Menu
← Guides

CAIQ Lite: how to answer it for a client

What the Cloud Security Alliance's short questionnaire asks, what Yes, No and N/A mean in version 4.1, who owns each control, and how to answer from the client's documents without overclaiming.

Updated 2026-09-22

What CAIQ Lite is

The Consensus Assessments Initiative Questionnaire (CAIQ) is the Cloud Security Alliance's self-assessment questionnaire for cloud services. Every question maps to a control in the Cloud Controls Matrix (CCM), CSA's catalogue of cloud security controls. The full CAIQ v4 follows all of CCM v4; it is long, and most customers never read every row of it.

CAIQ Lite is the reduced version. In v4.1.0 it has about 140 questions drawn from CCM-Lite — a minimum set of foundational requirements, instead of the 207 in the full matrix — organised under the same 17 domains:

  • Audit & Assurance
  • Application & Interface Security
  • Business Continuity Management and Operational Resilience
  • Change Control and Configuration Management
  • Cryptography, Encryption & Key Management
  • Datacenter Security
  • Data Security and Privacy Lifecycle Management
  • Governance, Risk and Compliance
  • Human Resources
  • Identity & Access Management
  • Interoperability & Portability
  • Infrastructure Security
  • Logging and Monitoring
  • Security Incident Management, E-Discovery, & Cloud Forensics
  • Supply Chain Management, Transparency, and Accountability
  • Threat & Vulnerability Management
  • Universal Endpoint Management

Clients meet it in two ways. A customer's procurement or security team sends it as part of buying the client's service. Or the client decides to complete it once and list it in CSA's STAR Registry as a Level 1 self-assessment, so that the next customer can be pointed to it before they ask.

The columns that matter

Each row of the questionnaire tab has a question id — A&A-02.1, IAM-01.1 — the question, and four columns for the response:

  • CSP CAIQ Answer: Yes, No or N/A.
  • SSRM Control Ownership: who is responsible for that part of the control.
  • CSP Implementation Description: optional and recommended. How the control is met, or why it is not.
  • CSC Responsibilities: optional and recommended. What the customer has to do on its own side.

The remaining columns — CCM control id, control specification, title and domain — tell you which control the question tests. Read the control specification when a question is ambiguous: it is usually clearer than the question.

The client is the CSP (cloud service provider). The customer who sent the questionnaire is the CSC (cloud service customer).

Yes, No and N/A mean something precise

CSA defines the three replies narrowly, and the definitions are in the questionnaire's introduction tab:

  • Yes: the part of the CCM control the question covers is met.
  • No: it is in scope of the assessment and not met. A No still names who owns the control, and can explain why it is not implemented and what would be needed.
  • N/A: the question is out of scope and does not apply to the service assessed. The ownership column is left blank, and the description can explain why.

Three mistakes come up again and again.

The policy Yes. A company has an information security policy that says access is reviewed quarterly. Nobody has ever run the review. The question asks whether access rights are reviewed; the honest answer is No, with the policy mentioned in the description. A Yes here is a statement the first follow-up call can disprove.

The planned Yes. A disaster-recovery test is scheduled but has not taken place. The question asks whether business continuity plans are tested. The answer is No, with the plan and — only if one is agreed — its date.

The convenient N/A. A client without a formal HR security programme marks the Human Resources questions N/A. They apply to any company with staff. N/A is for what genuinely does not exist in the service, such as datacenter questions for a company that runs entirely on a cloud provider's infrastructure — and even then the better answer is often "Yes, third-party outsourced".

Control ownership

CAIQ v4 asks who owns each control, using five values:

  • CSP-owned: the client is fully responsible and accountable.
  • CSC-owned: the customer is.
  • Third-party outsourced: a supplier in the chain — typically the infrastructure provider underneath — implements the control, while the client stays fully accountable.
  • Shared CSP and CSC: both share implementation and accountability.
  • Shared CSP and third party: implementation is shared with a supplier, with the client accountable.

A SaaS client running on a major cloud platform will mark physical and environmental security, and much of the infrastructure layer, as third-party outsourced or shared with the third party. That is accurate, and it is not a weakness. It is the supply chain as it is, and customers expect to see it.

Where it gets harder is the boundary with the customer. Identity management is typical: the client secures its platform, the customer decides who in its own organisation gets an account and with what rights. That is "Shared CSP and CSC", and the CSC Responsibilities column is where the customer's part is written down.

Answering from the documents

A client with a current documentation set can answer most of CAIQ Lite from it. A rough map:

CAIQ domainUsually answered from
Audit & Assurance, GovernanceSecurity overview, information security policies
Application & Interface Security, Change ControlSecure development policy
Business ContinuityBusiness continuity and disaster recovery policy
CryptographySecurity overview (encryption at rest and in transit)
Data Security and PrivacyRecords of processing, retention schedule, DPA
Human ResourcesAcceptable use policy, offboarding procedure
Identity & Access ManagementAccess control policy
Logging and MonitoringSecurity overview, access control policy
Security Incident ManagementIncident response policy
Supply ChainVendor management policy, sub-processor list

Work domain by domain, not row by row:

  1. Take the answer from a document section or a confirmed fact, and cite the section in the implementation description. "Access is granted by the CTO and recorded; see Access control policy, section 3."
  2. Where the documents are silent, do not answer from general knowledge of how such companies usually operate. Mark the row for the client to confirm.
  3. Where the client does not have the control, answer No and say what is planned, if a plan exists. Do not invent a date.
  4. Mark N/A only for what genuinely does not apply to the service.

The descriptions matter more than the Yes/No column. A procurement reviewer looking at 140 Yes answers learns nothing; one who reads "encryption at rest is provided by the database provider's platform; we have not audited it ourselves" learns exactly how much weight to put on the answer.

When the facts are not in the documents

Some questions will not be answered by any document the client has: background checks, security awareness training, penetration testing, key rotation. For each, ask the person at the client who actually knows — usually the CTO or the head of engineering — and write the answer down as a confirmed fact, so the next questionnaire does not ask them again.

Be precise about what they tell you. "We use a password manager" answers a different question from "passwords are required to be stored in the company password manager". The second is a control; the first is a habit.

Common follow-up questions

Once the questionnaire is returned, the customer's reviewer will pick a few rows and ask for more. The usual ones:

  • Evidence for a Yes. Which document, which date. Answers drawn from the documentation set can point to it directly.
  • Dates for a No. When will the control be in place? If no date is agreed, say so — a date given under pressure becomes a contractual commitment.
  • Ownership disputes. Why is this control marked as shared? Be ready to explain the boundary in a sentence.
  • Sub-processors. Which suppliers are behind "third-party outsourced". The sub-processor list answers this.

The licence

CSA's copyright notice limits what can be done with the questionnaire. It may be downloaded, viewed and printed; it may not be modified or redistributed; and its use is described as personal, informational and non-commercial. Portions may be quoted with attribution.

In practice that means two routes:

  • Answer the copy the customer sends. Filling in a questionnaire you were asked to complete is what it is for.
  • Submit to the STAR Registry. That is CSA's own channel for publishing a self-assessment.

Publishing a filled-in CAIQ Lite file on the client's own website is redistribution. A trust page can say the questionnaire has been completed and is available on request, or link to the STAR Registry entry.

Keeping it current

A CAIQ answered once and never revisited drifts from reality within months: a new sub-processor, a changed backup schedule, a control that was planned and is now in place. Tie the answers to the facts they came from, so that when a fact changes, the answers that rest on it are flagged for review — not discovered wrong by the next customer.

In clausebench

Upload the customer's CAIQ Lite and choose the question column. Each answer is drafted from the client's confirmed facts and documents and marked confirmed, to check or gap. A confirmed answer names the document section it rests on; a gap is written as an honest "not in place". You review, and the export fills the customer's own copy. Approved answers go to the answer library, so the next questionnaire that asks the same thing starts from what you already approved.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.