- What they do
- Assessor
- Which standards
- On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
- Standards
- Pricing
- Not published
Framework Cloud & Government Authorization
CSA STAR
CSA STAR (Security, Trust, Assurance and Risk) is the Cloud Security Alliance's public registry and assurance program for cloud providers. It is built on the Cloud Controls Matrix (CCM v4, 197 control objectives in 17 domains) and its companion questionnaire, the CAIQ. Level 1 is a self-assessment: the provider completes the CAIQ and publishes it in the STAR Registry.
Level 2 is third-party assurance: STAR Certification (an ISO/IEC 27001 certification extended with a CCM maturity assessment) or STAR Attestation (a SOC 2 examination extended with the CCM), plus C-STAR for the Greater China market.
In writing, a provider needs the same documented ISMS or SOC 2 control set as the underlying scheme, plus a CCM mapping and a completed CAIQ that states how each control is implemented. Level 1 entries must be kept current, and Level 2 listings expire with the underlying certificate or attestation.
help
Who has to comply
Voluntary. Cloud service providers use it to publish their security posture; some enterprise and public sector buyers ask for a STAR Registry entry in procurement. No statutory trigger.
What the assessor asks to see
Completed CAIQ v4 with implementation statements; CCM control mapping to the ISMS or SOC 2 control set; ISO 27001 certificate or SOC 2 report from an approved auditor; policies and procedures per CCM domain; evidence of control operation for the maturity scoring (STAR Certification) or the SOC 2 period (STAR Attestation).
Levels
Level 1 is a published self-assessment (CAIQ) with no auditor. Level 2 is third-party assurance in one of three forms: STAR Certification (ISO/IEC 27001 plus CCM maturity, three-year certificate), STAR Attestation (SOC 2 plus CCM, renewed every twelve months) and C-STAR (GB/T 22080 plus CCM for Greater China, three years).
CSA's earlier Level 3 continuous concept is not an active listing tier; check the STAR page for current options.
Assessors
Who assesses CSA STAR
Level 1: none (self-assessment). Level 2 STAR Certification: an accredited ISO/IEC 27001 certification body that is also a CSA-approved STAR auditor. Level 2 STAR Attestation: a licensed CPA firm performing a SOC 2 examination that is a CSA-approved STAR auditor.
Accredited by CSA approves STAR auditors; the underlying ISO certification body is accredited by a national accreditation body (ANAB, UKAS and peers) and the CPA firm is licensed and peer reviewed under AICPA rules.
Public register of assessors: https://cloudsecurityalliance.org/star/registry
- What they do
- Assessor
- Which standards
- On the public register for CSA STAR.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for CSA STAR.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for CSA STAR.
- Standards
- Pricing
- Not published
Consultants
Who helps with CSA STAR
Yes. ISO 27001 and SOC 2 readiness consultants add the CCM mapping and CAIQ preparation to their standard engagements; GRC platforms ship CCM templates. Typical shape: complete the CAIQ for Level 1, then fold the CCM into the next ISO or SOC 2 cycle for Level 2.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CSA STAR consultant listing yet. Claim yours →
Software
Tools for CSA STAR
Tools that name this framework in their own material.
Related reading
- CSA STAR certification - Azure complianceExplains how STAR certification is built on an ISO 27001 audit plus the Cloud Controls Matrix maturity scoring.Microsoft
- CSA STAR attestation - Azure complianceShows the other Level 2 route, a SOC 2 engagement run against the Cloud Controls Matrix, and how the two differ.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CSA STAR
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CSA STAR
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.