CIOPages
All RFP packages

RFP Package · Foundational IT & Infrastructure

Content Delivery Network (CDN) & Edge Platforms RFP questions and template

124 questions, 10 demo scenarios and a five-vendor scorecard for choosing Content Delivery Network (CDN) & Edge Platforms software, in one Excel workbook.

What this package is for

Use it to run a Content Delivery Network (CDN) & Edge Platforms software selection, from the first long list to the final scorecard.

What the category covers. Questions for buying a CDN and edge platform: caching and purge, delivery and TLS, DDoS, WAF, bot and API protection, edge compute, network reach, media delivery, configuration control, observability and multi-origin or multi-CDN failover. Bought by infrastructure, security and platform engineering leaders choosing the edge that sits in front of their public applications.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 26 questions screen out products that lack something you need.
  • RFP, to the shortlist. 65 questions ask how each product does the work.
  • Deep dive, to the finalists. 33 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. List the purge scopes your product supports, for example single URL, cache tag, URL prefix, hostname or full property.

Why it matters. Without tag or prefix purge, the buyer must list every affected URL when content changes. That slows releases and leaves stale objects in cache that nobody listed.

Good answer
  • Each supported scope is listed with its documented API endpoint and request example
  • Cache tags can be attached through an origin response header
  • Prefix purge behavior for URLs with query strings is defined in the documentation
Red flags
  • Only single-URL purge is available
  • Tag or prefix purge is mentioned, but the plan or tier that includes it is not stated
  • Full-property purge requires a support ticket

2. Which of these client-facing protocols can your edge serve for our hostnames: TLS 1.3, HTTP/2, and HTTP/3 over QUIC?

Why it matters. If the edge cannot negotiate current protocol versions, clients fall back to older handshakes and connection models, which add round trips on every new connection. The buyer may also be unable to meet internal policies that require TLS 1.3.

3. Describe how DDoS mitigation is engaged for traffic to our hostnames, including any step that must happen after an attack begins.

Why it matters. If mitigation must be activated or traffic rerouted to scrubbing after detection, attack traffic reaches the buyer's services during that interval.

Capability areas

Caching, Cache Keys & Purge (13)

Cache-key design and normalization, TTL and header handling, caching of partially personalized content, tiered or mid-tier caching, origin shielding, and purge or invalidation by URL, tag, prefix and at scale. Excludes media-specific segment caching, which sits in MED.

Delivery Performance, Protocols & TLS (11)

TLS termination and certificate lifecycle at the edge, HTTP/2, HTTP/3 and QUIC support, compression, image optimization, connection handling to origin, restricting origin access to the provider's edge (origin authentication or private connectivity), and how delivery latency is measured against the buyer's user geographies. Excludes network footprint and capacity, which sit in NET.

DDoS Protection (9)

Always-on detection and mitigation of network-layer and application-layer DDoS attacks at the edge, mitigation capacity, time to mitigate, and handling of attack traffic in usage and billing records. Excludes WAF rule logic, bot classification and origin access restriction (DLV).

Web Application Firewall (10)

Managed rule sets, custom rules, false-positive tuning, monitor-only and enforce modes, exception handling, rule update cadence, virtual patching for newly disclosed vulnerabilities, and the effect of inspection on latency. Excludes API schema enforcement, which sits in API.

Bot Management (10)

Separating verified good bots from scrapers, credential-stuffing and other automated abuse; detection signals, challenge and mitigation actions, user-friction controls, AI crawler handling, and reporting on bot traffic. Excludes volumetric DDoS.

API Protection, Rate Limiting & mTLS (8)

API discovery and inventory, schema validation, per-client and per-endpoint rate limiting, token and key validation at the edge, and client mTLS. Excludes general WAF signatures and the vendor's own management API.

Edge Compute & Programmability (13)

Runtime model and isolation, cold-start behavior, language support, CPU, memory and request limits, edge key-value and object storage, inference at the edge, local development, testing and CI/CD tooling, debugging of edge code, and portability of edge logic off the platform. Excludes declarative configuration rules, which sit in OPS.

Network Reach, Peering & Capacity (10)

Point-of-presence density and peering near the buyer's users and origins, anycast routing behavior, total egress and attack-absorption capacity, regional and in-country delivery and processing options, and how new or degraded PoPs are disclosed. Excludes traffic steering across providers, which sits in TRF.

Media Streaming & Large-File Delivery (9)

Live and on-demand streaming delivery at scale, segment and manifest caching, origin shielding for media origins, large-file and download delivery, token-authenticated media URLs, and fit with packaging and DRM workflows. Excludes encoding and transcoding services.

Configuration, Automation & Change Control (10)

Coverage of delivery and security configuration by API and infrastructure-as-code tooling, versioned and staged configuration, testing changes before global rollout, rollback, propagation time across the edge, and role-scoped change permissions. Excludes general SSO and identity integration, which sit in the integration module.

Edge Analytics, Logging & Observability (11)

Real-time traffic, cache and security analytics; raw log streaming to SIEM and observability tools; log fields, sampling and delivery latency; alerting on origin errors and attack events; visibility into edge-code execution; and usage reports per property and region in the units the vendor bills. Excludes log retention terms covered by the data-protection module and price terms covered by the commercial module.

Traffic Steering, Failover & Multi-CDN (10)

Origin health checks, origin failover and load balancing, geographic and weighted routing, edge behavior when the origin is unreachable, and support for running alongside a second CDN with configuration parity and health-based steering. Excludes the vendor's own corporate disaster recovery, which sits in the business-continuity module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Replay our traffic with security enabled
  2. Mass purge then a traffic spike
  3. Respond to a disclosed vulnerability
  4. Stop credential stuffing, keep crawlers
  5. Build and debug an edge function
  6. Change configuration as code
  7. Live application-layer DDoS simulation
  8. Fail the primary origin
  9. Deliver live and on-demand media
  10. Onboard and protect an API

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Content Delivery Network (CDN) & Edge Platforms RFP questions are there?

124 solution questions in 12 capability areas: 26 for the RFI, 65 for the RFP and 33 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Content Delivery Network (CDN) & Edge Platforms