Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Join Identity Week America to explore secure credentials, biometrics, and digital identity solutions while connecting with industry experts. Save 20% on your ticket with code CSASAVE20

STAR-Enabled Solution:

Drata

Drata Logo

Drata

Drata builds the world's most advanced security and compliance automation platform with the mission to help businesses earn and keep the trust of their users, customers, partners, and prospects. With Drata, companies can quickly and successfully complete audits, continuously monitor controls, and seamlessly expand their security assurance efforts as they scale.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Organizations who have the CSA Trusted Cloud Provider trustmark demonstrate a commitment to organizational security. They are a CSA Corporate Member, volunteer regularly for CSA, and have at least one staff member who has earned their CCSK.
Organizations who have the CSA STAR Enabled Solution trustmark have leveraged or incorporated the CCM framework or CAIQ into their commercial offerings, and who demonstrate alignment with CSA STAR, CCM, and CAIQ best practices. View the STAR Enabled Solutions Registry or learn more about becoming a STAR Enabled Solution here.
Information about Drata
Listed Since: 08/24/2021

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.2

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed almost 2 years ago, on October 17, 2024.

(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the assessment has not been updated within its validity period. We suggest contacting this organization directly to request that they submit an updated assessment.