CAIQ v4 Explained: What It Is and How to Fill It In
If you sell SaaS to enterprises, CAIQ is the questionnaire you will meet most often. It is worth understanding properly, because answering it well makes almost every other questionnaire easier.
What CAIQ is
The Consensus Assessments Initiative Questionnaire is published by the Cloud Security Alliance. It is the questionnaire form of the Cloud Controls Matrix (CCM). For each control in the CCM, CAIQ asks whether you implement it.
Version 4 covers 17 control domains and roughly 260 questions:
| Domain | What it covers |
|---|---|
| A&A | Audit and assurance |
| AIS | Application and interface security |
| BCR | Business continuity and operational resilience |
| CCC | Change control and configuration management |
| CEK | Cryptography, encryption and key management |
| DCS | Datacenter security |
| DSP | Data security and privacy lifecycle |
| GRC | Governance, risk and compliance |
| HRS | Human resources security |
| IAM | Identity and access management |
| IPY | Interoperability and portability |
| IVS | Infrastructure and virtualisation security |
| LOG | Logging and monitoring |
| SEF | Security incident management and forensics |
| STA | Supply chain management and transparency |
| TVM | Threat and vulnerability management |
| UEM | Universal endpoint management |
How the answer format works
Each question takes a Yes, No, or NA, plus free text.
The dropdown matters more than it looks. These are data-validated cells: writing "Partially" or "Yes, but only in production" into a cell that only accepts Yes/No/NA will make Excel flag the file as invalid when your customer opens it. Put the nuance in the comment column, not the answer column.
CAIQ v4 also introduces shared responsibility columns, saying whether the control is owned by you, by your cloud provider, or shared. Filling these in honestly is one of the fastest ways to look competent, because it shows you understand where your obligations actually stop.
Where teams get it wrong
Answering Yes because the cloud provider does it. If AWS encrypts the disk, that is AWS's control, not yours. The shared responsibility column exists precisely for this. Claiming it as your own control is the kind of thing that unravels badly during an audit.
Treating NA as a soft no. NA means the control genuinely does not apply. You have no datacenters because you are entirely on managed cloud, so physical datacenter controls are not yours. It does not mean "we haven't got to this yet". That is a No.
Inconsistency across domains. CAIQ asks about encryption in CEK, in DSP, and obliquely in IVS. Answer them on different days and you will describe your posture three different ways. Reviewers notice.
Leaving the comment blank on a Yes. A bare Yes invites a follow-up. "Yes. AES-256 at rest via AWS KMS with customer-managed keys, documented in our Encryption Standard §3" ends the conversation.
Writing it fresh every time. CAIQ does not change much between customers. If you are re-deriving the same 260 answers for each prospect, that is the actual cost, not the questionnaire itself.
Should you publish it?
CSA maintains the STAR Registry, where you can publish a completed CAIQ publicly. For companies selling into enterprise, this is often worth doing: a prospect who can download your CAIQ before contacting you is a prospect who does not send you their own questionnaire.
The tradeoff is that you are publishing a detailed description of your security posture, including its gaps. Most companies find that acceptable; some do not. Decide deliberately.
A practical order of work
- Answer GRC, IAM and CEK first. They are the domains buyers weight most heavily, and the answers feed the rest.
- Do the shared responsibility columns as you go, not afterwards.
- Mark anything you are unsure about rather than guessing, and batch those to whoever knows.
- Keep every answer. The next CAIQ should be a review, not a rewrite.
FillTrust detects CAIQ's layout automatically, including the dropdown constraints, and drafts answers from your own documentation. Try it with a real CAIQ.