SIG Lite vs. CAIQ Lite: which questionnaire your client is being sent
Two standard vendor questionnaires, two different owners and licences. What each covers, who asks for which, and how to answer both from one set of documents.
Updated 2026-09-22
Two standards, one purpose
Both questionnaires exist so that a customer does not have to write its own list of security questions for every supplier, and so that a supplier does not have to answer a hundred differently worded versions of the same list. Both come in a full version and a shorter one. For a consultant, both arrive the same way: a client forwards a spreadsheet and a deadline.
They differ in who publishes them, what they are built around, who tends to send them, and what you are allowed to do with them afterwards. Getting those differences right saves rework and avoids answers the customer's reviewer reads the wrong way.
CAIQ Lite at a glance
- Publisher: the Cloud Security Alliance (CSA).
- Built around: the Cloud Controls Matrix (CCM). Every question maps to a CCM control. Version 4.1 of CAIQ Lite has about 140 questions under the CCM's 17 domains, drawn from CCM-Lite, a minimum set of foundational requirements.
- Answers:
Yes,NoorN/Aper question; who owns the control — the provider, the customer, a third party in the supply chain, or shared; and two optional descriptions: how the provider meets the control, and what the customer must do on its side. - Who sends it: customers buying cloud and SaaS services. It is also the form of a Level 1 self-assessment in CSA's STAR Registry.
- Licence: free to download, but it may not be modified or redistributed, and its use is described as personal, informational and non-commercial.
SIG Lite at a glance
- Publisher: Shared Assessments, as part of the Standardized Information Gathering questionnaire (SIG).
- Built around: third-party risk management across many kinds of supplier, not only cloud services. Questions are grouped by risk domain and mapped to a range of frameworks and regulations, which is why regulated industries like it.
- Answers: mostly
Yes,NoorN/Awith comments. The customer usually scopes which sections apply to the supplier before sending it. - Who sends it: larger enterprises, financial institutions and others with a formal third-party risk programme; typically the customer's risk or vendor management team.
- Licence: licensed by Shared Assessments. Suppliers normally answer the copy the customer provides rather than publishing a version of their own.
The number of questions in both changes with each release. Quote the version printed on the file you were sent rather than a number from memory.
How to tell which one arrived
Open the workbook and look at three things:
- Question ids. CAIQ uses control-style ids such as
IAM-01.1orDSP-07.1. SIG ids are grouped by risk domain. - Answer columns. CAIQ has "CSP CAIQ Answer" and "SSRM Control Ownership". SIG has its own response and comment columns, and often a scoping tab that the customer has filled in.
- The cover tab. Both name their publisher and version. A customer's own questionnaire derived from either will usually say so, or will look like one of them with its numbering removed.
If it is a customer's own questionnaire, it is still worth knowing which standard it came from: the definitions of the answers usually carry over.
The unit of assessment is different
The single most useful thing to know before answering:
- CAIQ asks about the service — the cloud product being bought. "Is data encrypted at rest?" means the data in that service.
- SIG asks about the organisation as a supplier — its governance, people, resilience and its own suppliers, as well as the service it provides.
So SIG asks things CAIQ rarely does: background screening of staff, security awareness training, board oversight of risk, insurance, business resilience across the organisation. For a small client, many of those answers will be No or partial. That is normal, and the customer's risk team expects it from a supplier of that size.
Ownership, and where the lines are
CAIQ makes ownership explicit: each control is the provider's, the customer's, a third party's, or shared. A SaaS client running on a large cloud platform will mark physical security and much of the infrastructure as outsourced to a third party. That is accurate and expected.
SIG handles the same reality differently: questions about the supplier's own suppliers — fourth parties, in third-party risk language — and how they are assessed. The answer comes from the same place: the client's vendor management policy and its sub-processor list.
One set of documents answers both
The wording differs; the facts do not. Both questionnaires ask whether access is reviewed, whether data is encrypted, whether there is an incident response process, how backups work and how suppliers are chosen. A client whose documents state those facts accurately — including what is not in place yet — can answer either questionnaire without starting again.
A practical map from topic to document:
| Topic | Both questionnaires ask | Answered from |
|---|---|---|
| Access control | Who gets access, reviews, offboarding | Access control policy |
| Encryption | At rest, in transit, key management | Security overview |
| Incidents | Detection, response, notification | Incident response policy |
| Continuity | Backups, recovery, testing | Business continuity policy |
| Suppliers | Selection, contracts, review | Vendor management policy, sub-processor list |
| Privacy | Purposes, retention, data subject rights | Privacy policy, records of processing, retention schedule |
| Development | Secure development, change control | Secure development policy |
| People | Screening, training, acceptable use | Acceptable use policy, and the client itself |
The last row is where SIG needs more than the documents. Ask the client, and record the answer as a confirmed fact so the next questionnaire does not ask again.
Honest answers read better than optimistic ones
In both questionnaires the temptation is the same: answer Yes wherever a policy mentions the topic. Resist it. The reviewer on the other side compares answers against each other and against the documents they asked for. A Yes to "access is reviewed quarterly" next to a policy that says "annually" is the row they will ask about.
A No with a plan is a normal answer from a growing company. "Not yet in place; planned" — without a date unless one is agreed — is better than a Yes that turns into a contractual warranty.
Which to offer proactively
For a SaaS client, completing CAIQ Lite and listing it in the STAR Registry is a reasonable way to answer "do you have a security questionnaire?" before it is asked. It fits the service-level unit and it is CSA's own publication route.
SIG is rarely offered proactively. It arrives from a specific customer, scoped by them, and is answered in their copy.
A trust page is where both meet: it can list the completed questionnaires as available on request, alongside the documents the answers rest on.
After the first one
The second questionnaire is where preparation pays off. Keep every approved answer with the fact or document section it came from. The next questionnaire — CAIQ, SIG or the customer's own — then starts from answers the client already confirmed, and when a fact changes, the answers that relied on it are known.
The same question, asked twice
Take encryption at rest. CAIQ Lite asks, in the Cryptography domain, whether data at rest is encrypted, and expects a Yes, No or N/A with an owner. A SaaS client on a managed database whose provider encrypts storage by default answers Yes, marks it as shared with the third party or outsourced to it, and says in the description that encryption is provided by the database provider's platform.
SIG asks about the same control from the supplier's side: whether a data classification policy defines what must be encrypted, whether keys are managed and by whom, and whether encryption covers backups and portable devices as well. The honest answers may be: encryption by the platform, yes; a classification policy, no; keys managed by the provider, yes; laptops, only where the operating system enforces it.
Nothing in the second set contradicts the first. It is more of the same fact, seen from the organisation rather than the service. That is why keeping answers tied to facts, rather than to the wording of one questionnaire, pays off: the facts carry over, the wording does not.
What clients usually ask
"Can we just send our last one?" Sometimes. A customer that asked for SIG will not accept a CAIQ, but will often accept an answered questionnaire as supporting evidence alongside its own scoped copy.
"Do we need both?" Only if customers ask for both. Complete the one in front of you; keep the answers for the next.
"Will a No lose us the deal?" Rarely on its own. A pattern of optimistic Yes answers that the documents do not support is more likely to.
In clausebench
Both are uploaded the same way: choose the question column and the answers are drafted from the client's confirmed facts and documents, each marked confirmed, to check or gap. Approved answers go to the library, so the SIG that follows the CAIQ starts with the overlapping answers already written, and the export fills the customer's own file.