Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
CSA STAR

CSA STAR: cloud assurance buyers can look up

Run the Cloud Controls Matrix with automated checks and structured evidence, publish your Level 1 self-assessment to the STAR registry, and take Level 2 certification or attestation on the ISO 27001 or SOC 2 evidence you already hold.

What is CSA STAR?

CSA STAR, the Cloud Security Alliance's Security, Trust, Assurance and Risk program, is a public registry where cloud service providers publish their security assurance, built on the CSA Cloud Controls Matrix, a cloud-specific control framework of 197 control objectives in 17 domains in version 4. STAR has two levels. Level 1 is self-assessment: the provider completes the Consensus Assessment Initiative Questionnaire against the Cloud Controls Matrix and publishes it to the registry, where buyers can read it. Level 2 is third-party assurance in one of two forms: STAR Certification, an ISO 27001 certification audit extended to the Cloud Controls Matrix by an accredited certification body, or STAR Attestation, a SOC 2 examination extended to the matrix by a CPA firm. Because both Level 2 forms build on assurance a provider usually already holds, STAR adds cloud-specific credibility at modest extra effort, and enterprise procurement teams search the registry during due diligence. The Cloud Controls Matrix is also mapped to ISO 27001, NIST and PCI DSS, which is why one evidence base serves them all.

In one paragraph

The Cloud Security Alliance's Security, Trust, Assurance and Risk program is a public registry of cloud providers' security assurance, built on the CSA Cloud Controls Matrix. Level 1 is a self-assessment published to the registry, using the Consensus Assessment Initiative Questionnaire; Level 2 is third-party assurance, either STAR Certification, an ISO 27001 audit extended with the Cloud Controls Matrix, or STAR Attestation, a SOC 2 examination extended with it. Buyers search the registry during vendor due diligence.

Who it's for

Cloud and SaaS providers whose enterprise buyers check the STAR registry, and providers that want their ISO 27001 or SOC 2 work to say something specifically about the cloud.

With Viglyn

How Viglyn runs CSA STAR

  • The Cloud Controls Matrix mapped to controls in the library, with automated checks on the cloud, identity, code and device controls and structured evidence requests for the rest
  • The Consensus Assessment Initiative Questionnaire answered from your controls, ready to publish as a Level 1 entry and to reuse in security reviews
  • Level 2 prepared on the ISO 27001 or SOC 2 evidence you already hold, with the matrix extension added to the audit scope
  • Shared evidence with ISO 27017 and ISO 27018, the other cloud extensions
  • The certification or attestation run inside Viglyn, with your auditor working through scoped access
Straight answers

The CSA STAR questions that decide it

STAR Certification or STAR Attestation?

Certification if you hold or are pursuing ISO 27001; it extends the certification audit to the Cloud Controls Matrix. Attestation if your buyers are North American and you hold or are pursuing SOC 2; it extends the examination. Viglyn runs either on the evidence you already have.

How long does CSA STAR take?

Level 1 takes days once your controls are in Viglyn: the questionnaire is answered from them. Level 2 follows your ISO 27001 or SOC 2 timeline, with the matrix extension adding little when the cloud controls are already checked automatically.

How much does CSA STAR cost with Viglyn?

CSA STAR counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's or CPA firm's fee for the Level 2 extension and the registry listing are separate and paid by you directly; we take no commission.

FAQ

More CSA STAR questions

What is the Cloud Controls Matrix?
The Cloud Security Alliance's control framework for cloud computing: 197 control objectives in 17 domains in version 4, from application security and data security to identity, infrastructure, logging and supply chain, each mapped to other standards. It is the backbone of every STAR level.
Is Level 1 worth doing?
Yes, as a start: it is free to publish, buyers do find it in the registry, and the questionnaire doubles as a ready-made answer to many security reviews. Level 2 is what carries weight with enterprise procurement, and Viglyn prepares it on the assurance you already hold.
Does STAR replace ISO 27001 or SOC 2?
No, it extends them. STAR Certification is ISO 27001 plus the Cloud Controls Matrix; STAR Attestation is SOC 2 plus the matrix. You need one of the base assurances first, and Viglyn runs both.

See CSA STAR run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.