GUIDES
Security questionnaires, explained.
The CAIQ, the SIG, the DDQ, the VSA — and the AI governance module that now appears inside all of them. What each one is, who sends it, what it asks, and how to answer it without a fortnight of internal archaeology.
Current as of July 2026.
GUIDE · CAIQ
What is the CAIQ?
The Consensus Assessments Initiative Questionnaire — the Cloud Security Alliance's standard security questionnaire, built on its Cloud Controls Matrix.
Read guide →
GUIDE · SIGWhat is the SIG questionnaire?
The Standardized Information Gathering questionnaire from Shared Assessments — the heavyweight of third-party risk.
Read guide →
GUIDE · DDQWhat is a vendor DDQ?
Due-diligence questionnaires: the catch-all name for the bespoke security and governance questionnaires enterprises send vendors.
Read guide →
GUIDE · VSAWhat is the VSA questionnaire?
The Vendor Security Alliance questionnaire — a standardised security questionnaire built by a coalition of companies to cut questionnaire fatigue.
Read guide →
GUIDE · THE AI MODULEThe AI module: the questionnaire section where deals stall.
Whatever the questionnaire — CAIQ, SIG, VSA, or a buyer's own DDQ — a dedicated AI governance section now appears inside it.
Read guide →
Free readiness check
See which sections you would fail today.
Free, no sign-up to see your result.