CIOPages
All RFP packages

RFP Package · Foundational IT & Infrastructure

Cloud Infrastructure & IaaS RFP questions and template

123 questions, 10 demo scenarios and a five-vendor scorecard for choosing Cloud Infrastructure & IaaS software, in one Excel workbook.

What this package is for

Use it to run a Cloud Infrastructure & IaaS software selection, from the first long list to the final scorecard.

What the category covers. Questions for choosing an infrastructure-as-a-service provider: compute, accelerators, containers, networks, data transfer charges, storage, managed databases, identity and keys, sovereignty, landing zones, cost management and migration. Each asks how the provider does the job, with deep-dive tests on the buyer's own workloads and data.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 25 questions screen out products that lack something you need.
  • RFP, to the shortlist. 64 questions ask how each product does the work.
  • Deep dive, to the finalists. 34 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. List the general-purpose, compute-optimized, memory-optimized, storage-optimized and ARM-based instance families you make generally available in each of [regions].

Why it matters. A family that exists in the vendor's catalog but not in the buyer's required regions forces a different region, a different instance shape, or a delayed migration. That changes cost, latency and residency assumptions made during planning.

Good answer
  • A region-by-region matrix that names each family and its current generation
  • Generally available families are marked separately from preview or limited-availability families
  • Availability is stated at zone level where a family is not offered in every zone of a region
Red flags
  • A global catalog list with no per-region breakdown
  • Preview or waitlist-only families are presented as available
  • No ARM-based family is offered in one or more of the buyer's regions, and the gap is not stated

2. List the GPU and provider-built accelerator instance types you make generally available in each of [regions].

Why it matters. If the accelerator types the buyer needs are not offered in the regions where the buyer's data must stay, the buyer's training or inference has to run elsewhere. That adds data-transfer cost and can conflict with the buyer's residency rules.

3. Which Kubernetes minor versions of your managed Kubernetes service are currently listed as conformant in the CNCF Certified Kubernetes Software Conformance program?

Why it matters. If the service is not certified for the versions the buyer runs, manifests, operators and tools built for upstream Kubernetes may behave differently or fail. The buyer then has no independent evidence of API compatibility.

Capability areas

Compute Instances, Placement & Scaling (11)

Virtual machine families (general, compute, memory, storage, ARM-based), bare metal and dedicated hosts, confidential computing instances, placement controls, spot or preemptible capacity, and auto-scaling on custom metrics. GPU and custom accelerators are covered in ACC, and containers and serverless are covered in CTR.

AI Accelerators & GPU Capacity (10)

GPU and provider-built accelerator availability by region, capacity reservations, queue and priority mechanisms for scarce silicon, cluster interconnect for distributed training, and inference serving options. Model governance and AI safety are out of scope and are covered by the AI modules.

Managed Kubernetes, Containers & Serverless (10)

Managed Kubernetes control plane, node management and upgrade behavior, conformance with upstream Kubernetes, container registries, and serverless function and container runtimes with their scaling and cold-start behavior. Underlying VM families are covered in CMP.

Regions, Zones & Network Architecture (12)

Region and availability-zone footprint, per-region service availability, virtual network design, private subnets, routing, load balancing, DNS, DDoS and edge protection, and dedicated private connectivity to our sites and other clouds. Transfer pricing is covered in EGR.

Data Transfer & Egress Economics (9)

How internet egress, inter-region, inter-zone, private-connectivity, and NAT or gateway data processing are metered and priced, any free allowances, and how we can see and attribute transfer charges by flow. General price lists and discount negotiation are covered by the commercial module. Cost reporting tools in general are covered in FIN.

Object, Block & File Storage (11)

Object, block, and file storage with durability design, performance tiers, lifecycle tiering, versioning and immutability, snapshots, and cross-region replication. Managed databases are covered in DBS, and the vendor's own BC/DR posture is covered by the business-continuity module.

Managed Databases & Data Services (10)

Managed relational, NoSQL, and in-memory databases, engine-version compatibility with open-source or commercial engines, high availability and point-in-time recovery, and integration with data-lake and warehouse services. Portability of these services off the platform is covered in MIG.

Identity, Access & Key Management Controls (10)

The customer-facing identity and policy model, organization-level guardrails, privileged access, customer-managed and externally held keys, HSM options, and audit logging of control-plane and data-plane actions. The vendor's internal security program and certifications are covered by the security and compliance modules.

Sovereignty, Residency & Jurisdiction (10)

Sovereign regions or separately operated legal entities, controls that pin data and metadata to a jurisdiction, operator personnel location and access approval, handling of foreign government access requests, national qualifications, and the provider's stack run in our own facilities or disconnected. DPA terms and sub-processor lists are covered by the data-protection module; key custody is covered in IAM.

Landing Zone, Infrastructure as Code & Operations (10)

Landing-zone tooling, Infrastructure-as-Code coverage and drift detection, policy-as-code enforcement, quota and limit management, observability (metrics, logs, traces), and planned-maintenance notification. Generic API and SSO availability are out of scope.

FinOps, Cost Visibility & Commitment Management (11)

Native cost and usage data granularity, tagging and cost-allocation enforcement, budgets and anomaly detection, forecasting, rightsizing recommendations, and tracking of reservation or committed-use utilization and coverage. Discount levels, payment terms, and contract structure are covered by the commercial module.

Workload Migration & Portability (9)

Inbound migration tooling for VMs, databases, and bulk data (online and offline transfer), migration assessment support, and the technical path and effort to move a workload and its managed-service dependencies to another provider. Contract exit terms and end-of-contract deletion are covered by the migration-exit module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Landing zone from code blocks a noncompliant resource
  2. Multi-tier application survives losing one zone
  3. Reserved GPUs train a model then serve it
  4. Tracing data-transfer charges back to their flows
  5. Sovereign workload with keys held outside the platform
  6. Moving an on-premises VM and database with rollback
  7. Upgrading a live cluster then scaling a function
  8. Tag enforcement, team cost allocation and spend alerts
  9. Recovering data after a simulated mass deletion
  10. Exit drill to a second provider

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Cloud Infrastructure & IaaS RFP questions are there?

123 solution questions in 12 capability areas: 25 for the RFI, 64 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Cloud Infrastructure & IaaS

For the business side of the same change: