You need one document: a short, structured Request for Proposal that spells out your goals, demands WCAG 2.2 AA accessibility and data protection by design, and provides every agency with the same brief to price against. Get that right and you turn a confusing agency search into a confident hire. This guide gives you copyable RFP sections, a UK compliance checklist and a simple scoring method you can use the same afternoon.
TL;DR:
- Short, structured RFPs should clearly define scope, objectives, and technical requirements, including WCAG 2.2 AA compliance and data protection measures from the start.
- Including a detailed timeline, budget range, and specific acceptance criteria helps prevent scope creep and ensures all agencies cost the project accurately.
- Using a weighted scoring rubric across proposal aspects like approach, experience, and price ensures objective comparison between agencies.
- For simple sites, a two- to four-page brief is sufficient, but complex projects require detailed technical and acceptance criteria to prevent budget overruns.
- Limiting proposals to three agencies and conducting interviews after scoring promotes a manageable and fair selection process.
Table of Contents
- RFP template: section-by-section content you can copy into a brief
- Setting scope and budget: brief length and detail by likely project size
- Technical, accessibility and data protection checklist to include in every UK RFP
- How to compare proposals quickly with a weighted scoring rubric
- Practical timeline and next steps after issuing an RFP
- Kukoo Creative perspective: common mistakes and what a good brief unlocks
- Get a bespoke RFP drafted or reviewed before you send it
- Official UK guidance and Kukoo resources to consult next
- Sources
- FAQ
RFP template: section-by-section content you can copy into a brief
A good RFP follows a consistent shape so every agency prices the same job. Practical UK templates for website briefs tend to share the same nine core sections, and that structure works whether you’re a sole trader or a growing team.
Start with a summary and project purpose: two short paragraphs explaining why you’re doing this, what “done” looks like, and what outcome you expect from the new site. Follow with company background and audiences: what you sell, who buys it, and any competitors or comparable sites you admire (skip the ones you don’t).
Set out objectives and success metrics next, mixing commercial goals (enquiries, sales, bookings) with behavioural ones (time on page, form completions). Then define scope and deliverables:
- Pages and templates you need, including any that repeat (product pages, location pages).
- CMS preference or openness to agency recommendation.
- Third-party integrations: CRM, booking systems, payment gateways.
- Who owns content creation, photography and copywriting.
Include a rough sitemap with content ownership noted against each page, so nobody assumes you’re writing the copy for forty product pages. Add a timeline with milestones, and build in time for accessibility testing and user testing rather than treating them as an afterthought squeezed before launch.
For budget, state your pricing model preference: fixed price, phased payments, or time and materials, and ask agencies to itemise optional extras separately rather than bundling them into one number. Finally, tell agencies what a proposal must include:
- Their proposed approach and process.
- Relevant team experience and case studies.
- A full cost breakdown with assumptions stated.
- Any risks or dependencies they’ve spotted in your brief.
Kukoo Creative’s own RFP examples and templates follow this same structure and are worth a look if you want a starting document rather than a blank page.
Setting scope and budget: brief length and detail by likely project size
Brief length should match project size, not ambition. A brief for a straightforward brochure site can run to two or four pages: summary, scope, budget range and a deadline. Agencies typically judge how much detail a brief needs by the size of the job, and shorter briefs work fine for smaller projects where the scope is simple and fixed.
Mid-range and complex projects need more. If you’re specifying a CRM integration, a booking API or performance targets such as page load speed, write those out as separate requirements rather than folding them into a general description. Vague technical requirements are where budgets creep.
- For simple sites, a two to four page brief covering summary, scope, budget and deadline is usually enough.
- For mid-range projects, add integrations, CMS features and performance targets as their own numbered requirements.
- For complex builds, include acceptance criteria for every integration so there’s no dispute at handover.
Giving a budget range or a worst-case ceiling, rather than a single fixed figure, tends to produce more honest proposals: agencies can tell you what’s achievable at the top and bottom of your range instead of guessing what you want to hear. Kukoo Creative’s 2026 UK budget bands are a useful reference point when you’re deciding which band your project sits in.
Pro Tip: If you’re unsure which band you’re in, describe your must-have features only and ask agencies to quote a “must-have” price and a “nice-to-have” price separately.
Technical, accessibility and data protection checklist to include in every UK RFP
Accessibility and data protection aren’t optional extras to negotiate later. Bake them into the RFP so every proposal prices them from the start.
- Require WCAG 2.2 level AA as a stated non-functional requirement, not a hoped-for nice-to-have.
- Ask for an accessibility testing plan that combines automated scanning with manual testing, plus a written report.
- Require a published accessibility statement and a schedule for remediation and annual review.
- Require data protection by design from the outset, with a clear cookie and consent approach.
- Ask for evidence: past accessibility audits, a security checklist, hosting and backup arrangements, and a Data Protection Impact Assessment if the project handles sensitive data.
- Define acceptance criteria for handover: source code, credentials, documentation and a training session for your team.
GOV.UK’s accessibility guidance requires public-sector services to meet WCAG 2.2 level AA and to publish and regularly update an accessibility statement, and recommends combining automated and manual testing with periodic audits. Your business may not be a public body, but treating that same standard as your baseline protects you from complaints and keeps your site usable for the widest possible audience, a point we’ve written about in more detail in our piece on why accessibility matters for UK business success.
On data protection, ICO guidance requires organisations to build in data protection by design and by default, and cookie consent must be freely given and based on a clear, positive action, following ICO guidance on cookies and PECR. Non-essential cookies must never be set before that consent is given. Our guide to cookie banner design walks through what a compliant banner actually looks like in practice.
How to compare proposals quickly with a weighted scoring rubric

Scoring proposals against a fixed rubric stops “gut feel” from deciding a decision that affects your business for years. A simple weighted model works well for most SME projects:
Score each agency out of ten on each row, multiply by the weight, and total the results. That single number makes shortlisting far less subjective than comparing five differently formatted PDFs.
Before scoring, normalise for scope differences. If one agency has quoted for fewer pages or skipped an integration, ask them to reprice against your exact brief rather than marking them down for a misunderstanding.
- Ask each shortlisted agency to price a minimum viable option, plus recommended and optional extras, separately.
- Check two or three references or completed projects that resemble your own.
- Use the interview stage to probe how they handle scope changes and who owns project risk.
The Design Council’s buyer guidance recommends inviting no more than three agencies to pitch, which keeps the process manageable and respects everyone’s time. Paid creative pitches are reasonable to request for larger projects, but for most SME briefs a written proposal plus a follow-up call gives you enough to decide.
Practical timeline and next steps after issuing an RFP
A predictable calendar keeps the process fair and stops it dragging on for months.
- Issue the RFP and give agencies at least two weeks to respond.
- Run a single shared Q&A document with one deadline for questions, so every agency sees the same answers.
- Score proposals against your rubric within a week of the deadline.
- Interview your top two or three agencies before making a decision.
- Confirm scope, change control and IP assignment in writing before signing anything.
Before kick-off, make sure you have a single point of contact, agreed content ownership, analytics access sorted, and clear sign-off roles on your side. Missing any of these is the most common reason projects stall in week one.
Kukoo Creative perspective: common mistakes and what a good brief unlocks
The briefs that go wrong share the same faults: fuzzy objectives, no accessibility requirement, no acceptance criteria, and a budget nobody has sanity-checked against the scope. Reviews of many briefs show a consistent pattern: the clearer the objectives, the fewer change requests appear halfway through a build.
Some processes pair design and development under one roof, so a brief reviewed at the start rarely needs reworking once build begins. Our RFP examples and budget guidance show what that clarity looks like on paper.
A brief that states its acceptance criteria upfront saves everyone from arguing about what “finished” means in week twelve.
— Kukoo
Get a bespoke RFP drafted or reviewed before you send it
If drafting a watertight RFP feels like one more job on an already full plate, some agencies can review your draft or write a bespoke one for your project, drawing on experience with UK business owners who have been through this process.

| What you get | Where to look |
|---|---|
| Brand and visual identity services for a refresh alongside your new site | Visual Identity, logo and polish services |
| Full web design and development, UX/UI, CRM builds and integrations | Services |
| Ongoing maintenance plans (Fix, Steady, Secure, Scale) once the site is live | Maintenance and support plans |
Pro Tip: Having a second pair of eyes review your draft RFP before circulating it can catch missing acceptance criteria more cheaply than change orders later.
Whether you need brand assets, a full build, or just a second opinion on your brief, get in touch through the Kukoo Creative services page to talk through your project.
Official UK guidance and Kukoo resources to consult next
For accessibility statements, see GOV.UK’s guidance. For cookies and consent, see ICO’s PECR guidance. For briefing practice, see the Design Council’s guide, and for accessibility’s link to search performance, this overview of accessibility and SEO is a useful read.
Sources
- Gov
- Data protection by design and by default – ICO
- Design Buyers’ Guide – Design Council
- Website brief template – Digital Culture Network
FAQ
What should a UK web design RFP include as a minimum?
At minimum, include a project summary, company background, objectives, scope and deliverables, a sitemap outline, timeline, budget indication and your selection criteria. This structure mirrors the nine core sections used in practical UK website brief templates and keeps proposals comparable.
Do I have to require WCAG 2.2 AA even as a small business?
You’re not legally required to meet WCAG 2.2 AA unless you’re a public sector body, but GOV.UK’s own guidance treats it as the practical baseline for accessible websites. Requiring it in your RFP protects a wider range of customers and avoids retrofitting accessibility fixes after launch.
How many agencies should I invite to pitch?
Design procurement guidance from the Design Council recommends inviting no more than three agencies to keep the process manageable for both sides. More than that tends to slow decision-making without improving your choice.
What data protection requirements must my RFP mention?
Your RFP should require data protection by design and by default, and a cookie consent approach that meets ICO PECR guidance, meaning non-essential cookies are never set before consent is given. Ask agencies how they’ll implement this technically, not just whether they’re aware of it.
How do I fairly compare proposals with different prices?
Score every proposal against the same weighted rubric covering approach, compliance, technical fit, experience and price, rather than comparing headline totals. Ask agencies to reprice against your exact brief where scope differs, so you’re comparing like with like before making a decision.