Glossary

CAIQ

The CAIQ — Consensus Assessments Initiative Questionnaire, pronounced “cake” — is a standardized security questionnaire published by the Cloud Security Alliance. It maps to the CSA’s Cloud Controls Matrix and asks cloud providers to answer a few hundred yes/no questions about their security controls, from encryption practices to incident response.

Why it exists

Every enterprise security review used to be a bespoke spreadsheet. The CAIQ standardizes the exercise: a vendor completes it once, publishes or shares it on request, and buyers get comparable answers across vendors. Completing a CAIQ and registering it in the CSA’s STAR registry is a common early credibility move for cloud vendors selling up-market.

CAIQ vs SIG vs bespoke questionnaires

The CAIQ is cloud-specific and free; the SIG is broader, covers third-party risk generally, and is licensed. In practice, mid-market buyers often accept a completed CAIQ or a SOC 2 report in place of their own questionnaire — which is exactly why having both prepared shortens security reviews from weeks to days.

Related Terms

SIG Questionnaire — The SIG is Shared Assessments' standardized vendor-risk questionnaire. SIG Core and SIG Lite let buyers assess vendors with one reusable question set.

Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.