Skip to main content

Explainers

What Is CSA STAR, and Does It Actually Matter?

CSA STAR ranges from a free self-assessment to an audited certification. Here is what a registry entry shows, and how it relates to ISO 27001 and SOC 2.

Solomon AmosPublished 22 Sep 20269 min read

CSA STAR turns up on a lot of vendor trust centres as a badge, but the badge on its own tells you almost nothing. The Cloud Security Alliance runs three different levels under the STAR name, ranging from a form a vendor fills in itself to an independent audit against a named standard. A vendor can point to "STAR" for any of the three and be telling the truth, which is exactly why the label needs unpacking before it goes into a vendor file. This piece works through what each level actually requires, what a registry entry shows once you open it, and how STAR sits next to the two frameworks buyers usually ask about instead: ISO 27001 and SOC 2.

What CSA STAR is

STAR stands for Security, Trust, Assurance and Risk. It is a programme run by the Cloud Security Alliance, a non-profit that publishes the Cloud Controls Matrix, a set of control objectives grouped into domains such as application security, identity management and data centre operations. STAR is the mechanism CSA built to let a cloud vendor show it has assessed itself, or been assessed, against that matrix. The output lives in a public registry that anyone can search, which is what makes it different from a SOC 2 report or an ISO 27001 certificate, both of which a vendor has to choose to publish rather than being listed automatically.

The three levels of STAR

The programme has three levels, and they are not stages of one process so much as three separate products aimed at different buyers. Level 1 is free and self-reported. Level 2 involves an independent third party and costs money. Level 3 adds continuous monitoring on top of Level 2 and is used by very few vendors.

LevelWhat it involvesWho checks itTypical cost to vendor
Level 1: Self-AssessmentVendor completes the CAIQ or maps its own controls to the CCM directlyNobody. It is self-attested and CSA does not verify the answersFree
Level 2: AttestationVendor's existing SOC 2 engagement is extended with CCM mappingsA licensed CPA firm, following AICPA attestation standardsCost of the underlying SOC 2 engagement plus the CCM mapping
Level 2: CertificationVendor's information security management system is audited against ISO 27001 with the CCM as additional controlsAn ISO 27001 certification body accredited for the STAR schemeCost of an ISO 27001 audit, usually run alongside it
Level 3: ContinuousLevel 2 evidence is supplemented with more frequent monitoring dataSame as Level 2, plus a continuous monitoring providerAdds ongoing monitoring cost on top of Level 2

The three levels of the CSA STAR programme, based on CSA's published programme description.

Level 1 and Level 2 answer completely different questions. Level 1 tells you a vendor has thought about the CCM and is willing to say, in writing, how it maps to its own controls. Level 2 tells you an outside party checked that mapping against a named audit standard. Treating the two as equivalent because they share the word "STAR" is the single most common misreading of the registry.

What the registry entry actually shows

Every listing in the CSA STAR registry carries a handful of fixed fields: the vendor name, the assessment level, the assessment type (Self-Assessment, Attestation or Certification), and the date it was published. Level 2 entries also name the assessing firm. Level 1 entries usually link to the completed CAIQ itself, so you can read the vendor's own answers rather than a summary. Level 2 entries link to a certificate or a letter from the assessor, which is a much shorter document than the underlying SOC 2 report or ISO 27001 statement of applicability, both of which stay private.

Diagram comparing a CSA STAR Level 1 self-assessment entry against a Level 2 certification entry in the registry
A STAR registry entry names the level and the type; only Level 2 entries name an assessor.

This is worth sitting with for a moment. A Level 1 entry from three years ago and a Level 2 certification renewed last month can sit next to each other in a search result looking almost identical, both carrying the word "STAR". The STAR framework page lists which vendors in the index hold which level, precisely because the registry's own search does not make the distinction obvious at a glance.

The CAIQ, STAR's self-assessment questionnaire

The Consensus Assessments Initiative Questionnaire, or CAIQ, is the document a vendor fills in for a Level 1 listing. It is built directly from the Cloud Controls Matrix: each control becomes a question the vendor answers, usually as a yes, no or partial, with room for a short explanation. CSA does not review the answers before publication.

  1. 1

    Vendor downloads the current CCM and CAIQ

    CSA publishes both as free downloads, currently built around CCM version 4.

  2. 2

    Vendor answers each control question

    Answers are typically yes, no or partial, with an optional narrative on how the control is implemented.

  3. 3

    Vendor submits the completed CAIQ to the STAR registry

    Submission is free and there is no independent check of the content before it goes live.

  4. 4

    Listing appears with a publication date

    CSA sets no mandatory expiry, so a stale CAIQ can remain listed unless the vendor withdraws or updates it.

How STAR Level 2 Certification relates to ISO 27001

STAR Certification is not a standalone audit. It is built on top of an existing ISO 27001 certification: the same accredited body audits the vendor's information security management system against ISO 27001's Annex A controls, then adds the CCM as a second, cloud-specific control set within the same audit. A vendor cannot hold STAR Certification without also holding ISO 27001, which means the certificate scope, the auditor and the three-year surveillance cycle are all inherited from the ISO 27001 engagement. If the underlying ISO 27001 certificate lapses or is withdrawn, the STAR Certification built on it stops being valid too, which matters given how many certificates were still citing the withdrawn 2013 edition after the transition deadline; the index covered what that looked like in practice.

How STAR Attestation relates to SOC 2

STAR Attestation follows the same logic with SOC 2 instead of ISO 27001. A CPA firm performs the SOC 2 Type II engagement and separately attests that the vendor's controls also satisfy the CCM, producing a combined attestation rather than two unrelated documents. The underlying report is still a SOC 2 report: there is no standalone "STAR SOC 2 certificate", and a vendor cannot get STAR Attestation without going through a real SOC 2 engagement first.

A trust centre that lists CSA STAR alongside ISO 27001 and a SOC 2 line side by side is a useful place to see how the three actually sit together in practice. Look at whether the STAR entry names a level, whether the ISO 27001 line names a certification body, and whether the SOC 2 line names a report type.

Algolia logo

Algolia · Trust report

Developer tools · Public evidence as of 29 Sep 2026

1Documents and agreements

Legal and review documents Algolia publishes or offers, as of 29 Sep 2026.

Algolia's trust centre lists ISO 27001, ISO 27017, CSA STAR and SOC 2 evidence together, useful for comparing how each is presented. Every line is a dated public record from the CSA STAR registry and Algolia's trust centre. A framework not shown means no public evidence was found, not that Algolia lacks it.CertReports

The difference in presentation is usually the tell. A framework stated without a report type, an assessor or a certificate number is worth a follow-up question before it goes in a vendor file. The index has a longer piece on what to ask for when SOC 2 and ISO 27001 both show up on the same page, and the same questions apply to a STAR line that does not say which level it is.

Does a STAR listing actually matter to buyers

3
STAR assessment levels
Self-Assessment, Attestation and Certification, with Continuous available as an add-on to Level 2
CCM v4
current control matrix version
the Cloud Controls Matrix version STAR assessments are currently measured against
Level 1
most common listing type
in the CertReports index on 2026-09-22, Level 1 Self-Assessment entries outnumber Level 2 entries
The STAR Registry documents the security and privacy controls provided by cloud computing offerings, and encompasses the key principles of transparency, rigorous auditing, and harmonization of standards.

How to check a STAR listing before you rely on it

Three checks catch most of the confusion. First, open the actual entry rather than trusting a badge: does it say Level 1 or Level 2, and does it name an assessor for Level 2. Second, check the publication date against how STAR listings actually age: a Level 1 Self-Assessment has no mandatory expiry and can be years old, while a Level 2 Certification follows the three-year ISO 27001 surveillance cycle and a Level 2 Attestation follows the roughly twelve-month cycle of the underlying SOC 2 report. Third, cross-check against the vendor's underlying ISO 27001 or SOC 2 status directly, since that can change independently of when the STAR entry was last touched.

Flowchart showing three checks for a CSA STAR registry listing: level, date and underlying framework
Reading a STAR listing takes three checks: the level, the date, and the framework it is built on.

None of this makes STAR worthless. A Level 2 Certification or Attestation is a genuine independent audit and a reasonable substitute for asking a vendor to walk through the CCM manually. A Level 1 entry is worth reading too, because a detailed, current CAIQ is more informative than no answer at all, but it should never be quoted as though it carries the same weight as an audit. The claim to watch for is a vendor describing itself as "SOC 2 certified" on the strength of a STAR Attestation; that phrasing is wrong regardless of which registry it is drawn from, because SOC 2 produces a report, not a certificate. The index's piece on that exact phrase covers why it keeps appearing anyway.

People also ask

Is CSA STAR the same as ISO 27001?

No. STAR Level 2 Certification is built on top of an ISO 27001 certification, using the same accredited auditor and the same three-year surveillance cycle, with the Cloud Controls Matrix added as extra cloud-specific controls. A vendor cannot hold STAR Certification without holding ISO 27001 first. STAR Level 1 has no connection to ISO 27001 at all; it is a free, self-reported questionnaire that nobody audits, so the answer depends entirely on which level of STAR is being referenced.

What is a CAIQ?

The CAIQ, or Consensus Assessments Initiative Questionnaire, is the form a vendor completes for a STAR Level 1 Self-Assessment. It turns each control in CSA's Cloud Controls Matrix into a question, usually answered yes, no or partial, with an optional explanation. The vendor submits it directly to the STAR registry and CSA does not review or verify the answers before publishing them, so a CAIQ is the vendor's own account of its controls rather than independently checked evidence.

Is STAR Level 1 worth anything?

It is worth reading but not worth treating as an audit. A detailed, current CAIQ gives more insight into a vendor's controls than a marketing page does, and it costs a buyer nothing to check. But nobody verifies the answers, there is no mandatory renewal, and a Level 1 entry can sit unchanged for years. Use it as a starting point for questions, not as a substitute for a Level 2 Certification, an Attestation, or a SOC 2 report.

How long does a STAR listing last?

It depends on the level. A Level 1 Self-Assessment has no fixed expiry; CSA recommends vendors refresh it, but a stale entry can remain listed indefinitely unless withdrawn. A Level 2 Certification follows the underlying ISO 27001 surveillance cycle, typically a three-year certificate with annual surveillance audits. A Level 2 Attestation follows the underlying SOC 2 report's own period, usually renewed roughly every twelve months alongside the SOC 2 engagement it is built on.

csa-starcloud-security-alliancecaiqiso-27001soc-2trust-centres
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Read next on CertReports

You might also like