


Listed Since: 02/26/2024
Last Updated: 02/11/2026
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.0.2
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

EU Cloud CoC (Level 2)
This trustmark signifies adherence to the EU Cloud CoC through a dedicated framework and legally demonstrates GDPR compliance. Cloud Service Providers that have successfully passed the EU Cloud CoC’s evaluation process have their Compliance Mark visible in both the Code’s Public Registry as well as here in the CSA STAR Registry.
STAR Level 2
Third-Party Audit
Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

ISO/IEC 42001
ISO/IEC 42001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) to ensure the responsible, ethical, and effective use of AI.
