CAIQ v4, and how to answer it without starting from scratch
The Consensus Assessment Initiative Questionnaire is the Cloud Security Alliance's standard way for a cloud provider to document its controls once, instead of answering the same questions for every customer.
In short
CAIQ v4 is the questionnaire form of the CSA's Cloud Controls Matrix: each control in the CCM becomes one or more yes/no questions with room for explanation. It arrives as a multi-tab Excel workbook, usually with a cover or instructions sheet first and the questions on a later tab. Answering it well is less about writing prose than about pointing at the policy or report that already says what you do.
CAIQ v4 at a glance
| Published by | Cloud Security Alliance (CSA) |
| Based on | The Cloud Controls Matrix (CCM), organised into control domains covering areas such as identity, encryption, logging, incident response and supply chain |
| Typical size | Several hundred questions — enough that answering by hand is a multi-day job |
| Format | Excel workbook, multiple sheets |
| Who asks for it | Enterprise buyers of cloud and SaaS products, often as an accepted substitute for their own form |
| Related | A completed CAIQ can be submitted to the CSA STAR registry, which some buyers check before they send you anything |
How the file is put together
The shape of the workbook is what trips most tools up, and it is worth knowing before you upload anything.
What Compliance Concierge does with a CAIQ v4
None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.
This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case.
The 17 control domains, and the seven that cost the most time
CAIQ questions are grouped by CCM domain, and the domains are not equally hard. These seven are where answers get sent back for rework — what each is really asking, which document normally answers it, and the mistake that shows up most often.
Audit & Assurance
- What it asks
- Whether an independent party audits you, how often, and whether the buyer may see the result.
- What answers it
- SOC 2 Type II report or ISO 27001 certificate with the statement of applicability, plus the date of the most recent one.
- Common mistake
- Naming a certification whose scope is not the product being sold — a parent company's ISO 27001 while the service runs in a subsidiary's environment. Scope is the first thing a reviewer checks.
Identity & Access Management
- What it asks
- Who can reach production, how that access is granted and revoked, and how often it is reviewed.
- What answers it
- Access control policy, joiner-mover-leaver procedure, the record of the last access review, MFA enforcement settings.
- Common mistake
- Answering “quarterly” because the policy says quarterly, when no review has actually been recorded. The question is about practice, and the follow-up asks for the last record.
Cryptography, Encryption & Key Management
- What it asks
- What is encrypted, with which algorithms, and who holds the keys.
- What answers it
- Cryptographic policy or encryption standard, the cloud provider's configuration, the key rotation procedure.
- Common mistake
- Claiming “encrypted at rest” because the platform does it by default, without knowing whether keys are provider-managed or customer-managed. That distinction is frequently the actual question.
Data Security & Privacy Lifecycle Management
- What it asks
- What data is held, where it lives, how long it is kept and how it is deleted.
- What answers it
- Retention and deletion policy, records of processing under Art. 30 GDPR, a data flow or residency description, the DPA.
- Common mistake
- Stating a retention period that contradicts the privacy policy or the DPA. Both are public documents and buyers do read them alongside the questionnaire.
Logging & Monitoring
- What it asks
- What is logged, how long logs are kept, and whether anyone reads them.
- What answers it
- Logging policy with a retention period, alerting configuration, the on-call rota.
- Common mistake
- Answering about application logs when the question is about security audit logs. LOG became its own domain in v4, so answer libraries built on v3 often have nothing to reuse here.
Security Incident Management, E-Discovery & Cloud Forensics
- What it asks
- What happens when something goes wrong, and how quickly the customer is told.
- What answers it
- Incident response plan with severity tiers and notification timelines, plus the record of the last test or tabletop exercise.
- Common mistake
- Inventing a notification deadline to fill the field. If the plan states no number, the honest answer is what it does state — and then fixing the plan.
Supply Chain Management, Transparency & Accountability
- What it asks
- Which subprocessors are used, what they can reach, and how they are assessed.
- What answers it
- The public subprocessor list, the vendor assessment procedure, the subprocessor clause of the DPA.
- Common mistake
- A subprocessor list that is out of date, or that omits the AI provider. This is currently the most closely read domain of the seven.
The remaining ten domains
- AIS Application & Interface Security
- BCR Business Continuity Management & Operational Resilience
- CCC Change Control & Configuration Management
- DCS Datacenter Security
- GRC Governance, Risk Management & Compliance
- HRS Human Resources Security
- IPY Interoperability & Portability
- IVS Infrastructure & Virtualization Security
- TVM Threat & Vulnerability Management
- UEM Universal Endpoint Management
CCM and CAIQ v4.1 were published on 27 January 2026: still 207 controls across the same 17 domains, but the questionnaire grew to 283 questions. Everything below applies to both — check the version cell on the cover sheet, because buyers send whichever they standardised on.
Frequently asked
What is the difference between CAIQ and the CCM?+
The Cloud Controls Matrix is the control framework: a structured list of what a cloud provider should have in place. CAIQ is the questionnaire built from it — the same controls phrased as questions a customer can send you. If you have mapped your controls to the CCM, you have already done most of the work of a CAIQ.
Can I reuse last year's CAIQ?+
Partly, and that is the point of keeping a reviewed answer library. Controls change slowly, but evidence goes stale: a penetration test date, a subprocessor list or a certification expiry that was true last year may not be now. Reuse the wording, re-check anything with a date in it.
Do I have to answer every question?+
Not necessarily, but leaving cells blank without explanation is what triggers follow-up rounds. A clear "not applicable, because we do not operate our own data centres" closes a question. An empty cell reopens it.
Is an AI-drafted CAIQ acceptable to a customer?+
What a customer objects to is an unbacked claim, not the tool that typed it. That is why every draft here carries its citation and why nothing exports until a person has approved it — the answer you send is one a human signed off, with the evidence attached.
Other assessments we cover: SIG & SIG Lite, HECVAT, VSA, TISAX / VDA ISA, DORA, ISO 27001. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.
Answer your CAIQ v4 with evidence
Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.