SIG questionnaire

The SIG questionnaire, CAIQ, and how to stop drowning in them.

The SIG questionnaire — Standardized Information Gathering, published by Shared Assessments — is the most widely used vendor security questionnaire in the US, and CAIQ is its main counterpart for cloud services. This page covers what each one is, how the full and lite versions differ, when a standard set beats a custom one, how to answer efficiently if you are the vendor receiving them, and the limit that applies to all of them.

Last reviewed

What the SIG questionnaire is

A standardized question set, maintained by a member organization, updated annually.

The Standardized Information Gathering questionnaire is published by Shared Assessments, a member-driven organization that maintains third-party risk tools and certifications. The SIG gives buyers a consistent set of questions covering the domains a vendor assessment normally reaches — governance, access control, application security, cloud, incident management, business resilience, privacy, and the vendor’s own management of its subcontractors.

Its value is standardization rather than insight. Because thousands of organizations use the same set, a vendor can answer once and reuse the response, and a buyer can compare two vendors’ answers to the same question rather than to two differently worded ones. That is a genuine efficiency for both sides, and it is the main reason the SIG persists.

It is licensed rather than free — access comes through Shared Assessments membership or a product license — and it is revised on an annual cycle, so a response completed two versions ago is not a like-for-like answer to the current set.

SIG Lite, SIG Core and CAIQ compared compared

Three instruments, three different questions being asked.

What it isUse it when
SIG LiteA condensed subset — a broad sweep across the domains without the depthScreening a lower-tier vendor, or triaging before deciding whether a full assessment is warranted
SIG Core / full SIGThe comprehensive set, running to several hundred questions across all domainsA critical vendor with production access or sensitive data at volume, where you need depth and a defensible record
CAIQThe Consensus Assessments Initiative Questionnaire, from the Cloud Security Alliance, mapped to the Cloud Controls MatrixAssessing a cloud service specifically — and note many providers publish a completed CAIQ openly in the CSA STAR registry, so check before you send one

Check the STAR registry first for any cloud provider. A published CAIQ costs you nothing and arrives immediately.

Standard set or your own questions?

A real trade-off, usually decided by habit rather than on the merits.

Standard sets win on comparability and reuse. The vendor may already have a completed response, your assessors do not have to invent questions, and answers line up across your portfolio. They are also easier to defend to an examiner, because the coverage is externally defined rather than argued.

Custom sets win on relevance. A standard questionnaire asks a payroll processor about container security and a SaaS analytics vendor about manufacturing controls. Sections that plainly do not apply get marked not-applicable in bulk, and that habit spreads to sections that do apply.

The practical answer for most programs: use a standard set as the base, cut it to the tier, and add a short custom section about the specific relationship — what this vendor will hold, which of your systems they reach, who else they will involve. The custom questions are usually where the useful answers come from, precisely because they cannot be answered from a saved response.

Security questionnaire automation

Worth having, and worth being clear-eyed about what it does not fix.

Automation helps both sides of this exchange. For the buyer: distribution, chasing, version control, mapping answers to a control framework, flagging responses that changed since last time, and holding remediation commitments with dates against them. For the vendor answering: a maintained answer library, so the same question asked three different ways does not get three different answers by three different people.

What automation does not change is where the data comes from. A questionnaire is self-reported, and automating it makes self-reporting faster rather than more reliable. If anything, speed makes the underlying problem easier to miss: a response arriving in two days rather than six weeks feels like a better assessment, and it is the same claim.

The pairing that works is automation plus independent evidence — the questionnaire for what only the vendor knows, and continuous external assessment for what their infrastructure shows. That is what smart assessments is built around, and vendor risk assessment covers how the two fit into one process.

If you are the one being asked

Half the traffic to a page like this is vendors with a SIG in their inbox and a deal waiting on it. This is how to make it cost less.

  • Build an answer library and keep it current
    Answer once, reuse everywhere, and review it on a schedule. The cost of these is almost entirely re-derivation — the same facts reassembled by whoever is free.
  • Publish what you can
    A trust page carrying your certifications, a summary of your controls and — for cloud services — a CAIQ in the STAR registry deflects a meaningful share of inbound questionnaires entirely.
  • Answer honestly, including the noes
    A no with a compensating control and a date reads as maturity. A yes that a follow-up question dismantles costs you the assessor’s trust on every other answer.
  • Attach evidence proactively
    A SOC 2 report, a certificate with its scope, a penetration test summary. It shortens the exchange and pre-empts the second round.
  • Know what your own perimeter shows
    Buyers increasingly assess you externally before they read your answers. An expired certificate or an exposed admin interface contradicting a confident response is a bad way to start the conversation — and you can see the same things they can.

The limit that applies to all of them

SIG, CAIQ, VSA, a bespoke set — every questionnaire shares one property: it is a self-report, describing intentions on the day it was completed, produced by the party with the least interest in an unflattering answer. That is not a reason to stop sending them; they are the only way to learn about governance, subcontractors and data flows. It is a reason never to let one be the whole assessment.

Questionnaire questions.

What is the SIG questionnaire?
A standardized vendor security questionnaire published by Shared Assessments, covering governance, access control, application and cloud security, incident management, resilience, privacy and subcontractor management. It is licensed, and revised annually.
What is the difference between SIG Lite and SIG Core?
SIG Lite is a condensed subset for screening and lower-tier vendors; SIG Core is the comprehensive set, running to several hundred questions, for critical vendors where depth is warranted.
What is CAIQ?
The Consensus Assessments Initiative Questionnaire, published by the Cloud Security Alliance and mapped to its Cloud Controls Matrix. It is aimed specifically at cloud services, and many providers publish a completed CAIQ in the CSA STAR registry — so check there before sending one.
Is the SIG questionnaire free?
No. Access is through Shared Assessments membership or a product license. CAIQ, by contrast, is freely available from the Cloud Security Alliance.
Do security questionnaires actually reduce risk?
They reduce it when the answers are validated against something independent and when findings turn into contract terms or remediation with dates. On their own they document a vendor’s claims — useful for the things only the vendor knows, insufficient as verification.

Stop waiting six weeks for a claim.

Book a 30-minute call and we will show you a vendor rated from the outside in minutes — then you will know which questions on the SIG are worth pressing.