← All postsHow-to

CAIQ: the cloud questionnaire worth filling in before anyone asks

The CAIQ is a spreadsheet of a few hundred yes-or-no questions about your cloud service. Completing it once turns most incoming security questionnaires into a file attachment.

How-toC

The CAIQ — Consensus Assessments Initiative Questionnaire — is a standardised set of questions published by the Cloud Security Alliance for cloud service providers to document their security controls. It maps to the Cloud Controls Matrix, the CSA’s control framework, and it exists so that providers and customers stop inventing a new questionnaire for every deal.

For a provider its value is leverage. Completing it once, properly, gives you a document you can send in response to most incoming enquiries — and because it is recognised, buyers frequently accept it in place of their own list. For a customer it does the reverse: it lets you compare two suppliers on the same questions instead of on two differently-shaped marketing pages.

What the CAIQ covers

  • Control domains spanning application security, identity and access management, encryption and key management, logging and monitoring, business continuity, supply chain, threat and vulnerability management, and governance.
  • A yes or no answer per question, with room to explain — and the explanation is what a serious reader actually reads.
  • The shared responsibility position: which control is yours, which is the customer’s, and which is inherited from your own cloud provider. This is the part most often filled in carelessly and most often queried.
  • Alignment to the Cloud Controls Matrix, which is what lets a buyer map your answers to their own framework.

Self-assessment, and what it is worth

A completed CAIQ can be published to the CSA’s STAR Registry as a self-assessment, which is the entry level of that programme; higher levels involve third-party audit. Be clear-eyed about what the self-assessment signals: it shows the provider has done the work of documenting its controls and is willing to publish the answers, which is genuinely more than most do — and it remains a self-report. Buyers who care will still ask for the audit report behind the claims, and providers who publish one should expect that.

Answer the shared responsibility questions precisely. "Yes" against a control your customer actually operates is not a small inaccuracy — it is the answer that produces an argument after an incident, when both sides discover each assumed the other had it covered.

Keeping it current is the hard part

The CAIQ is filled in once with great effort and then rots quietly. Your subprocessor list changes, a control is automated, the penetration test cadence shifts, a region is added. A stale questionnaire is worse than none, because it is being relied on. Set a review cycle — annually at minimum, plus a trigger on any material infrastructure change — and give each domain an owner rather than leaving the whole sheet to one person who has since changed jobs.

It is a spreadsheet, so treat it as one

Ettex Sheets holds the completed questionnaire with a column for the answer, the explanation, the owner and the last review date, so what is stale is visible at a glance; Ettex Records keeps the evidence behind each domain and the versions sent to specific customers; and the wider process of responding to buyers is covered in security questionnaire.

Plainly: this is a spreadsheet and a record, not a compliance platform, and we are not the CSA. The questionnaire and the Cloud Controls Matrix are the CSA’s documents, published on their site, and the registry is theirs to run.

Frequently asked

What is the CAIQ?

The Consensus Assessments Initiative Questionnaire — a standardised set of security questions for cloud service providers, published by the Cloud Security Alliance and mapped to the Cloud Controls Matrix.

Is the CAIQ audited?

The basic level is a self-assessment. Higher levels of the CSA STAR programme involve third-party audit; the self-assessment is a published self-report.

Do we have to complete it?

No, it is voluntary. Providers complete it because it answers most incoming buyer questionnaires with one document.

How often should it be updated?

At least annually, and whenever infrastructure, subprocessors or controls change materially. A stale questionnaire is relied on by buyers, which makes it worse than none.

DK
Written by Daria K.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.