The habit I see most often is answering SIG and CAIQ questionnaires the way the sales team would like: Yes on any line that’s even partly true, and NA on anything someone else runs. That isn’t what the answers mean. The Cloud Security Alliance (CSA) defines a CAIQ Yes as a control that “is implemented and meets the requirement”, so a partly built control is a No with its status written in the implementation description, and an NA needs a written justification tied to the service being assessed.
Last year’s answers are probably stale already. CSA released the STAR Level 1 questionnaire on CAIQ v4.1 (the Consensus Assessments Initiative Questionnaire) on 27 January 2026, with 283 questions set against the 207 controls of Cloud Controls Matrix (CCM) v4.1. Shared Assessments released the 2026 Standardized Information Gathering (SIG) questionnaire on 19 September 2025, and the SIG now measures risk across 21 domains. And for a firm delivering from India, several lines ask things Indian law has already settled: the six-hour incident clock set by the Indian Computer Emergency Response Team (CERT-In), where logs are kept, and which time servers your systems sync to.
Where questionnaire answers go wrong
Questionnaire answers go wrong in the same few places: the reflexive Yes, the whole-company answer, the NA that really means someone else does it, and the old answer nobody re-read. Each one looks fine on the day it’s sent. Trouble starts at the evidence request.
The reflexive Yes starts with sales wanting every line green before the deal closes. Commenters on Hacker News describe where that leads: automated vulnerability scans reported as penetration tests, and TLS in transit described as end-to-end encryption. Those answers hold until someone asks for the test report. But a questionnaire answer isn’t marketing copy (it is a written statement the client relies on when it decides to hand you its data).
The whole-company answer is subtler. A client reviewing one service asks about “all systems”, and the team answers for the entire firm, or answers in words that do not match the SOC 2 system description the client already holds.
Then there’s NA used to mean “we don’t run that” or “the client runs that”. Neither is what NA means on the CAIQ, and the ownership column exists for the second case.
Copied answers do slower damage. Last year’s wording goes into this year’s questionnaire unread, so a retired tool or an old retention period survives another cycle, and an AI autofill tool will spread a weak answer into every new questionnaire it touches. Is a wrong answer any truer for being sent to ten clients? It’s only harder to take back.
Two workarounds do not work either. Attaching a policy PDF in place of an answer tells the assessor what you intend, not what you do. And “documentation will be provided separately”, which one Hacker News commenter suggests as a way to buy time, only moves the question to a worse moment.
Worth flagging: CSA’s guidance asks that implementation descriptions be “documented relevant to question in focus and not in general nature”. My read is that as buyers move to web-delivered and AI-scored assessments, a generic description gets easier to flag automatically, so specificity stops being a matter of style and becomes a pass-or-fail point.
It helps to picture the analyst scoring your SIG. That person reads each line against the evidence you send, and as I see it, a line that claims more than the evidence shows costs more credibility than an honest No.
How to answer SIG and CAIQ questionnaires
The way to answer SIG and CAIQ questionnaires is line by line, for the service under review only, using the answer meanings the frameworks’ own publishers define. Scope comes first. A question about “all systems” is answered for the systems in scope for this service, and the answer says so, so nobody reads it as a claim about the whole firm.
SIG questions may not be edited without written permission under the Terms of Use, according to the Shared Assessments SIG FAQ. So a line broader than your service gets scoped in the comment, never reworded. The same FAQ notes that up to 100 custom questions can be added, and that the Content Library’s detail-level questions are not included in the standard SIG questionnaires (so nobody is answering the whole library).
Every SIG example here is comment wording only. That’s where scope and caveats live on the SIG, so here’s the one I’d put on a broad line (the SOW number and city are placeholders):
Comment: This response covers the payroll processing service delivered to you under SOW 3 from our Pune delivery centre. Our public marketing website and internal HR systems are outside this service and are not reflected in this answer.
Yes, No and NA on the CAIQ
Yes, No and NA on the CAIQ each have a fixed meaning in the Cloud Security Alliance’s guidance, and none of them is “partly”. CSA describes the STAR Level 1 CAIQ v4.1 as “a set of Yes/No questions”, and its 2022 STAR compliance guidance defines the three answers. Yes means “the CCM control in question is implemented and meets the requirement”. No means it isn’t, and the implementation description documents the status of implementation or who has taken on ownership; NA means the control is not in scope and not applicable to the cloud assessment, with a documented justification.
So what goes on the line when a control is only half built? The v4.1 answer dropdown offers no Partial. A partly built control is a No that says what exists, what’s missing, who owns it and when it lands. On business continuity testing, a No I’d send reads like this (the dates and risk ID are illustrative):
No. SSRM ownership: CSP-owned. Implementation description: A business continuity plan for the service under assessment was approved in March 2026. Its first annual test has not yet been run; the test is scheduled for November 2026 and tracked as risk item R-14. The approved plan is available under NDA.
Bottom line: that No survives evidence review. A Yes on the same facts fails the moment the assessor asks for the test report, and I’d rather lose a point on the scorecard than the reviewer’s trust.
NA works when the control doesn’t apply to the service. For a team that delivers only inside a client’s hosted virtual desktop (VDI), a backup line might read:
NA. Implementation description: Our team works only inside the client’s hosted virtual desktop. No customer data is stored on our infrastructure or endpoints, so backup of customer data is not applicable to this service. Backup of the client environment remains with the client.
Fair warning: if the control is in scope and the client runs it, the answer isn’t NA at all. That’s what the ownership column is for. On evidence, point to it and say what’s available under NDA, rather than pasting architecture detail into a document that circulates beyond its sender.
Control ownership and the SSRM column
Control ownership in the CAIQ is recorded in the SSRM column, which is mandatory on every Yes or No line. SSRM is CSA’s shared security responsibility model, and the frame matters: in the CAIQ, you (the responding vendor) are the cloud service provider, or CSP, and your client is the cloud service customer, or CSC. Indian teams that deliver inside a client’s environment tend to read the column backwards.
The column took five values, per CSA’s notes on the CAIQ v4 release and its 2022 guidance. CSP-owned means you are responsible and accountable, and CSC-owned means the customer implements the control. 3rd party-outsourced means a third-party CSP implements it while you stay accountable, and the two shared values (Shared CSP and CSC, and Shared CSP and 3rd party) split the work between the parties named.
The column arrived with CAIQ v4 in 2021, when CSA also cut the question count from 310 in v3.1 to 261. Version 4.1 runs to 283 questions, and its workbook lists a sixth value, Not Determined. Ownership set in 2021 needs re-checking.
Here’s how the column works on the physical security line for an Indian SaaS team in a public-cloud India region:
Yes. SSRM ownership: 3rd party-outsourced. Implementation description: Physical and environmental controls for the hosting facilities are implemented by our infrastructure provider. We rely on its independent assurance reports and its published CAIQ, reviewed annually under our supplier review procedure. Our own offices hold no customer data.
And the commonest mistake I see on that line is NA. Hyperscalers make the correct answer easy to support: Microsoft publishes its CAIQ responses through the STAR Registry, as Microsoft Learn describes, and AWS publishes its own CAIQ as a PDF. In my view this is the column that decides how a small Indian SaaS team’s answers read, because a firm without its own SOC 2 leans hardest on inherited controls.
One answer library for SIG and CAIQ
One answer library serves both SIG and CAIQ because the SIG itself maps to the CAIQ. Shared Assessments lists CSA CAIQ 4.0 and CCM v4 among the SIG’s mappings, alongside ISO 27001:2022, NIST CSF 2.0, DORA, NIS 2 and GDPR. That helps EU clients working through NIS2 flow-down to Indian vendors: one set of answers traces to both.
The SIG’s mechanics support this, per the SIG FAQ. A service provider can use a Response Template to fill in responses proactively, responses migrate from any version back to 2021, and subject-matter-expert questionnaires can be sent internally and appended, which settles who fills in which domain. SIG EV, the web-based delivery, does not change how vendors respond.
Think of it this way: the library is the single source, and each questionnaire is a view of it. Hacker News threads from small-company founders describe 100-question custom questionnaires arriving from 100-person clients, and one practitioner’s advice there is to keep a standard CAIQ current and ask the client to accept it. Some vendors do that, and I’d offer it rather than insist.
Every library answer should use the same scope as your SOC 2 system description and your ISO/IEC 27001:2022 ISMS scope. If you’re scoping a SOC 2 report for an Indian service business, settle that boundary first and write the library to it. Without either report? A STAR Level 1 CAIQ is a self-assessment, so a firm still answers from the controls it has.
And tag each answer with its framework version. SIG content follows an annual release cycle, and under CSA’s CCM v4.1 transition timeline only v4.1-based STAR submissions are accepted from December 2027, with CCM and CAIQ v4.0.x withdrawn in January 2028.
Indian obligations in SIG and CAIQ questionnaires
The Indian obligations that surface in SIG and CAIQ questionnaires come mostly from CERT-In’s Directions of 28 April 2022 and, on privacy lines, from the Digital Personal Data Protection Act, 2023 (DPDP Act). Issued under section 70B(6) of the Information Technology Act, 2000, the CERT-In Directions apply to service providers, intermediaries, data centres, body corporate and government organisations. They require listed cyber incidents to be reported to CERT-In within six hours of noticing them, a designated Point of Contact, and logs of all ICT systems kept for a rolling 180 days within Indian jurisdiction. Clocks must sync to the NTP servers of the National Informatics Centre (NIC) or the National Physical Laboratory (NPL), or to servers traceable to them.
The clash I’d flag first is the incident clock. Say the client’s contract sets 24 hours’ notice to the client, while CERT-In sets six hours to CERT-In. Both apply, to different recipients, so disclose the regulator clock rather than let the client discover CERT-In heard first. The two clocks get reconciled in a written breach response plan, and the comment then reads like this (the 24-hour figure stands in for whatever your contract says):
Comment: Confirmed security incidents affecting client data are notified to you within 24 hours of confirmation under our incident response procedure. As a body corporate in India we also report the incident types listed in the CERT-In Directions of 28 April 2022 to CERT-In within six hours of noticing them, and our CERT-In point of contact is designated.
In practice, logging and time-sync lines are simpler, because the Directions hand you the wording:
Comment: Logs from all in-scope systems are retained for a rolling 180 days within India, as the CERT-In Directions require, and forwarded to your SIEM for the longer retention period in our contract. System clocks synchronise to NTP servers traceable to NIC and NPL.
Data-location lines under VDI delivery need two facts, stated separately: the data sits in the client’s tenant, and it is accessed from India.
Which privacy law applies, then? The short answer: where an India-based firm processes personal data of people outside India under a contract with a person outside India, section 17(1)(d) of the DPDP Act disapplies most of Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16. Section 8(5)’s duty to take reasonable security safeguards still applies, and failing to maintain those safeguards carries a penalty of up to Rs 250 crore under the Act’s Schedule.
The DPDP Rules, 2025 were notified on 14 November 2025 with an eighteen-month phased compliance period. For the full section 17(1)(d) analysis, see the piece on vendor security questionnaires from US tax and accounting firms.
My advice is to write the CERT-In and DPDP lines into your answer library as standing comments now, and put two review dates on them. One is the end of the DPDP Rules’ eighteen-month phase-in that began on 14 November 2025. The other is December 2027, after which CSA accepts only v4.1-based STAR submissions.
FAQs
Can I send my SOC 2 report instead of filling in the questionnaire?
A SOC 2 report is an auditor’s examination of controls at a service organisation relevant to security, availability, processing integrity, confidentiality or privacy, as the AICPA’s SOC 2 guide frames it. The SIG and CAIQ ask line-level questions that the buyer scores one by one, so the two documents do different jobs. I’d send both, and point individual answers at the report section that evidences them.
Should I publish my CAIQ on the STAR Registry?
STAR Level 1 is a complimentary self-assessment, submitted as the CAIQ and updated annually, according to CSA’s STAR levels page. The registry is publicly accessible, so competitors and prospects can read what you file, and optional Valid-AI-ted scoring costs USD 595 (free to CSA corporate members). If you publish, write every answer knowing a stranger will read it.
Which one will a client send me, a SIG or a CAIQ?
The CAIQ is built for cloud services against the CCM, while the SIG covers any third party, with SIG Lite for lower-risk or preliminary assessments and SIG Core for providers handling highly sensitive or regulated data, per Shared Assessments’ Which SIG Should I Use? guide. CSA offers the CAIQ as a free download. The SIG is a licensed product (the corporate licence costs USD 7,000 a year), so a SIG reaches you from a licensed customer.
References
- STAR Level 1: Security Questionnaire (CAIQ v4.1). Cloud Security Alliance, 27 January 2026 (workbook v4.1.0: answer definitions, SSRM values, 283 questions)
- The CSA Cloud Controls Matrix v4.1: Strengthening the Future of Cloud Security. Cloud Security Alliance, 2 December 2025
- CCM v4.1 Transition Timeline. Cloud Security Alliance, 19 February 2026
- How to Achieve CSA STAR Compliance. Cloud Security Alliance, 2 September 2022
- CAIQ v4 Released: Changes from v3.1 to v4. Cloud Security Alliance, 7 June 2021
- STAR program and levels. Cloud Security Alliance
- SIG EV. Shared Assessments
- SIG FAQ. Shared Assessments
- Which SIG Should I Use? (2024 SIG). Shared Assessments
- 2026 SIG Workbook: Key Updates and Enhancements. Shared Assessments, 18 July 2025
- Directions under sub-section (6) of section 70B of the Information Technology Act, 2000. Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and Information Technology, 28 April 2022
- The Digital Personal Data Protection Act, 2023. Ministry of Electronics and Information Technology, Government of India
- Digital Personal Data Protection Rules, 2025 (backgrounder). Press Information Bureau, Government of India, 17 November 2025
- ISO/IEC 27001:2022, Information security management systems: Requirements. International Organization for Standardization
- System and Organization Controls: SOC Suite of Services. AICPA & CIMA
- CSA STAR Self-Assessment. Microsoft Learn (vendor documentation)
- CSA Consensus Assessments Initiative Questionnaire. Amazon Web Services (vendor documentation)
This article is for educational purposes only and does not constitute professional, financial, legal, or immigration advice. For guidance specific to your situation, consult a qualified professional.


Allow notifications