Attestation, assessment and label schemes
CSA STAR:CCM v4
A public registry of cloud provider security posture built on the Cloud Controls Matrix. Its value is transparency: buyers read the entry directly rather than asking for a document.
What you receive
Public registry entry (Level 1 self-assessment or Level 2 third-party)
Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and is normally delivered on top of an ISO/IEC 27001 audit.
This scheme does not produce a certificate. If a body has offered you one for CSA STAR, that alone tells you what their audit work is worth.
Who needs it
Cloud service providers whose buyers check the STAR registry as a first-pass filter.
Prerequisites
For Level 2, a current or concurrent ISO/IEC 27001 certification.
How this engagement is delivered
Audited and certified by Securo Cert LLC.
Accredited artifactThe partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.
Frequent questions
What do we actually receive?
Public registry entry (Level 1 self-assessment or Level 2 third-party). Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and is normally delivered on top of an ISO/IEC 27001 audit.
How long is it valid?
Level 2 follows the underlying 27001 cycle.
What has to be in place first?
For Level 2, a current or concurrent ISO/IEC 27001 certification.