Back to Field Notes
International Standards/Field Note

CSA CCM and STAR — Cloud Assurance Without the Theater

CCM is the de facto cloud control framework. STAR is the public registry. Used together they collapse cloud due diligence by weeks.

Author

Diana Petrov

Director, Governance Practice

Published

January 9, 2026

Read

9 min

Share
AI-generated illustration of a shipping terminal facility
AI-generated illustration of a shipping terminal facility
Key Takeaways
  • 01The CSA Cloud Controls Matrix (CCM) is the de facto control framework for cloud computing. The STAR registry publishes provider self-assessments and third-party attestations against it.
  • 02Buyers: filter STAR to Level 2+ attestations, pull the CAIQ, map the responses to your high-criticality CCM controls. Treat anything below Level 2 as 'self-asserted' and require compensating controls.
  • 03Sellers: publish a Level 1 self-assessment within 12 months of launch and a Level 2 third-party attestation within 24. Procurement velocity benefit is substantial.
  • 04Large enterprises will accept a CAIQ in lieu of a custom 600-question security questionnaire 70%+ of the time. Adoption is procurement-pragmatic, not just security-driven.

The Cloud Security Alliance's Cloud Controls Matrix (CCM) is a control framework specifically designed for cloud computing. The STAR registry publishes cloud providers' self-assessments and third-party attestations against the CCM. Together they form the most efficient assurance ecosystem in cloud security today.

How buyers should use STAR

  • 01Filter the STAR registry to providers with Level 2 attestations or higher
  • 02Pull the CAIQ (Consensus Assessments Initiative Questionnaire) for the provider
  • 03Map the provider's responses to your high-criticality CCM controls
  • 04Treat anything below Level 2 as 'self-asserted' and add compensating controls

How sellers should use CCM

Publish a STAR Level 1 self-assessment within 12 months of launch and Level 2 third-party attestation within 24. The procurement velocity benefit is substantial — large enterprises will accept a CAIQ over a custom 600-question security questionnaire in 70%+ of cases.

#CSA#CCM#STAR

/WRITTEN_BY

Diana Petrov

Director, Governance Practice · Alexa Cybersecurity