SIG vs CAIQ vs VSA: A Simple Guide to the Big Three

Aug 19, 2026
9
min read
Sailee Sarangdhar
Sailee Sarangdhar
SIG vs CAIQ vs VSA: A Simple Guide to the Big Three
Share this post

SIG vs CAIQ vs VSA: A Simple Guide to the Big Three

You opened a spreadsheet from a prospect this morning. It has 300 rows, a tab you do not recognize, and a column asking for a control ID. There is a second one sitting in your inbox from a different prospect, asking most of the same things in a different order.

The three acronyms that keep showing up are SIG, CAIQ, and VSA. Telling them apart saves real hours, because each one wants something different from you. If you have filled out enough of these, the questions start to blur together no matter whose logo is on the file.

All three are asking about the same controls. What changes is who sends them, how deep they go, and whether you can answer one before it ever lands in your inbox.

Key Takeaways

  • SIG is the enterprise workhorse, and the buyer covers the license, not you. Shared Assessments licenses SIG to the companies sending it out, so vendors filling one out owe nothing.
  • CAIQ is the only one you can answer before a buyer asks. Completed CAIQs get published to a public registry, which means prospects can read your answers without emailing you first.
  • VSA is the free short one, built by the companies doing the assessing. It comes in two versions, and the shorter one is the one that covers privacy.
  • SIG and CAIQ both added AI governance questions in 2026. An answer library built before this year has a gap that buyers are already probing.
  • All three ask substantially the same underlying questions. Wording, depth, and answer format change from one to the next, but your actual controls stay the same, which is why answer reuse works so well.

SIG vs CAIQ vs VSA: Quick Comparison Table

SIG CAIQ VSA
Full name Standardized Information Gathering questionnaire Consensus Assessments Initiative Questionnaire Vendor Security Alliance questionnaire
Run by Shared Assessments Cloud Security Alliance (CSA) Vendor Security Alliance
Cost to you as responder Free, since the buyer holds the license Free Free
Scope Whole vendor relationship, 21 risk domains Cloud services, 17 domains Security, plus privacy in the Core version
Current version Updated yearly, 2026 edition current CCM and CAIQ v4.1, released January 2026 Published versions are several years old
Answer format Scoped by domain, with detail fields Yes, No, or NA against numbered control IDs Yes or No plus open text
Publish in advance? No Yes, through the CSA STAR Registry No
Who sends it Banks, insurers, healthcare, large enterprise Anyone buying cloud or SaaS Tech companies, less often than the other two

What Is the SIG Questionnaire, and Who Sends It

SIG stands for Standardized Information Gathering questionnaire. It comes from Shared Assessments, a membership group that has been building third party risk tooling since 2005.

Two things about SIG surprise people the first time.

The first is that it is a licensed product. You cannot download a blank SIG the way you can grab a CAIQ. The company sending it pays for access, either through membership or a standalone subscription. The money part trips people up, so worth being clear: the license sits on the buyer side. If you are the vendor filling one out, you owe nothing. What you give up is the ability to grab a blank copy and pre-fill it on your own schedule.

The second surprise is how broad it is. SIG covers more than security. It spans 21 risk domains across the full surface of a vendor relationship, so expect questions about business continuity, hiring and background checks, physical facilities, privacy, data governance, compliance programs, and your own vendors. That last one, sometimes called fourth party or nth party risk, catches teams off guard. The buyer wants to know who you depend on.

Source: HYPR

SIG ships in three depth tiers, now set up as scoping presets. SIG Lite runs around 126 to 128 questions and gets used for low risk vendors or early screening. SIG Core is the standard depth for most vendor populations. SIG Detail goes deepest, shows up for critical vendors, and can run past a thousand questions.

Shared Assessments updates SIG every year. The 2026 release added an ISO/IEC 42001 reference for AI management systems, deepened the NIST SP 800-171 mapping, and introduced embedded guidance called Hover Helpers meant to cut down on clarification emails. In March 2026 they launched SIG EV, a browser-based platform for building and scoring assessments. Vendors can still complete a SIG offline in Excel and let the buyer import it.

SIG shows up most often from financial services, insurance, healthcare, and large enterprises with a mature third party risk function. Keep one thing in your back pocket for the sales conversation. A completed SIG does not work like a certification. What you hand back is a structured set of assertions, and the buyer decides whether your answers clear their risk bar. That framing helps when someone treats a returned SIG like a pass or fail exam.

What Is CAIQ, and Which Version You Need in 2026

CAIQ stands for Consensus Assessments Initiative Questionnaire. It comes from the Cloud Security Alliance, and it is free.

CAIQ is the question form of another CSA document called the Cloud Controls Matrix, or CCM. The CCM is a catalog of cloud security control objectives grouped into domains. CAIQ turns each control into a question you answer yes, no, or not applicable, with space for supporting detail.

Version numbers matter here more than usual, so check which one landed in your inbox. CSA released CCM v4.1 in January 2026. It carries 207 controls across 17 domains, up from 197 in v4.0.13, and the matching CAIQ v4.1 has 283 questions. Eleven new control specifications came in, spread across data center security, logging, incident response, supply chain, and threat and vulnerability management. One identity and access control came out.

Source: Fractional CISO 

The STAR Registry accepts both v4.0.x and v4.1 submissions through December 2027. After that, new submissions have to use v4.1, and v4.0.x gets withdrawn in January 2028. If you already keep a STAR listing, schedule the refresh instead of waiting for the deadline to force it.

The mapping back to the CCM is why CAIQ files look different from the other two. Every row carries a control ID built from a domain abbreviation and a number. If you see identifiers like IAM-01, CEK-03, or DSP-07 in a column, you are looking at a CAIQ.

Where the finished answers go is what really sets CAIQ apart. You can submit a completed CAIQ to the CSA STAR Registry, which is public and free to search. Buyers can look you up and read your answers without contacting you at all. Answer once, publish, and deflect a share of inbound requests before they ever reach your team.

Be precise about what that publication means, though. STAR Level 1 is a self assessment. You attest to your own controls, nobody audits the answers, and the listing needs an annual refresh to stay current. Level 2 involves a third party audit and produces a certification or attestation. Level 3 is built around continuous automated monitoring. CSA also offers a paid option called Valid-AI-ted that runs AI checks on CAIQ responses for completeness and consistency, which sits somewhere between a plain self assessment and a real audit. Buyers who care about the difference between these levels will know the difference, so avoid presenting a Level 1 listing as a certification.

What Is the VSA Questionnaire, and When to Skip It

VSA stands for Vendor Security Alliance questionnaire. The VSA is a nonprofit coalition formed by Airbnb, Atlassian, Docker, Dropbox, and Uber, companies that got tired of both sending and receiving redundant security questionnaires and built a shared one instead. The first questionnaire came out on October 1, 2016.

It is free, and it comes in two versions that people mix up constantly.

VSA-Full is the deeper one, focused on security across sections covering data protection and access controls, security policies, proactive and reactive security measures, software supply chain, application security, and compliance. VSA-Core is the shorter one, and it is the version that adds privacy, covering US breach notification requirements, CCPA, and GDPR. If someone tells you Core is just a trimmed down Full, that is wrong. Core trades security depth for privacy coverage.

The interesting part about VSA is who wrote it. Security teams doing the assessing built it, rather than a standards body, so the questions read like things a working security engineer actually wants to know.

Source: CYBERZONI

In practical terms, VSA shows up less often than the other two, and the publicly available materials carry dates that have not moved in a while. The group said it would refresh the questionnaire every year, and that cadence appears to have lapsed. If you are deciding where to spend prep time, VSA ranks lowest of the three for most vendors.

One naming trap worth knowing. Google published an open source tool also called VSAQ, the Vendor Security Assessment Questionnaire. Different project, similar acronym, and the repository was archived in November 2022. If someone mentions VSAQ, ask which one they mean before you go hunting for the wrong document.

AI Governance Questions Hit SIG and CAIQ in 2026

Both SIG and CAIQ picked up AI governance content this year, separately, which says a lot about where buyer attention has moved.

On the SIG side, the 2026 release added the ISO/IEC 42001 reference, so AI management questions now sit inside the standard question set rather than arriving as a custom bolt-on. On the CSA side, the AI Controls Matrix v1.1 shipped in June 2026 with a companion AI-CAIQ, the first standardized AI assessment questionnaire most vendors will run into.

What that means in practice is simple enough. Once AI governance questions live in the standard questionnaire, a buyer who skips them looks negligent, so they will not skip them. An answer library built before this year has a real gap. Getting structured answers ready about model usage, training data handling, vendor AI subprocessors, and human review beats improvising essay responses under deadline pressure. Our post on AI governance for enterprise knowledge digs into what to actually document.

Why SIG, CAIQ, and VSA Overlap, and How to Reuse Answers

If you ever line all three up next to each other, you’ll notice they’re all asking the same questions in different orders. 

Each of them wants to know whether you encrypt data at rest. Each one wants your access review cadence, your incident response process, your backup and recovery testing, your background check policy, your subprocessor list. The security posture being described stays the same no matter which logo sits on the spreadsheet.

What changes is the shape. SIG asks inside a scoped risk domain with a detail field. CAIQ asks against a numbered control objective. VSA asks in plainer language and fewer words. Same fact, three costumes.

That is why questionnaire work feels so much worse than it should. Each round is mostly reformatting. A security engineer writes a careful answer about key rotation in March, then rewrites the same answer in May because the new questionnaire words the question differently and wants it in a different cell.

Two things follow from that.

First, build a source of truth once instead of a library of finished questionnaires. Knowledge stored as answered facts about your controls maps to any format. Knowledge stored as a folder of completed PDFs turns every new format into a fresh translation job. That is the thinking behind a questionnaire knowledge base, and it separates a system that compounds from a pile that ages.

Second, get the reusable parts into shape so they can be pulled instead of rewritten. Most teams already have the raw material sitting in old responses, policy docs, and audit reports. Digging it out under a deadline is where the hours go.

How to Identify a SIG, CAIQ, or VSA File in 10 Seconds

Open the file and look for these tells:

Control IDs in a column. Short domain codes followed by numbers, like AIS-02 or TVM-04. That is a CAIQ, and the IDs trace back to the Cloud Controls Matrix. Check the version label while you are in there.

A copyright notice from Shared Assessments. That is a SIG. You will usually see multiple tabs too, plus a scoping structure that switches whole sections on and off.

Short, plainly worded questions with privacy mixed into security, no license notice. Most likely a VSA. If privacy shows up, you are probably looking at Core rather than Full.

Custom logo, no recognizable structure, 40 questions. A questionnaire the buyer wrote themselves, which is still the most common category overall. Standardized formats get the attention, but plenty of buyers just make their own.

Which Security Questionnaire to Prepare For First

Prep effort should follow two things. How often you see a format, and whether prepping it deflects future work.

CAIQ is the clear first priority for any cloud or SaaS vendor. It is free, cloud buyers request it most, and it is the only one of the three where a completed copy sits in public and answers questions for you. The payoff shows up twice. Faster responses next time, and fewer requests arriving in the first place. If you are building one now, build against v4.1 so you skip doing the work twice.

SIG comes second, and how high depends on your buyers. Selling into financial services, insurance, or healthcare means you will see SIG, and your answers should be organized against its risk domains before anyone asks. Selling to Series B startups means you may never see one.

VSA is worth reading once so you recognize it on sight. Building a dedicated prep motion around it makes sense only if your specific buyers use it.

Underneath all three, the prep that pays off most has nothing to do with any single questionnaire. A maintained, current, findable set of answers about your security program beats format-specific prep every time. Formats change every year. Your controls do not. Teams who keep a trust center and a current answer library accurate spend far less time on any questionnaire, in any format.

How to Automate CAIQ Responses

CAIQ earns automation ahead of the other two, because the finished file goes somewhere. Automate a SIG and you finish that SIG faster. Automate a CAIQ and you finish it faster, then publish it to the STAR Registry where it keeps working for you.

Six steps get you from a blank workbook to a live STAR listing. Connect your sources, upload the file, generate answers, review them, export, and submit. Most of the effort sits in the first step.

Here’s how 1up handles it:

Connect your sources

Point 1up at wherever your security knowledge already lives. Cloud storage, security policy repositories, compliance materials, your website and API docs, past completed questionnaires. Third party connectors cover Confluence, Google Drive, Notion, SharePoint, and more. If you already keep an answer library in another tool, you can migrate it over instead of starting from scratch.

Upload the questionnaire

CAIQ ships as a spreadsheet, and 1up handles Word, Excel, PDF, and web portal formats. It extracts and analyzes every query, skipping the header rows, definitions, and instructions padding out the CSA workbook. You pick your answer language and which sources to pull from before it starts.

Generate answers in bulk

1up reads each question, finds matching content in your knowledge base, and drafts a response from the sources you selected. It handles hundreds or thousands of questions at a time, and it pulls only from material you connected, so every answer traces back to something real.

Review and adjust

Every answer comes with options. Short, long, or a previous response from your library, so you can match the level of detail the buyer asked for. 1up also spots formatting elements like dropdowns rather than dumping everything into free text. Edit anything that misses and save the fix back to your knowledge base, and 1up uses your preferred wording next time a similar question shows up.

Export and publish

You get back the same file you uploaded with answers embedded, which keeps the control ID column and the Yes/No/NA structure intact for STAR submission. Give it a final read, submit to the registry, then set a calendar reminder for the annual refresh.

Handle the portals too

Plenty of buyers refuse spreadsheets and send you into Venminder, Panorays, or Whistic instead, and those portals often will not let you export the document at all. Fire up the 1up browser extension and ask it to scan the questionnaire. It reads every query on the page, generates answers, and lets you edit them on the fly without leaving the window.

Worth doing after your first CAIQ run: check the Weaknesses view. It flags topics where answers needed heavy editing, which gives you a direct list of where your documentation runs thin. Usually a more honest gap analysis than anything you would sit down and produce on purpose.

Answer It Once and Let the Format Sort Itself Out

Three acronyms, three layouts, one set of facts about your security program. SIG asks broadly and comes from your regulated buyers. CAIQ asks against numbered cloud controls and can sit in public working for you. VSA asks plainly and shows up least often. Sorting out which is which takes about ten seconds once you know the tells, and that alone saves a chunk of the confusion.

The bigger win comes from where you put your effort. Chasing each format separately means redoing the same work every quarter, because Shared Assessments and CSA both refresh on annual cycles and 2026 already added AI governance questions to both. Building a current, findable answer library means the next questionnaire is mostly review instead of research.

Start with CAIQ v4.1 if you sell cloud or SaaS. Get your SIG answers organized if you sell into regulated industries. Keep the underlying knowledge accurate either way, and every format after that gets easier.

Ready to stop rewriting the same answers in three formats? See how 1up automates security questionnaire responses using knowledge you already have.

FAQs

SIG comes from Shared Assessments and covers the whole vendor relationship across 21 risk domains, including business continuity, hiring, physical security, and your own vendors. CAIQ comes from the Cloud Security Alliance and focuses on cloud security controls across 17 domains, with every question tied to a numbered control ID. The other big difference is publication. A completed CAIQ can be submitted to the public CSA STAR Registry, where buyers can read your answers without contacting you. SIG has no equivalent, and the buyer holds the license, so you cannot pre-fill one on your own schedule.

Use CAIQ v4.1, released in January 2026 alongside CCM v4.1. It has 283 questions mapped to 207 controls across 17 domains. The STAR Registry still accepts v4.0.x submissions through December 2027, and v4.0.x gets withdrawn in January 2028. If you are building a CAIQ from scratch now, going straight to v4.1 avoids doing the work twice. If you already have a STAR listing on an older version, schedule the update rather than waiting for the deadline.

No. The SIG license sits on the buyer side, either through Shared Assessments membership or a standalone subscription. If you are the vendor responding, you owe no fee. What you give up is easy access to a blank copy, so you cannot download one and pre-fill it the way you can with CAIQ or VSA. Building your answers into a knowledge base ahead of time gets you most of the same benefit.

Sailee Sarangdhar

Sailee Sarangdhar

Sailee Sarangdhar is a Content Lead at 1up where she oversees content creation, strategy, collaboration, and publishing.

(Read more by
Sailee
)

Related Reads

Why Most Internal AI Assistants Get Built and Then Abandoned

04 Aug 2026
8
min read
Read blog

Building AI Governance for Enterprise Knowledge

28 Jul 2026
6
min read
Read blog

Why Your Internal AI Assistant Gives Wrong Answers: A Document Audit Guide

30 Jul 2026
10
min read
Read blog

Top AI Tools for Customer Success Teams in 2026

20 Jul 2026
6
min read
Read blog

How to NOT Use AI for Sales: 7 Mistakes That Lose Deals

17 Jul 2026
7
min read
Read blog
Table of contents

1up your sales team

See a demo of how 1up automates answers in seconds.
Book a Demo