TrustCenter

The CAIQ questionnaire, explained

The CAIQ is the cloud buyer's standard questionnaire. Completing it once and publishing it can answer dozens of reviews without a spreadsheet.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

The CAIQ, the Consensus Assessments Initiative Questionnaire, is a Cloud Security Alliance questionnaire that asks a cloud or SaaS provider which controls from the Cloud Controls Matrix it implements. Answers are mostly yes, no or not applicable, with room for explanation. A provider can complete it once and publish it to the CSA STAR registry as a Level 1 self-assessment, which many buyers accept in place of their own questionnaire.

When do buyers ask for a CAIQ?

Cloud-first buyers, technology companies and public sector teams familiar with CSA materials ask for it most. A buyer who sends a custom spreadsheet will often accept a current CAIQ if you offer it. It suits SaaS companies whose controls map naturally to cloud security domains.

Should we publish our CAIQ on CSA STAR?

Publishing a STAR Level 1 self-assessment is free and makes your answers visible to anyone. That is useful if you want to be found by cloud buyers and comfortable with the answers being public. If you prefer to share selectively, keep the completed CAIQ gated in your trust centre instead. Level 2 involves a third-party audit or certification, typically built on SOC 2 or ISO 27001.

How do we answer it well?

  • Answer honestly, including "no". A "no" with a compensating control reads better than a "yes" your SOC 2 report contradicts.
  • Reference your reports. Point to SOC 2 or ISO 27001 evidence where it supports an answer.
  • Separate what the cloud provider does. Physical security and hypervisor controls usually belong to AWS, Azure or Google Cloud. Say so and reference their reports.
  • Date it and review yearly. The CCM and CAIQ are revised, so note the version you answered.

Cloud-specific control questions are covered in depth on CloudCompliance, a sister site in this network.

Comparing it with the questionnaire banks send? See SIG Lite vs CAIQ.

Common questions

Is the CAIQ free to use?

The Cloud Security Alliance publishes the CAIQ and the Cloud Controls Matrix for free download. Publishing a Level 1 self-assessment on the STAR registry is also free.

Does a CAIQ replace a SOC 2 report?

No. A CAIQ is your own statement of controls. A SOC 2 report is an independent auditor's opinion on them. Many buyers want both, and the CAIQ carries more weight when the report backs it.

Get your CAIQ completed

From your existing evidence, reviewed by you before it goes anywhere.

Get matched