Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join Identity Week America to explore secure credentials, biometrics, and digital identity solutions while connecting with industry experts. Save 20% on your ticket with code CSASAVE20

STAR Registry Listing for

Descope

Descope

Descope is a drag-and-drop customer authentication and identity management platform. Our visual workflows, SDKs, and APIs help customers easily create and modify any user journey interaction with their apps. Hundreds of organizations use Descope to improve user onboarding with passwordless auth, enhance user protection with risk-based MFA, and unify identities across customer-facing apps with federated SSO.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.
Information about Descope
Listed Since: 03/27/2024

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 16 days ago, on July 23, 2026.

STAR Level 2

Cloud Controls Matrix

STAR Attestation v3.0

Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.

Created or renewed over 2 years ago, on March 27, 2024.

(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the assessment has not been updated within its validity period. We suggest contacting this organization directly to request that they submit an updated assessment.