Cloud Security Alliance Security Trust Assurance and Risk
· About Cloud Security Alliance Security Trust Assurance and Risk
Key Takeaways
- CSA STAR applies to cloud service providers that want to publish security and privacy assurance information in CSA’s public registry, and it offers three assurance levels from self-assessment to certification and continuous monitoring.[1][8][3]
- The STAR Registry is maintained by the Cloud Security Alliance, which positions the program as a public source of trust information for cloud and AI offerings, not a government mandate.[1][3][15]
- CSA released CCM v4.1 and CAIQ v4.1 in January 2026, began accepting both v4.0 and v4.1 submissions in March 2026, and will require v4.1 for new STAR submissions after December 2027.[12]
- Organizations already in the registry have a two-year transition period to move to CCM v4.1, with the transition ending in December 2027.[12]
- Level 2 STAR certification is tied to ISO/IEC 27001 assessments plus CCM-based certification requirements, while Level 3 is described as continuous monitoring.[6][8]
- Fees, submission requirements, and registry eligibility are set by CSA; there is no public regulatory fine regime because STAR is a voluntary assurance program rather than a statute.[10][1]
What It Is
Security, Trust, Assurance, and Risk (STAR) is CSA’s cloud assurance program and public registry for cloud service security and privacy controls.[1][3] It is built around the Cloud Controls Matrix (CCM) and related assessment artifacts, with the registry used to publish a provider’s assurance posture.[1][3][8]
The program is administered by the Cloud Security Alliance (CSA), not a government regulator.[1][3] It is a voluntary industry framework and registry, although it is often used by procurement, risk, legal, and compliance teams as evidence of cloud due diligence.[1][15]
CSA’s current public materials show that the STAR program was updated in 2026 and that CCM v4.1 / CAIQ v4.1 were officially released in January 2026.[12] CSA started accepting both v4.0 and v4.1 submissions in March 2026, and it states that after December 2027 new STAR submissions must use v4.1.[12]
Who Must Comply
STAR does not impose legal mandatory compliance thresholds in the way a statute or regulator does; instead, it is applicable to cloud service providers, SaaS vendors, and AI/cloud service operators that choose to seek STAR listing or certification.[1][8][15]
Because it is voluntary, there is no territorial scope, extraterritorial reach, or statutory exemption framework comparable to GDPR, NIS2, or sectoral security laws.[1][3] The practical “threshold” is business-driven: providers participate when customers, marketplaces, procurement frameworks, or internal governance require third-party assurance.[1][4][15]
For Level 2 certification, CSA’s published requirements tie the assessment to an ISO/IEC 27001-based certification process and CCM controls, so the provider must be in a position to undergo that audit path.[6] For Level 1 self-assessment, CSA indicates the offering is open to cloud service providers and can be submitted as a CAIQ or CCM-based document package.[8]
There are no listed statutory exemptions because STAR is not a law; however, different STAR artifacts and levels may be unavailable or impractical depending on the service type, scope, or whether the organization seeks registry publication.[1][8][10]
Core Requirements
- Complete the relevant self-assessment or certification package. STAR Level 1 uses the CAIQ or a CCM-aligned self-assessment, while Level 2 relies on third-party certification against CCM within an ISO/IEC 27001 assessment context.[6][8]
- Map controls to the Cloud Controls Matrix. Providers must demonstrate how their cloud security and privacy controls align to CSA’s CCM, which is the program’s core control framework.[1][3][12]
- Submit evidence to the STAR Registry. CSA’s registry is the public disclosure mechanism for the provider’s assurance posture and supporting artifacts.[1][15]
- Maintain version alignment with CCM v4.1. For new submissions, CSA says v4.1 becomes mandatory after December 2027, while existing entries have until then to transition.[12]
- Use approved assurance paths at higher levels. CSA’s Level 2 materials require certifying bodies to meet specific requirements for STAR certification assessments, and Level 3 is framed around continuous monitoring.[6][8]
- Pay the applicable registry or attestation fee. CSA publishes submission pricing by employee band for STAR Registry submissions and attestation fees.[10]
Deadlines and Penalties
| Milestone | Date | What applies | |---|---:|---| | CCM v4.1 and CAIQ v4.1 officially released | January 2026 | New version of the control set and self-assessment instruments launched.[12] | | Both v4.0 and v4.1 accepted for STAR submissions | March 2026 | Transition period begins for Level 1 and Level 2 registry submissions.[12] | | New STAR submissions must use v4.1 | After December 2027 | CSA says new listings must be based on v4.1 after the transition ends.[12] | | Existing registry services transition deadline | December 2027 | Existing listings have a two-year transition period to move to v4.1.[12] |
Maximum fines: none. STAR is a voluntary CSA program, so CSA does not publish statutory fines, administrative penalties, or criminal sanctions for non-participation or non-transition.[1][3]
Other sanctions: the practical consequence of failing to meet program requirements is loss of the ability to obtain or maintain STAR registry status, certification validity, or the associated trust mark/assurance posture, which can affect procurement and customer trust.[1][15][10]
How to Comply
- Define the STAR scope. Decide which cloud service, tenant, business unit, or product line will be listed, and align that scope with the evidence you can defend in procurement and audit.[1][15]
- Select the assurance level. Use Level 1 for self-assessment, Level 2 when you need third-party certification, and only plan for Level 3 if continuous monitoring is part of your operating model.[8][6]
- Map existing controls to CCM v4.1. Build a control crosswalk from your current security program to CSA’s CCM, and identify gaps by domain rather than by ad hoc questionnaire response.[12][3]
- Align your security management system to ISO 27001. Level 2 is explicitly linked to ISO/IEC 27001 assessment practice, so an ISO 27001-aligned ISMS will reduce duplication and audit friction.[6]
- Use NIST CSF 2.0 for program structure. Map governance, identify, protect, detect, respond, and recover activities to CCM domains to show coverage and simplify executive reporting; this is a practical mapping exercise, not a CSA mandate.
- Adopt ISO/IEC 42001 where AI services are in scope. CSA’s registry now includes AI-related assurance materials, and ISO 42001 is directly relevant when the service includes AI management controls or AI trustmark ambitions.[11][15]
- Run a version-transition plan now. If you maintain a current listing or plan a new one, move to CCM v4.1 before the December 2027 cutoff to avoid rework and submission delays.[12]
- Prepare evidence and governance. Maintain policy, architecture, logging, incident response, vendor risk, and audit evidence in a form that can be reused for customer reviews, certification, and renewal.[3][6]
Related Regulations
- ISO/IEC 27001 overlaps strongly with STAR Level 2 because CSA’s certification path is explicitly tied to ISO 27001 assessment practice and CCM controls.[6]
- ISO/IEC 42001 overlaps for AI services because CSA’s STAR for AI materials now incorporate AI-management-system certification and registry publication.[11][15]
- NIST CSF 2.0 is not a competing legal regime, but it overlaps as a control-structure framework that can be mapped to CCM for internal governance.[3][12]
- GDPR can conflict operationally if registry disclosures expose personal data or security details that require data minimization, but GDPR does not replace STAR’s voluntary assurance model.
- NIS2 can overlap for EU operators because it imposes mandatory cybersecurity governance, while STAR remains a voluntary market-facing assurance mechanism.
FAQ
Does CSA STAR apply to companies outside the United States?
Yes. STAR is an international, voluntary CSA program and is not limited to U.S. companies.[1][3] Providers anywhere can submit to the registry if they want to publish assurance information or pursue certification.[1][15]
Is CSA STAR a legal requirement?
No. STAR is an industry assurance and registry program, not a law or regulator-issued mandate.[1][3] The practical pressure comes from customers, procurement teams, and risk programs that prefer or require independent cloud assurance.[1][15]
What happens if we do not move to CCM v4.1?
CSA states that new STAR submissions after December 2027 must use v4.1, and current registry participants have a two-year transition period ending then.[12] If a provider stays on an older version, it risks failing to meet registry or certification requirements for future submissions.[12]
Does STAR Level 2 require ISO 27001?
CSA’s published requirements say STAR certification assessments are conducted to CCM as part of an ISO/IEC 27001 assessment.[6] That means ISO 27001 is central to the Level 2 pathway, although the practical certification scope still depends on the certifying body and the provider’s chosen service scope.[6]
Can AI services be listed in STAR?
Yes. CSA’s 2026 materials show STAR for AI and related registry enhancements, including the ability to accept ISO/IEC 42001 certifications for AI management systems.[11][15] This is an expansion of the STAR ecosystem, not a replacement for the cloud-focused core registry.[3][15]
Sources
- CSA STAR main page
- CSA STAR resources
- STAR Program Overview (CSA)
- CCM v4.1 Transition Timeline (CSA blog)
- Requirements for Bodies Providing STAR Certification (CSA)
- STAR Registry submissions pricing (CSA)
- CSA STAR for AI
- Microsoft compliance overview: CSA STAR self-assessment
- CSA press release on AIUC-1 in STAR Registry
Put it into practice
- Generate the policy: CSA STAR policy generator (generatepolicy.com)
- Buy the policy pack: Cloud Security Bundle (cyberpolicy.shop)
- Build it yourself: Build Series Vol. 09 — Cloud & SaaS Security Posture (ciso.diy)