The Frameworks Behind Every Assessment
EvaluationCat maps its assessments to recognized standards — not proprietary checklists. Here's what each framework covers and when to use it.
ISO/IEC 27001:2022
Information Security Management Systems
- Evaluates
- Your organization's overall ISMS
- Structure
93 Annex A controls
4 domains: organizational, people, physical, technological
- Answers
- “How well does my organization manage information security?”
- About
- The international standard for information security management. Annex A defines the control set; certification requires an accredited external audit, while self-assessment establishes your readiness baseline.
CSA CCM v4 / CAIQ 4.1
Cloud Controls Matrix & Consensus Assessments Initiative Questionnaire
- Evaluates
- Your SaaS / cloud service controls
- Structure
207 controls (CCM v4.1)
17 security domains, IAM to supply chain
- Answers
- “How secure is my cloud service as a product?”
- About
- Published by the Cloud Security Alliance as part of the STAR program. The CCM defines cloud security controls; the CAIQ turns them into standardized questions buyers use in vendor due diligence.
CSA AI-CAIQ v2.0
AI-specific extension of the CAIQ
- Evaluates
- Governance, security & privacy of AI systems
- Structure
242 control questions across 18 domains
Dedicated Model Security domain
- Answers
- “How responsibly is my AI system built and operated?”
- About
- Adapts the CAIQ methodology to AI-native products — covering model governance, training data provenance, prompt-level abuse resistance, and production monitoring of AI behavior.
How They Fit Together
These frameworks answer different questions and stack rather than compete:
- ISO 27001 covers your organization's management system — policies, people, processes, physical security.
- CAIQ / CCM covers your cloud service's technical controls — the layer your customers directly consume.
- AI-CAIQ adds the AI-specific layer on top when your product includes machine learning or generative AI.
A SaaS company preparing for enterprise sales typically benefits from both ISO 27001 (organizational credibility) and CAIQ alignment (buyer questionnaire coverage). Scoring for all frameworks follows our published methodology.
