← All posts

CAIQ vs SIG: Which Questionnaire Should You Maintain?

If you sell cloud-hosted software, you will eventually be asked for both a SIG and a CAIQ — sometimes by the same buyer, sometimes within the same week. They look similar, they cover overlapping ground, and they are not interchangeable. Knowing which one belongs where saves real time.

Two questionnaires, two publishers, two audiences

The SIG — the Standardized Information Gathering questionnaire — is published by Shared Assessments, originally created for financial-services vendor due diligence and now used as a general-purpose third-party risk questionnaire across industries. It spans the full range of third-party risk domains and assesses any kind of vendor: software, infrastructure, professional services, anyone touching the buyer’s data or systems.

The CAIQ — the Consensus Assessment Initiative Questionnaire — is published by the Cloud Security Alliance. It is purpose-built for cloud service providers. The current release (CAIQ v4) maps directly to the Cloud Controls Matrix, the CSA’s controls framework specifically for cloud services. If your offering is delivered as SaaS, PaaS, or IaaS, the CAIQ is the cloud-specific questionnaire buyers will use to evaluate you.

Both are spreadsheets. Both ask Yes/No/N/A questions with evidence requests. Both are designed to be filled in once and reused across many buyers. The differences are scope and depth — not format.

How they overlap

A substantial fraction of the CAIQ overlaps with the cloud-hosting section of the SIG. Both ask about:

  • How customer data is segregated in shared infrastructure
  • Encryption at rest and in transit
  • Key management and rotation
  • Identity and access management for the cloud control plane
  • Audit logging for administrative and customer actions
  • Incident response specific to cloud workloads
  • Service-level commitments and data portability
  • Compliance with cloud-relevant frameworks (SOC 2, ISO 27017, ISO 27018, FedRAMP)

If you have answered one honestly, you have most of the substance for the other. The wording, the framework references, and the level of cloud-specific detail differ — so a copy-and-paste between the two will produce answers that sound off, but the underlying facts and evidence are the same.

Where they diverge

The CAIQ goes deeper than the SIG on cloud-native concerns:

  • Multi-tenancy isolation. How customer A is prevented from accessing customer B’s data when both share underlying infrastructure
  • API security. Authentication, authorisation, rate limiting, and abuse detection for service APIs
  • Hypervisor and container security. How the underlying virtualisation or container runtime is hardened and patched
  • Service composition. Which subservice providers (other CSPs, CDN providers, payment processors) you depend on and how their controls flow through to your customers
  • Customer-managed configuration. Which settings the customer controls vs which the provider controls — a key concept the SIG mostly ignores

The SIG goes deeper than the CAIQ on:

  • Corporate governance, board oversight, and risk-management programmes
  • Human resources security (background checks, training, terminations)
  • Physical security of corporate offices and data centres
  • Detailed application development lifecycle questions for any custom-built software
  • End-user device security for your workforce

If you’re a small cloud-software company, the CAIQ probes the architecture of your service; the SIG probes the architecture of your business. Both matter, and they probe different things.

When buyers send each one

Buyers send the CAIQ when:

  • Their procurement process explicitly flags cloud or SaaS vendors for additional review
  • Their security or risk team is cloud-literate and prefers cloud-native frameworks
  • They are themselves regulated by a body (financial services, healthcare) that expects cloud-specific due diligence
  • They have standardised on CSA frameworks internally
  • They have already received your SOC 2 report and want to dig deeper into cloud architecture

Buyers send the SIG when:

  • Their procurement runs a general-purpose vendor review programme not specific to cloud
  • They evaluate many kinds of vendors (cloud, on-prem, professional services) and want one consistent format
  • They are in a regulated industry that has long-standing Shared Assessments adoption (banking, insurance)
  • They want a broader picture of your business and operations, not just your cloud service

Many buyers send both, often staggered: SIG first as the general vendor onboarding, CAIQ later when their cloud security team gets involved. Some buyers send a single hybrid spreadsheet built from both.

Do you need to maintain both

If your only offering is a cloud-hosted product and you sell into industries where the CAIQ is the dominant questionnaire, maintaining a CAIQ alone is workable — and the CSA STAR registry actually lets you publish your completed CAIQ so prospects can self-serve. This shortens many vendor onboardings significantly.

In practice, though, most companies that face one questionnaire face both. The realistic posture is to maintain a single answer library structured by topic rather than by questionnaire — access control, encryption, incident response — and then map answers into whichever spreadsheet a buyer sends. The work is in writing and evidencing each answer once; reformatting into a different spreadsheet is mechanical.

Where to start

Three realistic options when the questionnaires start arriving:

  1. Answer each one from scratch on demand. Works for the first one or two; doesn’t scale once both formats are in rotation. The third spreadsheet that lands in your inbox in a single quarter is the moment teams switch to option two.
  2. Build a topic-indexed answer library. Worth doing the moment you face the second questionnaire. Our step-by-step questionnaire playbook walks the structure, and the free SIG Lite answer-library template gives you a starting frame that translates to CAIQ rows just as well.
  3. Outsource the response. If a SIG, SIG Lite, or CAIQ is blocking a live deal and you don’t have the bandwidth, vendor security questionnaire help answers the full document at a fixed price quoted up front, with a typical turnaround of about three days. You keep the populated library at the end, so the next CAIQ or SIG is straightforward.

The questionnaire that comes next won’t be the last one. The answer library is the part that compounds; everything else is a one-time exercise.

FAQ

Can we send a CAIQ in place of a SIG?

Some buyers accept it for the cloud-hosting questions; most do not accept it as a full replacement. The SIG asks about parts of your business — HR, governance, physical security — that the CAIQ doesn’t cover. Send what was asked for unless the buyer explicitly invites a substitution.

Where do I get the official CAIQ?

The current CAIQ template is published by the Cloud Security Alliance at cloudsecurityalliance.org under the Cloud Controls Matrix. The current major version is CAIQ v4. The spreadsheet is free to download. Self-publishing your completed CAIQ in the CSA STAR registry is optional but accelerates many vendor onboardings.

Is the CAIQ the same as STAR Level 1?

CAIQ Self-Assessment is the document. STAR Level 1 is the public registry tier where a vendor uploads a completed CAIQ for buyers to view. STAR Level 2 adds a third-party audit on top of the self-assessment. STAR Level 3 adds continuous monitoring. If you’re starting from zero, completing the CAIQ and publishing it as STAR Level 1 is the first step.

Does SOC 2 replace either questionnaire?

No, but it shortens both. A SOC 2 report describes which controls you run and whether they operated effectively — buyers can cite it against many SIG and CAIQ questions instead of asking you to re-answer them. You still complete the questionnaire; many cells are shorter because they point at the report.