CAIQ: the Consensus Assessments Initiative Questionnaire

The CAIQ is the Cloud Security Alliance's standard security self-assessment for cloud providers. It turns every control objective in the Cloud Controls Matrix into yes/no questions you answer about your own environment, so a buyer can read one artifact they already know instead of writing a questionnaire of their own.

CAIQ vs CAIQ-Lite vs the Cloud Controls Matrix

These three are one family, not three competing questionnaires. The CCM defines the controls, the CAIQ asks about them, and the Lite editions are the same thing at a smaller size. Versions and counts below are the Cloud Security Alliance's own, taken from the artifact page linked in each row.

ArtifactWhat it isCurrent versionSize
Cloud Controls Matrix (CCM)CCM v4.1 on cloudsecurityalliance.orgThe control framework. It states what a cloud provider is expected to have in place, and every other artifact on this page derives from it.v4.1, released 27 January 2026207 control objectives across 17 domains
CAIQSTAR Level 1 Security Questionnaire (CAIQ v4.1)The questionnaire layer. It turns each CCM control objective into yes/no questions the provider answers about its own environment, with room to explain.v4.1, released 27 January 2026283 questions across the same 17 domains
CCM-Lite and CAIQ-LiteCCM-Lite and CAIQ-Lite v4The shortened editions. They keep every domain but drop to a subset of controls, for a smaller vendor or an earlier stage of a review.v4, released 27 January 202696 controls and 138 questions

Two details catch teams out. The question count moved: CAIQ v4.0 asked 261 questions and v4.1 asks 283. And the CAIQ ships twice, once as a reference copy inside the CCM workbook that the STAR Registry will not accept, and once as the STAR Level 1 Security Questionnaire that it will.

Who asks you for a CAIQ

  • Enterprise procurement and third-party risk teams, at vendor onboarding and again at annual reassessment. A completed CAIQ frequently satisfies a reviewer who would otherwise send a bespoke questionnaire of their own.
  • Buyers browsing the CSA STAR Registry, where providers publish their self-assessments for anyone to read without asking.
  • Security reviewers inside an existing customer, when your architecture, subprocessors, or certifications change mid-contract.
  • Your own sales team, which needs one current answer set it can send the same day rather than reopening the last spreadsheet.

Publishing is the cheapest of these. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, and a completed questionnaire on the STAR Registry answers buyers who never contact you at all.

How long a CAIQ takes

The honest answer is that it tracks your documentation, not your headcount. 283 questions is a lot of typing but very little thinking: almost every one of them is already answered somewhere in a policy, an audit report, a control narrative, or last year's questionnaire. The time goes into finding those answers, deciding which are still true, and getting the ones that are not in front of the person who owns them.

That is also why the second CAIQ is rarely cheaper than the first for teams working out of a folder of spreadsheets. Nothing carries forward, so a reassessment repeats most of the retrieval. Teams that keep a sourced knowledge base pay the cost once and spend later cycles reviewing rather than rebuilding.

How to fill out a CAIQ

  1. 1

    Download the copy that matches your goal

    The Cloud Security Alliance ships the questions twice. A reference copy sits inside the CCM workbook and cannot be submitted to the STAR Registry; the STAR Level 1 Security Questionnaire is the copy that can. Pick the second one if you intend to publish.
  2. 2

    Fix the scope before the first answer

    Name the specific service, environment, and regions the assessment covers. A CAIQ answered across two products at once produces answers a reviewer cannot rely on, and it is the most common reason a submitted questionnaire comes back with follow-ups.
  3. 3

    Answer from a document, never from memory

    Each yes should trace to a policy, a control narrative, an audit report, or a configuration you can show. Reviewers escalate on unsupported claims far more often than on an honest no.
  4. 4

    Use the notes column instead of over-claiming

    Partial coverage, a compensating control, or a dated roadmap item all read better than a yes you cannot evidence. The notes are what the reviewer actually reads when the yes/no is ambiguous.
  5. 5

    Route the real gaps to the owning team

    Send the handful of questions nobody can answer to the engineer or the control owner who can, and keep the rest moving. Do not stall the whole questionnaire on them.
  6. 6

    Publish it so the next buyer self-serves

    Put the finished questionnaire on the STAR Registry, on your trust center, or both. Every buyer who reads it there is a questionnaire your team never has to answer again.

Where to get the official CAIQ

We do not republish the questions on this page. The copyright notice the Cloud Security Alliance attaches to the questionnaire allows personal, informational, non-commercial use and explicitly forbids redistribution, so the only correct place to get the question text is from CSA:

CAIQ, CCM, and STAR are published by the Cloud Security Alliance. The version numbers, control counts, and question counts on this page are theirs, taken from the artifact pages linked above.

How Wolfia answers a CAIQ

Wolfia reads the CAIQ workbook you were sent, drafts every answer from your own policies, audit reports, and previous questionnaires, and puts a citation on each one so a reviewer can check the claim instead of trusting it. Questions your corpus genuinely cannot answer come back as gaps rather than as confident guesses.

CAIQ questions people ask before they answer one

What does CAIQ stand for?

CAIQ stands for Consensus Assessments Initiative Questionnaire. It is published by the Cloud Security Alliance and it asks a cloud provider a set of yes/no questions about the security controls defined in the Cloud Controls Matrix, so a buyer can read one standard self-assessment instead of writing their own questionnaire.

How many questions are in the CAIQ?

CAIQ v4.1, released on 27 January 2026, has 283 questions across the 17 domains of the Cloud Controls Matrix. The previous generation, CAIQ v4.0, had 261. The Cloud Security Alliance ships the question set in two forms: a reference copy inside the CCM workbook, and a STAR Level 1 Security Questionnaire copy that is the only one the STAR Registry accepts.

What is the difference between the CAIQ and the CCM?

The Cloud Controls Matrix is the control framework and the CAIQ is the questionnaire built on top of it. CCM v4.1 defines 207 control objectives across 17 domains; the CAIQ turns those objectives into 283 questions a provider answers about itself. You do not pick one or the other: answering the CAIQ is how you evidence the CCM.

What is CAIQ-Lite and when should I send it instead?

CAIQ-Lite is the shortened edition. The Cloud Security Alliance publishes it alongside CCM-Lite, which narrows the 207 controls down to 96, and CAIQ-Lite asks 138 questions across the same 17 domains. It suits a smaller vendor or an early-stage review where the buyer wants coverage of every domain without the full question set.

Who asks a vendor for a CAIQ?

Enterprise procurement and third-party risk teams ask for it during vendor onboarding and at annual reassessment, and cloud marketplaces and prospects read it from the CSA STAR Registry. Because it is a standard artifact, a completed CAIQ often satisfies a buyer who would otherwise send their own bespoke questionnaire.

Is submitting a CAIQ to the CSA STAR Registry free?

Yes. The Cloud Security Alliance describes the STAR Level 1 self-assessment as a complimentary offering, so publishing a completed CAIQ to the registry costs nothing. The optional Valid-AI-ted variant, which machine-scores the submission, carries a fee unless you are a CSA corporate member.

How long does a CAIQ take to complete?

It tracks your documentation, not your headcount. A team assembling answers by hand from scattered policies works through 283 questions over several days and repeats most of that effort at the next reassessment. A team with a maintained, sourced knowledge base answers most of the questionnaire on the first pass and only reviews the gaps.

Stop retyping the same 283 answers

Bring the CAIQ a buyer just sent you and we will answer it live, from your documents, with a citation on every line.