The SIG questionnaire, CAIQ, and how to stop drowning in them.
The SIG questionnaire — Standardized Information Gathering, published by Shared Assessments — is the most widely used vendor security questionnaire in the US, and CAIQ is its main counterpart for cloud services. This page covers what each one is, how the full and lite versions differ, when a standard set beats a custom one, how to answer efficiently if you are the vendor receiving them, and the limit that applies to all of them.
Last reviewed
What the SIG questionnaire is
A standardized question set, maintained by a member organization, updated annually.
The Standardized Information Gathering questionnaire is published by Shared Assessments, a member-driven organization that maintains third-party risk tools and certifications. The SIG gives buyers a consistent set of questions covering the domains a vendor assessment normally reaches — governance, access control, application security, cloud, incident management, business resilience, privacy, and the vendor’s own management of its subcontractors.
Its value is standardization rather than insight. Because thousands of organizations use the same set, a vendor can answer once and reuse the response, and a buyer can compare two vendors’ answers to the same question rather than to two differently worded ones. That is a genuine efficiency for both sides, and it is the main reason the SIG persists.
It is licensed rather than free — access comes through Shared Assessments membership or a product license — and it is revised on an annual cycle, so a response completed two versions ago is not a like-for-like answer to the current set.
SIG Lite, SIG Core and CAIQ compared compared
Three instruments, three different questions being asked.
| What it is | Use it when | |
|---|---|---|
| SIG Lite | A condensed subset — a broad sweep across the domains without the depth | Screening a lower-tier vendor, or triaging before deciding whether a full assessment is warranted |
| SIG Core / full SIG | The comprehensive set, running to several hundred questions across all domains | A critical vendor with production access or sensitive data at volume, where you need depth and a defensible record |
| CAIQ | The Consensus Assessments Initiative Questionnaire, from the Cloud Security Alliance, mapped to the Cloud Controls Matrix | Assessing a cloud service specifically — and note many providers publish a completed CAIQ openly in the CSA STAR registry, so check before you send one |
Check the STAR registry first for any cloud provider. A published CAIQ costs you nothing and arrives immediately.
Standard set or your own questions?
A real trade-off, usually decided by habit rather than on the merits.
Standard sets win on comparability and reuse. The vendor may already have a completed response, your assessors do not have to invent questions, and answers line up across your portfolio. They are also easier to defend to an examiner, because the coverage is externally defined rather than argued.
Custom sets win on relevance. A standard questionnaire asks a payroll processor about container security and a SaaS analytics vendor about manufacturing controls. Sections that plainly do not apply get marked not-applicable in bulk, and that habit spreads to sections that do apply.
The practical answer for most programs: use a standard set as the base, cut it to the tier, and add a short custom section about the specific relationship — what this vendor will hold, which of your systems they reach, who else they will involve. The custom questions are usually where the useful answers come from, precisely because they cannot be answered from a saved response.
Security questionnaire automation
Worth having, and worth being clear-eyed about what it does not fix.
Automation helps both sides of this exchange. For the buyer: distribution, chasing, version control, mapping answers to a control framework, flagging responses that changed since last time, and holding remediation commitments with dates against them. For the vendor answering: a maintained answer library, so the same question asked three different ways does not get three different answers by three different people.
What automation does not change is where the data comes from. A questionnaire is self-reported, and automating it makes self-reporting faster rather than more reliable. If anything, speed makes the underlying problem easier to miss: a response arriving in two days rather than six weeks feels like a better assessment, and it is the same claim.
The pairing that works is automation plus independent evidence — the questionnaire for what only the vendor knows, and continuous external assessment for what their infrastructure shows. That is what smart assessments is built around, and vendor risk assessment covers how the two fit into one process.
If you are the one being asked
Half the traffic to a page like this is vendors with a SIG in their inbox and a deal waiting on it. This is how to make it cost less.
- Build an answer library and keep it currentAnswer once, reuse everywhere, and review it on a schedule. The cost of these is almost entirely re-derivation — the same facts reassembled by whoever is free.
- Publish what you canA trust page carrying your certifications, a summary of your controls and — for cloud services — a CAIQ in the STAR registry deflects a meaningful share of inbound questionnaires entirely.
- Answer honestly, including the noesA no with a compensating control and a date reads as maturity. A yes that a follow-up question dismantles costs you the assessor’s trust on every other answer.
- Attach evidence proactivelyA SOC 2 report, a certificate with its scope, a penetration test summary. It shortens the exchange and pre-empts the second round.
- Know what your own perimeter showsBuyers increasingly assess you externally before they read your answers. An expired certificate or an exposed admin interface contradicting a confident response is a bad way to start the conversation — and you can see the same things they can.
The limit that applies to all of them
Questionnaire questions.
What is the SIG questionnaire?
What is the difference between SIG Lite and SIG Core?
What is CAIQ?
Is the SIG questionnaire free?
Do security questionnaires actually reduce risk?
Related reading.
Stop waiting six weeks for a claim.
Book a 30-minute call and we will show you a vendor rated from the outside in minutes — then you will know which questions on the SIG are worth pressing.