1.3 CSA Assurance Tools: CCM v4.1, CAIQ v4.1 & the STAR Registry

Key Takeaways

  • CCM v4.1 is CSA's current cloud control framework, with 207 controls across 17 domains.
  • CAIQ v4.1 turns CCM controls into 283 assessment questions for cloud providers and customers.
  • STAR Level 1 is a provider self-assessment published in the registry; it is transparency evidence, not an independent audit.
  • STAR Level 2 adds third-party assurance through STAR Certification or STAR Attestation.
  • Mappings among frameworks reduce duplicated assessment work but never make different legal or audit obligations identical.
Last updated: September 2026

1.3 CSA Assurance Tools: CCM v4.1, CAIQ v4.1 & the STAR Registry

Quick Answer: CSA's current Cloud Controls Matrix v4.1 contains 207 controls across 17 domains. The corresponding CAIQ v4.1 contains 283 questions that help assess how those controls are implemented. The current CSA STAR program page presents Level 1, a published self-assessment, and Level 2, an independent third-party assessment through STAR Certification or STAR Attestation. These tools improve transparency, but none transfers the cloud customer's own responsibilities to the provider.

+CSA's 2026 CCM v4.1 transition notice states that the CCSK curriculum and exam remain unchanged for the time being. Use the current CCM and CAIQ for operational assurance work, but use the CCSK v5 Study Guide and curriculum to determine exam coverage.

Cloud assurance answers a different question from technical configuration. A firewall rule may show how a specific network control is configured; an assurance artifact explains whether a provider designed, operates, and independently tested a broader control environment. A defensible provider review combines both layers and checks the artifact's scope, dates, exceptions, and applicable services.

Cloud Controls Matrix v4.1

The CCM is a cloud-focused control framework. Version 4.1, released by CSA in January 2026, expands the matrix to 207 controls while retaining 17 domains. Examples include Audit and Assurance, Business Continuity Management and Operational Resilience, Cryptography, Encryption and Key Management, Data Security and Privacy Lifecycle Management, IAM, Infrastructure and Virtualization Security, Logging and Monitoring, and Threat and Vulnerability Management.

Each matrix row should be read as a control objective, not as proof that a provider satisfies it. Useful columns and companion material identify implementation guidance, cloud-service applicability, ownership, and mappings to other standards. The reviewer must still ask:

  • Is the relevant cloud service inside the assessment scope?
  • Is the control operated by the provider, the customer, or both for this service model?
  • What evidence supports the implementation claim?
  • Are there exceptions, subservice organizations, or customer-control considerations?
  • Is the artifact current enough for the risk decision?

For example, a provider may operate and patch the IaaS hypervisor, while the customer patches the guest operating system. A provider's clean infrastructure report does not demonstrate that the customer's guest is secure.

CAIQ v4.1

The Consensus Assessments Initiative Questionnaire operationalizes CCM as a structured set of questions. CAIQ v4.1 contains 283 questions. It gives procurement and security teams a consistent starting point instead of sending a different proprietary spreadsheet to every provider.

A useful CAIQ response contains more than yes or no. It should identify the service scope, describe the mechanism, name the supporting artifact, state any shared-responsibility dependency, and explain exceptions. Reviewers should challenge answers that merely link to marketing pages or claim that a control is not applicable without explaining why.

CAIQ is valuable for comparison and initial due diligence, but a completed questionnaire remains a representation by the responding organization unless an independent assessment covers it. Risk determines what additional evidence is required.

STAR Level 1: self-assessment

At STAR Level 1, an organization publishes a self-assessment in the STAR Registry, commonly through a CAIQ or CCM-based submission. Level 1 improves public transparency and can accelerate early vendor screening. Its limitation is equally important: the provider prepared the answers. A reviewer should not describe Level 1 as an independent certification, attestation, or audit opinion.

Level 1 may be proportionate for a low-impact service. A regulated or high-impact workload may require independent assurance, contract terms, architecture review, testing evidence, and continuous monitoring in addition to the self-assessment.

STAR Level 2: independent assessment

CSA currently presents two Level 2 paths:

  • STAR Certification combines ISO/IEC 27001 with CCM criteria and is performed through the certification ecosystem.
  • STAR Attestation combines SOC 2 reporting with CCM criteria and is performed by an independent CPA firm.

The paths produce different artifacts and should be evaluated according to the buyer's jurisdiction, customer commitments, and assurance needs. Always verify the exact scope, assessment period, services, locations, and qualifications or exceptions. The words certified or attested do not mean every customer configuration is secure.

Continuous control monitoring is still a valuable operating practice. However, it should not be labeled a current third STAR level unless CSA's current program materials explicitly present it that way. A customer can combine registry evidence with CSPM, API evidence, service health data, contract monitoring, and its own control tests without inventing an assurance tier.

Framework mappings and the limits of inheritance

CCM mappings help a team reuse evidence across related requirements. They can show that one technical control contributes to multiple standards. Mapping does not establish legal equivalence, expand an audit's scope, or erase organization-specific obligations. Treat assess once, use many as an efficiency goal rather than a compliance guarantee.

A strong assurance workflow is:

  1. Classify the planned data and business impact.
  2. Define mandatory legal, contractual, availability, and security requirements.
  3. Review the provider's Level 1 record, if available, and current CAIQ responses.
  4. For higher risk, inspect the applicable Level 2 artifact and confirm scope and period.
  5. Map provider controls and customer controls to the service model.
  6. Record gaps, compensating controls, owners, due dates, and residual risk acceptance.
  7. Monitor changes in services, sub-processors, artifacts, and customer configuration.

Common interpretation errors

  • Counting a self-assessment as an audit: Level 1 has no independent opinion.
  • Ignoring scope: a provider's report may exclude a new region or service used by the customer.
  • Assuming inheritance is automatic: customers inherit only controls actually delivered by the provider and still implement customer-side controls.
  • Treating mappings as certification: a CCM-to-standard mapping is a cross-reference, not a legal conclusion.
  • Using stale counts or domain codes: verify the current CCM and CAIQ version before quoting numbers or identifiers.
Loading diagram...
CCM, CAIQ, and STAR assurance relationship
Test Your Knowledge

A hospital is evaluating a SaaS provider that has published a completed CAIQ v4.1 in the STAR Registry. Why might that artifact be insufficient by itself for the final high-risk approval?

A
B
C
D
Test Your Knowledge

An IaaS customer reviews CCM responsibilities for vulnerability management. Which allocation is correct?

A
B
C
D
Test Your Knowledge

What is the most accurate use of a CCM mapping to another framework?

A
B
C
D