CSA STAR Registry
- Document
- undated document
- Event
- no single event
- Retrieved
- 16 September 2026
The workload
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire, CAIQ, is the document behind the security-questionnaire workload a solo founder's first enterprise sale usually creates. CSA's own STAR Registry page describes it, verified, as offering 'an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,' answered with 'a set of Yes/No/NA questions and space to justify the response' — control by control, mapped to the Cloud Controls Matrix (CCM). The registry page describes 'CAIQ Lite' as a simplified version of CCM v4.1 covering '96 carefully chosen controls, a subset of the original 207,' verified, setting the scale of the full questionnaire. Filling one out once and publishing it is meant to spare a vendor re-answering the same questions for every new enterprise buyer, verified from the registry's stated purpose.
What the documents show
Access note: Cloud Security Alliance's live site returned a scheduled-maintenance page throughout this research; the text quoted here comes from Internet Archive captures of the STAR Registry (28 August 2026) and the CCM/CAIQ v4 artifact page (4 September 2026), the most recent snapshots available, rather than a live fetch on 16 September 2026. Within the registry capture, verified: STAR has two levels, and 'At level one organizations submit a self-assessment' (where a published CAIQ sits) while 'At level two organizations earn a certification or third-party attestation.' That is the direct answer to whether a CAIQ substitutes for an audit — it does not: Level 1 is self-reported, and only Level 2 involves an independent check comparable to a SOC 2 or ISO 27001 audit.
The operating cost
Neither captured page lists a fee for completing or publishing a Level 1 self-assessment. The real cost is the labor of answering several hundred controls with justification text, scaling with how many systems and vendors a company's stack touches; this entry treats that as an estimate, not a figure either document states, since no dollar or hour figure was found on the pages retrieved.
The stop condition
A CAIQ ties to a specific Cloud Controls Matrix version — the registry names CCM v4.1 for CAIQ Lite — so a self-assessment answered against an older CCM version stops accurately describing current practice once CSA revises the matrix, an editorial reading of the version-numbering itself, since neither page states an explicit expiration date for a published questionnaire.
- Is a prospective vendor's published CAIQ a Level 1 self-assessment or a Level 2 third-party attestation, and does that distinction matter for the decision being made?
- Which CCM version does the published questionnaire reference, and is it the current one?
- Would completing a CAIQ actually reduce the number of one-off security questionnaires a growing customer base sends, or would large buyers still insist on their own form regardless?
A CAIQ is a standardized answer sheet, not an audit. CSA's own two-level registry structure makes that distinction explicit, and it is worth carrying into any claim that a vendor's published questionnaire is equivalent to independent verification.
Sources & reading trail
Describes what CAIQ and CAIQ Lite ask for, the 207-control CCM v4.1 baseline, and the Level 1 self-assessment versus Level 2 certification/attestation distinction.
Source published: Not established · Retrieved: 16 September 2026
Confirms CSA's own naming and pairing of the Cloud Controls Matrix and CAIQ as a single versioned artifact.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.