CIOPages
All RFP packages

RFP Package · Industry Solutions

IoT Platform & Edge Computing RFP questions and template

129 questions, 10 demo scenarios and a five-vendor scorecard for choosing IoT Platform & Edge Computing software, in one Excel workbook.

What this package is for

Use it to run a IoT Platform & Edge Computing software selection, from the first long list to the final scorecard.

What the category covers. Software that connects, secures, updates and manages fleets of devices and gateways, ingests their telemetry, and connects industrial equipment and cellular assets to enterprise systems. Bought by IT, OT and product engineering leaders who run connected products or plant and field equipment at scale.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 27 questions screen out products that lack something you need.
  • RFP, to the shortlist. 67 questions ask how each product does the work.
  • Deep dive, to the finalists. 35 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 110 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Can a device from our production line connect to your platform for the first time and end up registered, credentialed and assigned to the correct tenant with no per-device manual step in the console or a script?

Why it matters. If each device needs a manual step, registering [device count] devices becomes a labor cost and a source of errors. Fleets that work as a pilot then stall at production volume.

Good answer
  • Describes the flow from first power-on to registered state and separates what is loaded at manufacturing from what the platform creates
  • No console action, script run or support request is needed per device
  • Shows the flow live with a device or simulator that has never connected before
Red flags
  • The 'zero-touch' flow requires uploading each device's key or certificate one at a time
  • Onboarding depends on vendor professional services for each production batch
  • The answer describes only bulk file import and not first-connection registration

2. Which update types can your platform deliver to devices: full firmware images, operating system or component packages, application binaries, configuration files, or individual configuration parameters?

Why it matters. If configuration changes require a full firmware release, every parameter change carries the risk and data cost of a firmware update. Any update type the platform cannot deliver needs a second tool and a second process.

3. Does your platform keep a twin for each device that stores the desired state set from the cloud separately from the state the device reports?

Why it matters. Without that separation, operators cannot tell whether a configuration change has taken effect on a device. Changes made while devices are offline can also be lost.

Capability areas

Device Provisioning & Onboarding (11)

Zero-touch and bulk provisioning, factory-to-cloud identity bootstrap, device registry creation, and claiming or transferring devices between tenants. Ongoing credential rotation and revocation sit in Device & Fleet Security.

Over-the-Air Firmware & Configuration Updates (13)

Firmware, software and configuration updates pushed to devices: signing, delta updates, staged and canary rollout, failure detection, automatic rollback, and update reporting. Deployment of containerized edge workloads sits in Edge Workload Orchestration.

Fleet Operations & Device Twin (11)

Day-to-day management of a live fleet: device shadow or twin, grouping and tagging, remote commands, health and connectivity monitoring, bulk operations, and demonstrated operation at production device counts. Provisioning and updates are covered in their own areas.

Device Messaging & IoT Protocols (10)

Device-to-cloud messaging over MQTT, HTTP, LwM2M and AMQP: broker behavior, QoS and retained messages, message ordering and deduplication, throttling, and payload handling. Industrial protocols and cellular network management are covered separately.

OT & Industrial Integration (12)

Connection to brownfield industrial equipment: OPC UA, Modbus, MQTT Sparkplug, PLC and historian connectors, industrial asset models, and gateway options for legacy controllers. General enterprise API integration is covered by the integration module.

Cellular & LPWAN Connectivity Management (9)

Management of the network layer for field assets: SIM and eSIM lifecycle, LTE-M, NB-IoT, 5G and LPWAN support, carrier switching, data-usage monitoring, and connectivity diagnostics. Commercial terms for data plans are covered by the commercial module.

Edge Runtime & Local Processing (12)

The software that runs on gateways and devices: hardware and OS support, footprint from gateway-class to constrained devices, local stream processing and rules, store-and-forward through disconnection, and autonomous operation when offline. Remote deployment and lifecycle of edge workloads sits in Edge Workload Orchestration.

Edge Workload Orchestration & ML Inference (9)

Remote deployment, versioning, configuration and rollback of workloads and ML models on edge nodes, plus monitoring of edge workload health and inference results. Model training and governance are out of scope and covered by the AI modules.

Device & Fleet Security (13)

Security of devices and their connection to the platform: per-device identity, mutual TLS, secure element and hardware root-of-trust support, certificate rotation and revocation, per-device authorization policies, device behavior anomaly detection, and quarantine. Corporate security posture and attestations are covered by the security and compliance modules.

Telemetry Ingestion, Rules & Time-Series Data (11)

Handling of device data after arrival: ingestion pipeline, schema and payload decoding, rules engine and alerting, time-series storage and query, downsampling, and routing of device data to downstream stores. Dashboards and applications are covered in Application Enablement.

Application Enablement & Analytics (8)

Building operator-facing value on device data: low-code app and dashboard builders, prebuilt vertical applications, asset-centric analytics, and triggering actions in field-service or maintenance workflows. AI governance and safety are covered by the AI modules.

Device Portability & Fleet Migration (10)

The device-side mechanics of leaving or changing platforms: re-pointing devices to another endpoint, credential portability, dependence on proprietary device SDKs or agents, and export of registry, twin and historical telemetry in documented formats. Contractual exit terms and general data export are covered by the migration-exit module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Zero-touch onboarding of factory-fresh devices
  2. Canary firmware rollout with forced rollback
  3. Fleet at peak load and mass reconnection
  4. Gateway outage with local buffering and backfill
  5. Brownfield line connection over OPC UA and Modbus
  6. Edge ML model rollout and rollback
  7. Compromised-device detection and quarantine
  8. Cellular data spike and carrier switch
  9. Exit drill to a broker we run
  10. Threshold breach to work order

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many IoT Platform & Edge Computing RFP questions are there?

129 solution questions in 12 capability areas: 27 for the RFI, 67 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 110 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
IoT Platform & Edge Computing

For the business side of the same change: