Akamai Edge Security & Network Resilience Platform
Subscription infrastructure resilience software delivering authoritative DNS, traffic steering, DDoS protection, and edge-based availability controls to maintain performance and continuity for critical services under attack, incident or peak demand.
Features
- Authoritative DNS hosting and routing controls
- DDoS mitigation for network attacks
- Traffic steering and policy-based routing to healthy origins
- Global load distribution and resilience configuration
- Health checks and automated failover workflows
- Edge-based performance and availability optimisation options
- Centralised visibility, analytics, and operational reporting
- Integration with monitoring/incident management processes
- Configuration options for multi-environment (hybrid/multi-cloud)
Benefits
- Improves service continuity during incidents and attacks
- Reduces downtime through automated failover and steering
- Minimises the impact of DDoS on critical public services
- Enhances resilience for peak demand and surge events
- Simplifies routing operations with policy-driven controls
- Increases performance and user experience consistency
- Supports multi-cloud and hybrid resilience strategies
- Improves operational insight and troubleshooting
- Reduces the risk of single points of failure
- Strengthens DNS and edge posture as core infrastructure
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 3 3 6 1 3 6 5 4 9 1 3 9 8
Contact
AKAMAI TECHNOLOGIES LIMITED
Ian Trask
Telephone: 07976794758
Email: itrask@akamai.com
About the service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Endpoint security
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Provides subscription infrastructure software only. Does not include hosting of buyer applications or bespoke network engineering; implementation and managed operations can be procured separately under Lot 3. Buyer is responsible for domain governance, change approval, and providing required access to DNS zones, traffic routing, and origin health information. Resilience outcomes depend on correct configuration, tested failover processes, and buyer origin readiness.
- System requirements
-
- Buyer-controlled DNS zone administration (or delegated access)
- Ability to implement routing changes and records updates
- Defined origin endpoints and health check targets
- Monitoring/alerting destination (optional)
- Named buyer administrators and change control process
- Network information required for allowlists/ACLs (if applicable)
- Log export target (optional)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard Support Initial Response Times
2 hours or less for Severity 1 issues
4 hours or less for Severity 2 issues
2 business days or less for Severity 3 issues - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Via Akamai Control Centre
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
24x7 support and consultancy
Service management and configuration changes
TAM and CSE dependent on service package - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- A fully managed integration of the service which includes a knowledge transfer of the basics can be included. Furthermore, there are formal training courses and available technical documentation. We also provide a community page.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Configuration settings can be exported in XML format
- End-of-contract process
- Customer access to the service via the portal is stopped and the service ceases to perform. There are no costs associated with contract ending, unless the customer chooses to renew.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- None
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The Application Security API allows you to access and modify your Security Configurations for App & API Protector. You can create, update, activate, and export versions of a security configuration. You can get selectable hostnames and add them to the selected list to protect your website or API content. You also can add, modify, or delete custom rules and assign policy actions.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Custom rules and other controls
Scaling
- Independence of resources
- Akamai operates globally in 130+ countries - the network includes 4400+ of Points of Presence (PoPs) and 1200+ interconnected networks, making it one of the world's largest Content Delivery Networks (CDNs)
Analytics
- Service usage metrics
- Yes
- Metrics types
-
# of Tickets opened
Reason for ticket opening
Ticket SLA times
SLA's met
SLA's exceeded
Reason behind - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Not required
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The Akamai platform has a 100% availability SLA
Users are refunded to credit equal to Customer’s or such domain’s committed monthly service fee for the contracted security - Approach to resilience
- Akamai is resilient due to its massive, globally distributed network, diverse connectivity, intelligent traffic routing that bypasses outages, robust security layers (like DDoS), and a focus on proactive, data-driven management, ensuring it can withstand everything from large attacks to connection failures by automatically rerouting traffic and maintaining performance
- Outage reporting
- Akamai will send notifications via the Portal, Akamai Community, email and/or any other pre-established channels of communication for Service Outages and www.akamaistatus.com
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Customer portal, Akamai Control Center, supports SAML integration. Active Directory can also act as SAML IDP.
Identity and Access Management provides administrators with tools to manage roles and access privileges of individual network users in Akamai Control Center.
From the Akamai Control Center (Web Administration Portal), authorized users will control CDN settings for websites/applications in Akamai, including default cache rules and default redirect rules, just like other settings, such as the security one. Administrators can create multiple user accounts to access Akamai Control Center and the flexibility to set specific roles and privileges for those users (Role-Based Access Control, RBAC). - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
InfoSec is chartered by the Akamai Information Security Policy to develop an Information Security Management System. This program and the policies defined within have been approved by the Chief Security Officer.
Akamai's ISMS consists of many different policies and standards covering the breadth of information security, and InfoSec reviews these for effectiveness, suitability, and adequacy regularly and at least annually. These polices are communicated broadly across the company. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Akamai has a comprehensive change management process and designated Quality Assurance teams responsible for carrying out the necessary testing after changes. All software components and their versions are tracked by our release management system.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Akamai has a comprehensive vulnerability management program that covers identification, tracking, and remediation of vulnerabilities in vendor applications, open-source software, and Akamai’s own development lifecycle.
Akamai is assessed under PCI DSS, SOC 2, FedRAMP, ISO 27001, and HIPAA, and is compliant with their corresponding vulnerability management requirements. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Akamai's detection tools and technologies are monitored and updated by the Network Operations Command Center (NOCC) and internal research teams. Updates to detection tools, threat signatures, and indicators of compromise occur on a weekly or more frequent basis.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The Incident Response (IR) team is committed to safeguarding security and efficiently managing security incidents. The team's expertise lies in evaluating situations, mitigating threats, and collaborating with stakeholders to facilitate swift recovery with minimal disruption. Their partnership with the Incident Coordinator Team (ICT), Incident Response and Protection Team (IRAPT), and Legal is essential in crafting a response plan. Reports are to SIRT. For each security incident meeting Incident criteria,the IR Team generates a Security Incident Report (SIR). This document serves as a record of the incident, encompassing aspects such as incident summary, notification details, root cause analysis, and lessons learned.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A time-limited trial may be offered prior to contract award for evaluation purposes. The trial provides restricted functionality, no service levels, and is not intended for production use. Scope and duration are agreed with the buyer and do not constitute a call-off contract.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 9%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- A-Lign Assurance
- ISO/IEC 27001 accreditation date
- Thursday 20 March 2025
- What the ISO/IEC 27001 doesn’t cover
- The certification does not cover customer-managed systems, customer-controlled configurations, customer content, or customer end-user environments. It also excludes third-party services, networks, or infrastructure that are not operated or managed by Akamai, except where explicitly included within Akamai’s defined service scope and contractual responsibilities.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- PCI DSS certification accredited by
- Specialized Security Services, Inc.
- PCI DSS accreditation date
- Monday 30 June 2025
- What the PCI DSS doesn’t cover
- The certification does not cover Akamai services that are not within the assessed PCI DSS scope, nor does it cover customer-managed applications, customer-controlled configurations, end-user devices, customer networks, or third-party services and infrastructure that are outside Akamai’s operational control, except where explicitly included within contractual scope.
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 35063cf9-ee5c-41f2-a933-9c86e01cbdd5
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- SOC 2 Type II (independent assurance report)
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce