Cloud vendor assessment

CAIQ, the Consensus Assessments Initiative Questionnaire

The CAIQ is the Cloud Security Alliance’s standard security self-assessment for cloud providers. It turns every control objective in the Cloud Controls Matrix into yes/no questions you answer about your own environment, so a buyer can read one artifact they already know instead of writing a questionnaire of their own.

Built for GRC, customer trust and sales engineering teams.

In short

What is the CAIQ

The CAIQ is the Consensus Assessments Initiative Questionnaire, the Cloud Security Alliance’s standard security self-assessment for cloud providers. It asks a provider yes/no questions about whether it meets each control objective in the Cloud Controls Matrix, and the Cloud Security Alliance states that CAIQ v4.1 carries 283 questions aligned to the latest controls. Because the Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, a completed CAIQ can be published on the STAR Registry at no cost, where buyers read it without sending you a questionnaire of their own.

What it is
A self-assessment of yes/no questions a cloud provider answers about its own environment, one set per control objective in the Cloud Controls Matrix, with a column to explain each answer.
Who publishes it
The Cloud Security Alliance. CAIQ v4.1 was released on 27 January 2026 with 283 questions, aligned to the 207 controls across 17 domains in Cloud Controls Matrix v4.1.
Who asks for it
Enterprise procurement and third-party risk teams at vendor onboarding and annual reassessment, and buyers who read completed self-assessments on the CSA STAR Registry without contacting you at all.
How long it takes
The Cloud Security Alliance publishes no completion time. Almost every one of the 283 questions is already answered somewhere in your policies, audit reports and past questionnaires, so the calendar is set by how fast you can find those answers and confirm they are still true.
One family

CAIQ vs CAIQ-Lite vs the Cloud Controls Matrix

These three are one family, not three competing questionnaires. The CCM defines the controls, the CAIQ asks about them, and the Lite editions are the same thing at a smaller size. Versions and counts below are the Cloud Security Alliance’s own, taken from the artifact page linked in each row.

Cloud Controls Matrix (CCM)

CCM v4.1 on cloudsecurityalliance.org
What it is
The control framework. It states what a cloud provider is expected to have in place, and every other artifact on this page derives from it.
Current version
v4.1, released 27 January 2026
Size
207 control objectives across 17 domains

CAIQ

STAR Level 1 Security Questionnaire (CAIQ v4.1)
What it is
The questionnaire layer. It turns each CCM control objective into yes/no questions the provider answers about its own environment, with room to explain.
Current version
v4.1, released 27 January 2026
Size
283 questions across the same 17 domains

CCM-Lite and CAIQ-Lite

CCM-Lite and CAIQ-Lite v4
What it is
The shortened editions. They keep every domain but drop to a subset of controls, for a smaller vendor or an earlier stage of a review.
Current version
v4, released 27 January 2026
Size
96 controls and 138 questions

Two details catch teams out. The question count moved, from 261 questions in CAIQ v4.0 to 283 in v4.1. And the CAIQ ships twice, once as a reference copy inside the CCM workbook that the STAR Registry will not accept, and once as the STAR Level 1 Security Questionnaire that it will.

A buyer who wants more than one cloud service assessed sends a SIG questionnaire instead, which Shared Assessments organises across 21 risk domains that reach past the technical controls.

Who asks

Who asks you for a CAIQ

  • Enterprise procurement and third-party risk teams, at vendor onboarding and again at annual reassessment. A completed CAIQ frequently satisfies a reviewer who would otherwise send a bespoke questionnaire of their own.
  • Buyers browsing the CSA STAR Registry, where providers publish their self-assessments for anyone to read without asking.
  • Security reviewers inside an existing customer, when your architecture, subprocessors, or certifications change mid-contract.
  • Your own sales team, which needs one current answer set it can send the same day rather than reopening the last spreadsheet.

Publishing is the cheapest of these. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, and a completed questionnaire on the STAR Registry answers buyers who never contact you at all.

Effort

How long a CAIQ takes

The honest answer is that it tracks your documentation, not your headcount. 283 questions is a lot of typing but very little thinking, because almost every one of them is already answered somewhere in a policy, an audit report, a control narrative, or last year’s questionnaire. The time goes into finding those answers, deciding which are still true, and getting the ones that are not in front of the person who owns them.

That is also why the second CAIQ is rarely cheaper than the first for teams working out of a folder of spreadsheets. Nothing carries forward, so a reassessment repeats most of the retrieval. Teams that keep a sourced knowledge base pay the cost once and spend later cycles reviewing rather than rebuilding.

The procedure

How to fill out a CAIQ

  1. 01

    Download the copy that matches your goal

    The Cloud Security Alliance ships the questions twice. A reference copy sits inside the CCM workbook and cannot be submitted to the STAR Registry; the STAR Level 1 Security Questionnaire is the copy that can. Pick the second one if you intend to publish.

  2. 02

    Fix the scope before the first answer

    Name the specific service, environment, and regions the assessment covers. A CAIQ answered across two products at once produces answers a reviewer cannot rely on, and it is the most common reason a submitted questionnaire comes back with follow-ups.

  3. 03

    Answer from a document, never from memory

    Each yes should trace to a policy, a control narrative, an audit report, or a configuration you can show. Reviewers escalate on unsupported claims far more often than on an honest no.

  4. 04

    Use the notes column instead of over-claiming

    Partial coverage, a compensating control, or a dated roadmap item all read better than a yes you cannot evidence. The notes are what the reviewer actually reads when the yes/no is ambiguous.

  5. 05

    Route the real gaps to the owning team

    Send the handful of questions nobody can answer to the engineer or the control owner who can, and keep the rest moving. Do not stall the whole questionnaire on them.

  6. 06

    Publish it so the next buyer self-serves

    Put the finished questionnaire on the STAR Registry, on your trust center, or both. Every buyer who reads it there is a questionnaire your team never has to answer again.

Big questionnaires

How to answer a 500 question CAIQ without burning out your security team

Check what you were actually sent before anyone starts typing. CAIQ v4.1 carries 283 questions, so a 500 question workbook is almost always the questionnaire plus the buyer’s own additions, or two assessments merged into one file. Separating those two piles is the first hour of work and it usually halves the second day.

The CAIQ rows themselves are retrieval rather than authorship. Nearly all of them are already answered in a policy, an audit report, a control narrative or last year’s questionnaire, so the job is finding those answers, confirming they are still true, and pasting them into the right rows. The buyer’s added questions are the ones that need a person, and they are usually a small minority of the file.

Then protect the team from the next one. Fix the scope to a single service, send only the genuinely unanswered rows to the control owner who can settle them, and publish the finished assessment on the STAR Registry or your own trust center so the following buyer reads it instead of mailing you a fresh spreadsheet.

The official copy

Where to get the official CAIQ

We do not republish the questions on this page. The copyright notice the Cloud Security Alliance attaches to the questionnaire allows personal, informational, non-commercial use and explicitly forbids redistribution, so the only correct place to get the question text is from CSA.

CAIQ, CCM, and STAR are published by the Cloud Security Alliance. The version numbers, control counts, and question counts on this page are theirs, taken from the artifact pages linked above.

Worked examples

Where to find a filled CAIQ-Lite example

Filled examples live on the CSA STAR Registry, which the Cloud Security Alliance describes as a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings. The self-assessments published there are complete answers from named providers, free to read, and free to publish your own next to.

Read them as evidence of the expected level of detail rather than as a template. Every answer is scoped to that provider’s own service, so copying one describes somebody else’s architecture, which is the single fastest way to fail the follow-up call. If you want to see the shape of the questions without downloading anything, the CAIQ-Lite questionnaire demo lets you answer one in the browser and export the result as CSV.

Keeping a published example current is the harder half. The Cloud Security Alliance moved the question set from 261 questions in CAIQ v4.0 to 283 in v4.1, and your own certifications, subprocessors and architecture move faster than that. Answers held in a maintained knowledge base survive both kinds of change, and a file on someone’s desktop does not.

With Wolfia

How Wolfia answers a CAIQ

Wolfia reads the CAIQ workbook you were sent, drafts every answer from your own policies, audit reports, and previous questionnaires, and puts a citation on each one so a reviewer can check the claim instead of trusting it. Questions your corpus cannot answer come back as gaps rather than as confident guesses.

Customer stories

How teams keep up with sales

All case studies
Amplitude product analytics dashboard
Amplitude

How Amplitude handles 400+ security questionnaires a year with a single reviewer

$1.5M+

Annual value delivered

Hours

Per security review, down from weeks

Read the story
The Juicebox team at a company gathering
Juicebox

How Juicebox closes enterprise deals 5x faster with the AI Trust Center

5x

Faster security reviews

Real time

Answers for AEs, down from an end-of-week wait

Read the story
FAQ

CAIQ questions people ask before they answer one

What does CAIQ stand for?

CAIQ stands for Consensus Assessments Initiative Questionnaire. It is published by the Cloud Security Alliance and it asks a cloud provider a set of yes/no questions about the security controls defined in the Cloud Controls Matrix, so a buyer can read one standard self-assessment instead of writing their own questionnaire.

How many questions are in the CAIQ?

CAIQ v4.1, released on 27 January 2026, has 283 questions across the 17 domains of the Cloud Controls Matrix. The previous generation, CAIQ v4.0, had 261. The Cloud Security Alliance ships the question set in two forms, a reference copy inside the CCM workbook and a STAR Level 1 Security Questionnaire copy that is the only one the STAR Registry accepts.

What is the difference between the CAIQ and the CCM?

The Cloud Controls Matrix is the control framework and the CAIQ is the questionnaire built on top of it. CCM v4.1 defines 207 control objectives across 17 domains; the CAIQ turns those objectives into 283 questions a provider answers about itself. You do not pick one or the other, because answering the CAIQ is how you evidence the CCM.

What is CAIQ-Lite and when should I send it instead?

CAIQ-Lite is the shortened edition. The Cloud Security Alliance publishes it alongside CCM-Lite, which narrows the 207 controls down to 96, and CAIQ-Lite asks 138 questions across the same 17 domains. It suits a smaller vendor or an early-stage review where the buyer wants coverage of every domain without the full question set.

Who asks a vendor for a CAIQ?

Enterprise procurement and third-party risk teams ask for it during vendor onboarding and at annual reassessment, and cloud marketplaces and prospects read it from the CSA STAR Registry. Because it is a standard artifact, a completed CAIQ often satisfies a buyer who would otherwise send their own bespoke questionnaire.

Is submitting a CAIQ to the CSA STAR Registry free?

Yes. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, so publishing a completed CAIQ to the registry costs nothing. The optional Valid-AI-ted variant, which machine-scores the submission, carries a fee unless you are a CSA corporate member.

We were sent a 500 question CAIQ. How do we answer it without burning out our security team?

Check what you were actually sent first. CAIQ v4.1 carries 283 questions, so a 500 question request is normally the questionnaire plus the buyer’s own additions, or two assessments merged into one workbook. Answer the CAIQ rows from your existing policies, audit reports and past questionnaires, route only the genuinely unanswered rows to the control owner who can settle them, and publish the finished self-assessment so the next buyer reads it instead of sending you their own version.

Where can we get a filled CAIQ-Lite example?

From the CSA STAR Registry, which the Cloud Security Alliance describes as a publicly accessible registry documenting the security and privacy controls provided by popular cloud computing offerings. Completed self-assessments there are real answers from real providers, free to read and free to publish your own alongside. Wolfia also hosts a CAIQ-Lite questionnaire demo you can answer in the browser and export as CSV.

Which software answers CAIQ, SIG and HECVAT from one security knowledge base?

Wolfia does. One knowledge base of your policies, audit reports and past responses answers a CAIQ workbook, a SIG, a HECVAT and the custom spreadsheet a buyer wrote itself, because the underlying questions repeat and only the format changes. Every answer carries a citation to the document it came from, and the file comes back in the format it arrived in.

How long does a CAIQ take to complete?

It tracks your documentation, not your headcount. A team assembling answers by hand from scattered policies works through 283 questions over several days and repeats most of that effort at the next reassessment. A team with a maintained, sourced knowledge base answers most of the questionnaire on the first pass and only reviews the gaps.

Bring us a live one

Stop retyping the same 283 answers

Bring the CAIQ a buyer just sent you and we will answer it live, from your documents, with a citation on every line.

Book an exploratory call
Get started

Take the waiting out of your sales cycle

See Wolfia answer your security questionnaires, RFPs, contract redlines and trust center requests. Unlimited seats and outcome-based pricing.

Book a demo