CAIQ Lite: how to answer it for a client
What the Cloud Security Alliance's short questionnaire asks, what Yes, No and N/A mean in version 4.1, who owns each control, and how to answer from the client's documents without overclaiming.
Updated 2026-09-22
What CAIQ Lite is
The Consensus Assessments Initiative Questionnaire (CAIQ) is the Cloud Security Alliance's self-assessment questionnaire for cloud services. Every question maps to a control in the Cloud Controls Matrix (CCM), CSA's catalogue of cloud security controls. The full CAIQ v4 follows all of CCM v4; it is long, and most customers never read every row of it.
CAIQ Lite is the reduced version. In v4.1.0 it has about 140 questions drawn from CCM-Lite — a minimum set of foundational requirements, instead of the 207 in the full matrix — organised under the same 17 domains:
- Audit & Assurance
- Application & Interface Security
- Business Continuity Management and Operational Resilience
- Change Control and Configuration Management
- Cryptography, Encryption & Key Management
- Datacenter Security
- Data Security and Privacy Lifecycle Management
- Governance, Risk and Compliance
- Human Resources
- Identity & Access Management
- Interoperability & Portability
- Infrastructure Security
- Logging and Monitoring
- Security Incident Management, E-Discovery, & Cloud Forensics
- Supply Chain Management, Transparency, and Accountability
- Threat & Vulnerability Management
- Universal Endpoint Management
Clients meet it in two ways. A customer's procurement or security team sends it as part of buying the client's service. Or the client decides to complete it once and list it in CSA's STAR Registry as a Level 1 self-assessment, so that the next customer can be pointed to it before they ask.
The columns that matter
Each row of the questionnaire tab has a question id — A&A-02.1, IAM-01.1 —
the question, and four columns for the response:
- CSP CAIQ Answer:
Yes,NoorN/A. - SSRM Control Ownership: who is responsible for that part of the control.
- CSP Implementation Description: optional and recommended. How the control is met, or why it is not.
- CSC Responsibilities: optional and recommended. What the customer has to do on its own side.
The remaining columns — CCM control id, control specification, title and domain — tell you which control the question tests. Read the control specification when a question is ambiguous: it is usually clearer than the question.
The client is the CSP (cloud service provider). The customer who sent the questionnaire is the CSC (cloud service customer).
Yes, No and N/A mean something precise
CSA defines the three replies narrowly, and the definitions are in the questionnaire's introduction tab:
- Yes: the part of the CCM control the question covers is met.
- No: it is in scope of the assessment and not met. A No still names who owns the control, and can explain why it is not implemented and what would be needed.
- N/A: the question is out of scope and does not apply to the service assessed. The ownership column is left blank, and the description can explain why.
Three mistakes come up again and again.
The policy Yes. A company has an information security policy that says access is reviewed quarterly. Nobody has ever run the review. The question asks whether access rights are reviewed; the honest answer is No, with the policy mentioned in the description. A Yes here is a statement the first follow-up call can disprove.
The planned Yes. A disaster-recovery test is scheduled but has not taken place. The question asks whether business continuity plans are tested. The answer is No, with the plan and — only if one is agreed — its date.
The convenient N/A. A client without a formal HR security programme marks the Human Resources questions N/A. They apply to any company with staff. N/A is for what genuinely does not exist in the service, such as datacenter questions for a company that runs entirely on a cloud provider's infrastructure — and even then the better answer is often "Yes, third-party outsourced".
Control ownership
CAIQ v4 asks who owns each control, using five values:
- CSP-owned: the client is fully responsible and accountable.
- CSC-owned: the customer is.
- Third-party outsourced: a supplier in the chain — typically the infrastructure provider underneath — implements the control, while the client stays fully accountable.
- Shared CSP and CSC: both share implementation and accountability.
- Shared CSP and third party: implementation is shared with a supplier, with the client accountable.
A SaaS client running on a major cloud platform will mark physical and environmental security, and much of the infrastructure layer, as third-party outsourced or shared with the third party. That is accurate, and it is not a weakness. It is the supply chain as it is, and customers expect to see it.
Where it gets harder is the boundary with the customer. Identity management is typical: the client secures its platform, the customer decides who in its own organisation gets an account and with what rights. That is "Shared CSP and CSC", and the CSC Responsibilities column is where the customer's part is written down.
Answering from the documents
A client with a current documentation set can answer most of CAIQ Lite from it. A rough map:
| CAIQ domain | Usually answered from |
|---|---|
| Audit & Assurance, Governance | Security overview, information security policies |
| Application & Interface Security, Change Control | Secure development policy |
| Business Continuity | Business continuity and disaster recovery policy |
| Cryptography | Security overview (encryption at rest and in transit) |
| Data Security and Privacy | Records of processing, retention schedule, DPA |
| Human Resources | Acceptable use policy, offboarding procedure |
| Identity & Access Management | Access control policy |
| Logging and Monitoring | Security overview, access control policy |
| Security Incident Management | Incident response policy |
| Supply Chain | Vendor management policy, sub-processor list |
Work domain by domain, not row by row:
- Take the answer from a document section or a confirmed fact, and cite the section in the implementation description. "Access is granted by the CTO and recorded; see Access control policy, section 3."
- Where the documents are silent, do not answer from general knowledge of how such companies usually operate. Mark the row for the client to confirm.
- Where the client does not have the control, answer No and say what is planned, if a plan exists. Do not invent a date.
- Mark N/A only for what genuinely does not apply to the service.
The descriptions matter more than the Yes/No column. A procurement reviewer looking at 140 Yes answers learns nothing; one who reads "encryption at rest is provided by the database provider's platform; we have not audited it ourselves" learns exactly how much weight to put on the answer.
When the facts are not in the documents
Some questions will not be answered by any document the client has: background checks, security awareness training, penetration testing, key rotation. For each, ask the person at the client who actually knows — usually the CTO or the head of engineering — and write the answer down as a confirmed fact, so the next questionnaire does not ask them again.
Be precise about what they tell you. "We use a password manager" answers a different question from "passwords are required to be stored in the company password manager". The second is a control; the first is a habit.
Common follow-up questions
Once the questionnaire is returned, the customer's reviewer will pick a few rows and ask for more. The usual ones:
- Evidence for a Yes. Which document, which date. Answers drawn from the documentation set can point to it directly.
- Dates for a No. When will the control be in place? If no date is agreed, say so — a date given under pressure becomes a contractual commitment.
- Ownership disputes. Why is this control marked as shared? Be ready to explain the boundary in a sentence.
- Sub-processors. Which suppliers are behind "third-party outsourced". The sub-processor list answers this.
The licence
CSA's copyright notice limits what can be done with the questionnaire. It may be downloaded, viewed and printed; it may not be modified or redistributed; and its use is described as personal, informational and non-commercial. Portions may be quoted with attribution.
In practice that means two routes:
- Answer the copy the customer sends. Filling in a questionnaire you were asked to complete is what it is for.
- Submit to the STAR Registry. That is CSA's own channel for publishing a self-assessment.
Publishing a filled-in CAIQ Lite file on the client's own website is redistribution. A trust page can say the questionnaire has been completed and is available on request, or link to the STAR Registry entry.
Keeping it current
A CAIQ answered once and never revisited drifts from reality within months: a new sub-processor, a changed backup schedule, a control that was planned and is now in place. Tie the answers to the facts they came from, so that when a fact changes, the answers that rest on it are flagged for review — not discovered wrong by the next customer.
In clausebench
Upload the customer's CAIQ Lite and choose the question column. Each answer is drafted from the client's confirmed facts and documents and marked confirmed, to check or gap. A confirmed answer names the document section it rests on; a gap is written as an honest "not in place". You review, and the export fills the customer's own copy. Approved answers go to the answer library, so the next questionnaire that asks the same thing starts from what you already approved.