Home Blog What is the CAIQ, and when will a buyer ask for it?

Security

What is the CAIQ, and when will a buyer ask for it?

Posted by Kevin Yun|August 11, 2026

The CAIQ is the Consensus Assessments Initiative Questionnaire, a free security questionnaire published by the Cloud Security Alliance that cloud providers complete to document their security controls. The current version, CAIQ v4, contains 261 yes-or-no questions, each mapped to a control in the Cloud Controls Matrix. A buyer asks for it when they want cloud-specific answers, and increasingly they check whether you have already published one before they ask you for anything at all.

This article covers what the CAIQ is and how it relates to the Cloud Controls Matrix, the file-naming trap that causes rejected submissions, what the CSA STAR Registry is and the difference between its two levels, how the CAIQ compares to the SIG and why most cloud vendors end up dealing with both, and the argument for completing one before anyone requests it.

The CAIQ and the Cloud Controls Matrix

The two are easy to confuse and the relationship is simple. The Cloud Controls Matrix, or CCM, is the controls framework: 197 control objectives across 17 security domains. The CAIQ translates those objectives into 261 specific yes-or-no questions. The CCM says what should be true; the CAIQ asks whether it is.

Version 4 streamlined the questionnaire from 310 questions in the previous version down to 261, and added sections covering the Shared Security Responsibility Model, which lets a provider describe which parts of a control they own and which parts the customer owns. That addition matters more than it sounds. A great deal of avoidable cloud risk comes from both parties assuming the other one handled something, and the SSRM sections exist to force that boundary into writing.

The scope is cloud services specifically, across IaaS, PaaS, and SaaS. If your product is a hosted SaaS application, you are in scope.

The free part, and the file that cannot be submitted

The CAIQ is genuinely free. No licence fee, no per-seat charge, no membership requirement, and submitting a completed CAIQ to the STAR Registry at Level 1 is also free. This is unusual in the questionnaire world and it is the main practical difference from the SIG, which requires a subscription or membership.

There is one trap, and it catches people every year. The CSA publishes two different downloads. One is "CCM + CAIQ v4," which bundles the controls matrix with the questionnaire and is explicitly for reference only. The other is "STAR Level 1: Security Questionnaire (CAIQ v4)," which is the version you fill in and submit. You cannot submit the bundled reference spreadsheet to the registry. Teams routinely complete the wrong file, discover this at submission, and redo the transcription.

Download the STAR Level 1 file first. Check the filename before you start typing, not after.

The STAR Registry, and its two levels

STAR stands for Security, Trust, Assurance and Risk, and the registry is a public directory of cloud provider security postures. It has two levels, and the distinction is the whole point.

Level 1 is a self-assessment. You complete the CAIQ, you submit it, it is published. Nobody audits it. Its value is transparency and speed: a buyer can read your answers without contacting you, and you can answer a request with a link instead of a spreadsheet. There is an optional paid submission tier that adds automated validation of responses, but the standard Level 1 entry is free and unaudited.

Level 2 is third-party. An organisation earns a certification or attestation from an independent auditor against the CCM. It carries more weight because someone other than you checked. It also costs money and takes time, and it is a later-stage decision for most small SaaS companies.

Self-assessments are updated annually, which is a commitment worth understanding before you publish. A STAR entry that has visibly gone stale is a worse signal than no entry, because it tells a reviewer that your security documentation is something you did once.

AWS, Azure, and Google Cloud all publish in the registry, which is part of why buyers have learned to look there.

CAIQ versus SIG, and why you may face both

They are not competitors and they do not fully overlap.

The SIG is broad third-party risk. It asks about your business as a vendor: governance, resilience, HR security, physical security, compliance, and much more besides the technical controls. The CAIQ is narrow and deep on cloud. It asks about shared responsibility boundaries, encryption at rest, key management, identity and access management, and tenancy — the questions a SIG asks at lower resolution.

The practical consequence is that a buyer running a serious assessment often wants both, or wants a SIG with the cloud sections answered to a depth the SIG alone does not reach. If you maintain a published STAR Level 1 entry, you can frequently satisfy the cloud portion of a broader questionnaire with a single line and a link, which is precisely why cloud-native vendors keep one current.

There is also a CAIQ-Lite, a 124-question short form used for early-stage vendor screens. Same 17 domains, fewer questions in each.

The case for doing it before anyone asks

Most security documentation is written reactively, when a deal is already waiting on it. The CAIQ is the strongest argument against that pattern, for three reasons.

It is free, so the only cost is your time. It is publishable, so the work is reusable across every buyer rather than consumed by one. And it is checkable without your involvement, which means it can do work for you in deals you do not yet know exist — a security reviewer building a shortlist can find your entry and move on to the next question rather than sending an email and waiting three days.

The 261 questions also function as a decent self-audit. Working through them surfaces the controls you assumed were in place and the ones nobody actually owns, and it is considerably cheaper to find those in a spreadsheet on a quiet week than in a follow-up call with a prospect's security team.

Several of the answers overlap with data protection documentation you may already maintain — encryption, retention, subprocessor relationships, incident response. Our guide to GDPR subprocessor management covers the vendor chain that the supply chain sections draw on.

Common mistakes with the CAIQ

Completing the reference file. "CCM + CAIQ v4" cannot be submitted to the registry. Download "STAR Level 1: Security Questionnaire (CAIQ v4)" before you start.

Publishing once and letting it age. Self-assessments are updated annually. A visibly stale entry signals that your documentation is a one-off, which is worse than having none.

Treating Level 1 as a certification. It is a self-assessment that nobody audited. Describing it as certification to a buyer who knows the registry damages your credibility on everything else.

Answering yes without reading the SSRM boundary. Several v4 questions turn on which party owns a control. Answering as though you own something the customer configures produces a contradiction the reviewer will find.

Assuming a CAIQ replaces a SIG. It covers cloud controls deeply and business risk barely. Buyers running full third-party assessments will still want the broader questionnaire.

FAQ

What does CAIQ stand for?

Consensus Assessments Initiative Questionnaire. It is published by the Cloud Security Alliance and consists of yes-or-no questions that let a cloud customer or auditor determine a provider's compliance with the Cloud Controls Matrix.

How many questions are in the CAIQ?

CAIQ v4 contains 261 questions, reduced from 310 in the previous version. They map to the 197 control objectives of the Cloud Controls Matrix v4 across 17 security domains. A shorter CAIQ-Lite exists with 124 questions for early-stage screening.

Is the CAIQ free?

Yes. The questionnaire is a free download from the CSA, and submitting a completed CAIQ to the STAR Registry for a Level 1 listing is also free. An optional paid submission adds automated validation of your responses.

What is the difference between STAR Level 1 and Level 2?

Level 1 is a self-assessment that you complete and publish yourself, with no independent review. Level 2 involves a certification or attestation from a third-party auditor. Level 1 is free and fast; Level 2 carries more weight with buyers and costs considerably more.

Closing thought

The CAIQ is unusual among security questionnaires in that the version you publish is the version everyone can read, which changes what it is for. A SIG is a document you send to one buyer. A STAR entry is a document that answers buyers you have not met, in the window between them shortlisting you and them contacting you, which is exactly the window where a small vendor is most likely to be quietly dropped for lack of visible evidence.

The same logic applies to the data protection half of the same conversation, which the CAIQ only partly covers. ComplyDog runs a hosted compliance portal on your own domain that keeps your DPA, subprocessor list, data subject request process, and security page public and current, so the privacy questions that follow a cloud security review have an answer already sitting at a URL. Two public documents, both maintained, is a materially different posture from a folder of completed spreadsheets.