RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Compliance & obligations

Compliance & obligations / Operating entry · Entry note · prepared 16 September 2026

One standard questionnaire is meant to end repeat security surveys

The Cloud Security Alliance's CAIQ standardises vendor security questions, and its STAR registry lets a completed one be reused.

web.archive.orgprimary record

CSA STAR Registry

Document
undated document
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The workload

The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire, CAIQ, is the document behind the security-questionnaire workload a solo founder's first enterprise sale usually creates. CSA's own STAR Registry page describes it, verified, as offering 'an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,' answered with 'a set of Yes/No/NA questions and space to justify the response' — control by control, mapped to the Cloud Controls Matrix (CCM). The registry page describes 'CAIQ Lite' as a simplified version of CCM v4.1 covering '96 carefully chosen controls, a subset of the original 207,' verified, setting the scale of the full questionnaire. Filling one out once and publishing it is meant to spare a vendor re-answering the same questions for every new enterprise buyer, verified from the registry's stated purpose.

What the documents show

Access note: Cloud Security Alliance's live site returned a scheduled-maintenance page throughout this research; the text quoted here comes from Internet Archive captures of the STAR Registry (28 August 2026) and the CCM/CAIQ v4 artifact page (4 September 2026), the most recent snapshots available, rather than a live fetch on 16 September 2026. Within the registry capture, verified: STAR has two levels, and 'At level one organizations submit a self-assessment' (where a published CAIQ sits) while 'At level two organizations earn a certification or third-party attestation.' That is the direct answer to whether a CAIQ substitutes for an audit — it does not: Level 1 is self-reported, and only Level 2 involves an independent check comparable to a SOC 2 or ISO 27001 audit.

The operating cost

Neither captured page lists a fee for completing or publishing a Level 1 self-assessment. The real cost is the labor of answering several hundred controls with justification text, scaling with how many systems and vendors a company's stack touches; this entry treats that as an estimate, not a figure either document states, since no dollar or hour figure was found on the pages retrieved.

The stop condition

A CAIQ ties to a specific Cloud Controls Matrix version — the registry names CCM v4.1 for CAIQ Lite — so a self-assessment answered against an older CCM version stops accurately describing current practice once CSA revises the matrix, an editorial reading of the version-numbering itself, since neither page states an explicit expiration date for a published questionnaire.

  • Is a prospective vendor's published CAIQ a Level 1 self-assessment or a Level 2 third-party attestation, and does that distinction matter for the decision being made?
  • Which CCM version does the published questionnaire reference, and is it the current one?
  • Would completing a CAIQ actually reduce the number of one-off security questionnaires a growing customer base sends, or would large buyers still insist on their own form regardless?

A CAIQ is a standardized answer sheet, not an audit. CSA's own two-level registry structure makes that distinction explicit, and it is worth carrying into any claim that a vendor's published questionnaire is equivalent to independent verification.

Sources & reading trail

CSA STAR Registry ↗

Describes what CAIQ and CAIQ Lite ask for, the 207-control CCM v4.1 baseline, and the Level 1 self-assessment versus Level 2 certification/attestation distinction.

Source published: Not established · Retrieved: 16 September 2026

Cloud Controls Matrix and CAIQ v4 ↗

Confirms CSA's own naming and pairing of the Cloud Controls Matrix and CAIQ as a single versioned artifact.

Source published: Not established · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.