The Consensus Assessments Initiative Questionnaire (CAIQ) is published by the Cloud Security Alliance (CSA) as the assessment layer of its Cloud Controls Matrix (CCM) - a cybersecurity controls framework written specifically for cloud computing rather than IT security generally. Since CCM v4, the two are shipped as a single package: CAIQ asks one yes/no/not-applicable question, with a text field to justify the answer, for each control objective in the matrix. Answer the matrix, and you have answered the questionnaire; there is no separate question set to maintain.
The 17 domains CAIQ questions are organized under
CCM v4.1 - the current release, superseding the original 2021 CCM v4.0 baseline - groups its 197 control objectives into 17 domains. A vendor's CAIQ response is really 17 short sections, each probing a different slice of how the provider actually runs its service:
| Domain | What it probes |
|---|---|
| A&A - Audit & Assurance | Independent audit cadence, scope, and how audit findings feed back into the risk program |
| AIS - Application & Interface Security | Secure development lifecycle, API security, and application-layer vulnerability management |
| BCR - Business Continuity Mgmt & Operational Resilience | Continuity and disaster-recovery planning, backup practices, and failover testing |
| CCC - Change Control & Configuration Management | Change-approval process, configuration baselines, and detection of unauthorized change |
| CEK - Cryptography, Encryption & Key Management | Encryption at rest and in transit, and how cryptographic keys are generated, stored, and rotated |
| DCS - Datacenter Security | Physical access control, environmental controls, and asset management at the facility level |
| DSP - Data Security & Privacy Lifecycle Mgmt | Data classification, handling across its lifecycle, and privacy-by-design practices |
| GRC - Governance, Risk & Compliance | Policy framework, formal risk management program, and mapping to external compliance obligations |
| HRS - Human Resources Security | Background screening, security training, acceptable-use policy, and staff offboarding |
| IAM - Identity & Access Management | Authentication, authorization, privileged-access controls, and least-privilege enforcement |
| IPY - Interoperability & Portability | Standardized interfaces and the customer's ability to extract and migrate its own data |
| IVS - Infrastructure & Virtualization Security | Hypervisor security, network segmentation, and isolation between tenant workloads |
| LOG - Logging & Monitoring | Log collection, retention, and integration with detection and audit-trail requirements |
| SEF - Security Incident Mgmt, E-Discovery & Cloud Forensics | Incident response planning, forensic readiness, and customer breach notification |
| STA - Supply Chain Mgmt, Transparency & Accountability | Disclosure of the provider's own subcontractors and downstream supply-chain dependencies |
| TVM - Threat & Vulnerability Management | Vulnerability scanning, patch management, and penetration-testing practices |
| UEM - Universal Endpoint Management | Device management, mobile security, and endpoint hardening standards |
The STA domain is worth flagging for this cluster specifically: it is CAIQ's built-in question set for exactly the disclosure this site covers in fourth-party risk - what the provider's own vendors and subcontractors are, not just what the provider itself does.
Where CAIQ fits inside CSA STAR
CAIQ is one artifact inside a larger transparency program, the Security, Trust, Assurance and Risk (STAR) registry and assurance program, which offers three distinct ways a provider can demonstrate CCM conformance:
- STAR Level 1 - Self-Assessment. The provider completes CAIQ (or the full CCM) itself and can publish the result to the public STAR Registry, where any prospective customer can look it up without asking. This is unaudited - it documents what the provider says, the same limitation any self-reported questionnaire carries.
- STAR Level 2 - Certification. An accredited third-party audits the provider against ISO/IEC 27001 plus the CCM as additional criteria, producing a certificate valid for three years - the cloud-specific analogue to a plain ISO 27001 certificate, covered generally in ISO/IEC 27036.
- STAR Level 2 - Attestation. A licensed CPA firm performs the engagement under a CSA-AICPA collaboration, auditing against SOC 2 Trust Services Criteria plus the CCM, and reissues it annually - the same underlying assurance model as a standard SOC 2 report, extended with cloud-specific controls.
The registry also lists a "Continuous" filter alongside Level 1 and Level 2, reflecting CSA's longstanding ambition for a monitoring-based Level 3; adoption of it remains far behind the two established levels, so treat a "STAR Continuous" claim as worth verifying directly rather than assuming it means the same thing every provider means. Separately, CSA has begun offering an AI-assisted validation add-on for Level 1 self-assessments - a sign of where questionnaire-based assurance is heading, and the same shift toward automated, evidence-checked assessment covered generally in automated evidence collection.
CAIQ vs. the Shared Assessments SIG
Both are structured, reusable vendor-security questionnaires, and the two are often used side by side rather than as substitutes. The practical differences: CAIQ's scope is fixed to the CCM's 17 cloud-specific domains, while the SIG covers a broader set of risk domains (privacy, financial viability, physical security among them) applicable to any third party, cloud or not. CAIQ answers are commonly published to CSA's public STAR Registry, so a customer can pull them without ever contacting the provider; SIG responses are typically exchanged bilaterally between the specific buyer and vendor rather than published centrally. In practice, many programs default to the SIG as their general-purpose questionnaire and reach for CAIQ - or point to a provider's existing STAR Registry entry - specifically when the vendor under review is a cloud service provider.
Turning CAIQ into TPRM actions
- Check the STAR Registry before sending a questionnaire. A cloud provider may have already published a current CAIQ or hold STAR Certification or Attestation - which can shortcut or entirely replace a bespoke ask.
- Read the STA domain answers specifically when subcontractor visibility matters, rather than only scanning for a pass/fail summary - it is the section written for exactly that disclosure.
- Treat Level 1 self-assessment as a starting point, not a verdict. Weight a Level 2 Certification or Attestation - or your own external evidence - more heavily for higher-tier vendors, the same tiering logic covered in vendor tiering.
- Watch certificate and attestation expiry dates - three years for Certification, one year for Attestation - and fold that into continuous monitoring rather than discovering a lapse at the next annual review.
- Don't stop at CAIQ for a critical cloud vendor. It documents controls the provider says it has; it does not observe the provider's actual internet-facing posture the way attack surface monitoring does.
Where this sits among TPRM platforms
CAIQ and the CCM are paper (or PDF) artifacts - what a platform contributes is turning STAR Registry lookups and questionnaire responses into a workable, current record. OneTrust and ProcessUnity are strong at managing questionnaire workflow and mapping responses into a broader GRC program. BitSight, SecurityScorecard, and UpGuard contribute the externally observable half of the picture that a self-reported CAIQ answer cannot - what a provider's attack surface actually looks like today. Rescana's approach pairs continuous, evidence-based monitoring with automated evidence collection so a vendor's STAR Registry status and CAIQ responses stay checked against current, verifiable signal rather than trusted at face value until the next renewal - the same gap covered generally in evidence-based risk scoring.
Frequently asked questions
What is the CSA CAIQ?
The Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized security questionnaire published by the Cloud Security Alliance (CSA) as part of its Cloud Controls Matrix (CCM). It asks one yes/no/not-applicable question, with a text field for justification, for each control objective in the CCM - 197 controls across 17 domains as of CCM v4.1. A cloud provider completes it once and can reuse the answers across every customer that asks, or publish the result publicly to CSA's STAR Registry.
What is the Cloud Controls Matrix and how does CAIQ relate to it?
The Cloud Controls Matrix (CCM) is CSA's cybersecurity controls framework written specifically for cloud computing, currently at version 4.1 with 197 control objectives across 17 domains covering areas like identity and access management, data security, and incident management. CAIQ is the assessment instrument built directly on top of it: since CCM v4 the two ship as a single package, with CAIQ providing exactly one question per CCM control so that answering the questionnaire and documenting conformance to the matrix are the same exercise.
What is CSA STAR and how does CAIQ fit into it?
CSA STAR (Security, Trust, Assurance and Risk) is CSA's registry and assurance program for demonstrating CCM conformance at three levels. Level 1 is self-assessment, where a provider completes CAIQ or the full CCM itself and may publish it to the public STAR Registry - unaudited, but freely reusable. Level 2 offers two audited options: STAR Certification, based on ISO/IEC 27001 plus the CCM and valid three years, and STAR Attestation, based on SOC 2 Trust Services Criteria plus the CCM and reissued annually. A 'Continuous' tier also appears in the registry, though it remains far less established than Levels 1 and 2.
What is the difference between CAIQ and the Shared Assessments SIG?
CAIQ, published by the Cloud Security Alliance, is scoped specifically to the Cloud Controls Matrix's 17 cloud-security domains and is commonly published to CSA's public STAR Registry, where any prospective customer can look it up directly. The SIG, published by Shared Assessments, covers a broader set of risk domains beyond cloud security - including privacy, financial viability, and physical security - and applies to any third party regardless of whether it is a cloud provider; SIG responses are typically exchanged directly between the buyer and vendor rather than published to a central registry. Many programs use the SIG as their default questionnaire and turn to CAIQ, or a provider's existing STAR Registry entry, specifically for cloud service providers.