CAIQ questionnaire help: a guide for small SaaS companies
Use the exact version your buyer sent. Control IDs, domain names and counts change between releases.
What the CAIQ is
CAIQ is the Consensus Assessments Initiative Questionnaire, published by the Cloud Security Alliance (CSA). It is a set of yes/no questions designed so cloud providers can describe how they meet the security controls in the CSA's Cloud Controls Matrix (CCM). Each CAIQ question maps to a CCM control, and the controls are grouped into domains such as identity and access management, encryption and key management, data security and privacy, incident management, supply chain management, and several more.
There is also a shorter variant, commonly called CAIQ-Lite, intended for quicker assessments. The full CAIQ has historically run to several hundred questions, and the exact count varies by version, so count the rows in the file you actually received.
The CSA also operates a public registry (STAR) where providers can publish a completed self-assessment. If a buyer asks for your CAIQ, they may accept a published or previously completed one. It is worth asking, as long as the answers are current and are still true.
How it differs from other questionnaires
- It is cloud-provider oriented. It assumes you operate a cloud service and asks about shared responsibility with your infrastructure provider.
- It is control-based, not narrative. Questions are closer to "Do you have a policy for X, and is it reviewed?" than "Describe how you handle X".
- It has a structured answer format. Typically Yes, No and NA columns, plus a column for notes or a description of the implementation. Some versions also ask who is responsible (you, the infrastructure provider, shared) for each control.
The Yes / No / NA columns
Because the format is so compact, small mistakes in these columns carry weight.
| Answer | Use it when | Watch out for |
|---|---|---|
| Yes | The control exists today and you can point to a document, a setting or a process. | Yes for a policy that exists on paper but is not followed. Yes for a control your hosting provider performs, not you. |
| No | The control does not exist, or only partly. Explain in the notes. | Silence. A "No" with a clear compensating control is better than a vague "Yes". |
| NA | The control genuinely does not apply to your service. | Using NA to hide a gap. Say why it does not apply. |
If a control is partly met, choose the more conservative column (usually No) and describe what exists in the notes column. Buyers reading a half-true "Yes" tend to find the gap later, which costs more than a plain "No" now.
Shared responsibility: say who does what
If you run on a major cloud provider, many infrastructure controls (physical security, hardware lifecycle, parts of network security) are performed by that provider. Many CAIQ questions are really asking "who does this?". A good pattern is:
Example only. Physical access to data centres is controlled by our infrastructure provider and covered by the provider's published attestations. We review those attestations annually. We do not operate our own data centres.
This is honest and specific. It avoids both overclaiming ("we secure our data centres") and leaving the question unanswered.
A practical approach
Step 1: Map your documents to the domains
List the domains in the file. Next to each, write which of your documents covers it: access control policy, encryption standard, backup and recovery procedure, incident response plan, vendor management policy, and so on. Gaps will show themselves immediately. Our guide to what enterprise buyers ask lists the evidence to prepare for the most common topics.
Step 2: Resolve scope and ownership questions once
Write down: what is in scope (production service, corporate IT), who the infrastructure provider is, and which controls are inherited from them. Use the same wording throughout.
Step 3: Answer the policy-level controls
Many CAIQ questions are "Do you have, maintain and review a policy for..." These are usually answerable straight from your policy set, provided the policies are dated and have been reviewed within the period stated. If a policy is older than the review cycle it claims, update and re-approve it before saying Yes.
Step 4: Answer the technical controls from configuration, not memory
For encryption, MFA, logging and backups, verify against actual settings: cloud console, identity provider, backup configuration. Note the date you checked.
Step 5: Use the notes column
The compact format can hide nuance. Keep notes short, factual and sourced, for example: "Enforced for all staff via identity provider; see SEC-POL-003 v1.4 §2."
Honest gap examples
Examples only. Replace with your own facts.
Control: Are independent audits or assessments of your security controls performed at planned intervals?
Column: No.
Notes: We have not yet had an independent audit. Internally, we review controls quarterly against our policy set. We can share the internal review record and are evaluating third-party assessment.
Control: Is there a formal, tested business continuity plan?
Column: No.
Notes: We have documented recovery procedures and automated daily backups with a 30-day retention. We have not completed a documented full recovery test.
Reusing a previous CAIQ
If you have answered a CAIQ before, treat the old answers as drafts, not facts:
- Check each against your current documents. Retention periods, subprocessors and tooling change often.
- Check the version. Control wording and IDs change between releases, so match by meaning rather than by ID.
- If you published a self-assessment externally, update the published copy when your answers change, or withdraw it. A public record that no longer matches reality is a liability.
The same discipline applies across questionnaires. If you also receive SIG-style files, see our SIG Lite guide for how the structures overlap.
Common mistakes
- Answering "Yes" to everything on the assumption that a mostly-Yes sheet is what buyers want. Experienced reviewers spot it and may ask for evidence on every row.
- Claiming inherited controls as your own.
- Using NA without a reason.
- Leaving the notes column empty even where a one-line source reference would settle the question.
- Letting the CAIQ contradict your DPA, privacy policy or website.
CAIQ on your desk? Run the free analyser to see how big and how repetitive it is (the file stays in your browser), then open a free workspace for a 10-answer preview from your own documents. You can also look at the demo with no signup.