
How Amplitude handles 400+ security questionnaires a year with a single reviewer
$1.5M+
Annual value delivered
Hours
Per security review, down from weeks
The CAIQ is the Cloud Security Alliance’s standard security self-assessment for cloud providers. It turns every control objective in the Cloud Controls Matrix into yes/no questions you answer about your own environment, so a buyer can read one artifact they already know instead of writing a questionnaire of their own.
Built for GRC, customer trust and sales engineering teams.
The CAIQ is the Consensus Assessments Initiative Questionnaire, the Cloud Security Alliance’s standard security self-assessment for cloud providers. It asks a provider yes/no questions about whether it meets each control objective in the Cloud Controls Matrix, and the Cloud Security Alliance states that CAIQ v4.1 carries 283 questions aligned to the latest controls. Because the Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, a completed CAIQ can be published on the STAR Registry at no cost, where buyers read it without sending you a questionnaire of their own.
These three are one family, not three competing questionnaires. The CCM defines the controls, the CAIQ asks about them, and the Lite editions are the same thing at a smaller size. Versions and counts below are the Cloud Security Alliance’s own, taken from the artifact page linked in each row.
Two details catch teams out. The question count moved, from 261 questions in CAIQ v4.0 to 283 in v4.1. And the CAIQ ships twice, once as a reference copy inside the CCM workbook that the STAR Registry will not accept, and once as the STAR Level 1 Security Questionnaire that it will.
A buyer who wants more than one cloud service assessed sends a SIG questionnaire instead, which Shared Assessments organises across 21 risk domains that reach past the technical controls.
Publishing is the cheapest of these. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, and a completed questionnaire on the STAR Registry answers buyers who never contact you at all.
The honest answer is that it tracks your documentation, not your headcount. 283 questions is a lot of typing but very little thinking, because almost every one of them is already answered somewhere in a policy, an audit report, a control narrative, or last year’s questionnaire. The time goes into finding those answers, deciding which are still true, and getting the ones that are not in front of the person who owns them.
That is also why the second CAIQ is rarely cheaper than the first for teams working out of a folder of spreadsheets. Nothing carries forward, so a reassessment repeats most of the retrieval. Teams that keep a sourced knowledge base pay the cost once and spend later cycles reviewing rather than rebuilding.
01
The Cloud Security Alliance ships the questions twice. A reference copy sits inside the CCM workbook and cannot be submitted to the STAR Registry; the STAR Level 1 Security Questionnaire is the copy that can. Pick the second one if you intend to publish.
02
Name the specific service, environment, and regions the assessment covers. A CAIQ answered across two products at once produces answers a reviewer cannot rely on, and it is the most common reason a submitted questionnaire comes back with follow-ups.
03
Each yes should trace to a policy, a control narrative, an audit report, or a configuration you can show. Reviewers escalate on unsupported claims far more often than on an honest no.
04
Partial coverage, a compensating control, or a dated roadmap item all read better than a yes you cannot evidence. The notes are what the reviewer actually reads when the yes/no is ambiguous.
05
Send the handful of questions nobody can answer to the engineer or the control owner who can, and keep the rest moving. Do not stall the whole questionnaire on them.
06
Put the finished questionnaire on the STAR Registry, on your trust center, or both. Every buyer who reads it there is a questionnaire your team never has to answer again.
Check what you were actually sent before anyone starts typing. CAIQ v4.1 carries 283 questions, so a 500 question workbook is almost always the questionnaire plus the buyer’s own additions, or two assessments merged into one file. Separating those two piles is the first hour of work and it usually halves the second day.
The CAIQ rows themselves are retrieval rather than authorship. Nearly all of them are already answered in a policy, an audit report, a control narrative or last year’s questionnaire, so the job is finding those answers, confirming they are still true, and pasting them into the right rows. The buyer’s added questions are the ones that need a person, and they are usually a small minority of the file.
Then protect the team from the next one. Fix the scope to a single service, send only the genuinely unanswered rows to the control owner who can settle them, and publish the finished assessment on the STAR Registry or your own trust center so the following buyer reads it instead of mailing you a fresh spreadsheet.
We do not republish the questions on this page. The copyright notice the Cloud Security Alliance attaches to the questionnaire allows personal, informational, non-commercial use and explicitly forbids redistribution, so the only correct place to get the question text is from CSA.
CAIQ, CCM, and STAR are published by the Cloud Security Alliance. The version numbers, control counts, and question counts on this page are theirs, taken from the artifact pages linked above.
Filled examples live on the CSA STAR Registry, which the Cloud Security Alliance describes as a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings. The self-assessments published there are complete answers from named providers, free to read, and free to publish your own next to.
Read them as evidence of the expected level of detail rather than as a template. Every answer is scoped to that provider’s own service, so copying one describes somebody else’s architecture, which is the single fastest way to fail the follow-up call. If you want to see the shape of the questions without downloading anything, the CAIQ-Lite questionnaire demo lets you answer one in the browser and export the result as CSV.
Keeping a published example current is the harder half. The Cloud Security Alliance moved the question set from 261 questions in CAIQ v4.0 to 283 in v4.1, and your own certifications, subprocessors and architecture move faster than that. Answers held in a maintained knowledge base survive both kinds of change, and a file on someone’s desktop does not.
Wolfia reads the CAIQ workbook you were sent, drafts every answer from your own policies, audit reports, and previous questionnaires, and puts a citation on each one so a reviewer can check the claim instead of trusting it. Questions your corpus cannot answer come back as gaps rather than as confident guesses.

$1.5M+
Annual value delivered
Hours
Per security review, down from weeks

5x
Faster security reviews
Real time
Answers for AEs, down from an end-of-week wait
CAIQ stands for Consensus Assessments Initiative Questionnaire. It is published by the Cloud Security Alliance and it asks a cloud provider a set of yes/no questions about the security controls defined in the Cloud Controls Matrix, so a buyer can read one standard self-assessment instead of writing their own questionnaire.
CAIQ v4.1, released on 27 January 2026, has 283 questions across the 17 domains of the Cloud Controls Matrix. The previous generation, CAIQ v4.0, had 261. The Cloud Security Alliance ships the question set in two forms, a reference copy inside the CCM workbook and a STAR Level 1 Security Questionnaire copy that is the only one the STAR Registry accepts.
The Cloud Controls Matrix is the control framework and the CAIQ is the questionnaire built on top of it. CCM v4.1 defines 207 control objectives across 17 domains; the CAIQ turns those objectives into 283 questions a provider answers about itself. You do not pick one or the other, because answering the CAIQ is how you evidence the CCM.
CAIQ-Lite is the shortened edition. The Cloud Security Alliance publishes it alongside CCM-Lite, which narrows the 207 controls down to 96, and CAIQ-Lite asks 138 questions across the same 17 domains. It suits a smaller vendor or an early-stage review where the buyer wants coverage of every domain without the full question set.
Enterprise procurement and third-party risk teams ask for it during vendor onboarding and at annual reassessment, and cloud marketplaces and prospects read it from the CSA STAR Registry. Because it is a standard artifact, a completed CAIQ often satisfies a buyer who would otherwise send their own bespoke questionnaire.
Yes. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, so publishing a completed CAIQ to the registry costs nothing. The optional Valid-AI-ted variant, which machine-scores the submission, carries a fee unless you are a CSA corporate member.
Check what you were actually sent first. CAIQ v4.1 carries 283 questions, so a 500 question request is normally the questionnaire plus the buyer’s own additions, or two assessments merged into one workbook. Answer the CAIQ rows from your existing policies, audit reports and past questionnaires, route only the genuinely unanswered rows to the control owner who can settle them, and publish the finished self-assessment so the next buyer reads it instead of sending you their own version.
From the CSA STAR Registry, which the Cloud Security Alliance describes as a publicly accessible registry documenting the security and privacy controls provided by popular cloud computing offerings. Completed self-assessments there are real answers from real providers, free to read and free to publish your own alongside. Wolfia also hosts a CAIQ-Lite questionnaire demo you can answer in the browser and export as CSV.
Wolfia does. One knowledge base of your policies, audit reports and past responses answers a CAIQ workbook, a SIG, a HECVAT and the custom spreadsheet a buyer wrote itself, because the underlying questions repeat and only the format changes. Every answer carries a citation to the document it came from, and the file comes back in the format it arrived in.
It tracks your documentation, not your headcount. A team assembling answers by hand from scattered policies works through 283 questions over several days and repeats most of that effort at the next reassessment. A team with a maintained, sourced knowledge base answers most of the questionnaire on the first pass and only reviews the gaps.
Bring the CAIQ a buyer just sent you and we will answer it live, from your documents, with a citation on every line.
See Wolfia answer your security questionnaires, RFPs, contract redlines and trust center requests. Unlimited seats and outcome-based pricing.
Book a demo