CIOPages
All RFP packages

RFP Package · Enterprise Applications

Enterprise E-Commerce Platforms RFP questions and template

130 questions, 10 demo scenarios and a five-vendor scorecard for choosing Enterprise E-Commerce Platforms software, in one Excel workbook.

What this package is for

Use it to run a Enterprise E-Commerce Platforms software selection, from the first long list to the final scorecard.

What the category covers. Software that runs online selling end to end or as APIs behind a front end the buyer builds: storefront, catalog and search, pricing and promotions, cart, checkout and payments, orders and inventory, customer accounts, B2B buying, channels and markets, and back-office integration. Bought by digital commerce, ecommerce and IT leaders replacing a commerce platform or moving to headless commerce.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 26 questions screen out products that lack something you need.
  • RFP, to the shortlist. 67 questions ask how each product does the work.
  • Deep dive, to the finalists. 37 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 80 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide a coverage matrix that lists, for each commerce function (catalog, pricing, inventory, cart, checkout, orders, customers, promotions), the public API operations that perform it, the events emitted when its data changes, and whether your merchant admin uses those same public operations.

Why it matters. Functions missing from the public API force the buyer to work through the admin or write custom code, and a front end the buyer builds cannot offer anything the API does not support. Resources with no change events force integrations to poll, which adds load and delay.

Good answer
  • Each function maps to named API operations with links to the public reference documentation
  • Gaps are marked explicitly, with a stated workaround or a planned date
  • Change events are listed per resource, covering create, update and delete
Red flags
  • A statement that everything is available through the API, with no matrix
  • Functions such as promotions, returns or inventory adjustments are absent from the matrix without explanation
  • The admin column is left blank or answered only with a general statement

2. Describe each storefront option you provide, such as a hosted storefront with prebuilt themes or starter code for a front end we build ourselves, including the page types each one covers.

Why it matters. If the vendor provides neither a theme nor starter code for a page type such as account or checkout, the buyer must design and build that page. That adds cost and time to the launch.

3. Describe your product model, including how product types define typed attributes, the attribute data types available and how the attributes that create variants are chosen.

Why it matters. If attributes are untyped text or fixed across all products, product data from the buyer's PIM loses its structure. Filters and comparisons then break, and variants need custom code.

Capability areas

Headless architecture, commerce APIs and extensibility (13)

Commerce API coverage across catalog, pricing, cart, checkout, orders and customers, and whether the merchant admin uses the same public APIs; headless and incremental decomposition; event and webhook delivery behavior; idempotency; API credentials scoped to commerce resources and actions, with rotation and revocation; custom fields, custom objects and extension points; configuration as code; sandbox parity; API versioning, rate limits and upgrade path without forking core. Generic API availability, SDK lists and SSO/SCIM are out (integration module).

Storefront, content and SEO (11)

Themes and templates, headless storefront starter kits, visual page builder and reusable sections, theme code editing with version history, content pages and blog, preview and scheduled publishing, responsive rendering, Core Web Vitals and image delivery, and SEO controls: metadata, sitemaps, automatic redirects, social sharing tags and URL stability across upgrades. Accessibility conformance documents (VPAT/ACR) are out (accessibility module).

Catalog, search and merchandising (12)

Product model with typed attributes, variants, bundles, kits, configurable and digital products (with download limits and link lifetime), media per product and variant, stock status on product pages, bulk import with failed-row reporting, multiple catalogs and assortments, staged catalog publishing, category pages from assignments and tags, storefront search relevance with typo tolerance, synonyms and autocomplete, facets, pin and boost, rule-based collections, related and recommended products, and ratings and reviews. Price calculation is out (PRC).

Pricing and promotions (10)

Price lists by store, currency and customer group, effective dates, tiered and bundle pricing, business-user price rules, price feeds from external pricing systems, the promotion engine, bulk single-use coupons, stacking and application order, and per-line discount allocation used for display and refunds. Contract pricing for B2B accounts is out (B2B).

Cart, checkout and payments (14)

Cart recalculation and persistence, guest cart merge, unavailable-item handling, add to cart from list and search pages, save for later, cart shipping estimates and gift options; guest and account checkout, configurable checkout steps and fields, address validation; multiple payment providers and routing, changing provider without changing the front end's checkout calls, hosted fields and tokenization, payment-page script control, wallets, buy now pay later and local methods, EMV 3-D Secure, partial capture and refund, gift cards, tax calculation and fraud screening holds. The vendor's PCI DSS attestation is out (compliance-certifications module).

Orders, inventory and fulfillment (13)

Order search, export (CSV and PDF documents), editing, holds, notes, staff-created orders, splits and status history; returns, exchanges and refunds; inventory per SKU per location, reservation and release, oversell prevention, backorders and preorders; buy online pick up or return in store; shipping zones, live rates and labels; shopper order tracking; transactional messages; and subscriptions. External OMS and WMS connectivity is out (INT).

Customer accounts and engagement (8)

Shopper registration and sign-in including social sign-in and passkeys, password reset and policy, saved addresses and payment tokens, wish lists, reorder and buy-again lists, price-drop and back-in-stock alerts, segmentation that drives prices and assortments, triggered emails, consent capture applied to tracking and email, shopper data export and deletion inside the commerce record, and credential-stuffing defenses. The vendor's DPA and sub-processor terms are out (data-protection-privacy module).

B2B buying (11)

Company accounts and hierarchies, buyer roles and spending limits, approval routing, quote-to-order, purchase-order numbers, payment on account, company-specific catalogs and contract prices, quick order and CSV upload to cart, buyer sign-in through the customer company's identity provider, and punchout with cXML or OCI. Consumer account features are out (CUS).

Multi-store, international and channels (10)

Several stores and brands from one account with shared or separate products and customers, custom domains, per-locale content and URLs with fallback, local currency display and charging, address formats, cross-border duties and restricted products, marketplace listing and order import, third-party seller marketplace model, social channels, point-of-sale connection, store finder, and channel recorded on each order. Admin UI language support is out (i18n-localization).

Back-office integration, data migration and ecosystem (11)

Prebuilt and certified connectors for ERP, OMS, WMS or 3PL, PIM, CMS, CRM, marketing automation, loyalty and reviews, with the maintainer of each stated; ERP-priced catalogs; product feeds; bulk export to a data warehouse; how much multi-vendor integration code the buyer owns and runs in a composable setup; and migration of catalog, customers, passwords and order history from a legacy platform. Data export on contract exit is out (migration-exit module).

Merchant admin, reporting and governance (8)

Business-user admin for catalog, prices, promotions, orders and customers; roles scoped by store and function; audit logs of admin and API changes with old and new values, retention and SIEM streaming; role dashboards, live activity, standard and custom reports; staging and production environments with data copy; app marketplace permissions; and release notes for changes that affect merchants. Generic admin SSO and MFA are out (integration module).

Scale, performance and peak readiness (9)

Peak checkout throughput and storefront load behavior, autoscaling for sale events and any notice required, cart, checkout, catalog and search latency at peak, CDN caching of catalog responses, documented catalog and price-list limits, product and price change propagation time, webhook delivery latency at peak, and load-test evidence. Uptime commitments and RTO/RPO are out (business-continuity-dr module).

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Flash sale on the last units in stock
  2. Company buyer reorders over a spending limit
  3. A merchandiser's day without developer help
  4. Importing our messy catalog file
  5. A mobile app on the same cart and checkout
  6. Split shipment, store return and partial refund
  7. Launching one storefront in a new market
  8. Cutting over from our current platform
  9. A store-scoped price change with an audit trail
  10. Promoting changes and applying a platform update

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Enterprise E-Commerce Platforms RFP questions are there?

130 solution questions in 12 capability areas: 26 for the RFI, 67 for the RFP and 37 deep-dive questions for the finalists. The workbook adds 80 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Enterprise E-Commerce Platforms