HomeFrameworksCloud & Government AuthorizationCSA STAR

Framework  Cloud & Government Authorization

CSA STAR

CSA STAR (Security, Trust, Assurance and Risk) is the Cloud Security Alliance's public registry and assurance program for cloud providers. It is built on the Cloud Controls Matrix (CCM v4, 197 control objectives in 17 domains) and its companion questionnaire, the CAIQ. Level 1 is a self-assessment: the provider completes the CAIQ and publishes it in the STAR Registry.

Level 2 is third-party assurance: STAR Certification (an ISO/IEC 27001 certification extended with a CCM maturity assessment) or STAR Attestation (a SOC 2 examination extended with the CCM), plus C-STAR for the Greater China market.

In writing, a provider needs the same documented ISMS or SOC 2 control set as the underlying scheme, plus a CCM mapping and a completed CAIQ that states how each control is implemented. Level 1 entries must be kept current, and Level 2 listings expire with the underlying certificate or attestation.

AI-compiled
Share
Sponsored
CSA
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CSA STAR
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Cloud service providers use it to publish their security posture; some enterprise and public sector buyers ask for a STAR Registry entry in procurement. No statutory trigger.

What the assessor asks to see

Completed CAIQ v4 with implementation statements; CCM control mapping to the ISMS or SOC 2 control set; ISO 27001 certificate or SOC 2 report from an approved auditor; policies and procedures per CCM domain; evidence of control operation for the maturity scoring (STAR Certification) or the SOC 2 period (STAR Attestation).

Levels

Level 1 is a published self-assessment (CAIQ) with no auditor. Level 2 is third-party assurance in one of three forms: STAR Certification (ISO/IEC 27001 plus CCM maturity, three-year certificate), STAR Attestation (SOC 2 plus CCM, renewed every twelve months) and C-STAR (GB/T 22080 plus CCM for Greater China, three years).

CSA's earlier Level 3 continuous concept is not an active listing tier; check the STAR page for current options.

Assessors

Who assesses CSA STAR

Level 1: none (self-assessment). Level 2 STAR Certification: an accredited ISO/IEC 27001 certification body that is also a CSA-approved STAR auditor. Level 2 STAR Attestation: a licensed CPA firm performing a SOC 2 examination that is a CSA-approved STAR auditor.

Accredited by CSA approves STAR auditors; the underlying ISO certification body is accredited by a national accreditation body (ANAB, UKAS and peers) and the CPA firm is licensed and peer reviewed under AICPA rules.

Public register of assessors: https://cloudsecurityalliance.org/star/registry

A-LIGNOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
BARR CertificationsOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR.
Standards
CSA STAR
Pricing
Not published
Schellman & CompanyOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR.
Standards
CSA STAR
Pricing
Not published
CoalfireOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
KirkpatrickPriceOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR.
Standards
CSA STAR
Pricing
Not published

Consultants

Who helps with CSA STAR

Yes. ISO 27001 and SOC 2 readiness consultants add the CCM mapping and CAIQ preparation to their standard engagements; GRC platforms ship CCM templates. Typical shape: complete the CAIQ for Level 1, then fold the CCM into the next ISO or SOC 2 cycle for Level 2.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CSA STAR consultant listing yet. Claim yours →

Software

Tools for CSA STAR

Tools that name this framework in their own material.

Related reading

  1. CSA STAR certification - Azure complianceExplains how STAR certification is built on an ISO 27001 audit plus the Cloud Controls Matrix maturity scoring.Microsoft
  2. CSA STAR attestation - Azure complianceShows the other Level 2 route, a SOC 2 engagement run against the Cloud Controls Matrix, and how the two differ.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CSA STAR

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CSA STAR

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.