
Security Vendor Prequalification Form for India (2026): Vetting Bidders Before You Invite Them
A ready-to-adapt prequalification questionnaire that vets a security vendor, installer or guarding agency on capability and compliance before the tender, so only firms that can actually deliver are invited to bid on price.
Before you ever discuss price, you should already know which security firms are worth talking to. A security vendor prequalification form is the short, structured questionnaire that every interested installer, systems integrator or guarding agency fills in before the tender goes out. It filters bidders on the things price cannot fix: whether they are a real, registered business, whether they have done work like yours, whether they hold the licences the law requires, and whether they can be trusted with your footage and your premises. Only the firms that clear it are invited to bid.
This is the form companion to the security vendor and installer evaluation guide, which explains how to judge a vendor. This page gives you the actual document to send out: what it asks, a filled worked example, and a blank template you can copy. It sits in the professional security resources library alongside the security tender template it feeds into.
Scope & how to read this. This is a ready-to-adapt professional template, not authoritative, legal or contractual wording. Set your own criteria and pass mark to suit your project, and get professional or legal review before you rely on any prequalification outcome to exclude a bidder. Licence requirements, thresholds and statutory duties come from your project, the applicable law and the relevant authority — verify them; this template does not set them.
What it is and where it sits
Prequalification is the gate between "anyone interested" and "the shortlist we send the tender to". It sits in the procurement stage, before the tender or request for proposal and well before award. The logic is simple: it is wasteful and risky to compare detailed priced bids from firms that turn out to be unregistered, uninsured, unlicensed, or that have never handled a project of your size. Prequalification screens all of that out first, on capability and compliance, so the priced competition that follows is between firms you would actually be willing to appoint.
Who produces it, who receives it:
- You (the client, PMC, consultant or facility manager) issue it as a form to complete, with a clear closing date and the objective criteria you will apply.
- Each interested vendor completes and returns it, attaching evidence — registration, licences, references, insurance.
- You score it against a pass mark set before you issued it, and invite only those who pass to bid.
A crucial rule: prequalification is about capability and compliance, not price. No rates, no quotes, no discounts belong on this form. Price is decided later, among qualified firms only. Mixing price into prequalification quietly lets a cheap-but-incapable vendor back into the room — exactly the outcome the gate exists to prevent.
The sections the form should capture
A good prequalification form is short enough that a capable firm can complete it honestly in an afternoon, and structured enough that you can score it fairly. Group the questions into clear sections, ask for evidence against each claim, and keep them focused on capability and compliance.
Company details and registration. Legal name, registered address, type of entity and year of incorporation, GST registration number, and the contact person for the bid. This confirms you are dealing with a real, traceable business.
Years in business and relevant experience. How long the firm has operated, and — more important — evidence of similar projects: comparable scope, comparable premises, comparable systems. Ask for a short list of reference projects with a contactable client, not a wall of logos.
Technical capacity. In-house team size and roles, relevant certifications held by the firm and its engineers, and any manufacturer or OEM partnerships and authorisations. An authorised partner can usually get support, spares and firmware that a grey-market reseller cannot.
Financial standing. A general, proportionate check that the firm can carry the work: a turnover band (a range, not a demand for full accounts at this stage) and a simple solvency declaration. Keep it fair — ask only for what a project of your size genuinely needs.
Statutory compliance. Labour-law compliance (registration, provident fund and employee insurance where applicable), and — for any firm that will supply guards — a valid licence under the private security agencies law. Guarding in India is a licensed activity; see private security agency regulation for what that licence means and how to check it. Ask for the licence number and a copy, and verify it.
Quality and safety. Any quality-management or safety systems the firm runs, its safety record, and how it manages work at height and electrical work. On premises, security work often touches both.
Cybersecurity and data-protection posture. Modern security systems record identifiable people, so a vendor's data hygiene is now a selection criterion, not an afterthought. Ask how they handle credentials, remote access, and any personal data or footage they touch — the vendor cybersecurity assessment sets out what good looks like. Because footage and access logs are personal data under the Digital Personal Data Protection (DPDP) Act, 2023, a vendor who will process it on your behalf should be able to describe how they protect it and agree to a data-processing arrangement.
After-sales, AMC capability and local support. Whether the firm offers an annual maintenance contract, its typical response time, spares availability, and — critically — whether it has a genuine local presence or subcontracts support to someone you never met.
Litigation and blacklisting declaration. A signed declaration on whether the firm is currently blacklisted by any government body or public-sector client, or has material litigation that would affect delivery. A truthful "yes, and here is the context" is often fine; a concealed one discovered later is grounds to disqualify.
Worked example prequalification form
The table below shows how a completed form reads, so you can see the shape and how scoring works. It is illustrative only.
Example only — adapt to your project. The weights, the pass mark and any band values below are generic placeholders to show the mechanism. Do not treat them as required standards. Set your own criteria and pass mark, before you issue the form, to suit your project.
| # | Criterion | What the form asks | Example response | Evidence attached | Weight | Assessed |
|---|---|---|---|---|---|---|
| 1 | Registration | GST number, incorporation year, entity type | Registered firm, GST provided, operating since (year) | GST certificate, incorporation doc | 10 | Pass |
| 2 | Relevant experience | Similar projects, contactable references | Lists comparable premises; two references given | Reference letters | 20 | Strong |
| 3 | Technical capacity | Team, certifications, OEM authorisations | In-house team; authorised partner for the proposed OEM | Authorisation letter, CVs | 20 | Strong |
| 4 | Financial standing | Turnover band, solvency declaration | Turnover band adequate for scope; solvent | Self-declaration | 10 | Pass |
| 5 | Statutory (PSARA, labour) | Guarding licence, labour compliance | Valid guarding licence; labour compliance confirmed | Licence copy, declaration | 15 | Pass (verify) |
| 6 | Cyber and data protection | Access, credentials, DPDP posture | Describes access controls; agrees to a data arrangement | Policy summary | 10 | Adequate |
| 7 | After-sales and local support | AMC, response time, local team | Offers AMC; local team; states response window | AMC sample | 10 | Adequate |
| 8 | Litigation / blacklisting | Signed declaration | Declares none; signed | Signed declaration | 5 | Pass |
Pass note (example only). In this illustration the firm clears every mandatory compliance item (registration, guarding licence, declaration) and scores well on capability, so it would be invited to tender — subject to verifying the licence and references before the invitation is confirmed. A firm that fails any mandatory compliance item is excluded regardless of its capability score. Set your own pass rule; do not copy these numbers as a standard.
Blank copy-ready template
Copy this into your own sheet, set your weights and pass mark first, and issue it. Add or remove rows to match your project.
| # | Criterion | What we ask the vendor to provide | Vendor response | Evidence attached | Weight | Assessment |
|---|---|---|---|---|---|---|
| 1 | Company and registration | Legal name, address, entity type, year, GST no. | ... | ... | ... | ... |
| 2 | Years in business | Years operating; ownership stability | ... | ... | ... | ... |
| 3 | Relevant experience | Similar projects; contactable references | ... | ... | ... | ... |
| 4 | Technical capacity | Team, certifications, OEM authorisations | ... | ... | ... | ... |
| 5 | Financial standing | Turnover band; solvency declaration | ... | ... | ... | ... |
| 6 | Statutory compliance | Labour compliance; guarding licence (if applicable) | ... | ... | ... | ... |
| 7 | Quality and safety | Quality/safety systems; work-at-height and electrical | ... | ... | ... | ... |
| 8 | Cyber and data protection | Access control, credentials, DPDP handling | ... | ... | ... | ... |
| 9 | After-sales / AMC / support | AMC offered; response time; local presence; spares | ... | ... | ... | ... |
| 10 | Litigation / blacklisting | Signed declaration; context if any | ... | ... | ... | ... |
| — | Total / pass | Weighted score against pre-set pass mark | ... | — | ... | Pass / Fail |
Data-processing note. Where the vendor will handle footage, access logs or other personal data on your behalf, ask them to confirm — at prequalification — that they will sign a data-processing agreement. Under the DPDP Act, 2023 you remain accountable for personal data handled on your behalf, so due diligence on a vendor's data posture belongs on this form.
Field guide: how to use and adapt it
The form only works if the process around it is disciplined. A few rules make it fair, defensible and genuinely useful.
- Set objective criteria and a pass mark before you issue it. Decide what "capable and compliant enough" means, and write the weights and the pass rule down first. Marking to a number you invented after seeing the responses is neither fair nor defensible.
- Verify claims, references and licences — do not just collect them. Call a reference or two. Check the guarding licence with the issuing authority. Confirm an OEM authorisation with the OEM. A form that is filed unread verifies nothing.
- Weight capability and compliance, and keep price out entirely. Make mandatory compliance items (registration, licence, declaration) pass/fail gates, and score the rest. Price belongs in the tender that follows, among qualified firms only.
- Do proper data-protection due diligence. Treat the cyber and data-protection section as a real criterion, not a tick box — you will hand this vendor access to systems that record people.
- Keep it fair, proportionate and documented. Ask only for what the project needs, apply the same criteria to every bidder, and keep the completed forms and your scoring so you can show why each firm passed or failed.
Common mistakes to avoid
| Mistake | Why it hurts | Do instead |
|---|---|---|
| No verification | Anyone can claim experience or a licence | Check references, licences and authorisations against source |
| Price creeps in | A cheap, incapable firm slips through the gate | Keep all pricing out; decide price later, among qualified firms |
| Unclear or moving pass mark | Decisions look arbitrary and are hard to defend | Fix weights and pass rule before issuing; apply consistently |
| Compliance treated as optional | Unlicensed or non-compliant vendors reach the shortlist | Make registration, licence and declaration pass/fail gates |
| Over-asking | Small capable firms opt out; you lose good bidders | Keep it proportionate to the project size |
How it connects to the tender, the DPA and the evaluation
Prequalification is the first document in a short chain, and each hands off cleanly to the next:
- Into the tender. Only firms that pass this form receive the security tender template. You have already confirmed they are registered, licensed, capable and compliant, so the tender can focus on scope, specification and price.
- Into the data-processing arrangement. The data-protection answers here feed the data-processing agreement you sign with the appointed vendor, guided by the vendor cybersecurity assessment.
- Into evaluation. When priced bids come back, you judge them with the vendor and installer evaluation guide — now confident every bidder already cleared the capability-and-compliance bar. Prequalification does not replace evaluation; it makes evaluation a contest between firms all worth appointing.
Used this way, the prequalification form quietly does the most valuable job in the whole procurement: it makes sure the cheapest bid you eventually accept comes from a firm that can actually deliver it safely and lawfully.
Key takeaways
- A security vendor prequalification form filters bidders on capability and compliance before the tender — never on price.
- Capture registration, experience, technical capacity, financial standing, statutory compliance (labour and, for guarding, the private-security licence), quality and safety, cyber and data protection, after-sales support, and a litigation and blacklisting declaration.
- Set objective criteria and a pass mark before issuing, and verify every claim, reference and licence against source.
- Treat data-protection posture as a real criterion; footage and access logs are personal data under the DPDP Act, 2023.
- Pass only capable, compliant firms into the tender and the evaluation that follow.
References
- Digital Personal Data Protection Act, 2023 — footage and access logs identifying people are personal data; a vendor processing them on your behalf should agree to a data-processing arrangement, and you remain accountable.
- Private security agencies regulation — guarding is a licensed activity in India; see private security agency regulation and verify any licence with the issuing authority.
- Your own procurement policy and any applicable public-procurement rules — the authoritative source for how you may set criteria, exclude bidders and document decisions; follow them over any generic template.
This is an educational template to adapt, not legal or contractual advice. Get professional or legal review before you rely on a prequalification outcome to exclude a bidder, and defer licence and statutory specifics to the applicable law and authority.
Export this guide
Related Guides — Deep-dive reading
Security Specification Template for India (2026): Defining What Good Looks Like
A ready-to-adapt technical specification template for security systems: the document that sits beside the BOQ in your tender and tells every bidder the required standard, performance and quality, so they quote the right thing and the installer builds to a known bar.
SecuritySTP Tender Preparation Guide: How to Write a Scope That Gets Comparable Bids
A practical guide to preparing an STP tender for Indian projects — how to define scope, fix the capacity and quality specification, set fair evaluation criteria, and structure the bid so the quotes you get back are genuinely comparable instead of a pile of apples and oranges.
Sewage Treatment PlantsSecurity Tender Template for India (2026): Inviting Bids Fairly
A ready-to-adapt security tender or invitation-to-bid template: what a tender package contains section by section, how it wraps the specification and BOQ, how to set evaluation criteria before bids open, and a blank structure you can copy for your own project.
SecurityRelated Tools — Try Free
Security Vendor Evaluation Scorecard
Rate a CCTV/security installer or guarding agency across eight weighted criteria for a hire / negotiate / walk-away verdict.
Vendor ScorecardContract Studio
AI generates professional architecture service agreements with milestones and scope.
ArchitectAIInterior Contract Template — India
Legally-refined contract template with payment milestones, timeline, warranty, and jurisdiction fields.
Contract Generator