What is the difference between SIG Lite and CAIQ?
Glassbreak Team · Published 2026-08-23
SIG and CAIQ are the two vendor security questionnaires you are most likely to be sent, and the practical differences between them matter more than the overlap. The CAIQ is free and public. The SIG is licensed and private. Everything else — length, structure, who asks for which — follows from those two facts.
CAIQ, in short
The Consensus Assessments Initiative Questionnaire is published by the Cloud Security Alliance. You can download the current version from CSA at no cost, and completed CAIQs are published openly on the CSA STAR Registry, which means you can read how other vendors answered before you write your own.
Its defining feature is alignment: CAIQ v4 maps directly onto the Cloud Controls Matrix v4, CSA's control framework. Each question corresponds to a CCM control, so a completed CAIQ is simultaneously a questionnaire response and a control mapping. For a reviewer who already thinks in CCM domains, that makes it fast to consume.
Submitting a completed CAIQ to the STAR Registry is what constitutes CSA STAR Level 1, a self-assessment. Level 2 involves third-party audit; Level 1 does not, and reviewers know the difference.
SIG, in short
The Standardized Information Gathering questionnaire comes from Shared Assessments, a member-driven organisation, and it is a licensed product. The workbook is distributed to members and purchasers rather than published, which is the single most useful thing to know if you have been searching for a free SIG Lite PDF: there isn't a legitimate one.
The SIG is released on an annual cycle, so the release year matters. A response written against an older revision may not line up with the workbook your customer is holding. This is also why old copies float around the web — they were current once.
SIG Lite is a reduced-scope version of the same instrument, drawn from the same underlying question library, intended for vendors assessed at a lower risk tier. It is not a separate standard and not a different methodology; it is the SIG with fewer questions.
Which you will be asked for
This is decided by the buyer, not the vendor. In broad terms: organisations with established third-party risk programmes — financial services especially — tend toward the SIG, with SIG Lite for lower-tier suppliers. Cloud-first buyers and organisations anchored on CSA guidance tend toward the CAIQ.
Neither choice says anything about how rigorous the assessment will be. A carefully reviewed SIG Lite is a harder examination than a CAIQ nobody reads.
Answering either one without wasting a fortnight
Write once, reuse. Both instruments ask the same underlying questions in different words: how is data encrypted at rest, who can access production, how are incidents notified, which sub-processors are involved. Maintaining those positions as durable text — rather than reconstructing them per questionnaire — is what turns a two-week exercise into a one-day one.
Answer at the right resolution. "Yes" with no detail invites a follow-up; three paragraphs invites a skim. One or two sentences stating the control and where it is evidenced is usually right.
Use N/A properly. Both provide a not-applicable option with a rationale field. Reviewers read rationales. An unqualified "yes" to a control that turns out to be partial is the answer that causes trouble later.
Publish what you can. Answering the common questions publicly means most requests arrive already half-satisfied. That is why our own positions are published rather than held back — you can read Glassbreak's answers to both instruments at /trust/security-questionnaire, covering 72 controls across thirteen domains, each marked met, partial, gap, or not applicable with the reasoning behind it.
A note on scope creep
Questionnaires are sent by procurement, and procurement rarely scopes them to the product being bought. You will be asked about physical data-centre controls you do not operate, about card data you never touch, and about employee counts that do not apply to a company of your size. Answer those as not applicable with a one-line reason and move on. The alternative — answering as though you operated the control — creates a representation you may later have to defend.
Frequently asked questions
- Can I download SIG Lite as a free PDF?
- No, and this is the most common reason searches for it end in frustration. The SIG is a licensed product of Shared Assessments, distributed as an Excel workbook to members and purchasers. Copies circulating on the open web are typically outdated releases republished without permission, and completing an old revision tends to waste effort because the requesting organisation will be working from the current one. If you need the SIG because a customer asked you for it, ask them which release they are working from — many licence-holders will send you the workbook they want populated.
- Is there such a thing as CAIQ Lite?
- There was. CSA published a shortened CAIQ-Lite in 2018, developed with input from Whistic, aimed at a faster first-pass assessment. It is not part of the CAIQ v4 line, so a request for "CAIQ Lite" today is usually either a reference to that older artefact or a loose way of asking for a scoped-down subset of the current CAIQ. Worth clarifying which is meant before spending time on it.
- Which one will a customer actually send me?
- It depends on their programme rather than on your product. Financial services and large enterprises with mature third-party risk functions lean toward the SIG, often SIG Lite for lower-tier vendors and the full SIG for anything touching regulated data. Cloud-native buyers and anyone anchoring on CSA guidance lean toward the CAIQ. A growing number of buyers will accept a published CAIQ or an existing SOC 2 report in place of a bespoke questionnaire, which is worth asking about before filling anything in.
- Do I have to answer every question?
- Not usefully. Both instruments include questions that will not apply to a given vendor, and both provide a not-applicable response with a rationale field. Reviewers read the rationale, and a well-argued N/A is treated far better than a stretched yes. The response that causes problems is an unqualified yes to a control that turns out on inspection to be partial — that is the finding that resurfaces during an audit.
- How does Glassbreak answer these?
- Our positions on both instruments are published at /trust/security-questionnaire — 72 control responses across thirteen domains, each marked met, partial, gap, or not applicable with the reasoning. Populated SIG Lite and CAIQ v4 workbooks in your own template are available on request, and we will return them within one business day.