SECURO CERT

Attestation, assessment and label schemes

CSA STAR:CCM v4

A public registry of cloud provider security posture built on the Cloud Controls Matrix. Its value is transparency: buyers read the entry directly rather than asking for a document.

What you receive

Public registry entry (Level 1 self-assessment or Level 2 third-party)

Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and is normally delivered on top of an ISO/IEC 27001 audit.

This scheme does not produce a certificate. If a body has offered you one for CSA STAR, that alone tells you what their audit work is worth.

Who needs it

Cloud service providers whose buyers check the STAR registry as a first-pass filter.

Prerequisites

For Level 2, a current or concurrent ISO/IEC 27001 certification.

How this engagement is delivered

Delivery mode — Direct

Audited and certified by Securo Cert LLC.

Accredited artifact

The partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.

Frequent questions

What do we actually receive?

Public registry entry (Level 1 self-assessment or Level 2 third-party). Level 1 is self-assessed and published by the provider. Level 2 requires an accredited certification body and is normally delivered on top of an ISO/IEC 27001 audit.

How long is it valid?

Level 2 follows the underlying 27001 cycle.

What has to be in place first?

For Level 2, a current or concurrent ISO/IEC 27001 certification.