Skip to main content

Evidence note

Cloud Controls Matrix and CAIQ v4.1

Practitioner Reference2026Cloud Security Alliance

What does it cover?

A structured cloud-security assurance framework and associated consensus assessment questionnaire.

Key points

  1. 1CCM v4.1 contains 207 controls across 17 domains.
  2. 2CAIQ v4.1 contains 283 assurance questions aligned to the framework.
  3. 3The framework illustrates how structured customer assurance can extend across many security and operational areas.

Why it matters. Lornets interpretation.

Enterprise readiness is better understood as a claims-and-evidence problem than a questionnaire-writing exercise. The customer needs defensible technical evidence behind relevant answers.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 1Not every enterprise procurement process uses CSA.
  2. 2Completing CAIQ does not independently establish that a supplier is secure.
  3. 3Self-assessment and independent assurance are distinct forms of evidence.

Source

Organisation
Cloud Security Alliance
Evidence type
Practitioner Reference
Published
2026-01-27
Version
4.1
Status
Current

View the original source

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Data & Privacy Engineering
  • Reliability & Recoverability
  • Observability & Operations

Where this applies

Related evidence

Last verified 2026-08-11

2026

Government Guidance

Supplier Assurance Questions

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

UK National Cyber Security Centre

  • Enterprise Assurance
  • Security & Supply Chain

2022

Technical Standard

ISO/IEC 27001:2022

ISO/IEC 27001 addresses organisational information-security management.

ISO / IEC, 2022 edition, with Amendment 1:2024 applicable

  • Enterprise Assurance
  • Security & Supply Chain