Guide

CAIQ vs SIG vs VSA: which questionnaire is which

A customer sends a spreadsheet and calls it "our standard security review". It might be one of several industry-standard formats, a trimmed-down version of one, or something written in-house. Knowing which you are looking at tells you how long it will take.

Last updated 10 August 2026 ~6 min read

Note on versions. All three frameworks below are revised periodically, and question counts and tier names change between releases. This guide describes what each format is for and how they differ structurally, which is stable — always download the current version from the publisher rather than relying on a count quoted in an article.

At a glance

  CAIQ SIG VSA
Published by Cloud Security Alliance (CSA) Shared Assessments Vendor Security Alliance
Scope Cloud services specifically Broad third-party risk, well beyond IT Security and privacy for tech vendors
Underlying control set Cloud Controls Matrix (CCM) Mapped to multiple standards and regulations Its own control set
Access Free to download from CSA Licensed — membership or purchase Free
Relative length Moderate Longest, and tiered by depth Shortest, with a fuller tier available
Public directory Yes — CSA STAR Registry No No

CAIQ

The Consensus Assessments Initiative Questionnaire is published by the Cloud Security Alliance. Its questions map directly onto the CSA Cloud Controls Matrix, a cloud-specific control framework, which makes CAIQ the most structurally predictable of the three: each question traces to a numbered control domain.

Its distinguishing feature is that completed CAIQs can be published to the CSA STAR Registry as a Level 1 self-assessment. That is a genuine lever: a public, current CAIQ is something you can point prospects at, and some will accept it in place of sending their own questionnaire. If you sell cloud software and answer questionnaires regularly, filling one in properly once is often the highest-return work available.

Because it is cloud-specific, expect concentration on multi-tenancy, data location and segregation, key management, and the shared responsibility boundary between you and your infrastructure provider.

SIG

The Standardized Information Gathering questionnaire comes from Shared Assessments and is the heavyweight of the three. It is used well beyond software — financial services and insurance third-party risk teams are heavy users — so its scope extends past information security into areas like resiliency, compliance and operational risk.

SIG is tiered: shorter and fuller variants exist so an assessor can scale depth to how critical the vendor is. If a customer sends you a SIG, establishing which tier you have been given is the first question to ask, because the difference in effort between tiers is very large.

Two practical consequences. First, SIG is a licensed product, so you cannot simply download the current version to prepare — you generally see it when a customer sends it. Second, its breadth means real not-applicable territory for a small software vendor; answer those explicitly with a reason rather than leaving them blank.

VSA — and why it is not VSAQ

The Vendor Security Alliance questionnaire is the leanest of the three, published free by an industry consortium and aimed squarely at assessing technology vendors. It typically comes in a core tier plus a fuller tier, and it is a reasonable choice if you want a serious questionnaire to self-assess against without licensing costs.

Do not confuse VSA with VSAQ. They are frequently conflated, including in articles that ought to know better. VSAQ — the Vendor Security Assessment Questionnaire — was an open-source questionnaire web application released by Google, not an industry-standard question set, and it has since been archived. If a customer says "VSAQ", it is worth confirming which they actually mean before you scope the work.

The most common format: bespoke

In practice, the questionnaire you receive most often is none of the above. It is a spreadsheet someone at the customer assembled — often starting from one of these frameworks, then adding questions specific to their industry, their regulator, or an incident they once had.

This is why building your process around a specific format does not work, and why the useful unit of preparation is evidence rather than a pre-filled template. The same underlying facts — your encryption approach, your access review cadence, your RTO — get asked in every format in different words. If your evidence is organised and your previous answers are searchable, format stops mattering very much.

Where SOC 2 and ISO 27001 fit

These are frequently discussed alongside the questionnaires above, but they are a different kind of artifact. SOC 2 is an audit report issued by a CPA firm; ISO 27001 is a certification of a management system. Neither is a questionnaire — they are third-party attestations you can offer in response to one.

Their practical value in this process is leverage. A current SOC 2 Type II will let you answer a good portion of any questionnaire by reference, and some reviewers will shorten or waive their questionnaire entirely on the strength of one. What it will not do is eliminate questionnaires — expect questions about anything outside the report's scope or audit period, and expect your answers to be checked for consistency against it.

What this means in practice

  • Identify the format and tier first. It is the difference between a half-day and a fortnight, and sales needs that estimate immediately.
  • If you sell cloud software, complete a CAIQ deliberately. Publishing it to the STAR Registry gives you something to send instead of answering, which is strictly better than answering faster.
  • Prepare evidence, not templates. Formats vary; the underlying facts do not. See the evidence checklist.
  • Keep answers with their sources. Cross-format reuse only works if you can find the answer you already wrote and check what it was based on — the core of the answering process.

Answer any format from one evidence base

citeproof takes whatever questionnaire a customer sends — standard format or bespoke spreadsheet — and answers it from your own evidence documents, citing the exact passage behind every answer.

See how it works →