Trust

What a CAIQ questionnaire really wants

We have filed two self-assessments on the Cloud Security Alliance's STAR Registry: one for cloud security, one for AI. Along the way we learned that most vendors misread what the questionnaire is asking for, and answer a question nobody posed.

Published: August 30, 2026 By: EvolvLabs

The document behind the acronym

The CAIQ, the Consensus Assessments Initiative Questionnaire, is the Cloud Security Alliance's standard security questionnaire. Hundreds of yes-or-no questions across domains like access control, encryption, logging, and incident response. Enterprise buyers send it, or something derived from it, to vendors during procurement. Vendors can also answer it proactively and publish the result on the CSA's public STAR Registry, which is what we did: a cloud assessment in June 2026 and an assessment under the newer AI framework in July.

The naive reading of a questionnaire this size is that it is an exam, and the goal is the highest possible score. That reading produces the glossy, all-Yes submissions that security reviewers have learned to distrust on sight.

Who actually reads your answers

The real reader is a security reviewer who has to defend your product in an internal meeting. They did not write the questionnaire and they do not love it either. What they need from you is simple: enough honest detail to predict where your product will cause them problems, and evidence that you understand your own system well enough to be worth trusting.

Read that way, the CAIQ is not asking "are you perfect?" It is asking "can you describe yourself accurately?" Those are very different tests, and the second one is passable by a small vendor on day one.

No is an answer

Our AI assessment went to the registry with 234 answers of Yes, 7 answers of No, and 79 marked not applicable. The seven Nos are on purpose, and each carries an explanation of what we do instead or when we expect the control to exist.

Yes No Not applicable No — 7, answered on purpose Yes — 234 Not applicable — 79 320 questions total, answered in the cloud service provider role.
The shape of an honest submission: 234 Yes, 7 No, 79 not applicable.

Here is the thing about a No with a reason: it proves you read the question. A reviewer who hits your seventh unexplained Yes in a row starts wondering whether anyone at your company actually checked. A reviewer who hits a No that says "not yet, here is the compensating control, here is the plan" has just met a vendor who tells the truth under mild pressure. For a company our size, that impression is worth more than a perfect score, because a perfect score from a small vendor is not believable anyway.

N/A means you know your own shape

Seventy-nine of our answers are not applicable, and that number is doing real work. We answered in the service-provider role under a shared responsibility model, which means some controls in the questionnaire belong to our customers, and some belong to the infrastructure layer beneath us. Marking those honestly, with the reasoning, shows the reviewer you know exactly where your responsibility starts and stops.

Vendors who answer Yes to questions that are not theirs to answer look better for about five minutes, until the reviewer maps the answers against the architecture and finds claims no vendor in that position could truthfully make.

Answer from documents that exist

Before we answered a single question, we wrote the policy pack: the security policies, the operational commitments, the shared responsibility model. Then the questionnaire became a reading exercise instead of a creative writing one. Every Yes points at a document a reviewer could ask for.

This is the discipline we would recommend above all others. If the honest answer to "is it written down?" is no, then the honest answer to the question is "not yet," whatever the aspiration. A questionnaire answered from aspirations becomes a list of commitments you did not know you made.

The mechanics nobody warns you about

Three practical notes from actually filing, for anyone about to try.

  • The registry importer is exact. Our first upload bounced because we used short answer codes where the CSA's tooling wanted its precise dropdown strings. Match their format character for character and the submission goes through.
  • Level 1 is self-attestation. Say so. A STAR Level 1 listing is your own signed assessment, not an audit. We state that plainly wherever we cite it, because the fastest way to lose a reviewer is to let them discover an overclaim themselves.
  • It expires. Listings renew annually, and the renewal is the natural moment to re-read the policy pack against reality. Put it on the calendar the day the listing goes live.

What it buys

Both of our listings are public on the CSA STAR Registry, and the material behind them lives in our Trust Center. The practical effect is that procurement conversations start from a document instead of a forty-email thread, and the first impression we make on a security reviewer is a stack of honest answers they can check.

That is what the questionnaire really wants: not perfection, just a vendor who can tell the truth about itself in writing. It costs a small company some weeks of honest work. It is the cheapest credibility we have ever bought.