home / frameworks / csa-star

// Industry frameworks and attestations

CSA STAR (Security, Trust, Assurance and Risk) and the Cloud Controls Matrix

CSA STAR is the Cloud Security Alliance's assurance program for cloud providers, built on the Cloud Controls Matrix. Providers can post a self-assessment (Level 1) or add an independent SOC 2 or ISO 27001 based audit (Level 2) to a public registry.

International

Overview

The Cloud Security Alliance (CSA) runs the Security, Trust, Assurance and Risk (STAR) program, a public way for cloud providers to show how they handle security and privacy. It is built on the Cloud Controls Matrix (CCM), a control framework for cloud computing, and its companion questionnaire, the Consensus Assessments Initiative Questionnaire (CAIQ). CCM v4.1 arrived in January 2026. It has 207 controls across 17 domains, adds 11 new control specifications, and comes with updated implementation and auditing guidelines and a CAIQ of 283 questions.

STAR has 2 levels of assurance. Level 1 is a self-assessment, in which the provider completes the CAIQ and posts it to the public STAR Registry. Level 2 adds an independent audit, either STAR Attestation, a SOC 2 engagement that also covers the CCM and is performed by a CPA firm, or STAR Certification, an ISO/IEC 27001 certification extended with the CCM and performed by a CSA-approved auditor. A third Level 2 option, C-STAR, serves the Greater China market. Since November 2025, CSA has also offered STAR for AI, which combines an AI-focused CAIQ with ISO/IEC 42001 certification at Level 2.

Canadian SaaS and cloud providers use STAR to answer customer security questionnaires once, in public, instead of filling in a different spreadsheet for each prospect. Providers that already hold ISO 27001 or a SOC 2 Type 2 report can add the CCM to that work and reach Level 2 without starting over. Canada has no STAR-specific regulator. STAR Certification needs an auditor that CSA has approved, in addition to the certification body's usual ISO 27001 accreditation. Providers listed in the registry before v4.1 have until December 2027 to move to the new version.

Who it applies to in Canada

Cloud service providers of all types, including SaaS, PaaS, and IaaS, and organizations that want to assess the security of the cloud services they buy.

Canadian cloud and SaaS providers use STAR to answer customer security questionnaires in a public, standard format and to extend existing ISO 27001 or SOC 2 work. Canadian buyers use the public STAR Registry to review providers before they sign.

Controls at a glance

CCM v4.1 has 207 control specifications in 17 domains, shown here with related domains grouped together.

Audit and governance (A&A, GRC)

  • Plan and perform independent audits and assessments
  • Track and fix audit findings
  • Governance program, policies, and risk management
  • Defined roles and responsibilities for security

Application and change security (AIS, CCC)

  • Secure application design, development, and testing
  • Change control and configuration baselines
  • Detect and handle unauthorized changes

Business continuity and resilience (BCR)

  • Business impact analysis and continuity strategy
  • Backups and recovery testing
  • Redundant equipment and resilient design

Cryptography and data protection (CEK, DSP)

  • Encryption and key management lifecycle
  • Data classification, inventory, and flow documentation
  • Privacy by design, retention, and secure deletion
  • Knowing and disclosing where data is located

Datacentre and infrastructure (DCS, IVS)

  • Physical security of facilities and equipment
  • Network and virtualization security
  • Segmentation and hardening of hosts and guests

People and identity (HRS, IAM)

  • Background checks, training, and acceptable use
  • Identity lifecycle and least privilege
  • Strong authentication and privileged access management

Interoperability and endpoints (IPY, UEM)

  • Data portability and exit provisions
  • Endpoint inventory, configuration, and malware protection
  • Mobile device management

Logging, incidents, and vulnerabilities (LOG, SEF, TVM)

  • Security monitoring and protection of logs
  • Incident response, e-discovery, and cloud forensics
  • Vulnerability identification, patching, and threat intelligence

Supply chain (STA)

  • Documented shared security responsibility model
  • Supply chain inventory and risk management
  • Supplier agreements and periodic reviews

Certification and assessment

At Level 1 the provider completes the CAIQ and submits it to the STAR Registry. At Level 2 the provider obtains an ISO 27001 certification or SOC 2 Type 2 report that also covers the CCM, completes the Level 1 self-assessment, and the results are published in the registry. Registry listings show which level and option each service holds.

Dates to know

2025-11-20
STAR for AI Level 2 introduced, combining an AI-CAIQ with ISO/IEC 42001 certification
2026-01-27
CCM v4.1 and CAIQ v4.1 released
2026-03
STAR Registry accepts both v4.0 and v4.1 submissions at Levels 1 and 2
2027-12
Only v4.1 submissions accepted at STAR Levels 1 and 2
2028-01
CCM v4.0.x and CAIQ v4.0.x withdrawn from active use

Resources

Official texts and free tools for CSA STAR. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. STAR program, Cloud Security Alliance
  2. Cloud Controls Matrix v4.1, Cloud Security Alliance
  3. CCM v4.1 transition timeline, Cloud Security Alliance
  4. The CSA Cloud Controls Matrix v4.1: strengthening the future of cloud security, Cloud Security Alliance