The SIG and the CAIQ are not competing versions of the same document. The SIG is a broad third-party risk assessment covering your whole business as a vendor, licensed by Shared Assessments and sent to you privately by a buyer. The CAIQ is a narrow, deep cloud security questionnaire published free by the Cloud Security Alliance that you can complete and publish yourself. They overlap at the edges and answer different questions.
This article works through the five differences that actually change what you do — publisher, cost, scope, format, and whether the result is public — then covers which one a given buyer is likely to ask for, whether either can substitute for the other, and what to do if you are starting from nothing and can only produce one this quarter.
The five differences that matter
Who publishes them. The SIG comes from Shared Assessments, a membership organization focused on third-party risk management. The CAIQ comes from the Cloud Security Alliance, an industry body whose corporate membership includes the major cloud providers. Both are credible with buyers; neither is a regulator.
What they cost. This is the sharpest practical difference. The SIG requires agreement to terms plus either Shared Assessments membership or an annual subscription, which means as a vendor you generally answer a file your buyer licensed rather than holding your own copy. The CAIQ is free — no licence fee, no per-seat charge, no membership — and submitting it to the STAR Registry at Level 1 is also free. If you want to prepare in advance without spending money, the CAIQ is the one you can just download.
What they cover. The SIG spans your business as a supplier: governance, resilience, personnel security, physical security, compliance, and much more alongside the technical controls. The CAIQ is cloud-specific across IaaS, PaaS, and SaaS, and goes deep on shared responsibility boundaries, encryption at rest, key management, identity and access management, and tenancy. Those are the questions a SIG asks at lower resolution.
Their shape. The SIG has historically been an Excel workbook driven by a tool called SIG Manager, with scoping by risk domain and control family, and in March 2026 Shared Assessments launched SIG Evolution, a browser-based platform for distributing and scoring assessments. Offline Excel completion is still supported and importable. The CAIQ is a single spreadsheet of yes-or-no questions with a fixed structure — CAIQ v4 holds 261 questions mapped to the 197 control objectives of the Cloud Controls Matrix v4 across 17 domains.
Whether the answers are public. The SIG you complete goes to one buyer. The CAIQ can be published on the CSA STAR Registry where anyone can read it. This is the difference with the largest downstream consequence and the one most vendors underweight.
The publishability point, expanded
A completed SIG is a private document with a single recipient. Its value is consumed by one deal. Do it again next quarter for the next buyer.
A published CAIQ works on buyers you have not met. A security reviewer building a shortlist can check the registry before contacting you, which means your answers do work in the window between being shortlisted and being emailed — precisely the window where a small vendor is most likely to be quietly dropped for lack of visible evidence.
Two caveats keep this honest. STAR Level 1 is a self-assessment that nobody audits, and calling it a certification in front of a reviewer who knows the registry will cost you more credibility than the entry earns. And self-assessments are updated annually, so a visibly stale entry is a worse signal than no entry, because it says your security documentation is something you did once.
STAR Level 2 involves a certification or attestation from an independent auditor. That carries real weight, costs real money, and is a later-stage decision for most small SaaS companies.
Which one a buyer will send you
Rough patterns, with the usual caveat that individual companies vary.
Financial services, insurance, healthcare, and large regulated enterprises lean SIG. These are the industries Shared Assessments was built around, and their third-party risk teams already hold licences and process SIGs at volume.
Cloud-forward technology buyers and security teams assessing infrastructure lean CAIQ, or check the STAR Registry first. If your prospect's security engineer is the one asking, the questions are more likely to be cloud-shaped.
Mid-market buyers without a formal TPRM function send a bespoke spreadsheet that borrows from both, or a vendor portal with its own questions. This is the most common experience for a small SaaS vendor, and it is the case where a reusable answer bank matters more than knowing either standard.
Anything you have answered once maps onto the next format. Our guide to building a reusable answer library covers the mapping work that makes format-agnostic answering possible.
Can one substitute for the other?
Partly, in one direction, and not at all in the other.
A published CAIQ can often satisfy the cloud portion of a broader assessment. If a SIG asks about encryption at rest, key management, and tenancy, pointing at your STAR entry answers those questions with a link and a line, and many buyers accept that. It reduces the SIG rather than replacing it.
A completed SIG does not substitute for a CAIQ. It covers cloud controls at lower resolution than a buyer asking specifically about cloud wants, and it is not published, so it cannot do the pre-contact work that a STAR entry does.
Neither substitutes for an attestation. A SIG produces structured vendor assertions and a STAR Level 1 entry is a self-assessment. A buyer who wants independent verification wants a SOC 2 report, an ISO 27001 certificate, or a STAR Level 2 attestation, and no amount of questionnaire completion produces one. If ISO 27001 is on your roadmap, our guide to ISO 27001 readiness covers what that path involves.
If you can only do one this quarter
Do the CAIQ, for three reasons that have nothing to do with which framework is better.
It is free, so the only cost is time. It is publishable, so the work compounds across every future buyer rather than being consumed by one. And you can start it today without a buyer, a licence, or a deal on the line, which means you are writing your security documentation while calm rather than under a procurement deadline.
The 261 questions also function as a self-audit. Working through them surfaces the controls you assumed existed and the ones nobody owns. Finding those in a spreadsheet on a quiet week costs considerably less than finding them in a call with a prospect's security team.
Then, when a SIG eventually arrives, a meaningful portion of it is already written.
Common mistakes comparing the CAIQ and SIG
Treating them as alternatives. They cover different ground. Most cloud SaaS vendors selling to enterprise eventually deal with both.
Assuming a completed SIG covers the cloud questions. It covers them at lower resolution than a cloud-focused reviewer wants, and it is not public.
Calling a STAR Level 1 entry a certification. It is an unaudited self-assessment. Level 2 involves a third-party auditor. Reviewers know the difference.
Publishing a CAIQ and forgetting it. Self-assessments are updated annually. Stale is worse than absent.
Waiting for a buyer to ask before starting either. The CAIQ costs nothing and can be done in advance. Doing it under deadline is a choice, not a requirement.
FAQ
What is the difference between the CAIQ and the SIG?
The SIG is a broad third-party risk questionnaire from Shared Assessments that covers your business as a vendor and requires a subscription or membership to license. The CAIQ is a free cloud-specific questionnaire from the Cloud Security Alliance, with 261 questions in version 4 mapped to the Cloud Controls Matrix, and it can be published publicly on the CSA STAR Registry.
Do I need both a CAIQ and a SIG?
If you sell cloud software to enterprise buyers, you will probably encounter both eventually. They are complements rather than alternatives: the CAIQ goes deep on cloud controls, and the SIG covers governance, resilience, personnel, and compliance alongside technical questions.
Is the CAIQ easier than the SIG?
Generally yes, for a cloud SaaS vendor. It is shorter, its questions are yes-or-no rather than narrative, its scope matches how your product actually works, and it is free to obtain. It is also fixed rather than scoped by the buyer, so you know what you are getting.
Can I send a buyer my CAIQ instead of completing their SIG?
You can offer it, and it frequently reduces the work by answering the cloud sections with a link. Buyers with a formal third-party risk process will usually still want the broader questionnaire completed, because the SIG asks about areas the CAIQ does not cover.
Closing thought
The useful way to hold these two apart is by what they are for rather than what they contain. The SIG answers "is this company safe to do business with," across everything a supplier relationship touches. The CAIQ answers "is this cloud service built the way it should be," in depth, publicly. A buyer with a mature risk function wants both answers and will get them from wherever is cheapest.
The overlap between them, and between both and every bespoke spreadsheet you will receive, is largely data protection documentation: subprocessors, DPAs, retention, deletion, residency, breach notification. ComplyDog publishes those on a compliance portal at your own domain so they answer once, in public, in whatever format the next questionnaire happens to use. Knowing which framework you are looking at is useful. Not having to rewrite the same twenty answers for each one is more useful.