CAIQ
The CAIQ — Consensus Assessments Initiative Questionnaire, pronounced “cake” — is a standardized security questionnaire published by the Cloud Security Alliance. It maps to the CSA’s Cloud Controls Matrix and asks cloud providers to answer a few hundred yes/no questions about their security controls, from encryption practices to incident response.
Why it exists
Every enterprise security review used to be a bespoke spreadsheet. The CAIQ standardizes the exercise: a vendor completes it once, publishes or shares it on request, and buyers get comparable answers across vendors. Completing a CAIQ and registering it in the CSA’s STAR registry is a common early credibility move for cloud vendors selling up-market.
CAIQ vs SIG vs bespoke questionnaires
The CAIQ is cloud-specific and free; the SIG is broader, covers third-party risk generally, and is licensed. In practice, mid-market buyers often accept a completed CAIQ or a SOC 2 report in place of their own questionnaire — which is exactly why having both prepared shortens security reviews from weeks to days.
SIG Questionnaire — The SIG is Shared Assessments' standardized vendor-risk questionnaire. SIG Core and SIG Lite let buyers assess vendors with one reusable question set.
Trust Services Criteria — The five Trust Services Criteria — security, availability, processing integrity, confidentiality, privacy — and how they define your SOC 2 scope.