ChaptersEventsBlog
How is your enterprise using AI Agents? Help us benchmark security and take the survey before November 30 →

Download Publication

CCM-Lite and CAIQ-Lite
CCM-Lite and CAIQ-Lite

CCM-Lite and CAIQ-Lite

Release Date: 06/04/2024

Working Group: Cloud Controls Matrix

The Cloud Security Alliance, in collaboration with the CCM Working Group, proudly presents the CCM-Lite and CAIQ-Lite File Bundle. These tools offer a streamlined way to assess cloud security.

CCM-Lite: 

The CCM-Lite is a simplified version of the Cloud Controls Matrix (CCM) v4. It includes 91 carefully chosen controls, a subset of the original 197. These controls are essential for any organization's cloud security, regardless of size or budget. They serve as the fundamental building blocks for a strong security posture.

CAIQ-Lite: Efficient Vendor Engagement

Accompanying the CCM-Lite is the CAIQ-Lite, which stems from the Consensus Assessments Initiative Questionnaire (CAIQ). It presents 124 focused questions across 17 control domains, from the CCM v4. This condensed approach streamlines vendor assessment, making it easier for cybersecurity professionals to engage with cloud vendors and enhance their security efforts.


Frequently Asked Questions:

Download this Resource

Bookmark
Share
View translations
Related resources
Introductory Guidance to AICM
Introductory Guidance to AICM
AICM Implementation & Auditing Guidelines (Frameworks)
AICM Implementation & Auditing Guidelines (Fram...
AI Controls Matrix
AI Controls Matrix
Implementing CCM: Threat & Vulnerability Management Controls
Implementing CCM: Threat & Vulnerability Management Controls
Published: 11/21/2025
It’s Time to Make Cloud Threat Modeling Continuous
It’s Time to Make Cloud Threat Modeling Continuous
Published: 11/20/2025
Understanding STAR for AI Level 2: A Practical Step Toward AI Security Compliance
Understanding STAR for AI Level 2: A Practical Step Toward AI Secur...
Published: 11/19/2025
VDI, DaaS, or Local Secure Enclaves? A CCM‑Aligned Playbook for BYOD in 2025
VDI, DaaS, or Local Secure Enclaves? A CCM‑Aligned Playbook for BYO...
Published: 11/04/2025

Interested in helping develop research with CSA?

Related Certificates & Training