Compyl
GRC Your Way

SIG vs CAIQ: Which Security Questionnaire Standard Should You Use?

Compyl Research

SIG vs CAIQ: Which Security Questionnaire Standard Should You Use?

By Compyl ResearchLast updated: August 11, 20267 min read

The SIG and the CAIQ are both standardized security questionnaires, but they solve different problems. Shared Assessments’ SIG is a licensed, broadly scoped third-party risk questionnaire covering 21 risk control areas for any vendor type. The Cloud Security Alliance’s CAIQ is a free, cloud-specific questionnaire of yes/no questions mapped to the Cloud Controls Matrix and published publicly in the STAR Registry.

Key takeaways
  • The SIG is maintained by Shared Assessments, spans 21 risk control areas, and ships in scoped tiers — the 2025 edition ran 128 questions for SIG Lite, 627 for SIG Core, and 1,936 for SIG Detail.
  • The CAIQ is maintained by the Cloud Security Alliance and mirrors the Cloud Controls Matrix. CAIQ v4.1, released January 27, 2026, contains 283 questions aligned to 207 controls across 17 domains.
  • Cost and distribution differ sharply. A standalone SIG license runs $7,000 per year, while the CAIQ is a free download that vendors publish openly to the CSA STAR Registry.
  • Use the CAIQ for cloud and SaaS providers where a public self-assessment already exists; use the SIG for regulated, high-risk, or non-cloud vendors where you need depth on resilience, Nth party, privacy, and ESG.
  • 2026 changed both. CSA set a December 2027 cutover to CAIQ v4.1, and Shared Assessments added ISO 42001 and operational resilience mappings plus a browser-based SIG EV platform launched in March 2026.

What Is the SIG Questionnaire?

The Standardized Information Gathering (SIG) questionnaire is maintained by Shared Assessments, a member-driven third-party risk consortium. Shared Assessments describes the SIG as a “configurable solution enabling the scoping of diverse third-party risk assessments,” updated annually to reflect new risks and regulatory change.

Its defining feature is breadth. The SIG covers 21 risk control areas, including Access Control, Application Management, Artificial Intelligence, Cloud Services, Cybersecurity Incident Management, Environmental/Social/Governance, Nth Party Management, Operational Resilience, Privacy Management, Supply Chain Risk Management, and Threat Management. That range is why it shows up so often in financial services, insurance, and healthcare vendor programs, where an assessment has to cover far more than infrastructure security.

The SIG is not one questionnaire but a content library you scope from. Assessors typically pick one of three presets. In the 2025 edition, Shared Assessments published counts of 128 questions for SIG Lite, 627 for SIG Core, and 1,936 for SIG Detail, with custom scoping available by domain, control family, or regulation. Those totals shift with each annual release, so always confirm against the version you are actually sending.

The SIG also maps to the frameworks your vendors are already certified against — ISO 27001 and 27002, NIST Cybersecurity Framework 2.0, NIST SP 800-53r5 and SP 800-171r3, PCI DSS 4.0, CMMC 2.0, GDPR, and FedRAMP — which is what makes it usable as the backbone of a third-party risk management program rather than a one-off security review.

Access is licensed. Shared Assessments lists a standalone SIG subscription at $7,000 per year for a corporate license, with the SIG included in all membership tiers.

What Is the CAIQ?

The Consensus Assessments Initiative Questionnaire (CAIQ) comes from the Cloud Security Alliance and is the question-form companion to the Cloud Controls Matrix (CCM). CSA defines the CAIQ as “a downloadable spreadsheet of yes or no questions that correspond to the controls of CSA’s Cloud Controls Matrix.” Version 4.0 carried 261 questions, down from 310 in v3.1.

The current release is CAIQ v4.1. CSA published CCM and CAIQ v4.1 on January 27, 2026 with 207 controls organized across 17 domains, and the accompanying transition guidance confirms 283 CAIQ questions aligned to those controls.

The bigger structural difference is distribution. A completed CAIQ is meant to be published, not exchanged bilaterally. CSA’s STAR program uses the CAIQ as its Level 1 self-assessment: providers submit their answers to a public registry at no cost, while Level 2 requires a third-party audit layered on ISO 27001, SOC 2, or equivalent. As of mid-2025, CSA reported the STAR Registry held more than 4,000 assessments.

One recurring misconception is worth killing here: the CAIQ is not a certification. It is a structured self-attestation. That is exactly why buyers should treat a published CAIQ the way they treat any other vendor claim — as a starting point that still needs evidence, much like the material a vendor posts in a trust center.

SIG vs CAIQ: What’s the Difference?

Both are standardized, both reduce bespoke questionnaire churn, and both map to common frameworks. They diverge on ownership model, scope, and how the answers travel.

Dimension SIG (Shared Assessments) CAIQ (Cloud Security Alliance)
Maintained by Shared Assessments (member consortium) Cloud Security Alliance
Underlying framework SIG Content Library, 21 risk control areas Cloud Controls Matrix v4.1 — 207 controls, 17 domains
Current version 2026 SIG workbook (annual release) CAIQ v4.1, published January 27, 2026
Question count 2025 edition: 128 (Lite) / 627 (Core) / 1,936 (Detail) 283 questions in v4.1 (261 in v4.0)
Answer format Yes/No/N/A plus narrative and evidence fields Primarily yes/no with implementation notes
Scope Any third party — cloud, BPO, staffing, logistics, plus privacy, ESG, resilience, Nth party Cloud service providers (IaaS, PaaS, SaaS)
Cost $7,000/year standalone corporate license; included with membership Free download; STAR Level 1 submission free
How answers are shared Exchanged privately between buyer and vendor Published publicly in the CSA STAR Registry
Assurance tier above it Standardized Control Assessment (onsite/validated testing) STAR Level 2 third-party audit
Best for Regulated industries, high-risk and non-cloud vendors, deep due diligence Fast cloud vendor triage and public transparency

The practical takeaway: the CAIQ is optimized for a vendor to answer once for everyone, while the SIG is optimized for a buyer to ask everything that matters for a specific risk tier.

Which Questionnaire Should You Use?

Start with the risk, not the format. Third-party exposure is no longer an edge case: Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of all breaches, a 60% increase year over year. The questionnaire you choose should match how much of that exposure a given vendor actually carries.

Use the CAIQ when

  • The vendor is a cloud or SaaS provider and already has a published CAIQ or STAR entry — you get an answer set today with no vendor effort.
  • You are triaging a long tail of low- to moderate-risk cloud tools and need consistent coverage fast.
  • You want the assessment to be comparable across providers, since every CAIQ maps to the same CCM controls.

Use the SIG when

  • The vendor is regulated, business-critical, or handles sensitive data, and you need depth on resilience, privacy, and subcontractors.
  • The vendor is not a cloud provider at all — payroll processors, call centers, logistics, clinical services — where CCM’s cloud framing leaves gaps.
  • Your program needs one questionnaire that also carries ESG, Nth party, and operational resilience content.
  • You are aligning to a formal vendor risk assessment process with tiered scoping by inherent risk.

Most mature programs do not pick one forever. They accept a published CAIQ for cloud vendors at lower tiers, escalate to SIG Lite or SIG Core as inherent risk rises, and reserve validated onsite testing for the small set of vendors that could take the business down.

What Changed in 2026?

Both standards moved this year, and both moves have deadlines attached.

CAIQ v4.1 starts a two-year cutover. CSA’s CCM v4.1 transition timeline confirms the registry began accepting both v4.0 and v4.1 submissions for STAR Levels 1 and 2 in March 2026; from December 2027 only v4.1-based Level 1 submissions are accepted, and v4.0.x is withdrawn in January 2028. The update adds 11 new control specifications across five domains — datacenter security, logging and monitoring, security incident management, supply chain management, and threat and vulnerability management — and removes one identity control. If you rely on vendor CAIQs, expect a mixed-version registry through 2027.

The 2026 SIG leans into AI and resilience. Per an analysis of the 2026 SIG update, the release adds a mapping to ISO/IEC 42001 for AI management systems, integrates Operational Resilience Framework content, and deepens the NIST SP 800-171 mapping for defense supply chain work — without expanding the domain count.

The SIG left the spreadsheet. Shared Assessments launched SIG Evolution (SIG EV) on March 17, 2026 at its Third Party Risk USA Summit: a browser-based platform that keeps the same questionnaire content but replaces Excel-based workflow with automated comparison and direct import of existing workbooks, while still allowing vendors to answer offline.

How Is AI Changing Security Questionnaires?

AI is reshaping questionnaires in three directions at once, and it matters for both sides of the exchange.

AI is answering them. Response teams now draft answers from an evidence library and prior submissions rather than starting cold, which is what makes security questionnaire automation the difference between a two-week turnaround and a two-day one. The discipline that makes it work is unglamorous: a curated, current answer library and named human review before anything goes out. A confidently wrong AI answer on a SIG is a misrepresentation, not a typo. Teams that want to answer questionnaires faster should invest in source-of-truth evidence first and generation second.

AI is validating them. CSA launched Valid-AI-ted on June 11, 2025 to score STAR Level 1 CAIQ submissions automatically, giving per-control feedback “in minutes instead of waiting weeks for manual spot checks” and letting buyers filter registry listings by score. CSA prices Valid-AI-ted at $595 for non-members, free for corporate members. That is a meaningful signal: the receiving side is starting to grade questionnaire quality mechanically.

AI is now the subject of the questions. Artificial Intelligence is already one of the SIG’s 21 risk control areas, and CSA launched STAR for AI on October 23, 2025, with Level 1 built on an AI CAIQ self-assessment and Level 2 tied to ISO/IEC 42001 certification. AI Controls Matrix v1.1, released July 14, 2026, expanded to 247 control objectives across 18 domains with a 320-question AI-CAIQ and a new Model Security domain covering model poisoning and prompt injection. Expect vendor AI questions to arrive as their own questionnaire, not as three bolt-on lines in your existing one.

Frequently asked questions

Is the CAIQ free to use?
Yes. The CAIQ is a free download from the Cloud Security Alliance, and submitting a completed CAIQ to the STAR Registry as a Level 1 self-assessment costs nothing. Optional add-ons carry fees: CSA prices its Valid-AI-ted scoring service at $595 for non-members, free for corporate members.
How many questions are in SIG Lite versus SIG Core?
In the 2025 SIG release, Shared Assessments published 128 questions for SIG Lite, 627 for SIG Core, and 1,936 for SIG Detail. Counts change with each annual edition and can be customized by scoping to specific risk domains, control families, or regulations, so confirm totals against the version you send.
Is the CAIQ a certification?
No. A CAIQ is a structured self-assessment against the Cloud Controls Matrix, published as STAR Level 1. Certification sits one tier up: STAR Level 2 requires an independent third-party audit built on an existing standard such as ISO 27001 or SOC 2. Treat a CAIQ as a claim requiring evidence.
When do vendors have to move to CAIQ v4.1?
CSA’s STAR Registry began accepting both v4.0 and v4.1 submissions in March 2026. From December 2027, only Level 1 submissions based on CAIQ v4.1 are accepted, and CCM and CAIQ v4.0.x are withdrawn in January 2028. Plan the re-mapping work before your next registry refresh.
Can you use the SIG and the CAIQ together?
Yes, and many programs do. A common pattern is accepting a vendor’s published CAIQ for lower-tier cloud services, then escalating to SIG Lite or SIG Core for regulated, business-critical, or non-cloud vendors. Sending both to the same vendor simultaneously duplicates effort without adding meaningful assurance.
Does the SIG cover AI risk?
Yes. Artificial Intelligence is one of the SIG’s 21 risk control areas, and the 2026 release added a mapping to ISO/IEC 42001 for AI management systems. For deeper AI-specific due diligence, CSA’s AI Controls Matrix v1.1 and its 320-question AI-CAIQ provide a dedicated assessment path.

Answer SIG and CAIQ Questionnaires Faster with Compyl

Compyl’s agentic GRC platform keeps a single source of truth for your controls and evidence, then maps it to SIG, CAIQ, and custom questionnaires so responses draft themselves and stay current. Book a demo to see how teams cut questionnaire turnaround from weeks to days.

Request a demo →

About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies