Short version
Three standard questionnaires, two publishers, one job.
All three exist so that a buyer does not have to write its own security questionnaire and a vendor does not have to answer a different one for every customer. The SIG and SIG Lite come from Shared Assessments and cover third-party risk broadly. The CAIQ comes from the Cloud Security Alliance and covers cloud services specifically.
| SIG Core | SIG Lite | CAIQ | |
|---|---|---|---|
| Publisher | Shared Assessments | Shared Assessments | Cloud Security Alliance (CSA) |
| Scope | Full third-party risk assessment across all risk domains, down to how each control is implemented | The same domains at a high level: does the control exist, not how it works | Cloud service security, mapped one-to-one to the CSA Cloud Controls Matrix (CCM) |
| Size | Several hundred to more than eight hundred questions depending on how the buyer scopes it | Roughly 126 to 128 questions in recent releases | 283 questions in v4.1 (January 2026); CAIQ Lite has 138 |
| Answer style | Yes / No / N/A with free-text detail and evidence references | Yes / No / N/A, short detail | Yes / No / N/A per question, with notes and a shared-responsibility column |
| Who sends it | Banks, insurers, and large enterprises assessing vendors with access to sensitive or regulated data | Buyers assessing lower-risk vendors, or as a first pass before a full SIG | Customers of cloud products; also self-published by vendors on the CSA STAR registry |
| Cost to obtain | Licensed from Shared Assessments | Licensed from Shared Assessments | Free download from CSA |
| Update cycle | Annual | Annual | Follows CCM versions (v4 in 2021, v4.1 in 2026) |
Question counts move every year and buyers often trim or extend the standard file, so treat the numbers as scale, not spec. What matters when one lands is which one it is, because that decides how many people you need and for how long.
SIG
SIG Core and SIG Lite.
The Standardized Information Gathering questionnaire is the general-purpose third-party risk questionnaire used across financial services, insurance, healthcare, and any enterprise with a mature vendor risk program. It is organized by risk domain: security policy, access control, network and application security, cloud hosting, business resilience, incident management, privacy, human resources, and more. Shared Assessments revises it annually, and buyers usually send the current year's file as an Excel workbook.
SIG Core
The full assessment. It asks not only whether a control exists but how it is implemented, who owns it, how often it is reviewed, and what evidence supports it. A buyer typically sends the Core to vendors that will hold regulated or sensitive data. Expect it to need input from security, IT, HR, legal, and whoever runs your cloud accounts, and expect it to take days of combined effort when answered from scratch.
SIG Lite
The same domains at a fraction of the depth: roughly 126 to 128 questions in recent years. It is the right instrument for lower-risk vendors, or a first screen before a Core. A team with current policies can usually turn a Lite around in a day.
One practical note: the SIG is licensed content. The vendor answering it does not need a license, but the file arrives in Shared Assessments' structure, with question IDs and domain headers, and the buyer expects it back in the same structure.
CAIQ
The CAIQ.
The Consensus Assessments Initiative Questionnaire is the Cloud Security Alliance's questionnaire for cloud service providers. Every question maps to a control in the CSA Cloud Controls Matrix, so it doubles as a self-assessment against that framework. The current release is CAIQ v4.1, published in January 2026, with 283 yes/no questions; a CAIQ Lite of 138 questions exists for shorter reviews.
Two things make the CAIQ different from the SIG in practice:
- It is free and public. Anyone can download it from CSA, and vendors can publish their completed CAIQ on the CSA STAR registry as a Level 1 self-assessment. Many cloud vendors answer it once, publish it, and point customers to it.
- It is cloud-specific. Questions assume you operate a cloud service and ask about shared responsibility, tenant isolation, virtualization, and supply chain. If you are not a cloud provider, large parts of it do not apply and should be marked N/A with a reason.
If your customers are mostly asking about a SaaS product, completing a CAIQ once and keeping it current is often the highest-return questionnaire work you can do, because it pre-empts a share of custom questionnaires.
Choosing
Which one you will get, and what to do about it.
- You do not choose; the buyer does. A regulated enterprise sends a SIG. A cloud-savvy buyer may accept a published CAIQ. Many smaller buyers send neither and use their own spreadsheet, often assembled from SIG and CAIQ questions.
- The answers overlap heavily. Encryption, access control, incident response, backups, vendor management, and HR screening appear in all three. If your source documents answer one, they answer most of the others; only the wording and numbering change.
- Answer from documents, not from the last questionnaire. Copying last year's SIG into this year's CAIQ propagates whatever was wrong or stale. Keep the policies current and answer from them each time; the how-to guide walks through that process.
- Ask before you start. Whether N/A is accepted, whether a SOC 2 report replaces any sections, and whether a published CAIQ is enough. Each yes removes hours.
Tooling
How Mattercite handles them.
Import the SIG, SIG Lite, or CAIQ workbook as received, in Excel or CSV. Question IDs and section headers are stripped so only the questions remain, and rows that already carry an answer import as answered. Each remaining question is answered from your uploaded policies and prior questionnaires with a citation to the source file and page; questions your documents do not support are flagged as Needs Information. You review, approve, and export back in the buyer's format. Details on the security questionnaires page.
Questions
Common questions.
Is SIG Lite a subset of SIG Core?
Yes, in substance. SIG Lite covers the same risk domains as SIG Core with far fewer questions, asking whether a control exists rather than how it is implemented and evidenced. A buyer that starts with a Lite may follow up with the Core for higher-risk vendors.
Do I need a Shared Assessments license to answer a SIG?
No. The buyer licenses the SIG and sends you the file. You answer it and return it in the same structure. A license only matters if you want to send SIGs to your own vendors or build tooling on the content.
Is the CAIQ free?
Yes. The Cloud Security Alliance publishes the CAIQ, CAIQ Lite, and the Cloud Controls Matrix for free download, and vendors can publish a completed CAIQ on the CSA STAR registry as a Level 1 self-assessment at no charge.
Can one set of answers cover SIG, SIG Lite, and CAIQ?
Largely. The controls they ask about overlap heavily, so the same set of current policies answers most of each. What differs is the wording, numbering, and depth, which is why answering from source documents each time, rather than copying between questionnaires, keeps the answers accurate.