1. Vendor background
- 1.1
Background, ownership, scale of MAU served.
- 1.2
3-5 reference customers in our model (B2C / B2B / hybrid).
A copy-into-Word RFP scaffold for selecting a CIAM platform (Auth0, Microsoft External ID, Ping, Akamai, WorkOS). Focuses on developer experience + B2B + ATO defense.
Who uses it
Product engineering / platform leadership at consumer or B2B SaaS companies.
Typical timeline
4-8 weeks RFP → shortlist → POC → award
21 questions across 8 sections. CC BY 4.0 — copy freely.
Background, ownership, scale of MAU served.
3-5 reference customers in our model (B2C / B2B / hybrid).
Supported authentication factors — password, passkey, social, OTP, SMS, biometric.
Passkey rollout maturity — registration UX, fallback flows, multi-device.
Account recovery flows — what mitigations against social engineering?
How is multi-tenant identity modeled (Organizations, realms, separate tenants)?
How are tenant-specific configurations isolated (branding, MFA policy, identity providers)?
Describe the customer-IdP federation experience (their Okta / Entra signing in to your platform).
SCIM 2.0 server conformance. Tested against which IdPs?
Custom-attribute handling. Push vs pull. Latency profile.
List SDKs (JavaScript, React Native, iOS, Android, server-side languages).
Describe custom logic extension points — Auth0 Actions, Rules, API connectors.
Describe local development workflow.
Describe credential-stuffing mitigation — rate limits, CAPTCHA escalation, bot mitigation.
Describe risk-based authentication signals.
Describe leaked-credential detection (HIBP-style screening).
Describe branding / customization options — colors, copy, fully custom UI vs hosted login.
Custom domain support.
MAU pricing tiers. Free tier + cap.
What features are per-tier vs per-MAU adders?
How do prices change at 100K, 1M, 10M MAU?
| Criterion | Weight | How to score |
|---|---|---|
| Passkey / phishing-resistant depth | 15% | WebAuthn implementation maturity + UX. |
| Multi-tenancy (if B2B) | 20% | Organizations model + per-tenant federation. |
| Developer experience | 15% | SDK quality + extension points + docs. |
| ATO defense | 15% | Bot mitigation + risk-based + leaked-credential screening. |
| TCO at projected MAU | 15% | Year 1, 2, 3 cost at projected user growth. |
| Compliance posture | 10% | SOC 2 + (if applicable) HIPAA, GDPR, PCI DSS. |
| Reference customer signal | 10% | 3-5 references. |
Vendor-neutral procurement assistance — from RFP to shortlist to bake-off to negotiation. We’ve seen every vendor pitch + every contract structure.