CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

Endpoint Detection & Response (EDR/XDR) RFP questions and template

128 questions, 10 demo scenarios and a five-vendor scorecard for choosing Endpoint Detection & Response (EDR/XDR) software, in one Excel workbook.

What this package is for

Use it to run a Endpoint Detection & Response (EDR/XDR) software selection, from the first long list to the final scorecard.

What the category covers. Software that records what happens on every endpoint, detects attacks from that telemetry and contains them, extended across identity, email, cloud-workload and network signals. Bought by CISOs and SOC leaders replacing antivirus or an incumbent EDR, consolidating security operations, or adding a managed detection and response service.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 23 questions screen out products that lack something you need.
  • RFP, to the shortlist. 67 questions ask how each product does the work.
  • Deep dive, to the finalists. 38 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide a matrix showing which prevention capabilities your agent enforces on each operating system and version in [OS versions in scope].

Why it matters. Prevention features often differ by operating system. A product that blocks on Windows but only alerts on macOS or Linux leaves those hosts without protection unless the buyer knows to compensate.

Good answer
  • Rows list each prevention capability (pre-execution, behavioral, script, exploit, ransomware, device control) and columns list each OS version and architecture, including ARM
  • The matrix marks capabilities that run in detect-only mode on a given OS
  • The matrix states OS dependencies, such as required kernel modules or system extensions
Red flags
  • A single 'supported' mark per OS with no breakdown by capability
  • Detect-only behavior on macOS or Linux is not disclosed
  • Legacy OS versions in scope are missing from the matrix

2. Provide a mapping of your shipped detection content to MITRE ATT&CK techniques and sub-techniques, broken out by operating system.

Why it matters. Without a technique-level mapping per operating system, the buyer cannot compare coverage against its threat model. Gaps on macOS or Linux stay hidden until an incident.

3. List each exclusion and suppression type your product supports, such as by file path, hash, code signer or command line. For each type, state whether it stops prevention, alerting, telemetry collection, or a combination.

Why it matters. If the buyer cannot tell what an exclusion turns off, an exclusion meant to silence one noisy alert can also stop blocking or stop recording activity on that host. That leaves a blind spot nobody intended.

Capability areas

Prevention & Protection (12)

Pre-execution and behavioral blocking of malware, exploits, scripts and ransomware, prevention policy modes, offline protection, and device control for removable media. Excludes detection-only analytics and post-incident remediation.

Detection Coverage & Content (12)

Behavioral detection of fileless, living-off-the-land and credential-theft techniques, ATT&CK technique mapping, custom detection authoring, and threat-intelligence enrichment of alerts. Excludes false-positive tuning workflow and cross-domain correlation.

False-Positive Management & Tuning (10)

Exclusion and suppression mechanics, scoping of exceptions, tuning workflow against the buyer's own business software, exception review and audit, and controls that keep policies from drifting into audit-only mode. Excludes detection authoring.

Investigation & Threat Hunting (12)

Real-time fleet-wide endpoint search, raw-telemetry retention and query language, process-tree and attack-timeline views, IOC and behavioral hunting, and live forensic collection. Excludes response actions and AI-assisted triage.

Response & Remediation (12)

Host isolation, process and file actions, remote shell, ransomware and malicious-change rollback, remediation without reimaging, and policy-driven automated response with scoped authority. Excludes managed-service response by vendor analysts.

Cross-Domain Correlation & Telemetry Breadth (11)

Ingestion and correlation of identity, email, cloud-workload and network telemetry with endpoint signals, incident grouping, attack-chain reconstruction, identity threat detection, and first-party versus third-party connector depth. Excludes container runtime protection itself.

Agent Footprint, Coverage & Integrity (12)

Agent CPU, memory and I/O overhead on laptops, servers and VDI, OS and architecture coverage including ARM and legacy versions, single-agent versus multi-module design, running alongside an incumbent security agent without conflicts, and tamper protection. Excludes update and rollout controls and the migration project itself (ADM).

Sensor & Content Update Control (10)

Staged, ring-based rollout of sensor versions, detection content and policy changes, buyer control over update timing, halt and rollback mechanics, and agent fail-safe behavior when an update misbehaves. Excludes the vendor's corporate disaster recovery.

Cloud Workload & Container Protection (10)

Runtime protection and telemetry for cloud VMs, containers, Kubernetes nodes and ephemeral workloads, deployment patterns for those workloads, and integration with a separate CWPP. Excludes cloud security posture management.

AI-Assisted Triage & Investigation (9)

AI features that summarize, prioritize, triage and investigate alerts, generate hunting queries, and recommend response, judged by the analyst work they remove on the buyer's data. Excludes generic AI governance, safety and autonomy controls covered by cross-cutting modules.

Managed Detection & Response and SOC Ecosystem Fit (9)

The vendor's own managed detection and response option, response authority granted to vendor analysts, escalation to the buyer, support for third-party MDR providers, and alert and telemetry streaming into SIEM, SOAR and ticketing tools. Excludes generic API and SSO availability.

Fleet Administration & Deployment (9)

Agent deployment and enrollment at scale, policy hierarchy and inheritance, role-based scoping of response actions, multi-site or multi-tenant management, sensor health and coverage-gap reporting, and moving policies, exclusions and groups over from an incumbent product. Excludes the vendor implementation services.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Ransomware detonation, containment and rollback
  2. Living off the land and credential dumping
  3. Phishing to account to endpoint as one incident
  4. Fleet-wide hunt from a threat advisory
  5. Tuning a week of business-software alerts
  6. Staged update rollout with halt and rollback
  7. Isolating and remediating an off-network laptop
  8. Agent overhead on a database server and VDI
  9. Container escape in a Kubernetes cluster
  10. Overnight alert handled by managed analysts

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Endpoint Detection & Response (EDR/XDR) RFP questions are there?

128 solution questions in 12 capability areas: 23 for the RFI, 67 for the RFP and 38 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Endpoint Detection & Response (EDR/XDR)

For the business side of the same change: