Guide · Assessment

CAIQ, the cloud provider's questionnaire.

Assessment · 7 min read · Updated July 2026

The CAIQ — the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance — is the questionnaire built specifically for cloud service providers. It maps question-for-question to the Cloud Controls Matrix, the CSA's cloud security control framework, so a buyer can check a provider's controls against a recognized standard. This guide covers what the CAIQ asks, how it relates to the Cloud Controls Matrix, and where it fits alongside broader security questionnaires.

In one sentence

The CAIQ is a standardized questionnaire from the Cloud Security Alliance that lets a cloud service provider document its security and privacy controls against the Cloud Controls Matrix, so buyers can assess the provider without sending a bespoke form.

What the CAIQ is

The CAIQ — Consensus Assessments Initiative Questionnaire — is published by the Cloud Security Alliance (CSA), the industry body behind much of the standard tooling for cloud security assurance. It is designed for one job: letting a cloud service provider document, in a consistent format, how it implements the controls a cloud buyer cares about.

Structurally, the CAIQ is a set of questions a provider answers — historically yes or no, with room to explain — each tied to a specific control. Because the format is standardized, a buyer evaluating three cloud vendors can compare their answers side by side instead of reading three differently shaped documents and trying to reconcile them.

How the CAIQ maps to the Cloud Controls Matrix

The CAIQ is not a standalone list of questions — it is the questionnaire form of the Cloud Controls Matrix (CCM), the CSA's cybersecurity control framework for cloud computing. Every CAIQ question corresponds to a CCM control, so an answer is really an assertion about a specific, named control.

That mapping is what gives the CAIQ its weight. The CCM is organized into control domains covering areas such as identity and access management, encryption and key management, data security, application security, and governance. It is also cross-referenced to other standards and frameworks, so a completed CAIQ can be read by buyers who work in different compliance vocabularies. Answer the CAIQ, and you have effectively documented your posture against the CCM.

Who uses the CAIQ, and when

The CAIQ is aimed squarely at cloud service providers — SaaS, PaaS, and IaaS vendors — and the buyers evaluating them. If you sell cloud software into security-conscious customers, you will be asked for one sooner or later.

It is most useful early in due diligence. A provider that publishes a completed CAIQ lets prospective buyers self-serve a first pass on cloud controls before any bespoke questionnaire is sent — often shortening what follows. The CSA also runs a public registry where providers can publish their CAIQ, which turns the document into a piece of proactive assurance rather than a reactive form you scramble to fill out per deal. Because a CAIQ is typically a self-attestation, buyers tend to read it as a structured starting point and then confirm the highest-stakes answers against independent evidence such as a SOC 2 report.

CAIQ vs the SIG and other questionnaires

The CAIQ is narrow by design. Where the SIG questionnaire from Shared Assessments is broad and cross-domain — covering everything from physical security to business resilience — the CAIQ is focused on cloud-specific controls mapped to the Cloud Controls Matrix.

In practice they are complementary, not competing. A mature program often uses the SIG, or its own tiered form, for overall vendor risk and asks for the CAIQ where a vendor's cloud posture specifically matters. Both are frequently read alongside a SOC 2 report or an ISO 27001 certificate, each covering part of the assurance picture. The skill is knowing which artifact answers which question, and not re-asking what one of them already settles. And none of them replaces an audit: a CAIQ documents what a provider says it does, while a SOC 2 report or an ISO 27001 certificate brings an independent auditor's view of it.

Publishing your CAIQ once

For a cloud provider, the CAIQ's standardization is leverage. The same controls are asked about by every buyer, so a completed CAIQ — kept current and stored in a reusable answer library — answers a large share of inbound cloud questions before a single bespoke form arrives.

The highest-leverage move is to publish it. A trust center that hosts your CAIQ, SOC 2 report, ISO certificate, and subprocessor list lets buyers verify your cloud posture on their own — turning the questionnaire from a recurring tax into a link you share once. Keeping it versioned matters as much as publishing it: an out-of-date CAIQ that no longer matches your architecture creates more questions than it answers.

Publish your cloud posture
Polestead's Trust Center is free at full depth.

Host your CAIQ, SOC 2 report, and subprocessor list behind NDA-gated access, with a reusable answer library, a custom domain, and unlimited imports — and no paid gates.

See the Trust Center →
FAQ

Common questions.

What is the CAIQ?+

The CAIQ (Consensus Assessments Initiative Questionnaire) is a standardized questionnaire from the Cloud Security Alliance for cloud service providers. Each question maps to a control in the Cloud Controls Matrix, so buyers can assess a provider's cloud security posture in a consistent, comparable format.

How does the CAIQ relate to the Cloud Controls Matrix?+

The CAIQ is the questionnaire form of the Cloud Controls Matrix (CCM). Every CAIQ question corresponds to a CCM control, so completing the CAIQ documents a provider's posture against the CCM's control domains.

What is the difference between the CAIQ and the SIG?+

The CAIQ is cloud-specific and maps to the Cloud Controls Matrix. The SIG, from Shared Assessments, is broad and covers many risk domains beyond cloud. Many programs use both — the SIG for overall vendor risk, the CAIQ for cloud controls.

Do buyers still send questionnaires if a vendor has a CAIQ?+

Often less. A published, current CAIQ lets buyers self-serve a first pass on cloud controls, which frequently shortens or removes a bespoke follow-up — especially when it is paired with a SOC 2 report or ISO 27001 certificate in a trust center.

Keep reading
Security questionnaires
The wider practice the CAIQ sits inside.
SIG questionnaire
The broad, cross-domain alternative.
Trust Center →
Publish your CAIQ once, free at full depth.