13.1 Procurement Process for Security Goods & Services

Key Takeaways

  • A requisition that cites device schedules, license SKUs, and cost accounts, plus budget approval, must precede solicitation
  • Chapter 12 already taught walks, package types, SOW parts, and evaluation ethics; this section places that package in an end-to-end buy
  • Lump sum, time-and-materials, unit price, and maintenance agreements price different risks; a stockroom PO is not a campus construction contract
  • Goods, services, and software licenses receive and invoice differently; a carton is not a programmed VMS
  • Owner-direct, GC-held, and buried electrical-sub paths change who issues the PO, not whether Door 4 still has to be named
Last updated: September 2026

Procurement Process for Security Goods and Services

Independent OpenExamPrep teaching for published PSP Domain 3 Task 2 knowledge is that buying the system is a process with named gates, not a handshake after Domain 2 prints a pretty set. Chapter 12 already taught how to solicit fairly: site visits, requests for information, addenda, package types, statement-of-work parts, and evaluation ethics. This section places that solicitation in the end-to-end procurement process that starts with a requisition and ends when receiving and invoice controls prove the owner paid for what arrived—and not for a crate of cameras that never become a programmed video-management system (VMS).

Exam focus: Requisition and budget approval come before a public advertisement. Contract type and purchase-order (PO) versus master services agreement (MSA) have to match the buy. Goods, services, and software licenses receive differently. Owner-direct, general contractor (GC), and security subcontractor are different payment and coordination paths.

Why the process exists

A complete construction-document (CD) set that nobody requisitions is a library book. A requisition that says “security, as needed” is how a warehouse gets four parking-lot cameras and no strike on Door 4. A PO issued on stockroom terms for a two-million-dollar campus access-control system (ACS) drops bonds, as-builts, and liquidated damages. An invoice paid on shipment alone funds hardware that sits in a box while the pharmacy anteroom still has a leftover mechanical key.

The process is a control chain. Each gate produces an artifact the next gate can audit: a requisition that cites drawings, a budget line that can pay capital and operating cost, a solicitation that Chapter 12 already made fair, an award that 13.2 can defend, a contract that names how extras will be priced, a receiving record that matches serial numbers, and an invoice that cannot clear unless those records agree.

Requisition

A requisition is the internal request to spend. It is not a vendor quote taped to an email. For physical security it should name:

  • The need in project language: Door 4 strike and contact, Camera 12 identification at the badge desk, a named VMS license tier—not “upgrade cameras.”
  • The attachments: issued CDs, door and camera schedules, specification sections, and any Chapter 12 addenda already in the file if this is a re-buy.
  • The cost account and whether the spend is capital, operating, or a split (hardware versus subscription).
  • The requestor and the approver who actually owns the budget (security director, facilities, IT, or a project control account).
  • Quantity logic that matches the schedule. “Forty readers, more or less” is how unit-price chaos starts.

Security requisitions fail in predictable ways. Operations writes “need more cameras” after a theft and skips the residual pairing from Domain 1. IT writes a cart of recorders that ignore lock power. Facilities copies last year’s locksmith PO for a new ACS. The professional move is to requisition the package Domain 2 already froze, or to requisition a defined study if Domain 2 is not done—not to hide a design project inside a goods cart.

Worked warehouse: the Door 4 residual still needs a latched leaf, a monitored contact, and a watched path. The requisition cites the door elevation, the spare-pair note, the capital account for hardware, and the operating account for monitoring. It does not say “dock kit, integrator to decide.”

Budget approval

Budget approval is the gate that turns a wish into authorized money. Independent study for this published task treats three splits as exam-relevant:

  1. Capital versus operating. Panels, cameras, locks, and raceway are usually capital. Software subscriptions, cloud VMS, cellular communicators, and many maintenance agreements are operating. A PO that tries to charge a three-year license to a capital project that closes next month will die in accounting—or worse, will be forced into a prepaid asset that nobody tracks at renewal.
  2. This project versus enterprise standards. Owner IT may already fund a VMS enterprise license. Buying a second brand on a local capital line creates a stranded head-end. Budget approval should see that conflict before solicitation.
  3. Contingency. Existing-condition risk at a live hospital or a dock with unknown conduit fill needs a published contingency, not a silent hope that the low bidder will absorb it.

Approve the total the owner is willing to spend on this buy, including tax, shipping, spare parts, training, and the first-year license. Approving “hardware only” and assuming licenses will appear from another department is how commissioning week produces a recorder with no channels.

If the approved budget cannot buy the CD scope, stop. Value-engineer in design (Chapter 11) or re-scope. Do not solicit a full campus and then award a half campus by silent exception. That is both a Chapter 12 ethics problem and a procurement-process failure.

Solicitation inherits Chapter 12

Solicitation is how the market sees the approved need. Do not re-teach the Chapter 12 ritual here. Use it:

  • 12.1 site visits, RFIs, substitution windows, addenda.
  • 12.2 request for proposal (RFP), request for qualifications (RFQ), invitation for bid (IFB/ITB), sole source.
  • 12.3 statement of work, timelines, cost model, key personnel, documentation.
  • 12.4 published evaluation criteria, technical compliance, contracting ethics.

This section’s job is timing and authority. You solicit after requisition and budget approval, using the documents those gates authorized. You do not advertise an IFB while the capital committee is still arguing, then cancel after six firms spent money walking the risers. You do not start a “quick quote” outside the Chapter 12 package because a salesperson is in the lobby.

If the buy is a box of matching cylinders on an existing spec, the solicitation may be a simple competitive quote under a purchasing policy. If the buy is an integrated ACS and VMS with a live database, you are in Chapter 12’s RFP or IFB world. The process step is the same idea: authorized need, published documents, fair competition or a justified exception.

Evaluation and award

Evaluation scores the offers against the published criteria (12.4) and the diligence in 13.2—interviews, finances, insurance, references, factory certification. This section only names the process fact: evaluation is a recorded step between offer opening and award, not a lunch.

Award is the documented selection: recommendation, required approvals, notice of award, and (where the owner’s rules require it) notice to unsuccessful firms. Award is not “start work Monday” unless a notice to proceed (NTP) or an executed contract says so. Public owners often cannot let a crew mobilize on a handshake. Private owners who skip the writing still have a file problem when the first extra appears.

Award should state what was bought: lump-sum amount, unit-price schedule, not-to-exceed (NTE) on time-and-materials (T&M), license quantities, and the maintenance term if it was in the same package. Ambiguous awards (“we picked Firm B”) produce two different memories of scope.

Contract types you must be able to tell apart

TypeWhat the owner is buyingWhen it fits security workExam trap
Lump sum (stipulated sum)One price for a defined CD and SOW scopeFinished drawings; forty matching readers; a specified dock openingUsing lump sum on a two-page wish list, then living on extras
Time and materialsHours at published rates plus materials, often with an NTEUnknown existing cans, emergency lock failures, small moves-adds-changes (MAC)Open T&M with no NTE and no timesheets
Unit priceA price per defined unit (door, camera, linear foot of fence)Quantities may grow (phased doors) but the unit is stableVague units (“per camera”) that ignore mounting, license, and cable
Maintenance agreementPreventive and corrective service after turnover, with response timesKeep a commissioned system alive; spare parts; firmwareTreating the maintenance agreement as a substitute for a missing install spec

Lump sum puts quantity risk on the contractor if the documents are complete. That is why Chapter 11 and Chapter 12 spent so much ink on CDs and addenda. A lump-sum security bid on schematic bubbles is a change-order machine wearing a fixed-price label.

T&M is honest when the can has not been opened. It is dishonest when the owner uses it to avoid writing a SOW. Require rates, markups, an NTE, daily tickets, and a right to convert to lump sum once the unknown is measured.

Unit price needs a measurement rule: a “door” includes the reader, strike, contact, request-to-exit, and the homerun to a stated distance—or it does not. If Camera 40 needs a pole and a fiber media converter, that is not the same unit as an interior dome on an existing drop.

A maintenance agreement is a different contract purpose. It assumes a baseline system exists (or will exist after acceptance in Chapter 14). Response times, included callouts, excluded consumables, and whether firmware and software upgrades are in scope belong here. Do not bury a campus install inside a “service agreement” to skip bonds. Chapter 16 returns to keeping that agreement honest after turnover.

Purchase order versus master services agreement

A purchase order is a one-time commercial instrument: quantity, price, ship-to, bill-to, and the buyer’s standard terms. It is the right tool for a carton of credentials, a spare power supply, or a small goods buy that the policy allows. It is the wrong sole instrument for a hospital pharmacy ACS if the PO terms never mention performance bonds, as-builts, factory certification, or liquidated damages. Those terms live in a construction or professional-services contract that the PO may reference.

A master services agreement (or master purchasing agreement) sets umbrella legal terms—insurance, indemnity, confidentiality, rate card, dispute forum—and then issues task orders, releases, or child POs for each job. MSAs fit on-call integrators, multi-site MAC programs, and recurring license true-ups. An MSA without a task-order SOW is a hunting license. A task order that says “do security at Building C” is a requisition failure wearing an MSA number.

Exam stems like to swap the labels. A “PO” that attaches the full Division 28 book, bonds, and a schedule is functioning as a construction contract. An “MSA” used to sole-source a two-million-dollar first install without Chapter 12 justification is still a noncompetitive award. Read the function, not the letterhead.

Receiving and invoice controls

Receiving is the physical and digital acceptance of what was ordered. For goods, match the PO line, packing list, and serial numbers. Photograph damage. Quarantine substitutions that skipped the Chapter 12 or-equal window. Security-specific receiving includes credential stock, key blanks, and panels that can store default passwords—those items need a chain of custody, not a pallet in a hallway.

For services, there is no carton. Receiving is a timesheet, a progress photo, a completed door, or a signed training roster. Do not “receive” programming because a camera box arrived.

For software licenses, receiving is an entitlement: license certificates, channel counts, feature flags, named-server locks, and whether the owner holds the account. An integrator who registers the VMS in the dealer portal only has created a hostage, not a delivery.

Invoice controls close the loop. The ordinary construction control is a three-way match: PO (or contract line), receiving or progress evidence, and invoice. Progress billing should track installed and tested work, not merely stored materials in the contractor’s warehouse—unless the contract expressly allows stored-materials payment with insurance and title transfer. Retainage holds a percentage until punch and closeout documents arrive (Chapter 14). Do not pay one hundred percent on a camera shipment while the VMS has no programmer assigned.

Worked clinic: the specified power supply will not fit the existing can. T&M tickets show hours to measure and a material line for a larger listed assembly. Receiving is the new can’s serial and the listing label, not the leftover hours. The invoice dies if the tickets claim “programming complete” while the panel is still in the cardboard.

Goods, services, and software licenses

Keep the three buys distinct on the requisition and the award.

Goods transfer title (or at least possession) in a thing: cameras, readers, locks, wire, racks. Warranty start dates, spare parts, and serial records matter. A goods-only buy does not install or program itself.

Services are labor and judgment: installation, programming, commissioning support, training, as-built drafting, assessment work. You accept services by performance criteria, not by a dock stamp.

Software licenses are rights: camera channels, analytic packs, client seats, maps, health-monitoring, and term versus perpetual plus a software maintenance agreement. License counts must match the camera schedule, not the number of boxes on the pallet. Cloud subscriptions are usually operating cost and need a renewal owner.

A single security project often contains all three. Write three lines. Paying a goods invoice as if it included programming is how the lowest-price installer in 13.2 wins on paper and fails on the VMS.

Owner, general contractor, and security subcontractor

Owner-direct: the owner contracts the Division 28 integrator. Security project management sees the programmer, the factory letters, and the invoice. Coordination with a separate GC for doors, ceilings, and power is a meeting problem: the integrator cannot set a strike if the leaf is not hung.

GC-held: the owner buys a building. Security is a subcontractor (sometimes under electrical). Payment and schedule run through the GC. That can enforce coordination. It can also hide a cheap sub who cannot program the VMS behind a GC bid that looked responsible. The owner’s security professional still has to put factory certification and key-personnel rules in the bid documents the GC will flow down.

Security sub under an electrical sub: two layers of markup and two chances to lose the programmer. Exam stems that bury Division 28 under “low voltage by electrician” are pointing at this risk.

None of these paths erase the procurement process. They change who issues the PO and who the invoice matches. The requisition still has to name Door 4. The budget still has to include licenses. Receiving still has to catch a crate that is not a working system.

The diagram below is the gate sequence. Section 13.2 is the diligence that makes the award gate real. Section 13.3 is the project-management overlay that keeps a 26-week camera from being a surprise the week after award.

Loading diagram...
End-to-end procurement gates for security goods and services
Test Your Knowledge

After Domain 2 issues construction documents, what is the proper start of the procurement process for a security system?

A
B
C
D
Test Your Knowledge

Which statement best matches contract instruments for security buys?

A
B
C
D
Test Your Knowledge

A shipment of cameras arrives and the integrator invoices the full contract. The VMS is unregistered and no programming has occurred. What is the most defensible control?

A
B
C
D