Based on CSA CCM v4 / CAIQ 4.1

CAIQ Assessment for Cloud & SaaS Security

Assess your SaaS or cloud service against the Cloud Security Alliance Consensus Assessments Initiative Questionnaire — the standard buyers use to evaluate cloud providers. Find your control gaps and get an actionable plan to close them.

What Is the CAIQ?

The Consensus Assessments Initiative Questionnaire (CAIQ) is published by the Cloud Security Alliance (CSA) as part of the STAR program. It offers a standardized set of questions that cloud customers and auditors use to assess the security posture of SaaS and cloud service providers.

Each question maps directly to a control in the Cloud Controls Matrix (CCM), CSA's cybersecurity control framework for cloud computing — currently at version 4.1 with 207 controls across 17 security domains.

If you sell B2B software, chances are your enterprise customers will send you a CAIQ during procurement or vendor due diligence. Being ready means knowing where you stand before they ask.

Why It Matters

  • Answer procurement questionnaires faster

    Your completed assessment becomes reusable evidence for RFPs and security reviews.

  • Build customer trust early

    Publishing your security posture removes friction from sales conversations.

  • Find gaps before auditors do

    A structured self-assessment surfaces weak controls before they become findings.

  • Complement ISO 27001

    ISO covers your organization's ISMS; CAIQ covers your cloud service controls. Together they tell the full story.

17 Security Domains Covered

The CCM organizes cloud security controls into 17 domains — from identity and access management to supply chain transparency.

01Audit & Assurance
02Application & Interface Security
03Business Continuity & Operational Resilience
04Change Control & Configuration Management
05Cryptography, Encryption & Key Management
06Datacenter Security
07Data Security & Privacy Lifecycle Management
08Governance, Risk & Compliance
09Human Resources
10Identity & Access Management
11Interoperability & Portability
12Infrastructure & Virtualization Security
13Incident Management
14Security Incident Management & Cloud Forensics
15Supply Chain Management & Transparency
16Threat & Vulnerability Management
17Universal Endpoint Management

From Answers to Action

Not just a questionnaire score — a complete path to closing your cloud security gaps

Score Your Posture

Rate each control area and get an instant cloud security coverage view.

Identify Gaps

See exactly which controls are missing or partial, ranked by severity.

AI Remediation

Each gap comes with concrete steps, recommended tools, cost, and effort.

Fix on a Roadmap

Prioritized 30/90/180-day plan so improvements happen in the right order.

SaaS Providers

Prepare for enterprise security reviews and shorten sales cycles with a defensible security posture.

Cloud Service Teams

Benchmark your controls against the industry-standard framework your customers already know.

Procurement & Buyers

Understand what a completed CAIQ tells you about a vendor — and what to ask next.

Availability note: our free assessment today is based on ISO/IEC 27001:2022 and covers the organizational, people, physical, and technological practices that overlap heavily with CCM domains. A dedicated standalone CAIQ questionnaire module is rolling out next. Start with the free assessment now — your results and account carry forward when the CAIQ module ships.

Know Your Cloud Security Before Your Customers Ask

Start with a free assessment. Get your security score, gap analysis, and remediation plan in about 30 minutes.

    Feedback
    Back to Top