CAIQ v4.1 Is Live — Do You Need to Remake Your STAR Questionnaire?
CAIQ v4.1 is live and STAR still accepts v4.0 through Dec 2027. No panic rebuild today - here is the CSA timeline, what changed, and a practical remapping plan.
Buyers or a GRC tool ask whether your published CAIQ is on v4.1. You already spent a painful quarter finishing a STAR Level 1 entry on v4.0. The founder question is immediate: Are we behind? Do we remake the whole questionnaire this week?
This post is for SaaS founders, Heads of Security or Compliance, and RevOps leads who already completed a CAIQ or plan to publish one to the CSA STAR Registry to cut questionnaire volume - and who now see v4.1 language in diligence. The goal is a calm cutover plan tied to official CSA dates, not a Friday fire drill.
The direct answer
You do not need to panic-rebuild today if you have a current v4.0 STAR entry. CSA STAR Registry has accepted both v4.0 and v4.1 submissions for Levels 1 and 2 since March 2026. Dual acceptance continues through December 2027.
You should plan a remapping before your next registry refresh and before December 2027, because CCM/CAIQ v4.0.x is withdrawn in January 2028. From December 2027, new STAR Level 1 and Level 2 submissions must be on v4.1 only. Existing registry entries get a transition window; new joiners after the cutover do not.
Treat that as a scheduled answer-bank project, not an emergency rewrite.
What changed in CAIQ / CCM v4.1
Per CSA CCM v4.1 transition timeline (19 February 2026) and Compyl August 2026 SIG vs CAIQ summary:
| Item | v4.0 / prior | v4.1 |
|---|---|---|
| CCM controls | prior v4.0.x baseline | 207 controls across 17 domains |
| CAIQ questions | 261 in v4.0 | 283 in v4.1 |
| New control specs | - | 11 new across DCS, LOG, SEF, STA, TVM |
| Removed | - | One IAM control removed |
| Lite variants | CCM-Lite / CAIQ-Lite | Also updated for v4.1 |
CSA released CCM and CAIQ v4.1 in January 2026 (artifact dated 27 January 2026; CSA transition blog cites 28 January for the CCM release note). Supporting Implementation and Auditing Guidelines shipped with the package. Mappings to other standards are being refreshed with industry partners - do not assume every old crosswalk still applies without checking CSA current mapping set.
Official STAR transition timeline (CSA dates only)
| Milestone | Date |
|---|---|
| CCM v4.1 and CAIQ v4.1 officially released | January 2026 |
| STAR Levels 1 and 2 accept both v4.0 and v4.1 submissions | March 2026 |
| New STAR Level 1 submissions v4.1-only; surveillance/recertifications on CAIQ v4.1 | December 2027 |
| New STAR Level 2 submissions v4.1-only | December 2027 |
| CCM/CAIQ v4.0.x withdrawn (archive/reference only; no further maintenance) | January 2028 |
CSA transition blog (19 February 2026) is the source for this table. Compyl (updated 11 August 2026) restates the same Dec 2027 / Jan 2028 cutover for practitioners.
CAIQ is still a self-assessment, not a certification
A completed CAIQ published to STAR Level 1 is a structured self-attestation against the Cloud Controls Matrix. It is not a certification.
STAR Level 2 remains the audited tier (attestation or certification layered on an independent audit such as ISO 27001 or SOC 2). Treat published CAIQ answers the way you treat Trust Center claims: useful starting evidence for buyers, not a free pass. Compyl August 2026 comparison makes the same point - and it is the framing Workstreet already uses in CAIQ vs SIG.
If a buyer asks are you CAIQ certified?, correct the language: you have a published STAR Level 1 self-assessment (and, separately, whatever audited certs you actually hold).
Practical remapping steps for a Workstreet-shaped SaaS
Use the dual-acceptance window to remap cleanly instead of scrambling in late 2027:
1. Diff v4.0 v4.1. Pull CSA change analysis / release notes. Inventory the 11 new control specs (DCS, LOG, SEF, STA, TVM), the removed IAM control, and any revised control language that changes how you previously answered.
2. Update the answer bank and Trust Center docs for the new control areas. Draft responses and cite evidence once - logging/monitoring depth, incident management, supply-chain / Nth-party language, threat and vulnerability management, datacenter/security-location claims as applicable to your delivery model.
3. Re-submit STAR Level 1 on v4.1 when the answer bank is ready (or at your next planned registry refresh). Do not wait until December 2027 if a major customer already filters on v4.1.
4. Keep SIG / custom DDQ answers in sync. Remapping CAIQ while letting SIG Lite/Core and custom questionnaires drift creates three answer sources. Sync the shared control themes in one pass; see SIG questionnaire and the questionnaire hub at security compliance questionnaires.
5. Package for sales. Update the one-pager your AEs share: STAR Level 1 on CAIQ v4.1; here is the Trust Center link. For packaging attestation vs questionnaire volume generally, see SOC 2 vs security questionnaires and building trust with a company trust page.
Light SIG contrast (not a deep dive)
SIG remains Shared Assessments licensed, buyer-scoped depth questionnaire across a broad third-party risk library. CAIQ remains CSA free, cloud-specific self-assessment designed for public STAR publication.
2026 also brought SIG Evolution (SIG EV), a browser-based platform Shared Assessments launched 17 March 2026 - mention it only as context that the SIG side is modernizing delivery, not as a reason to abandon CAIQ. For the full comparison, use Workstreet existing CAIQ vs SIG post. This article is the version-cutover page, not a rewrite of that explainer.
What withdrawn means for your old CAIQ
When CSA withdraws CCM/CAIQ v4.0.x in January 2028, the documents remain in CSA archives for reference, but they are no longer maintained or updated. For STAR, the operational consequence is sharper: after December 2027, new Level 1 and Level 2 submissions must use v4.1. If your go-to-market story depends on a public STAR listing, plan the remapping so your next submission - or the refresh that lands you past the cutover - is already on v4.1.
You do not need to delete a v4.0 PDF from your Trust Center the day v4.1 ships. You do need a dated plan for which version prospects will see after the cutover.
How buyers will notice the version cutover
Expect diligence friction in three places before the hard deadline:
1. Registry filters and AI scoring. CSA Valid-AI-ted service scores STAR Level 1 CAIQ submissions; as more listings move to v4.1, buyers who sort by freshness or score will prefer current-version entries. Do not invent a required Valid-AI-ted score - treat scoring as an optional quality signal, not a Workstreet claim.
2. GRC platforms and questionnaire portals. Tools that ship CAIQ templates will default to v4.1. A vendor still answering from a v4.0 export will look out of date even while STAR dual-accepts both.
3. Customer security questionnaires. Some EU and US enterprise DDQs already ask CAIQ version or CCM version. A one-line answer - STAR Level 1 on CAIQ v4.1 as of [month] - is cleaner than explaining dual acceptance mid-deal.
The remap is therefore a revenue-enablement task as much as a GRC hygiene task.
Evidence habits that make remapping cheaper
The expensive part of a CAIQ is not typing yes/no. It is finding evidence and keeping narrative answers consistent. Before you open the v4.1 spreadsheet:
- Freeze a control-to-evidence index for shared themes (access, logging, incident response, vulnerability management, supplier management).
- Note which answers are policy only vs policy + technical evidence vs screenshot / config export.
- Assign an owner for each of the 11 new control areas so the work does not bounce between Security and Eng without a due date.
- Decide whether STAR Level 2 is on your roadmap. If you already hold SOC 2 or ISO 27001 and want the audited STAR tier later, remap Level 1 language so it will not contradict a future Level 2 narrative.
Workstreet questionnaire automation work starts from that evidence index - the same habit that reduces custom DDQ thrash in SOC 2 vs security questionnaires.
A 90-day remap outline (example, not a CSA mandate)
This is a practical sequencing template for a mid-stage SaaS; adjust to your registry refresh date:
| Window | Outcome |
|---|---|
| Days 1-15 | Diff complete; gap list for 11 new controls + removed IAM; owners named |
| Days 16-45 | Draft answers and evidence links; Legal/Security review on supply-chain and incident claims |
| Days 46-60 | Trust Center and sales one-pager updated; SIG/custom DDQ sync for overlapping themes |
| Days 61-90 | STAR Level 1 v4.1 submitted (or queued for next refresh); old v4.0 labeled as superseded in internal docs |
If your next STAR refresh is already inside Q4 2027, compress this plan now. If you refreshed in early 2026 on v4.0, you still have runway - use it.
Soft next step
If v4.1 remapping is competing with live deal questionnaires, Workstreet can help update the answer bank, keep Trust Center claims aligned with STAR language, and automate recurring questionnaire responses so CAIQ, SIG, and custom DDQs do not drift. That is questionnaire and Trust Center program help - not a claim that Workstreet is a CSA auditor or that a published CAIQ replaces SOC 2 or ISO evidence.

