


Listed Since: 09/29/2015
Last Updated: 11/08/2025
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
STAR Level 2
Third-Party Audit
Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

STAR Attestation (CCM v3)
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.

STAR Certification (CCMv4)
A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).
