Pass your CAIQ security questionnaire
Most CAIQ questions assume you have a pentest, scans, and policies in hand. Pentest Today generates that evidence so your answers are 'yes — here's proof.'
What a CAIQ review asks for
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized set of yes/no security questions mapped to the Cloud Controls Matrix.
Scan
Authenticated and external scans across web, API, and cloud surface the issues before an assessor does — de-duped, triaged, and mapped to CVE/CVSS.
Pentest
Approved-target scans become a client-ready pentest report: validated findings, evidence, reproduction steps, remediation, and the retest letter auditors accept.
Policy Generator
Generate the policies and system architecture diagrams the review expects — access control, cryptography, incident response — pre-mapped to controls.
SIG
The Shared Assessments Standardized Information Gathering (SIG) questionnaire is a comprehensive third-party risk questionnaire used across industries.
Vendor Security Questionnaire
Enterprise buyers send a security questionnaire before they'll sign — asking how you test, protect, and monitor their data.
SOC 2
SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Type II
A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.
ISO 27001
ISO/IEC 27001 certifies that you run an Information Security Management System (ISMS) with the Annex A controls in place.
HIPAA
The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).
CAIQ, answered
What is the CAIQ?
It's a CSA-standardized questionnaire that lets cloud providers document security controls against the Cloud Controls Matrix, so buyers don't have to send custom questionnaires.
Is the pentest a real test or just a scanner dump?
Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.
How fast can I get a report?
Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.
Get the evidence for your CAIQ review this week.
Start a scan on an approved target and walk in with the report, policies, and diagrams already done.