Skip to main content

Help us improve the Digital Marketplace - send your feedback

AKAMAI TECHNOLOGIES LIMITED

Akamai Edge Security & Network Resilience Platform

Subscription infrastructure resilience software delivering authoritative DNS, traffic steering, DDoS protection, and edge-based availability controls to maintain performance and continuity for critical services under attack, incident or peak demand.

Features

  • Authoritative DNS hosting and routing controls
  • DDoS mitigation for network attacks
  • Traffic steering and policy-based routing to healthy origins
  • Global load distribution and resilience configuration
  • Health checks and automated failover workflows
  • Edge-based performance and availability optimisation options
  • Centralised visibility, analytics, and operational reporting
  • Integration with monitoring/incident management processes
  • Configuration options for multi-environment (hybrid/multi-cloud)

Benefits

  • Improves service continuity during incidents and attacks
  • Reduces downtime through automated failover and steering
  • Minimises the impact of DDoS on critical public services
  • Enhances resilience for peak demand and surge events
  • Simplifies routing operations with policy-driven controls
  • Increases performance and user experience consistency
  • Supports multi-cloud and hybrid resilience strategies
  • Improves operational insight and troubleshooting
  • Reduces the risk of single points of failure
  • Strengthens DNS and edge posture as core infrastructure

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at itrask@akamai.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 1 3 3 6 1 3 6 5 4 9 1 3 9 8

Contact

AKAMAI TECHNOLOGIES LIMITED Ian Trask
Telephone: 07976794758
Email: itrask@akamai.com

About the service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Endpoint security
  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Provides subscription infrastructure software only. Does not include hosting of buyer applications or bespoke network engineering; implementation and managed operations can be procured separately under Lot 3. Buyer is responsible for domain governance, change approval, and providing required access to DNS zones, traffic routing, and origin health information. Resilience outcomes depend on correct configuration, tested failover processes, and buyer origin readiness.
System requirements
  • Buyer-controlled DNS zone administration (or delegated access)
  • Ability to implement routing changes and records updates
  • Defined origin endpoints and health check targets
  • Monitoring/alerting destination (optional)
  • Named buyer administrators and change control process
  • Network information required for allowlists/ACLs (if applicable)
  • Log export target (optional)

User support

Email or online ticketing support
Yes
Support response times
Standard Support Initial Response Times
2 hours or less for Severity 1 issues
4 hours or less for Severity 2 issues
2 business days or less for Severity 3 issues
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Via Akamai Control Centre
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
24x7 support and consultancy
Service management and configuration changes
TAM and CSE dependent on service package
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
A fully managed integration of the service which includes a knowledge transfer of the basics can be included. Furthermore, there are formal training courses and available technical documentation. We also provide a community page.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Configuration settings can be exported in XML format
End-of-contract process
Customer access to the service via the portal is stopped and the service ceases to perform. There are no costs associated with contract ending, unless the customer chooses to renew.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
None

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
The Application Security API allows you to access and modify your Security Configurations for App & API Protector. You can create, update, activate, and export versions of a security configuration. You can get selectable hostnames and add them to the selected list to protect your website or API content. You also can add, modify, or delete custom rules and assign policy actions.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Custom rules and other controls

Scaling

Independence of resources
Akamai operates globally in 130+ countries - the network includes 4400+ of Points of Presence (PoPs) and 1200+ interconnected networks, making it one of the world's largest Content Delivery Networks (CDNs)

Analytics

Service usage metrics
Yes
Metrics types
# of Tickets opened
Reason for ticket opening
Ticket SLA times
SLA's met
SLA's exceeded
Reason behind
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Not required
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The Akamai platform has a 100% availability SLA
Users are refunded to credit equal to Customer’s or such domain’s committed monthly service fee for the contracted security
Approach to resilience
Akamai is resilient due to its massive, globally distributed network, diverse connectivity, intelligent traffic routing that bypasses outages, robust security layers (like DDoS), and a focus on proactive, data-driven management, ensuring it can withstand everything from large attacks to connection failures by automatically rerouting traffic and maintaining performance
Outage reporting
Akamai will send notifications via the Portal, Akamai Community, email and/or any other pre-established channels of communication for Service Outages and www.akamaistatus.com

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Customer portal, Akamai Control Center, supports SAML integration. Active Directory can also act as SAML IDP.
Identity and Access Management provides administrators with tools to manage roles and access privileges of individual network users in ​Akamai Control Center​.
From the Akamai Control Center (Web Administration Portal), authorized users will control CDN settings for websites/applications in Akamai, including default cache rules and default redirect rules, just like other settings, such as the security one. Administrators can create multiple user accounts to access Akamai Control Center and the flexibility to set specific roles and privileges for those users (Role-Based Access Control, RBAC).
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Less than 1 month

Security governance

Named board-level person responsible for service security
No
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
InfoSec is chartered by the Akamai Information Security Policy to develop an Information Security Management System. This program and the policies defined within have been approved by the Chief Security Officer.
Akamai's ISMS consists of many different policies and standards covering the breadth of information security, and InfoSec reviews these for effectiveness, suitability, and adequacy regularly and at least annually. These polices are communicated broadly across the company.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Akamai has a comprehensive change management process and designated Quality Assurance teams responsible for carrying out the necessary testing after changes.  All software components and their versions are tracked by our release management system.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Akamai has a comprehensive vulnerability management program that covers identification, tracking, and remediation of vulnerabilities in vendor applications, open-source software, and Akamai’s own development lifecycle.
Akamai is assessed under PCI DSS, SOC 2, FedRAMP, ISO 27001, and HIPAA, and is compliant with their corresponding vulnerability management requirements.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Akamai's detection tools and technologies are monitored and updated by the Network Operations Command Center (NOCC) and internal research teams. Updates to detection tools, threat signatures, and indicators of compromise occur on a weekly or more frequent basis.
Incident management type
Supplier-defined controls
Incident management approach
The Incident Response (IR) team is committed to safeguarding security and efficiently managing security incidents. The team's expertise lies in evaluating situations, mitigating threats, and collaborating with stakeholders to facilitate swift recovery with minimal disruption. Their partnership with the Incident Coordinator Team (ICT), Incident Response and Protection Team (IRAPT), and Legal is essential in crafting a response plan. Reports are to SIRT. For each security incident meeting Incident criteria,the IR Team generates a Security Incident Report (SIR). This document serves as a record of the incident, encompassing aspects such as incident summary, notification details, root cause analysis, and lessons learned.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A time-limited trial may be offered prior to contract award for evaluation purposes. The trial provides restricted functionality, no service levels, and is not intended for production use. Scope and duration are agreed with the buyer and do not constitute a call-off contract.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
9%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
A-Lign Assurance
ISO/IEC 27001 accreditation date
Thursday 20 March 2025
What the ISO/IEC 27001 doesn’t cover
The certification does not cover customer-managed systems, customer-controlled configurations, customer content, or customer end-user environments. It also excludes third-party services, networks, or infrastructure that are not operated or managed by Akamai, except where explicitly included within Akamai’s defined service scope and contractual responsibilities.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
Yes
PCI DSS certification accredited by
Specialized Security Services, Inc.
PCI DSS accreditation date
Monday 30 June 2025
What the PCI DSS doesn’t cover
The certification does not cover Akamai services that are not within the assessed PCI DSS scope, nor does it cover customer-managed applications, customer-controlled configurations, end-user devices, customer networks, or third-party services and infrastructure that are outside Akamai’s operational control, except where explicitly included within contractual scope.
Cyber essentials
Yes
Cyber Essentials Certificate Number
35063cf9-ee5c-41f2-a933-9c86e01cbdd5
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • SOC 2 Type II (independent assurance report)

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Introducing transparency to pay and reward processes
  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Creation of outreach activities to create a pipeline of employees for the future contract delivery
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at itrask@akamai.com. Tell them what format you need. It will help if you say what assistive technology you use.