The enterprise procurement team sent two questionnaires. A SIG Lite for the general security review, and a CAIQ Lite because the vendor was delivering a cloud-native SaaS product and the procurement standard called for a cloud-specific screen alongside the generic one. The 138 questions on the CAIQ Lite looked reasonable next to the 128 on the SIG. The security engineer at the vendor worked through both over a couple of days, pulled the answers from the same policies and evidence, submitted them together, and closed the deal a month later.
Nine months after that, the vendor added a data warehouse subprocessor to the pipeline. The person who filled out the CAIQ was no longer at the company. The next customer questionnaire that came in — a full CAIQ this time, from a bigger buyer, six months after the original submission — was assigned to someone who pulled the previous CAIQ Lite from the file share and copy-pasted the answers. The subprocessor question in the new CAIQ still said “no additional subprocessors beyond those listed in DPA Exhibit A.” That answer was true when the CAIQ Lite was filed. It stopped being true four months later, and nobody re-asked the question. The buyer never found out from the questionnaire.
The questionnaire itself is not the problem. Treating a static, self-attested cloud questionnaire as if it were a continuous statement about a moving cloud environment is the problem. What follows is what CAIQ Lite is, what it actually proves, where it is the right tool, and what has to sit around it for the answer to still be true six months after the file was submitted.
What is CAIQ Lite?
CAIQ Lite is the abbreviated version of the Consensus Assessments Initiative Questionnaire published by the Cloud Security Alliance. Every question in CAIQ traces back to a specific control in the Cloud Controls Matrix, the CSA’s reference framework for cloud security. That direct lineage is what distinguishes it from the generic vendor questionnaires — CAIQ is not asking about security in the abstract; it is asking about a specific CCM control the buyer’s auditor already knows how to score.
The lineage matters. CCM v4 is 197 controls across 17 domains; the full CAIQ v4 breaks those controls into 261 questions (some controls are covered by more than one question). CAIQ Lite is not a separate framework — it is a subset of CAIQ, selected by CSA to hit the higher-priority controls a buyer needs answered before they open a deeper assessment cycle. The original 2018 CAIQ Lite had around 73 questions drawn from CAIQ v3. The current v4 release, published by CSA in January 2026, runs 138 questions across the same 17 domains. Which version a buyer is working from depends on when their procurement standard was last updated, so a vendor should confirm which release the incoming questionnaire tracks against.
Either CAIQ variant can also be filed publicly to CSA’s STAR Registry, a discovery layer enterprise procurement teams check when they want to see a vendor’s cloud posture without sending their own questionnaire first. STAR has three assurance levels — vendor self-attestation, third-party audit, and continuous auditing — and every level is anchored to the same CAIQ document.
Speed and framework match. Filling out the full 261-question CAIQ against real evidence takes materially longer than a 138-question Lite — in our experience, days rather than an afternoon. Procurement teams reach for the Lite first, and only escalate to the full CAIQ or ask for a STAR Level 2 attestation if the vendor is handling something sensitive enough to justify the extra cycle. The other reason buyers pick CAIQ over an ad-hoc cloud spreadsheet: the answers arrive already mapped to CCM controls, which is the framework the buyer’s own SOC 2 or ISO 27001 auditor scores against.
What questions does CAIQ Lite ask?
The 138 questions in CAIQ Lite v4 are drawn from the same 17 CCM v4 domains that structure the full CAIQ. The Lite selects the higher-signal controls from each domain rather than covering the domain exhaustively — every domain gets a handful of questions rather than the fifteen or so that the full CAIQ would put against it.
The domains themselves are the standard cloud-security taxonomy:
- Audit and Assurance — the vendor’s internal audit program and third-party attestations.
- Application and Interface Security — the SDLC, API security, and change control on customer-facing surfaces.
- Business Continuity Management and Operational Resilience — recovery from disruption.
- Change Control and Configuration Management — configuration drift and how change lands in production.
- Cryptography, Encryption, and Key Management — what it sounds like, at rest and in transit, plus whether the customer can hold their own keys.
- Datacenter Security — the physical facility controls.
- Data Security and Privacy Lifecycle Management — data classification, data handling, and deletion.
- Governance, Risk Management, and Compliance — the policy library, risk register, and compliance mapping.
- Human Resources Security — background checks, onboarding, and separation.
- Identity and Access Management — authentication, authorization, and privileged access.
- Infrastructure and Virtualization Security — the hypervisor and workload-isolation controls.
- Interoperability and Portability — the customer’s ability to leave the vendor.
- Logging and Monitoring — the vendor’s telemetry and the customer’s access to it. The one genuinely new domain CSA added in CCM v4.
- Security Incident Management, E-Discovery, and Cloud Forensics — detection, response, and notification.
- Supply Chain Management, Transparency, and Accountability — the vendor’s own subprocessors.
- Threat and Vulnerability Management — scanning, patching, and pen-testing cadence.
- Universal Endpoint Management — the vendor’s workforce endpoints across desktop, mobile, and IoT. CCM v4 expanded and renamed this from the v3 Mobile Security domain.
A vendor’s CAIQ Lite response tells the buyer whether the vendor has controls named across those 17 domains. A full CAIQ response tells the buyer how each control is implemented, line by line, and typically expects evidence attached to the answer. Neither format tells the buyer whether the answers are still current, whether a subprocessor was added yesterday, or whether an incident happened in the window between filing and reading. That is not a knock on the format — it is outside the job the format was designed to do.
What a completed CAIQ Lite actually proves — and what it doesn’t
This is the part that gets glossed over. The form measures a moment. It has no mechanism for measuring anything after that moment, because measuring after the moment was never the job it was designed to do.
What it proves:
- Someone at the vendor, in writing, attested to these specific cloud controls
- The attestation is dated and, if filed to STAR, is publicly discoverable
- The vendor was willing to publish their answers in a standardized, machine-readable format
- A baseline exists that can be compared against a future CAIQ if one is filed
What it doesn’t prove:
- That the controls are still true today, or were verified rather than self-reported
- That anything changed in the vendor’s cloud environment since submission
- That the person answering understood the CCM control the way CSA drafted it
- Anything about a subprocessor the vendor added after the file was submitted
Neither column is a knock on CAIQ Lite specifically. The full CAIQ and a Level 2 STAR attestation each carry the same point-in-time gap; the Level 2 audit at least removes the “self-reported” caveat for the day of the audit, but it does not extend past that day. A cloud vendor risk program that treats “CAIQ Lite on file” or “STAR Registry entry exists” as a closed item — reviewed once at onboarding, filed, forgotten — is measuring the day it was signed and calling it current. The questionnaire did not fail. The program treating a point-in-time cloud attestation as an ongoing state did.
The CSA STAR Registry is a genuinely useful discovery layer — enterprise procurement teams check it before they send their own version of the questionnaire. But a STAR Level 1 entry is the vendor’s own answers, unverified. A three-year-old STAR filing on the Registry today reads as freshly as one filed last week unless the buyer checks the date field. Vendors who file once and never refresh, and buyers who trust the Registry entry without checking recency, are both loading the same landmine.
Where CAIQ Lite is genuinely the right tool
None of this is an argument against using CAIQ Lite. For what it is built for, it is the right tool and arguably the correct default in cloud-vendor procurement:
- Screening a lower-tier cloud vendor — a workflow tool that touches metadata but not customer PII does not justify a 261-question full CAIQ. Lite is proportionate to the risk.
- Fast procurement cycles — when a deal has a deadline and the cloud relationship is bounded, the Lite’s speed is the point.
- Filing to the STAR Registry as a Level 1 attestation — publishing a CAIQ Lite (or the full CAIQ) makes the vendor’s answers discoverable and cuts the number of one-off questionnaires that arrive from prospects.
- Being on the receiving end — if an enterprise customer sends a CAIQ Lite, filling it out well and fast is how the deal closes. The questionnaire response side of this is covered in the sibling article in depth.
The failure mode is not choosing CAIQ Lite. It is treating a CAIQ Lite on file — or a STAR Registry entry — as equivalent to knowing a cloud vendor’s current posture indefinitely, with no refresh cadence attached.
CAIQ Lite vs SIG Lite: when a buyer sends each
Enterprise buyers do not treat CAIQ Lite and SIG Lite as substitutes. Both formats often arrive together, and understanding why makes the response side less confusing.
SIG Lite is generic. It covers whatever controls the buyer’s vendor-risk team decided to prioritize when they built their standard, and it is agnostic to whether the vendor is a SaaS product, a professional services firm, or a physical hardware supplier. That flexibility is the whole point — one questionnaire covers most vendor types, which is why it dominates procurement inboxes.
CAIQ Lite is not agnostic. Every question in CAIQ is tied to a specific CCM v4 control, which means every question assumes the vendor is delivering something cloud-shaped. Buyers with mature vendor-risk programs send CAIQ Lite specifically when the vendor is a cloud-native SaaS, IaaS, or PaaS provider — because the CCM control language matches how their own auditors think about cloud, and because a CAIQ response maps directly to the framework the buyer’s SOC 2 or ISO 27001 auditor is already using to evaluate the buyer’s vendor-management program.
In practice: a vendor selling SaaS to an enterprise customer will often receive both. The SIG Lite covers the general control posture — HR, physical security, business continuity — while the CAIQ Lite covers the cloud-specific overlay. The answers overlap heavily because both are drawn from the same underlying evidence library, but the framing differs by framework. Answering both well from a shared knowledge base is faster than answering either one in isolation, which is the case for treating the response function as a system rather than a per-questionnaire scramble.
Filling it out: template, STAR self-attestation, platform
There are three ways a vendor typically fills out a CAIQ Lite when it lands in the inbox, and they represent three different bets about how often this is going to happen and how much preparation the vendor is willing to do up front.
The template approach: someone opens the XLSX CSA publishes, works through the 138 questions from memory or by asking colleagues, and sends it back. It is the fastest path the first time and the slowest path every subsequent time, because none of the work compounds. When the next CAIQ Lite arrives — or the same customer’s renewal cycle asks for a fresh one — the process starts over from the same blank template. The answers drift. The person who filled it out the first time may or may not be around. Whatever institutional memory existed lived in a spreadsheet that is now two versions behind the CCM revision the buyer’s procurement standard was updated against.
The STAR self-attestation approach: the vendor completes a full CAIQ once, files it publicly to the CSA STAR Registry at Level 1, and points every subsequent buyer at the Registry entry. This is a real improvement on the template approach for a vendor that gets a lot of CAIQ requests, because the filing does the work of a public trust page for cloud controls. The trap is the same one the third bullet in the checklist covered above: filing once and letting the Registry entry go stale is worse than not filing at all, because the buyer sees an authoritative-looking record that is quietly no longer true.
The platform approach: an answer library and response workflow that maintains the vendor’s current posture as source-of-truth, generates the CAIQ Lite response from that library on demand, and updates automatically when a control changes. This is the model vCISO Lite runs on for questionnaire response — the CAIQ Lite (and the full CAIQ, and every other cloud-vendor questionnaire that shows up in the inbox) becomes an output of the current-state knowledge base rather than a fresh spreadsheet exercise every time.
The whole first half of this article is about a vendor’s CAIQ Lite measuring a moment instead of a state. A manually maintained answer library — spreadsheet, doc, notion page — has the exact same failure mode, just self-inflicted. The fix is not a better spreadsheet. It is a knowledge base tied to actual current business context, so when a control changes the next CAIQ Lite pulls the current answer automatically instead of whatever was true whenever the library was last touched.
What closes the gap
Static questionnaires and continuous cloud posture monitoring are not competing approaches to the same problem — they answer two different questions. CAIQ Lite answers “what did this cloud vendor attest to on this date.” Continuous monitoring answers “is anything observable about this vendor’s cloud posture different right now.” A vendor risk program that only asks the first question has a blind spot exactly as wide as the time between assessments — which, for most SMB buyers re-sending questionnaires annually, is up to twelve months.
Closing that gap does not require replacing the questionnaire. It requires putting a refresh cadence and a monitoring layer on top of it: a defined re-assessment interval scaled to vendor tier, and outside-in signal (TLS posture, certificate transparency logs, breach disclosure monitoring, exposed cloud storage buckets) that can flag “something changed” between formal assessments instead of waiting for the next cycle. vCISO Lite’s vendor risk module runs the CAIQ Lite / full CAIQ cycle for Tier-1 and Tier-2 cloud vendors on a scheduled cadence rather than a one-time onboarding step, and layers continuous posture monitoring on top of the Tier-1 vendors where the gap matters most.
Bottom line
CAIQ Lite is a good, standard, appropriately fast tool for what it measures: a cloud vendor’s attested posture on a specific date, mapped to the Cloud Controls Matrix so the buyer’s auditor recognizes the framework. It was never going to measure anything past that date, and no amount of asking more questions on the form fixes that — the full CAIQ and a Level 2 STAR attestation have the identical gap, just with a longer form or an auditor’s signature in front of it. The fix is not a longer questionnaire. It is not treating the questionnaire as the whole cloud vendor risk program.
Sources
- Cloud Security Alliance, Consensus Assessments Initiative Questionnaire (CAIQ) v4, cloudsecurityalliance.org/artifacts/consensus-assessments-initiative-questionnaire-v4
- Cloud Security Alliance, Cloud Controls Matrix (CCM) v4, cloudsecurityalliance.org/research/cloud-controls-matrix
- Cloud Security Alliance, CAIQ Lite, cloudsecurityalliance.org/artifacts/caiq-lite
- Cloud Security Alliance, STAR Registry, cloudsecurityalliance.org/star
- Cloud Security Alliance, STAR Program Overview and Levels, cloudsecurityalliance.org/star/overview