Blog

What Is the CAIQ Questionnaire? A Clear Guide

What Is the CAIQ Questionnaire? A Clear Guide
The CAIQ questionnaire documents a cloud provider's security controls. Learn how it works and how to finish it without the grind.

If you sell or buy cloud services, the CAIQ shows up sooner or later. It is the standard way the cloud industry documents and compares security controls, and understanding it saves real time on both sides of a vendor review. This guide breaks down what the CAIQ questionnaire is, how it works, and how you can handle it without burning weeks of your team’s time.

What Is the CAIQ Questionnaire?

CAIQ stands for Consensus Assessments Initiative Questionnaire. It is a standardized security questionnaire created by the Cloud Security Alliance (CSA), the nonprofit dedicated to best practices for a secure cloud and the source of much of the best-known guidance for cloud computing. At its core, the CAIQ is a downloadable spreadsheet of yes-or-no questions, a standardized set tied to a specific control in the CSA’s Cloud Controls Matrix (CCM).

The point of the CAIQ is security control transparency. A cloud service provider answers questions to document the security controls it has in place, and you, as a cloud customer, read those answers to assess the provider’s security posture before signing on. CAIQ gives you a single shared format, so you can compare providers on the same terms rather than inventing a new questionnaire each time.

CAIQ and the Cloud Controls Matrix

The CAIQ and the CCM are two halves of one system. The Cloud Controls Matrix is a cybersecurity controls framework for cloud computing. It defines 197 control objectives across 17 security domains, covering areas from identity and access management to data security and supply chain. The CCM describes what strong cloud security looks like.

The CAIQ turns that framework into questions. Each CAIQ question reflects the latest best practices captured in the CCM and asks whether a given control is in place and how it is implemented. CAIQ and CCM ship together and share the same 17 domains, which is why teams reference them in the same breath.

What Is in CAIQ v4?

The current version is CAIQ v4. It includes 261 yes-or-no questions across the 17 control domains, down from 310 in version 3.1. The CSA trimmed the count through better alignment, not by cutting coverage.

Version 4 added columns for the Shared Security Responsibility Model, so a cloud service provider can mark whether it owns a control, the customer owns it, a third party handles it, or responsibility is shared. That update greatly clarified who is accountable for what across a cloud relationship.

The Condensed Version of CAIQ

For faster reviews, the CSA publishes CAIQ-Lite. This condensed version carries 124 questions instead of 261, and still covers all 17 control domains. It suits early vendor screening or a lower-risk cloud-based tool where a full deep dive is overkill.

CAIQ-Lite is not only for internal use. Since October 2024, the CSA has accepted a lighter CCM-Lite and CAIQ-Lite submission into the STAR Registry, aimed at startups and SMEs as a first step toward a full Level 1 self-assessment. Larger or higher-risk providers still complete the full 261-question CAIQ for a standard Level 1 listing.

Who Uses the CAIQ and Why?

The CAIQ serves two audiences across IaaS, PaaS, and SaaS services. A cloud service provider (CSP) uses CAIQ to document its cloud security controls in one place and answer buyer questions once, rather than fifty times. On the other side, you, as a cloud consumer or auditor, use the same set of questions to determine whether a provider’s controls meet your bar.

For cloud customers, the value is consistency. Reading a completed CAIQ is faster than parsing a dozen custom questionnaires, and the answers line up with a known framework. CAIQ helps you compare service providers without having to reinvent the process each time. For providers, a completed CAIQ becomes a reusable asset that speeds up future security reviews.

CAIQ and the CSA STAR Registry

When a provider finishes the CAIQ, it can submit the completed questionnaire to the CSA STAR Registry to earn STAR Level 1. STAR Level 1 is a free self-assessment, the entry tier of the CSA’s cloud security assurance program, and the published entry lets you check a cloud provider’s compliance posture at any time.

Major cloud service providers maintain STAR Level 1 listings in the registry, which is part of how procurement teams pre-fill cloud supplier reviews. Keeping that entry current signals ongoing diligence and spares you from having to ask the same questions by email.

How the CAIQ Compares to Other Questionnaires

The CAIQ is cloud-specific. It comes from the Cloud Security Alliance and maps to the CCM, so it goes in depth on cloud topics such as shared responsibility, tenancy, and encryption. That focus sets it apart from a broad third-party risk management questionnaire, such as the SIG, which spans a wider range of vendors with less cloud depth.

Most security and compliance teams end up handling multiple questionnaires at once, the CAIQ among them. Knowing when to use CAIQ and when to reach for a broader questionnaire keeps your program from over-assessing low-risk vendors.

How to Complete the CAIQ Without the Grind

A 261-question spreadsheet looks daunting, but most answers already exist. Map your CCM domains to evidence you already hold: your SOC 2 report, your ISO 27001 audit, and your existing policies. A large share of the questions will answer themselves. Assign each of the 17 domains to an owner so the right person handles the questions they know best.

The manual work is the real cost. Filling out the CAIQ by hand, then reformatting the same answers for the next buyer’s custom form, eats hours your team could spend on actual cybersecurity. This is where automation changes the math. Our TITAN AI platform leverages RespondAI technology to draft answers from your existing documentation and map them across frameworks, turning a multi-day exercise into a fast one. TITAN Assess pairs that with automated workflows so the CAIQ, and every questionnaire after it, moves quicker.

To see how TITAN AI turns the CAIQ and other security questionnaires from weeks of work into hours, request a demo.