CSA STAR turns up on a lot of vendor trust centres as a badge, but the badge on its own tells you almost nothing. The Cloud Security Alliance runs three different levels under the STAR name, ranging from a form a vendor fills in itself to an independent audit against a named standard. A vendor can point to "STAR" for any of the three and be telling the truth, which is exactly why the label needs unpacking before it goes into a vendor file. This piece works through what each level actually requires, what a registry entry shows once you open it, and how STAR sits next to the two frameworks buyers usually ask about instead: ISO 27001 and SOC 2.
What CSA STAR is
STAR stands for Security, Trust, Assurance and Risk. It is a programme run by the Cloud Security Alliance, a non-profit that publishes the Cloud Controls Matrix, a set of control objectives grouped into domains such as application security, identity management and data centre operations. STAR is the mechanism CSA built to let a cloud vendor show it has assessed itself, or been assessed, against that matrix. The output lives in a public registry that anyone can search, which is what makes it different from a SOC 2 report or an ISO 27001 certificate, both of which a vendor has to choose to publish rather than being listed automatically.
The three levels of STAR
The programme has three levels, and they are not stages of one process so much as three separate products aimed at different buyers. Level 1 is free and self-reported. Level 2 involves an independent third party and costs money. Level 3 adds continuous monitoring on top of Level 2 and is used by very few vendors.
| Level | What it involves | Who checks it | Typical cost to vendor |
|---|---|---|---|
| Level 1: Self-Assessment | Vendor completes the CAIQ or maps its own controls to the CCM directly | Nobody. It is self-attested and CSA does not verify the answers | Free |
| Level 2: Attestation | Vendor's existing SOC 2 engagement is extended with CCM mappings | A licensed CPA firm, following AICPA attestation standards | Cost of the underlying SOC 2 engagement plus the CCM mapping |
| Level 2: Certification | Vendor's information security management system is audited against ISO 27001 with the CCM as additional controls | An ISO 27001 certification body accredited for the STAR scheme | Cost of an ISO 27001 audit, usually run alongside it |
| Level 3: Continuous | Level 2 evidence is supplemented with more frequent monitoring data | Same as Level 2, plus a continuous monitoring provider | Adds ongoing monitoring cost on top of Level 2 |
The three levels of the CSA STAR programme, based on CSA's published programme description.
Level 1 and Level 2 answer completely different questions. Level 1 tells you a vendor has thought about the CCM and is willing to say, in writing, how it maps to its own controls. Level 2 tells you an outside party checked that mapping against a named audit standard. Treating the two as equivalent because they share the word "STAR" is the single most common misreading of the registry.
What the registry entry actually shows
Every listing in the CSA STAR registry carries a handful of fixed fields: the vendor name, the assessment level, the assessment type (Self-Assessment, Attestation or Certification), and the date it was published. Level 2 entries also name the assessing firm. Level 1 entries usually link to the completed CAIQ itself, so you can read the vendor's own answers rather than a summary. Level 2 entries link to a certificate or a letter from the assessor, which is a much shorter document than the underlying SOC 2 report or ISO 27001 statement of applicability, both of which stay private.
This is worth sitting with for a moment. A Level 1 entry from three years ago and a Level 2 certification renewed last month can sit next to each other in a search result looking almost identical, both carrying the word "STAR". The STAR framework page lists which vendors in the index hold which level, precisely because the registry's own search does not make the distinction obvious at a glance.
The CAIQ, STAR's self-assessment questionnaire
The Consensus Assessments Initiative Questionnaire, or CAIQ, is the document a vendor fills in for a Level 1 listing. It is built directly from the Cloud Controls Matrix: each control becomes a question the vendor answers, usually as a yes, no or partial, with room for a short explanation. CSA does not review the answers before publication.
- 1
Vendor downloads the current CCM and CAIQ
CSA publishes both as free downloads, currently built around CCM version 4.
- 2
Vendor answers each control question
Answers are typically yes, no or partial, with an optional narrative on how the control is implemented.
- 3
Vendor submits the completed CAIQ to the STAR registry
Submission is free and there is no independent check of the content before it goes live.
- 4
Listing appears with a publication date
CSA sets no mandatory expiry, so a stale CAIQ can remain listed unless the vendor withdraws or updates it.
How STAR Level 2 Certification relates to ISO 27001
STAR Certification is not a standalone audit. It is built on top of an existing ISO 27001 certification: the same accredited body audits the vendor's information security management system against ISO 27001's Annex A controls, then adds the CCM as a second, cloud-specific control set within the same audit. A vendor cannot hold STAR Certification without also holding ISO 27001, which means the certificate scope, the auditor and the three-year surveillance cycle are all inherited from the ISO 27001 engagement. If the underlying ISO 27001 certificate lapses or is withdrawn, the STAR Certification built on it stops being valid too, which matters given how many certificates were still citing the withdrawn 2013 edition after the transition deadline; the index covered what that looked like in practice.
How STAR Attestation relates to SOC 2
STAR Attestation follows the same logic with SOC 2 instead of ISO 27001. A CPA firm performs the SOC 2 Type II engagement and separately attests that the vendor's controls also satisfy the CCM, producing a combined attestation rather than two unrelated documents. The underlying report is still a SOC 2 report: there is no standalone "STAR SOC 2 certificate", and a vendor cannot get STAR Attestation without going through a real SOC 2 engagement first.
A trust centre that lists CSA STAR alongside ISO 27001 and a SOC 2 line side by side is a useful place to see how the three actually sit together in practice. Look at whether the STAR entry names a level, whether the ISO 27001 line names a certification body, and whether the SOC 2 line names a report type.
Algolia · Trust report
Developer tools · Public evidence as of 29 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 1 verified, 5 vendor-stated.
1Documents and agreements
Legal and review documents Algolia publishes or offers, as of 29 Sep 2026.
- Privacy policy · Public
The difference in presentation is usually the tell. A framework stated without a report type, an assessor or a certificate number is worth a follow-up question before it goes in a vendor file. The index has a longer piece on what to ask for when SOC 2 and ISO 27001 both show up on the same page, and the same questions apply to a STAR line that does not say which level it is.
Does a STAR listing actually matter to buyers
- 3
- STAR assessment levels
- Self-Assessment, Attestation and Certification, with Continuous available as an add-on to Level 2
- CCM v4
- current control matrix version
- the Cloud Controls Matrix version STAR assessments are currently measured against
- Level 1
- most common listing type
- in the CertReports index on 2026-09-22, Level 1 Self-Assessment entries outnumber Level 2 entries
The STAR Registry documents the security and privacy controls provided by cloud computing offerings, and encompasses the key principles of transparency, rigorous auditing, and harmonization of standards.
How to check a STAR listing before you rely on it
Three checks catch most of the confusion. First, open the actual entry rather than trusting a badge: does it say Level 1 or Level 2, and does it name an assessor for Level 2. Second, check the publication date against how STAR listings actually age: a Level 1 Self-Assessment has no mandatory expiry and can be years old, while a Level 2 Certification follows the three-year ISO 27001 surveillance cycle and a Level 2 Attestation follows the roughly twelve-month cycle of the underlying SOC 2 report. Third, cross-check against the vendor's underlying ISO 27001 or SOC 2 status directly, since that can change independently of when the STAR entry was last touched.
None of this makes STAR worthless. A Level 2 Certification or Attestation is a genuine independent audit and a reasonable substitute for asking a vendor to walk through the CCM manually. A Level 1 entry is worth reading too, because a detailed, current CAIQ is more informative than no answer at all, but it should never be quoted as though it carries the same weight as an audit. The claim to watch for is a vendor describing itself as "SOC 2 certified" on the strength of a STAR Attestation; that phrasing is wrong regardless of which registry it is drawn from, because SOC 2 produces a report, not a certificate. The index's piece on that exact phrase covers why it keeps appearing anyway.
People also ask
Is CSA STAR the same as ISO 27001?
No. STAR Level 2 Certification is built on top of an ISO 27001 certification, using the same accredited auditor and the same three-year surveillance cycle, with the Cloud Controls Matrix added as extra cloud-specific controls. A vendor cannot hold STAR Certification without holding ISO 27001 first. STAR Level 1 has no connection to ISO 27001 at all; it is a free, self-reported questionnaire that nobody audits, so the answer depends entirely on which level of STAR is being referenced.
What is a CAIQ?
The CAIQ, or Consensus Assessments Initiative Questionnaire, is the form a vendor completes for a STAR Level 1 Self-Assessment. It turns each control in CSA's Cloud Controls Matrix into a question, usually answered yes, no or partial, with an optional explanation. The vendor submits it directly to the STAR registry and CSA does not review or verify the answers before publishing them, so a CAIQ is the vendor's own account of its controls rather than independently checked evidence.
Is STAR Level 1 worth anything?
It is worth reading but not worth treating as an audit. A detailed, current CAIQ gives more insight into a vendor's controls than a marketing page does, and it costs a buyer nothing to check. But nobody verifies the answers, there is no mandatory renewal, and a Level 1 entry can sit unchanged for years. Use it as a starting point for questions, not as a substitute for a Level 2 Certification, an Attestation, or a SOC 2 report.
How long does a STAR listing last?
It depends on the level. A Level 1 Self-Assessment has no fixed expiry; CSA recommends vendors refresh it, but a stale entry can remain listed indefinitely unless withdrawn. A Level 2 Certification follows the underlying ISO 27001 surveillance cycle, typically a three-year certificate with annual surveillance audits. A Level 2 Attestation follows the underlying SOC 2 report's own period, usually renewed roughly every twelve months alongside the SOC 2 engagement it is built on.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
Vendor Security Questionnaire Questions Answered by Public Evidence
Solomon Amos · 26 Sep 2026 · 8 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read