Frameworks

CSA CAIQ explained: the questionnaire behind the Cloud Controls Matrix and STAR

A cloud provider that answers the CAIQ once can reuse that answer for every customer who asks - and, if it publishes the result to CSA's STAR Registry, for customers who never ask at all. That reuse is the whole design premise. Here is what the questionnaire actually covers, how it ties to the Cloud Controls Matrix, and where it fits alongside a SOC 2 report or a SIG response.

The Consensus Assessments Initiative Questionnaire (CAIQ) is published by the Cloud Security Alliance (CSA) as the assessment layer of its Cloud Controls Matrix (CCM) - a cybersecurity controls framework written specifically for cloud computing rather than IT security generally. Since CCM v4, the two are shipped as a single package: CAIQ asks one yes/no/not-applicable question, with a text field to justify the answer, for each control objective in the matrix. Answer the matrix, and you have answered the questionnaire; there is no separate question set to maintain.

The 17 domains CAIQ questions are organized under

CCM v4.1 - the current release, superseding the original 2021 CCM v4.0 baseline - groups its 197 control objectives into 17 domains. A vendor's CAIQ response is really 17 short sections, each probing a different slice of how the provider actually runs its service:

DomainWhat it probes
A&A - Audit & AssuranceIndependent audit cadence, scope, and how audit findings feed back into the risk program
AIS - Application & Interface SecuritySecure development lifecycle, API security, and application-layer vulnerability management
BCR - Business Continuity Mgmt & Operational ResilienceContinuity and disaster-recovery planning, backup practices, and failover testing
CCC - Change Control & Configuration ManagementChange-approval process, configuration baselines, and detection of unauthorized change
CEK - Cryptography, Encryption & Key ManagementEncryption at rest and in transit, and how cryptographic keys are generated, stored, and rotated
DCS - Datacenter SecurityPhysical access control, environmental controls, and asset management at the facility level
DSP - Data Security & Privacy Lifecycle MgmtData classification, handling across its lifecycle, and privacy-by-design practices
GRC - Governance, Risk & CompliancePolicy framework, formal risk management program, and mapping to external compliance obligations
HRS - Human Resources SecurityBackground screening, security training, acceptable-use policy, and staff offboarding
IAM - Identity & Access ManagementAuthentication, authorization, privileged-access controls, and least-privilege enforcement
IPY - Interoperability & PortabilityStandardized interfaces and the customer's ability to extract and migrate its own data
IVS - Infrastructure & Virtualization SecurityHypervisor security, network segmentation, and isolation between tenant workloads
LOG - Logging & MonitoringLog collection, retention, and integration with detection and audit-trail requirements
SEF - Security Incident Mgmt, E-Discovery & Cloud ForensicsIncident response planning, forensic readiness, and customer breach notification
STA - Supply Chain Mgmt, Transparency & AccountabilityDisclosure of the provider's own subcontractors and downstream supply-chain dependencies
TVM - Threat & Vulnerability ManagementVulnerability scanning, patch management, and penetration-testing practices
UEM - Universal Endpoint ManagementDevice management, mobile security, and endpoint hardening standards

The STA domain is worth flagging for this cluster specifically: it is CAIQ's built-in question set for exactly the disclosure this site covers in fourth-party risk - what the provider's own vendors and subcontractors are, not just what the provider itself does.

Where CAIQ fits inside CSA STAR

CAIQ is one artifact inside a larger transparency program, the Security, Trust, Assurance and Risk (STAR) registry and assurance program, which offers three distinct ways a provider can demonstrate CCM conformance:

The registry also lists a "Continuous" filter alongside Level 1 and Level 2, reflecting CSA's longstanding ambition for a monitoring-based Level 3; adoption of it remains far behind the two established levels, so treat a "STAR Continuous" claim as worth verifying directly rather than assuming it means the same thing every provider means. Separately, CSA has begun offering an AI-assisted validation add-on for Level 1 self-assessments - a sign of where questionnaire-based assurance is heading, and the same shift toward automated, evidence-checked assessment covered generally in automated evidence collection.

CAIQ vs. the Shared Assessments SIG

Both are structured, reusable vendor-security questionnaires, and the two are often used side by side rather than as substitutes. The practical differences: CAIQ's scope is fixed to the CCM's 17 cloud-specific domains, while the SIG covers a broader set of risk domains (privacy, financial viability, physical security among them) applicable to any third party, cloud or not. CAIQ answers are commonly published to CSA's public STAR Registry, so a customer can pull them without ever contacting the provider; SIG responses are typically exchanged bilaterally between the specific buyer and vendor rather than published centrally. In practice, many programs default to the SIG as their general-purpose questionnaire and reach for CAIQ - or point to a provider's existing STAR Registry entry - specifically when the vendor under review is a cloud service provider.

Turning CAIQ into TPRM actions

Where this sits among TPRM platforms

CAIQ and the CCM are paper (or PDF) artifacts - what a platform contributes is turning STAR Registry lookups and questionnaire responses into a workable, current record. OneTrust and ProcessUnity are strong at managing questionnaire workflow and mapping responses into a broader GRC program. BitSight, SecurityScorecard, and UpGuard contribute the externally observable half of the picture that a self-reported CAIQ answer cannot - what a provider's attack surface actually looks like today. Rescana's approach pairs continuous, evidence-based monitoring with automated evidence collection so a vendor's STAR Registry status and CAIQ responses stay checked against current, verifiable signal rather than trusted at face value until the next renewal - the same gap covered generally in evidence-based risk scoring.

Frequently asked questions

What is the CSA CAIQ?

The Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized security questionnaire published by the Cloud Security Alliance (CSA) as part of its Cloud Controls Matrix (CCM). It asks one yes/no/not-applicable question, with a text field for justification, for each control objective in the CCM - 197 controls across 17 domains as of CCM v4.1. A cloud provider completes it once and can reuse the answers across every customer that asks, or publish the result publicly to CSA's STAR Registry.

What is the Cloud Controls Matrix and how does CAIQ relate to it?

The Cloud Controls Matrix (CCM) is CSA's cybersecurity controls framework written specifically for cloud computing, currently at version 4.1 with 197 control objectives across 17 domains covering areas like identity and access management, data security, and incident management. CAIQ is the assessment instrument built directly on top of it: since CCM v4 the two ship as a single package, with CAIQ providing exactly one question per CCM control so that answering the questionnaire and documenting conformance to the matrix are the same exercise.

What is CSA STAR and how does CAIQ fit into it?

CSA STAR (Security, Trust, Assurance and Risk) is CSA's registry and assurance program for demonstrating CCM conformance at three levels. Level 1 is self-assessment, where a provider completes CAIQ or the full CCM itself and may publish it to the public STAR Registry - unaudited, but freely reusable. Level 2 offers two audited options: STAR Certification, based on ISO/IEC 27001 plus the CCM and valid three years, and STAR Attestation, based on SOC 2 Trust Services Criteria plus the CCM and reissued annually. A 'Continuous' tier also appears in the registry, though it remains far less established than Levels 1 and 2.

What is the difference between CAIQ and the Shared Assessments SIG?

CAIQ, published by the Cloud Security Alliance, is scoped specifically to the Cloud Controls Matrix's 17 cloud-security domains and is commonly published to CSA's public STAR Registry, where any prospective customer can look it up directly. The SIG, published by Shared Assessments, covers a broader set of risk domains beyond cloud security - including privacy, financial viability, and physical security - and applies to any third party regardless of whether it is a cloud provider; SIG responses are typically exchanged directly between the buyer and vendor rather than published to a central registry. Many programs use the SIG as their default questionnaire and turn to CAIQ, or a provider's existing STAR Registry entry, specifically for cloud service providers.