
- 01The CSA Cloud Controls Matrix (CCM) is the de facto control framework for cloud computing. The STAR registry publishes provider self-assessments and third-party attestations against it.
- 02Buyers: filter STAR to Level 2+ attestations, pull the CAIQ, map the responses to your high-criticality CCM controls. Treat anything below Level 2 as 'self-asserted' and require compensating controls.
- 03Sellers: publish a Level 1 self-assessment within 12 months of launch and a Level 2 third-party attestation within 24. Procurement velocity benefit is substantial.
- 04Large enterprises will accept a CAIQ in lieu of a custom 600-question security questionnaire 70%+ of the time. Adoption is procurement-pragmatic, not just security-driven.
The Cloud Security Alliance's Cloud Controls Matrix (CCM) is a control framework specifically designed for cloud computing. The STAR registry publishes cloud providers' self-assessments and third-party attestations against the CCM. Together they form the most efficient assurance ecosystem in cloud security today.
How buyers should use STAR
- 01Filter the STAR registry to providers with Level 2 attestations or higher
- 02Pull the CAIQ (Consensus Assessments Initiative Questionnaire) for the provider
- 03Map the provider's responses to your high-criticality CCM controls
- 04Treat anything below Level 2 as 'self-asserted' and add compensating controls
How sellers should use CCM
Publish a STAR Level 1 self-assessment within 12 months of launch and Level 2 third-party attestation within 24. The procurement velocity benefit is substantial — large enterprises will accept a CAIQ over a custom 600-question security questionnaire in 70%+ of cases.


