TrustCenter

SIG Lite vs CAIQ: which questionnaire you were sent and how to answer it

Both arrive as a spreadsheet with a deadline. They come from different organizations, ask about different things, and reward different preparation. Knowing which one you have saves most of the first day.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

SIG Lite is the short version of the Standardized Information Gathering questionnaire from Shared Assessments, sent mostly by banks, insurers and large enterprises running third-party risk programs. The CAIQ is the Cloud Security Alliance's questionnaire on its Cloud Controls Matrix, sent mostly by cloud-savvy technology buyers. The SIG asks how you manage risk across your whole company; the CAIQ asks which cloud security controls your service implements.

How do you tell which one you were sent?

Look at the file before the questions. A SIG workbook carries the Shared Assessments name and a version year, and its questions are grouped into risk domains such as enterprise risk management, information assurance, third-party management and business resiliency. A CAIQ workbook carries the Cloud Security Alliance name and a version number, and its rows are organized by Cloud Controls Matrix domain codes such as IAM, DSP or BCR, each question tied to a control ID. If it is neither, it is a custom questionnaire, and the questionnaire help page covers those.

How do SIG Lite and the CAIQ compare?

SIG Lite and CAIQ side by side
SIG LiteCAIQ
Published byShared Assessments, revised every yearCloud Security Alliance, versioned with the Cloud Controls Matrix
LicenceLicensed; the buyer usually holds it and sends you the fileFree to download
Who sends itFinancial institutions, insurers, large enterprises with a formal vendor risk programTechnology companies, cloud-first buyers, some public-sector teams
What it coversYour company's whole risk posture: governance, HR, vendors, resilience, privacy, as well as technical controlsThe security controls of your cloud service, mapped to the Cloud Controls Matrix
Answer formatMostly yes, no or not applicable, with comments; the buyer may ask for evidence per answerMostly yes, no or not applicable per control question, with room for explanation
Can you publish it?Not publicly; share a completed copy under NDAYes, as a CSA STAR Level 1 self-assessment, or keep it gated
Bigger siblingSIG Core, for higher-risk relationships, much longerThe full Cloud Controls Matrix, and STAR Level 2 with third-party assessment

What evidence does each one expect?

A SIG reviewer at a bank reads your answers against their own risk policy and asks for documents: policies with review dates, your business continuity plan, your vendor list and how you assess those vendors, insurance, and your SOC 2 report or ISO 27001 certificate. Federally regulated financial institutions assess vendors under OSFI Guideline B-10, so expect follow-ups on subcontractors, data location, continuity and exit planning.

A CAIQ reviewer reads for coverage of cloud controls: identity and access, encryption and key management, logging, change control, data location and segregation between tenants. The evidence is usually your SOC 2 report or ISO 27001 certificate plus a clear statement of which controls belong to your cloud provider. Physical security, for instance, is AWS's, Azure's or Google Cloud's, and you answer by referencing their reports rather than claiming it. The cloud-side controls are covered in depth on CloudCompliance.

How long does each take to answer?

Effort depends far more on your evidence than on the template. With a current SOC 2 report and an answer library, SIG Lite and the CAIQ are each roughly a day of matching and review. Without them, the first one of either can take a senior person most of a week, nearly all of it spent finding documents. SIG Core is several days even with a library. The questionnaire volume tool estimates what a year of these costs you.

How do you answer either one once and reuse it?

  1. Map it to your report. Many SIG domains and nearly every CAIQ domain line up with SOC 2 common criteria or ISO 27001 Annex A controls. Record the mapping as you go.
  2. Answer from approved wording. Pull from the library, and add new answers back to it after approval.
  3. Explain every not applicable. A blank or bare N/A reads as avoidance. One sentence on why it does not apply is enough.
  4. Date and version it. Note the SIG year or CAIQ version you answered. Both change, and a reviewer will check.
  5. Store the completed copy. Keep it in your trust centre's gated library. The next buyer often accepts a recent completed SIG Lite or CAIQ instead of sending their own.

Publishing a CAIQ is a choice, not a default

A STAR Level 1 entry is free and makes your answers public, which helps cloud buyers find you. If any answer is a no you would rather explain in person, keep the completed CAIQ behind your NDA gate instead.

Common questions

Is SIG Lite the same as the SIG?

SIG Lite is a shorter subset of the full SIG, intended for initial screening and lower-risk vendors. The full version, SIG Core, goes deeper in every domain and is sent to vendors handling sensitive data or critical services.

Can we send a CAIQ when a buyer asks for a SIG?

Sometimes. Offer your completed CAIQ or your SOC 2 report and ask whether it covers their needs. Banks with a formal program usually still want their own SIG, but many technology buyers will accept a standard questionnaire you already have.

Do we need to pay to answer a SIG?

Usually not. The buyer holds the Shared Assessments licence and sends you the questionnaire. You only need a licence if you want to use the SIG yourself, for instance to assess your own vendors.

Does a SOC 2 report answer a SIG or a CAIQ?

It answers a large share of both, and reviewers will often accept a reference to the relevant section of the report. It does not cover everything. The SIG asks about governance and resilience topics outside a typical SOC 2 scope, and the CAIQ asks cloud questions the report may not describe in that form.

Get a SIG or CAIQ completed from your evidence

Drafted from the documents you already have and reviewed by you before it goes anywhere.

Get matched