in 2H 2026. EDGE grant 2026
Verify: enterprisesg.gov.sg
InvoiceNow (Peppol e-invoicing) Phased GST InvoiceNow mandate — new voluntary GST registrants from 1 Apr 2026, existing businesses 2028–2031; onboarding grant up to S$1,000 (SME) / S$5,000 (larger). Your business’s mandate date (IRAS notifies pre-2026 registrants by mid-2026) and your Peppol Access Point. InvoiceNow & Vendors@Gov
Verify: iras.gov.sg · imda.gov.sg/invoicenow
FBO / SBO telecom licence (IMDA) Required to own/operate telecom facilities (FBO) or resell telecom services (SBO); Individual vs Class. Which licence class the vendor holds for the specific service. FBO vs SBO licences
Verify: imda.gov.sg
CSA cybersecurity service licence (CSRO) Required for penetration testing and managed-SOC monitoring — the only two licensable service types. A current licence for that specific service; from 16 Mar 2026 licensees also hold Cyber Trust certification. CSA licensing
Verify: csa.gov.sg
Certifications to look for MTCS SS 584 (Tier 1–3), ISO/IEC 27001, ISO/IEC 42001 (AI), Cyber Essentials / Cyber Trust (2025). Tier, scope, and validity — treat certifications as signals, not proof. Certifications guide
Verify: csa.gov.sg · singaporestandardseshop.sg

Vendor-question bank

Copy these into your RFQ or a first call. Each group is one click to copy.

Scope & delivery

  • What comparable Singapore projects have you delivered in the last 24 months, with reachable references?
  • Who is on the delivery team, and are they local or offshore?
  • What does your project governance, milestone sign-off, and handover look like?

Singapore fit & licensing

  • What is your UEN, and which IMDA or CSA licence covers this specific service?
  • Can you show the current licence and its validity?
  • Which vendor/partner certifications are relevant here, and can we verify them?

Security & PDPA

  • Who is your Data Protection Officer, and what is your breach-notification process and timeline back to us?
  • For any penetration testing or managed-SOC work, can you show your current CSA licence?
  • Which certifications do you hold (ISO/IEC 27001, Cyber Essentials, Cyber Trust, MTCS), and what is their scope and validity?

Data location & exit

  • Where is our data stored and processed, and who can access it?
  • What is the data-export format and handover process if we terminate?
  • Which subprocessors do you use, and where are they?

Commercial & SLA

  • What is the pricing model, what is excluded, and how is GST handled?
  • What are the SLA targets, exactly how are they measured, and what service credits apply?
  • What happens to price on renewal or in a multi-year term?

Copy-paste contract clauses

These are template clauses to start a conversation, not legal advice. Adapt them to your contract with qualified legal advice.

PDPA data-processing

The Vendor shall process Personal Data only on the Customer’s documented instructions and solely to provide the Services, maintain reasonable security arrangements, and assist the Customer with access and correction requests. The Vendor shall notify the Customer without undue delay, and in any case within [24] hours of becoming aware of a data breach, providing enough detail for the Customer to meet its 3-calendar-day PDPC notification obligation.

Audit rights & supervisory access

On reasonable notice, the Customer (and, where the Customer is regulated, its auditors and the Monetary Authority of Singapore) may audit the Vendor’s controls, records, and premises relevant to the Services. For any material outsourcing, the Vendor shall support annual reviews and preserve regulatory supervisory access for the term and any exit period.

Incident-notification SLA

The Vendor shall notify the Customer of any security incident affecting the Services within [X] hours of detection, with a severity classification, initial impact assessment, and evidence retention. The Vendor shall provide updates at agreed intervals and a written post-incident review within [Y] business days.

Data location & access

The Vendor shall store and process Customer Data only in [approved locations] and shall not relocate or grant access outside those locations without the Customer’s prior written consent. The Customer, its auditors, and its regulators shall retain access to the data and the Vendor for as long as the arrangement and applicable rules require.

Exit & handover

On expiry or termination the Vendor shall, at the Customer’s election, return or securely delete all Customer Data in an agreed machine-readable format, provide transition assistance for up to [X] days, and certify deletion in writing. The Vendor shall not withhold data or handover pending any dispute over fees.

IP ownership & source-code escrow

All deliverables and custom-developed materials shall vest in the Customer on payment. Pre-existing Vendor IP is licensed to the Customer to the extent needed to use the deliverables. For business-critical custom software, the Vendor shall place source code and build instructions in escrow with [escrow agent], released on defined trigger events.

Procurement FAQ

Do I need to check a vendor’s IMDA or CSA licence?

Only for specific services. Telecom services need an IMDA FBO or SBO licence; penetration testing and managed-SOC monitoring need a current CSA licence (via the CSRO). Most other IT services are not licensable, so the absence of a licence is only a red flag for those specific service types.

What must a vendor prove about PDPA compliance?

A named Data Protection Officer, a grasp of the 11 PDPA obligations, and a breach-notification process that gets information to you fast enough to meet your own 3-calendar-day PDPC notification window. Ask before you hand over any personal data.

Which grant can I use for a tech purchase?

Today, the Productivity Solutions Grant (PSG) funds up to 50% of qualifying pre-approved solutions — but you must apply before committing to purchase. From 2H 2026, EDGE consolidates PSG, EDG and MRA into one grant of up to S$100,000/year, extended to non-SMEs.

Do I need to be on InvoiceNow?

Increasingly, yes. The GST InvoiceNow requirement is phasing in: new voluntary GST registrants from 1 April 2026, and existing GST-registered businesses between 2028 and 2031 by turnover band. IRAS will notify pre-2026 registrants of their date. Connect through a Peppol Access Point.

What certifications should I look for?

ISO/IEC 27001, the CSA Cyber Essentials or Cyber Trust (2025) marks, MTCS SS 584 tier for cloud, and ISO/IEC 42001 for AI management. Treat them as maturity signals to verify (scope and validity), not as proof of a good fit.

How is buying from government different?

Public-sector buying runs through GeBIZ, with defined modes (SVP, ITQ, ITT, period contracts), CorpPass registration, pass/fail mandatory declarations, invoicing via Vendors@Gov and InvoiceNow, 30-day payment from a valid invoice, and debarment risk for poor delivery.

Updates without email

Newsletter signup is paused

We are not accepting email addresses while the operator identity, email processor, retention schedule, confirmation process, and unsubscribe lifecycle remain unpublished.