Pentest Today.
security questionnaire

Pass your CAIQ security questionnaire

Most CAIQ questions assume you have a pentest, scans, and policies in hand. Pentest Today generates that evidence so your answers are 'yes — here's proof.'

What a CAIQ review asks for

The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized set of yes/no security questions mapped to the Cloud Controls Matrix.

✓Evidence of penetration testing and vulnerability management
✓Documented access control and encryption practices
✓Incident response and business continuity policies
✓Data classification and handling documentation
✓Architecture diagrams mapped to the Cloud Controls Matrix

What closes each requirement

ControlWhat they askEvidenceWhere it comes from
TVM · threat and vulnerability managementWhether testing runs on a defined cadence and last round's findings actually closed — the row's 'yes' is worthless without a report a reviewer can open and check the date on.The penetration test report, scoped to the assessed environment, plus the retest that restates each finding as fixed or not fixed — the artifact behind the 'yes' rather than the word alone.The pentest workflow's client-ready PDF and the retest workflow.
IAM · identity and access managementWhether accounts are individually attributable, whether administrative access requires a second factor, and whether access gets reviewed on a cadence — three separate questions a rushed CAIQ answer often collapses into one blanket 'yes'.The Access Control Policy's account, authentication, and review sections, with the enforcement scope pulled from the intake's own authentication method and MFA status instead of asserted.The policy pack, generated from the intake's authMethod and mfaStatus fields.
CEK · cryptography, encryption and key managementWhich algorithms protect data at rest and in transit, and who holds the keys — not whether encryption is used at all, which every vendor already answers yes to.The Data Handling Policy's encryption standard, filled in from the intake's own encryption summary where one exists, and marked to be confirmed rather than guessed where it doesn't.The policy pack, from the intake's encryptionSummary field.
SEF · security incident managementWhether a documented process exists for detecting, triaging, and closing an incident, with a named owner and a defined communication path — asked before anything has gone wrong, not after.The Incident Response Policy, checked for two things a reviewer actually verifies: a named individual accountable for running the process, and a lifecycle that goes past 'we noticed' into containment and recovery.The policy pack, drawing its named contact directly from the intake's incidentResponseOwner field rather than a generic title.
STA · supply chain management, transparency and accountabilityWhich subprocessors touch the environment, how each was assessed before onboarding, and whether that list is the same one the architecture diagram draws — a mismatch here is the fastest way to lose a reviewer's confidence in the rest of the submission.The Vendor Management Policy's assessment and tiering process, checked against the generated architecture and data-flow diagram, which draws each third party outside the trust boundary instead of naming it in a sentence.The policy pack and the diagram generator, both built from the intake's keyVendors field, so the list on the row and the drawing can't disagree.
DSP · data security and privacy lifecycleHow customer data is classified, where it's permitted to travel, and what happens to it at the end of its life — retention and deletion, not only where it sits today.The Data Handling Policy's classification and retention sections, scoped to the data types and hosting setup the intake actually names rather than a generic default.The policy pack, generated from the intake's customerDataTypes and hostingSetup fields.

A CAIQ row, answered against the CCM

Two CCM-mapped rows, evidence attached — not the internal generator draft
CCM domain: TVM (Threat & Vulnerability Management) Question, in plain terms: is penetration testing performed on a defined schedule, with prior findings tracked through to closure? Answer: Partial. Testing runs at least annually against the assessed scope; two findings from the most recent round remain open past their internal remediation target. Evidence attached: penetration test report, dated; retest report covering the two open findings. CCM domain: IAM (Identity & Access Management) Question, in plain terms: does administrative access to production require a second authentication factor? Answer: Yes. Multi-factor authentication is enforced on all administrative and production access paths. Evidence attached: Access Control Policy; identity-provider export listing enforcement by role. CCM domain: DSP (Data Security and Privacy Lifecycle Management) Question, in plain terms: is customer data classified, and does the classification determine how long it's retained? Answer: Partial. Data types are classified in the Data Handling Policy; a formal deletion schedule per classification is still being finalized. Evidence attached: Data Handling Policy.

Illustrative example of reviewed rows. The generator's own draft carries a draft answer, an evidence source, a confidence level and a review flag per row; this is what a row looks like after that review. Not taken from a customer engagement.

How this review actually runs

A CAIQ typically arrives one of two ways: a buyer sends the spreadsheet directly, or a buyer asks whether you're listed in the CSA STAR registry and reads your public entry instead of sending their own copy. Both paths test the same seventeen Cloud Controls Matrix domains, and both expect the same thing behind every 'yes' — an artifact a reviewer could actually open, not just an assertion.

Answering it starts the way answering any vendor security questionnaire does: each row gets matched against a topic, and a draft is grounded in your intake and the documents already in your security packet wherever they cover it. The deterministic baseline returns four things for a matched row — a draft answer, a named evidence source, a confidence level, and a review flag — before anything reaches a reviewer. What actually ships is reviewed and edited from there, so the specific confidence attached to any one delivered answer isn't something to take as fixed; the four-field shape is what holds.

Where it fails is predictable: a 'yes' with no evidence source named, because the row read like every other yes/no question and got answered from memory instead of from a document. A STAR listing amplifies that failure rather than hiding it — a reviewer who checks your public entry against the questionnaire you actually sent finds the same gap twice.

What gets this sent back

A 'yes' with no evidence source named. A CCM-mapped answer that names no artifact reads as unverifiable by design, and a careful reviewer treats every unattached 'yes' on the sheet the same way — as one they now have to ask about directly.
The CAIQ answered differently than the CSA STAR listing. A registry entry marked one way and a questionnaire response marked another for the same domain tells the reviewer the two were filled out by different people at different times, and both get read again more slowly.
Encryption answered 'yes' with no algorithm or key-management detail behind it. CEK questions exist to catch exactly this: a vendor who encrypts something but can't say what, or who holds the keys. A bare 'yes' invites the follow-up the row was built to force.
A subprocessor on the STA row that the architecture diagram doesn't show. A vendor named in the questionnaire but missing from the diagram — or the other way round — reads as evidence the two documents were never compared before either one shipped.
Answering from memory instead of from the packet. An answer nobody can point at a document holds up fine until the one time it's wrong, and a CAIQ submission survives roughly one such check before every other answer on it gets read the same way.
Free · no account

Start your Pentest

Our agent swarm and human experts test your endpoints and deliver an audit, fast.

CAIQ, answered

What is the CAIQ?

The Consensus Assessments Initiative Questionnaire is a Cloud Security Alliance document mapping yes/no security questions to the seventeen domains of the Cloud Controls Matrix. Cloud providers publish answers, sometimes to the CSA STAR registry, so buyers evaluating them read one standardized answer set instead of a custom questionnaire.

Do I have to answer every CAIQ question?

Most buyers expect a complete response, but 'not applicable' with a stated reason is a legitimate answer for a domain that genuinely doesn't apply to your service model. What draws scrutiny is a blank row or a 'yes' with nothing behind it — both read as unanswered rather than as a considered response.

What's the difference between the CAIQ and a general vendor security questionnaire?

The CAIQ is one standardized document mapped to the Cloud Controls Matrix; a vendor security questionnaire is whatever a specific buyer's team wrote, and its rows vary by company. Most of the underlying evidence overlaps, which is why a maintained answer library serves both instead of starting each one from a blank page.

What does publishing to the CSA STAR registry actually do?

Publishing to the CSA STAR registry puts a completed CAIQ where a buyer can read it before a deal even starts, instead of waiting for one to be sent. It doesn't replace the underlying evidence — a reviewer who finds a STAR listing still expects the same artifacts behind it that a mailed questionnaire would need.

Does a CAIQ 'yes' need evidence attached?

Yes, in practice. Every affirmative answer implies evidence exists somewhere, even when the question doesn't ask for it directly. Reviewers who catch one unbacked 'yes' tend to re-check the rest of the sheet, so the safer habit is attaching the document behind every affirmative rather than waiting to be asked.

How often does a CAIQ need to be updated?

Annually is the common expectation, and again after a change that affects a domain's answer — a new subprocessor, a changed encryption standard, a new region. Because the underlying evidence is what actually changes, updating the source documents and regenerating answers keeps a STAR listing from going stale.

Is the pentest a real test or just a scanner dump?

Both scanning and AI triage are scoped to your approved targets, and every finding is reviewed and signed off by a human before delivery — so the report reflects verified findings, not raw scanner noise.

How fast can I get a report?

Most reports turn around in hours, not weeks. You connect an approved target, we scan and verify, and you export a client-ready report and policy pack.

Get the evidence for your CAIQ review this week.

Start a scan on an approved target and walk in with the report, policies, and diagrams already done.