CIOPages
All RFP packages

RFP Package · Enterprise Applications

Headless & Composable CMS RFP questions and template

122 questions, 10 demo scenarios and a five-vendor scorecard for choosing Headless & Composable CMS software, in one Excel workbook.

What this package is for

Use it to run a Headless & Composable CMS software selection, from the first long list to the final scorecard.

What the category covers. 122 questions on how a headless CMS models, edits, approves, localizes and delivers structured content, from content types and schema migration to edge caching, assets, personalization and agent access. Most questions ask the vendor to show the behavior on our content in a demo, sandbox or test, with a placeholder wherever the target is ours to set.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 26 questions screen out products that lack something you need.
  • RFP, to the shortlist. 65 questions ask how each product does the work.
  • Deep dive, to the finalists. 31 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 80 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Show an administrator creating a new content type with named fields in your administration interface, without writing code or running a deployment.

Why it matters. If content types can only be defined in code that a developer deploys, every new content need waits in the engineering queue. Content teams then reuse ill-fitting types or add one-off fields.

Good answer
  • A new content type with several named fields is created and saved entirely in the browser interface
  • An author can create an item of the new type immediately after it is saved, with no build or deploy step
  • If the vendor also supports defining types in code, the vendor explains how interface-created and code-defined types are kept in sync
Red flags
  • Content types can only be defined in schema files that a developer commits and deploys
  • The interface creates the type, but a front-end or studio rebuild is needed before authors can use it
  • The demo uses a prebuilt type instead of creating one live

2. Describe how we define content types, fields and validation rules as code kept in our version control system, so that a command-line tool or API applies them to an environment.

Why it matters. If the content model exists only in the administration interface, the buyer cannot review, version or reproduce model changes across environments. Differences between environments then go unnoticed until a front end breaks.

3. In which views can authors add, reorder and remove components on a page: a form view of the item's fields, a visual rendering of our front-end page, or both?

Why it matters. If authors cannot assemble and rearrange page components themselves, routine page changes route back through engineering and the content calendar slows after launch.

Capability areas

Content Modeling & Structure (12)

Content types and fields defined without code, field types, validation at save, references and reusable components, usage tracking, hierarchical taxonomies, page templates and documented model limits. Schema change on existing content and environment promotion are covered in SCH.

Schema Evolution & Environments (9)

Schema-as-code, scripted migrations that change content types on existing items without data loss, separate development, test and production environments, content branching, and promotion of models and configuration between environments. Generic hosting and environment pricing are out.

Authoring & Editorial Experience (13)

Rich text output, drag-and-drop component placement, in-context visual editing and live preview on a headless front end, autosave, concurrent-editing protection, version history, comparison and restore, comments, paste cleanup, document import and pre-publish accessibility checks. Accessibility conformance of the authoring interface itself belongs to the accessibility module.

Workflow, Scheduling & Releases (11)

Configurable approval stages per content type or section, task assignment and notification, scheduled publish and unpublish by time zone, editorial calendar, shareable preview URLs, grouped releases, warnings about unpublished references, archiving, approval records and bulk actions. Infrastructure timing of cache clearing is covered in EDG.

Localization & Translation (9)

Per-locale item versions with fallback, field-level localization, flagging of missing or outdated translations, translation round trips by XLIFF or connector, right-to-left content, per-locale URL paths or domains, and the number of locales per account. Product UI language and vendor support languages belong to the i18n module.

Delivery & Management APIs (12)

Delivery APIs (REST and/or GraphQL) and their query capabilities, the management API and its schema description, webhooks and event payloads, SDKs and support for our front-end frameworks, rate limits, API versioning and bulk import and export. Generic API availability and SSO or SCIM provisioning belong to the integration module.

Edge Delivery, Caching & Multi-Site (9)

Global CDN delivery, cache invalidation on publish and its timing, live or real-time content updates, response time under peak load, traffic spikes, continued delivery when authoring is down, and running several sites or brands from one account with shared content. Uptime commitments belong to cross-cutting modules.

Digital Asset & Media Management (9)

Media library for images, video, audio and documents, on-the-fly renditions with focal points and modern formats, asset metadata and search, bulk upload, replacement in place, license expiry, file size and volume limits, and integration with a dedicated DAM. Enterprise DAM features beyond working media are out.

Composability, Extensions & Personalization (10)

The extension and app framework, custom fields and UI extensions, federation of external data such as PIM, commerce or CRM records without copying them, connectors to analytics and marketing tools, content variants by segment or visitor context, segment preview, consent-aware personalization, A/B testing, and form and social-posting hooks. Generic connector catalogs belong to the integration module.

AI-Assisted Authoring & Agent-Ready Delivery (8)

AI-assisted drafting, transformation and translation inside the editor and how those outputs enter workflow, plus machine-readable delivery of structured content to AI assistants and agents through structured APIs or an agent protocol interface. Model governance, bias, AI safety and agent permission controls belong to the AI cross-cutting modules.

Content Governance, Permissions & Content Operations (11)

Roles and groups with permissions scoped by site, section, content type, locale and action, access-review reporting, content-level audit trail, single-item restore, author search and dashboards, and reports on stale content, ownerless items, review dates and broken or unpublished links. Identity provider sign-in, MFA, session and network controls belong to the integration and security modules.

SEO, URLs & Legacy Content Migration (9)

Page titles, meta and social tags, readable editable URLs, automatic redirects on URL change, redirect volume, XML sitemaps, canonical and noindex settings, schema.org structured data from fields, visitor site search over published content, and phased, scripted migration of content, assets and URLs from our current CMS. Data export on exit belongs to the migration-exit module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. One product family delivered to web, app and email
  2. A marketer builds a landing page alone
  3. Restructure a live content type in stages
  4. Launch a campaign in several locales at once
  5. Update source text and translate the change
  6. AI agent queries content and AI draft gets reviewed
  7. Manage images from upload to license expiry
  8. A regional editor works outside the role's scope
  9. Move one section off the legacy CMS
  10. Personalize a page only where consent allows

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Headless & Composable CMS RFP questions are there?

122 solution questions in 12 capability areas: 26 for the RFI, 65 for the RFP and 31 deep-dive questions for the finalists. The workbook adds 80 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Headless & Composable CMS