xmodoxmodo

Frameworks · Global standards

CSA STAR

CSA STAR is the Cloud Security Alliance's assurance programme for cloud providers. It is built on the Cloud Controls Matrix, which has 207 controls across 17 domains in version 4.1, released in January 2026. Level 1 is a published self-assessment against the Consensus Assessment Initiative Questionnaire. Level 2 is validated by an accredited third party, as a STAR Attestation built on SOC 2 or a STAR Certification built on ISO/IEC 27001.

Who it applies to

It applies to cloud service providers that publish their security status to the STAR Registry. It also applies to providers whose enterprise or government customers, including DESC in Dubai, accept STAR Level 2 in place of a further audit.

Main requirements

Cloud Controls Matrix

Version 4.1 has 207 controls across 17 domains, from audit and assurance to universal endpoint management.

Level 1

The provider publishes a completed CAIQ self-assessment to the STAR Registry.

Level 2

An accredited assessor issues a STAR Attestation (based on SOC 2) or a STAR Certification (based on ISO/IEC 27001).

Transition

CCM v4.0 and v4.1 are both accepted during the transition, and v4.1 is encouraged for new submissions.

How xmodo supports it

  • 1

    The Cloud Controls Matrix is set up with each of its controls, and xmodo generates the CAIQ for Level 1 from the status of your controls.

  • 2

    Controls map to SOC 2 and ISO/IEC 27001, which is how you reach Level 2 within one programme. They also map to ISO/IEC 27017 and the DESC CSP standard.

  • 3

    The CCM edition is a structured field, so moving from v4.0 to v4.1 is a version migration that carries evidence forward.

Related frameworks

CSA STAR shares requirements with the frameworks below. Controls you already run for any of them count towards CSA STAR as well.

Frequently asked questions

Do we need STAR if we already hold SOC 2 or ISO 27001?

Level 2 is built on them. A STAR Attestation extends a SOC 2 examination with the CCM, and a STAR Certification extends an ISO/IEC 27001 audit with the CCM. xmodo shows which CCM controls your existing programme already satisfies.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo