CSA Consensus Assessments Initiative Questionnaire v4.1
The CAIQ v4.1 is a standardised security assessment questionnaire with 283 questions mapped to the Cloud Controls Matrix v4.1. Used for CSA STAR Level 1 self-assessment, it enables cloud providers to document their security posture and customers to evaluate provider compliance. Released January 2026, it replaces CAIQ v4.0 (transition deadline December 2027).
283
Questions
17
CCM Domains
STAR L1
Self-Assessment
v4.1
Current (Jan 2026)
Governance, risk management, audit assurance, compliance policies, and third-party assessment requirements.
Data security lifecycle management, encryption and key management, data residency, and privacy controls.
Identity management, virtualisation security, datacenter security, and network security controls.
Business continuity, incident management, change management, vulnerability management, and logging.
Align CAIQ questions to applicable CCM v4.1 controls and determine organisational scope.
Complete all 283 Yes/No questions with supporting evidence and implementation details.
Identify 'No' responses and create remediation timelines with responsible owners.
Publish completed CAIQ to the CSA STAR Registry for public transparency.
Engage a third-party auditor for CCM-based certification and enhanced assurance.
Update CAIQ annually; adopt v4.1 format before the December 2027 transition deadline.