CIOPages
All RFP packages

RFP Package · Industry Solutions

Enterprise Blockchain & Web3 RFP questions and template

125 questions, 10 demo scenarios and a five-vendor scorecard for choosing Enterprise Blockchain & Web3 software, in one Excel workbook.

What this package is for

Use it to run a Enterprise Blockchain & Web3 software selection, from the first long list to the final scorecard.

What the category covers. Questions for enterprise distributed-ledger and tokenization platforms: the on-ledger data boundary, transaction privacy and selective disclosure, consensus and finality, token lifecycle and atomic settlement, smart contracts, participant identity, keys and custody, network governance, interoperability and node operations. Bought by technology, digital-asset and operations leaders choosing a ledger platform or deciding whether to join a network.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 26 questions screen out products that lack something you need.
  • RFP, to the shortlist. 62 questions ask how each product does the work.
  • Deep dive, to the finalists. 37 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Does the product natively support storing a transaction payload off-ledger while recording only a reference and cryptographic hash of that payload on the shared ledger?

Why it matters. Without a built-in off-ledger pattern, every byte of business data is replicated to every node that holds the ledger. The buyer must then either expose data to participants who should not hold it or fund custom code to split it out.

Good answer
  • The off-ledger payload pattern is a documented product feature, not a custom integration.
  • The hash algorithm and reference format are specified in the documentation.
  • The documentation lists the supported off-chain storage targets.
Red flags
  • Off-ledger storage is described as something the buyer's developers would build.
  • The only supported option is writing the full payload to the ledger.
  • The vendor cannot name the hash algorithm or reference format used.

2. What is the default visibility of a transaction in your product: broadcast to all nodes, shared with a defined subset of participants, or sent only to the parties named in it?

Why it matters. If the default is broadcast and confidentiality must be configured per workflow, one missed configuration exposes a transaction to every participant on the network.

3. Does your product support a read-only participant role for a regulator or auditor that can receive and validate transactions within a defined scope but cannot sign, submit or approve transactions?

Why it matters. If a regulator or auditor can only be added as a full participant, it may gain the ability to sign or approve transactions. The alternative is to export data off-ledger, where it can no longer be checked against the ledger.

Capability areas

Use-Case Fit & On-Ledger Data Boundary (9)

How the product supports deciding which records go on the shared ledger versus off-chain, off-chain storage and hashing patterns, data-residency placement of ledger data, and handling of erasure obligations against immutable records. Excludes the vendor's general DPA and privacy program, which the data-protection module covers.

Transaction Privacy & Confidentiality Model (12)

Default visibility of a transaction (broadcast, need-to-know, point-to-point), channels, private data collections, sub-transaction privacy, and confidentiality of counterparties and amounts while staying provable. Excludes disclosure to third parties such as auditors, which is covered under SEL.

Selective Disclosure & Regulator/Auditor Access (9)

How one party's view, or a single transaction, is disclosed to an auditor, regulator or supervisor without exposing other participants, including zero-knowledge or proof-based disclosure and observer-node roles. Excludes general reporting dashboards.

Consensus, Finality & Performance (12)

Consensus mechanism, whether finality is deterministic or probabilistic, latency to settlement, throughput under a realistic transaction mix and contract complexity, fee or gas predictability, and behavior when validators or participants fail. Excludes node hosting and monitoring, which are covered under OPS.

Tokenization & Asset Lifecycle (13)

Token models and standards, issuance, transfer, redemption, corporate actions, fractionalization, and regulated-asset controls such as allow-lists, transfer restrictions, freeze and forced transfer. Excludes the cash leg and settlement mechanics, which are covered under SET.

Atomic Settlement & Cash Leg (10)

Atomic delivery-versus-payment and payment-versus-payment, supported cash-leg instruments (stablecoin, tokenized deposit, wholesale CBDC, off-ledger payment rails), and handling of partial, failed or timed-out settlement. Excludes asset issuance and lifecycle events.

Smart Contract Development, Audit & Upgrade (11)

Contract languages and tooling, testing and simulation, formal verification or static analysis support, support for independent audit, and multi-party governance of contract and protocol upgrades. Excludes the vendor's own secure SDLC, which the security module covers.

Participant Identity, Permissioning & Compliance Controls (10)

How participants and their users are identified and certified, role and permission models on the ledger, KYC/AML hooks, sanctions screening, and the ability to restrict or suspend a participant. Excludes workforce SSO into the vendor's admin console, which the integration module covers.

Key Management & Custody (9)

Generation, storage and use of signing keys, HSM and external custody integration, multi-signature and threshold signing, key rotation, and key-loss or key-compromise recovery for participants and assets. Excludes the vendor's internal encryption-at-rest practices.

Network Governance & Consortium Durability (10)

Who governs the protocol and the network, how members join, leave or are removed, voting and change-control mechanisms, production counterparties already transacting on the network, and developer-ecosystem depth. Excludes the vendor's corporate financials, which the vendor-profile module covers.

Cross-Ledger Interoperability & System-of-Record Integration (11)

Bridges, cross-chain messaging and atomic swaps to other ledgers, oracle and off-chain data feeds, and event streams that post ledger state into core systems such as ERP, treasury and custody. Excludes generic REST APIs and SDKs, which the integration module covers.

Node Operations & Network Resilience (9)

Node deployment and lifecycle, ledger-specific monitoring and alerting, state backup and resynchronization, recovery of a failed or rejoining node, and ledger growth and pruning. Excludes the vendor's corporate BCP and support SLAs.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Counterparty node fails during a settlement
  2. Disputed trade corrected without rewriting history
  3. Auditor sees one participant's transactions only
  4. Tokenized fund units from issuance to redemption
  5. New member admitted, scoped, then suspended
  6. Live contract upgrade approved by several participants
  7. Erasure request for personal data linked on-ledger
  8. Compromised signing key revoked and replaced
  9. Sanctions hit freezes a holder's tokens
  10. Asset moved to another ledger and posted to ERP

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Enterprise Blockchain & Web3 RFP questions are there?

125 solution questions in 12 capability areas: 26 for the RFI, 62 for the RFP and 37 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Enterprise Blockchain & Web3

For the business side of the same change: