Framework Overview

The Frameworks Behind Every Assessment

EvaluationCat maps its assessments to recognized standards — not proprietary checklists. Here's what each framework covers and when to use it.

Available now

ISO/IEC 27001:2022

Information Security Management Systems

Evaluates
Your organization's overall ISMS
Structure

93 Annex A controls

4 domains: organizational, people, physical, technological

Answers
“How well does my organization manage information security?”
About
The international standard for information security management. Annex A defines the control set; certification requires an accredited external audit, while self-assessment establishes your readiness baseline.
Run ISO 27001 assessment
Available now

CSA CCM v4 / CAIQ 4.1

Cloud Controls Matrix & Consensus Assessments Initiative Questionnaire

Evaluates
Your SaaS / cloud service controls
Structure

207 controls (CCM v4.1)

17 security domains, IAM to supply chain

Answers
“How secure is my cloud service as a product?”
About
Published by the Cloud Security Alliance as part of the STAR program. The CCM defines cloud security controls; the CAIQ turns them into standardized questions buyers use in vendor due diligence.
Run CAIQ assessment
Available now

CSA AI-CAIQ v2.0

AI-specific extension of the CAIQ

Evaluates
Governance, security & privacy of AI systems
Structure

242 control questions across 18 domains

Dedicated Model Security domain

Answers
“How responsibly is my AI system built and operated?”
About
Adapts the CAIQ methodology to AI-native products — covering model governance, training data provenance, prompt-level abuse resistance, and production monitoring of AI behavior.
Run AI-CAIQ assessment

How They Fit Together

These frameworks answer different questions and stack rather than compete:

  • ISO 27001 covers your organization's management system — policies, people, processes, physical security.
  • CAIQ / CCM covers your cloud service's technical controls — the layer your customers directly consume.
  • AI-CAIQ adds the AI-specific layer on top when your product includes machine learning or generative AI.

A SaaS company preparing for enterprise sales typically benefits from both ISO 27001 (organizational credibility) and CAIQ alignment (buyer questionnaire coverage). Scoring for all frameworks follows our published methodology.

A note on certification: self-assessment is preparation, not certification. Only an accredited certification body can issue ISO 27001 certification. EvaluationCat helps you arrive at that audit ready — no gaps left to surprise you.
    Feedback
    Back to Top