AuditXYZ

Compliance Framework

Cloud Security Alliance Security, Trust, Assurance, and Risk Registry (CSA STAR)

CSA STAR is the global cloud security assurance programme with three certification levels. This guide covers self-assessment, certification, attestation, and how STAR differentiates cloud providers.

$5,000–$100,0001–6 months2024 (continuous updates)
Issuing BodyCloud Security Alliance (CSA)
First Published2011-09-01
Latest Version2024 (continuous updates)
Typical Cost$5,000–$100,000
Typical Timeline1–6 months
Audit RequiredNo
Audit FrequencyLevel 1: Self-assessment, updated annually. Level 2: Third-party audit, follows ISO 27001 or SOC 2 cycle. Level 3: Continuous monitoring.
Geographyglobal

CSA STAR: Cloud Security Trust and Assurance Guide

The CSA Security, Trust, Assurance, and Risk (STAR) Registry is the world's most comprehensive cloud security assurance programme. It provides a three-tiered framework for cloud service providers to demonstrate their security posture, building on the Cloud Controls Matrix (CCM) with progressive levels of assurance from self-assessment through continuous monitoring. The STAR Registry is publicly accessible, enabling cloud consumers to evaluate provider security before procurement.

What CSA STAR Is and Who Issues It

The Cloud Security Alliance (CSA) is a not-for-profit organization with a mission to promote the use of best practices for security assurance within cloud computing. Founded in 2009, CSA has grown into a global organization with chapters across North America, Europe, and Asia-Pacific, and its Cloud Controls Matrix (CCM) has become the de facto control framework for cloud security across the industry.

CSA STAR was launched in 2011 as the public-facing registry for cloud provider security assessments. It was designed to address a market gap: cloud customers needed a standardized, accessible way to evaluate potential providers' security posture, while providers needed a recognized mechanism for demonstrating security trustworthiness beyond marketing claims. The STAR programme built on existing frameworks — ISO 27001 and SOC 2 — rather than replacing them, adding cloud-specific additional requirements through the CCM.

The CSA operates the STAR Registry as a public database accessible without registration at cloudsecurityalliance.org. Providers listed in the registry have undergone some level of assessment, and the type and currency of that assessment is clearly disclosed. Consumers can filter by assessment type, geography, and industry to find providers that meet their requirements.

The CSA Cloud Controls Matrix (CCM) v4.0 — the foundation of all STAR assessments — contains 197 control specifications across 17 control domains, covering security governance, risk management, compliance, human resources security, asset management, data security, infrastructure security, key management, DevSecOps, network security, supply chain management, threat intelligence, universal endpoint management, cryptography, logging, IAM, application security, and business continuity.

Who Should Pursue CSA STAR

CSA STAR is most valuable for cloud service providers — IaaS, PaaS, and SaaS providers — who want to differentiate their security posture in the cloud marketplace. Specific scenarios where STAR provides competitive advantage include:

  • Enterprise sales cycles: Procurement teams increasingly include STAR status in vendor security questionnaires. A STAR Level 2 listing can streamline or replace lengthy manual security reviews
  • Government and regulated sector contracts: Agencies and regulated companies often require third-party security assurance. STAR Level 2 provides credible independent validation
  • Global market access: The STAR Registry is recognized across North America, Europe, and Asia-Pacific, providing a single assessment recognized by enterprise buyers globally
  • Customer transparency: The public STAR Registry listing demonstrates security commitment without requiring an NDA or report-sharing process

For cloud consumers, STAR is primarily a research tool. Searching the registry before vendor selection, checking the currency of assessments, and reviewing the CAIQ (Consensus Assessments Initiative Questionnaire) responses gives procurement and security teams structured information that would otherwise require time-consuming questionnaires.

Over 1,500 cloud providers are currently listed on the STAR Registry, ranging from global hyperscalers to niche SaaS providers. The volume demonstrates that STAR has achieved the critical mass needed for buyers to routinely check it.

The Three STAR Levels in Depth

Level 1 — Self-Assessment

Level 1 requires the provider to complete the Consensus Assessments Initiative Questionnaire (CAIQ), which maps the organization's security controls to each of the 197 CCM control specifications. The CAIQ asks providers to state whether each control is implemented, partially implemented, or not implemented, with brief explanatory text.

Completed CAIQs are submitted to CSA for publication on the STAR Registry. CSA does not audit or verify CAIQ responses — the self-assessment is unverified. However, the public nature of the registry creates accountability: inaccurate responses risk discovery during customer due diligence, and CAIQ responses form a baseline against which future assessments are compared.

Level 1 is free to complete and submit. The CAIQ itself is available free from the CSA. The primary cost is the internal time required to gather information from across the organization and complete accurate responses. For a well-documented cloud provider with organized compliance practices, Level 1 completion typically takes 40–80 hours of internal effort.

Level 2 — Third-Party Assessment

Level 2 provides independent validation of security controls through a CSA-authorized auditor. Two paths are available:

STAR Certification combines ISO 27001 certification with an additional assessment of CCM control requirements by a CSA-authorized certification body. The ISO 27001 audit covers the management system; the CSA-authorized auditor then assesses the CCM-specific controls. The resulting STAR Certification demonstrates both ISO 27001 conformance and additional cloud-specific security controls.

STAR Attestation combines SOC 2 attestation with an additional CCM assessment by a CSA-authorized CPA firm. The SOC 2 attestation covers the trust service criteria; the additional CCM procedures address cloud-specific controls. The STAR Attestation option is common among US-headquartered cloud providers who already undergo annual SOC 2 audits.

Both Level 2 paths require engagement of a CSA-authorized assessor. The CSA maintains a list of authorized certification bodies and CPA firms on its website. The underlying ISO 27001 or SOC 2 engagement is conducted first, then the CCM additional assessment is layered on — typically adding a few days of auditor time and $10,000 to $30,000 in incremental cost.

Level 3 — Continuous Monitoring

Level 3 extends Level 2 by adding automated, continuous assessment of cloud security controls rather than relying solely on point-in-time or period-of-time assessments. Providers at Level 3 use approved CSA continuous monitoring tools to generate real-time security data that is fed into the STAR Registry, providing near-real-time assurance rather than annual snapshots.

Level 3 is the most mature and expensive tier, and the market for CSA-approved continuous monitoring tools is still developing. Large cloud providers and those selling into highly security-sensitive markets are the primary adopters.

The Assessment Process

For Level 1, the process is self-directed: obtain the CAIQ, complete responses with supporting evidence references, and submit through the CSA portal. Annual updates are expected to keep the listing current.

For Level 2 STAR Certification:

  1. Engage a CSA-authorized ISO 27001 certification body
  2. Complete the ISO 27001 Stage 1 (documentation) and Stage 2 (evidence) audits
  3. The certification body simultaneously or subsequently assesses CCM criteria not covered by ISO 27001
  4. Upon successful completion, the certification body submits the STAR certificate to CSA for registry publication
  5. Annual surveillance audits maintain both ISO 27001 and STAR status; full recertification every 3 years

For Level 2 STAR Attestation:

  1. Engage a CSA-authorized CPA firm (with SOC 2 attestation capability)
  2. Complete the SOC 2 Type 2 attestation engagement
  3. The CPA firm assesses CCM criteria beyond the Trust Service Criteria scope
  4. The firm submits the STAR Attestation to CSA; the report summary is published on the registry
  5. Annual renewal follows the SOC 2 cycle

Costs and Timeline

ActivityTypical CostTimeline
Level 1 CAIQ completion (internal)$0 – $5,000 internal time2–6 weeks
Level 1 STAR Registry listing feeMinimal1 week
ISO 27001 certification (prerequisite for Level 2)$20,000 – $100,0006–18 months
SOC 2 Type 2 attestation (prerequisite for Level 2)$30,000 – $200,0006–9 months
CCM additional assessment for Level 2$10,000 – $30,000 incremental2–4 weeks incremental
Level 2 total (including prerequisites)$30,000 – $100,000+6–18 months
Level 3 continuous monitoringVariable, market developingOngoing

CSA CCM (95% overlap): The CCM is the control framework underlying all STAR assessments. STAR is the registry and assurance programme; CCM is the control specification. Organizations pursuing STAR must achieve CCM alignment. The CCM v4.0's 197 controls across 17 domains are cloud-specific and complement rather than duplicate ISO 27001 and SOC 2.

ISO 27001 (70% overlap): ISO 27001 is the most common prerequisite for STAR Level 2 Certification. The overlap is high because both address information security management; the CCM adds cloud-specific controls not fully addressed by ISO 27001 Annex A. Organizations with ISO 27001 already in place have the strongest foundation for STAR Level 2. See the ISO 27001 guide for detailed coverage of the prerequisite certification.

SOC 2 (60% overlap): SOC 2 is the alternative Level 2 prerequisite for US-based providers. The overlap is significant but lower than ISO 27001 because SOC 2's Trust Service Criteria are broader and less specifically cloud-focused. The CCM assessment for STAR Attestation adds cloud security controls that SOC 2 does not explicitly require. See the SOC 2 guide for full coverage.

How Automation Helps

Managing CSA STAR compliance — maintaining accurate CAIQ responses, keeping control evidence current, preparing for the annual CCM assessment, and coordinating with ISO 27001 or SOC 2 audit cycles — benefits significantly from compliance automation. LowerPlane maps the CSA CCM within its 50+ framework library and integrates with ISO 27001 and SOC 2 compliance programs, avoiding duplicated documentation across overlapping frameworks. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. Compare platforms at our best compliance automation platforms guide.

Frequently Asked Questions

How current must a STAR Registry listing be to be useful to enterprise buyers? Level 1 self-assessments should be updated annually to remain credible — out-of-date CAIQ responses raise questions about whether the provider is actively maintaining its security programme. Level 2 listings automatically show the certificate or attestation dates; most enterprise buyers treat reports over 12 months old with caution, consistent with SOC 2 and ISO 27001 norms.

Can a cloud provider get STAR listed without ISO 27001 or SOC 2? Yes — Level 1 self-assessment has no prerequisite and is independent of ISO 27001 or SOC 2. Level 2 requires one of these as a foundation. A provider without either may start with Level 1 to establish a public presence on the registry while working toward Level 2.

Is STAR Certification or STAR Attestation better? Neither is inherently superior — the right choice depends on your existing certifications and target market. US-focused providers with SOC 2 programs typically choose STAR Attestation to build on existing audit relationships. International providers with ISO 27001 typically choose STAR Certification. Providers with both can pursue either, or in some cases obtain both forms.

How does STAR relate to FedRAMP for US government cloud procurement? STAR and FedRAMP serve overlapping but distinct purposes. FedRAMP is a US government authorization programme for cloud services specifically, with its own control baseline (NIST SP 800-53) and authorization process. STAR is commercial market assurance. Some FedRAMP-authorized providers also hold STAR listings, but the two are independent programmes with different authorization bodies and control sets.

What happens if a provider's STAR assessment reveals security gaps? For Level 1 self-assessments, providers typically address gaps through a remediation plan before publishing the CAIQ, or they disclose the gap and planned remediation. For Level 2 assessments, gaps that prevent certification or attestation must be remediated before the certificate is issued. The public nature of the registry creates strong incentive to address gaps proactively rather than risk a public listing with significant exceptions.

Request a CSA STAR consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

CSA CCMHigh95%
ISO 27001Medium70%
SOC 2Medium60%

Related frameworks

Get matched with a CSA STAR auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.