CAIQ questionnaire help: a guide for small SaaS companies

Use the exact version your buyer sent. Control IDs, domain names and counts change between releases.

What the CAIQ is

CAIQ is the Consensus Assessments Initiative Questionnaire, published by the Cloud Security Alliance (CSA). It is a set of yes/no questions designed so cloud providers can describe how they meet the security controls in the CSA's Cloud Controls Matrix (CCM). Each CAIQ question maps to a CCM control, and the controls are grouped into domains such as identity and access management, encryption and key management, data security and privacy, incident management, supply chain management, and several more.

There is also a shorter variant, commonly called CAIQ-Lite, intended for quicker assessments. The full CAIQ has historically run to several hundred questions, and the exact count varies by version, so count the rows in the file you actually received.

The CSA also operates a public registry (STAR) where providers can publish a completed self-assessment. If a buyer asks for your CAIQ, they may accept a published or previously completed one. It is worth asking, as long as the answers are current and are still true.

How it differs from other questionnaires

The Yes / No / NA columns

Because the format is so compact, small mistakes in these columns carry weight.

AnswerUse it whenWatch out for
YesThe control exists today and you can point to a document, a setting or a process.Yes for a policy that exists on paper but is not followed. Yes for a control your hosting provider performs, not you.
NoThe control does not exist, or only partly. Explain in the notes.Silence. A "No" with a clear compensating control is better than a vague "Yes".
NAThe control genuinely does not apply to your service.Using NA to hide a gap. Say why it does not apply.

If a control is partly met, choose the more conservative column (usually No) and describe what exists in the notes column. Buyers reading a half-true "Yes" tend to find the gap later, which costs more than a plain "No" now.

Shared responsibility: say who does what

If you run on a major cloud provider, many infrastructure controls (physical security, hardware lifecycle, parts of network security) are performed by that provider. Many CAIQ questions are really asking "who does this?". A good pattern is:

Example only. Physical access to data centres is controlled by our infrastructure provider and covered by the provider's published attestations. We review those attestations annually. We do not operate our own data centres.

This is honest and specific. It avoids both overclaiming ("we secure our data centres") and leaving the question unanswered.

A practical approach

Step 1: Map your documents to the domains

List the domains in the file. Next to each, write which of your documents covers it: access control policy, encryption standard, backup and recovery procedure, incident response plan, vendor management policy, and so on. Gaps will show themselves immediately. Our guide to what enterprise buyers ask lists the evidence to prepare for the most common topics.

Step 2: Resolve scope and ownership questions once

Write down: what is in scope (production service, corporate IT), who the infrastructure provider is, and which controls are inherited from them. Use the same wording throughout.

Step 3: Answer the policy-level controls

Many CAIQ questions are "Do you have, maintain and review a policy for..." These are usually answerable straight from your policy set, provided the policies are dated and have been reviewed within the period stated. If a policy is older than the review cycle it claims, update and re-approve it before saying Yes.

Step 4: Answer the technical controls from configuration, not memory

For encryption, MFA, logging and backups, verify against actual settings: cloud console, identity provider, backup configuration. Note the date you checked.

Step 5: Use the notes column

The compact format can hide nuance. Keep notes short, factual and sourced, for example: "Enforced for all staff via identity provider; see SEC-POL-003 v1.4 §2."

Honest gap examples

Examples only. Replace with your own facts.

Control: Are independent audits or assessments of your security controls performed at planned intervals?
Column: No.
Notes: We have not yet had an independent audit. Internally, we review controls quarterly against our policy set. We can share the internal review record and are evaluating third-party assessment.

Control: Is there a formal, tested business continuity plan?
Column: No.
Notes: We have documented recovery procedures and automated daily backups with a 30-day retention. We have not completed a documented full recovery test.

Reusing a previous CAIQ

If you have answered a CAIQ before, treat the old answers as drafts, not facts:

The same discipline applies across questionnaires. If you also receive SIG-style files, see our SIG Lite guide for how the structures overlap.

Common mistakes

CAIQ on your desk? Run the free analyser to see how big and how repetitive it is (the file stays in your browser), then open a free workspace for a 10-answer preview from your own documents. You can also look at the demo with no signup.