Screenata

Beyond SOC 2

What is CSA and CCM?

September 14, 20263 min read

What is CSA and CCM?

CSA is the Cloud Security Alliance, a nonprofit organization that publishes security best practices for cloud computing. CCM is its Cloud Controls Matrix, a control framework written specifically for cloud services. Version 4.1 of the CCM contains 207 controls across 17 domains and maps to ISO 27001, NIST SP 800-53, PCI DSS, and other standards. CSA also runs the STAR program, which lets cloud providers publish self-assessments or third-party validation against the CCM.

What the Cloud Controls Matrix covers

The CCM's 17 domains cover the ground of a general security framework, with more attention to how responsibility splits between a cloud provider and its customer.

AreaDomains includeWhat is cloud-specific
Governance and riskGovernance, Risk and Compliance; Audit and AssuranceShared responsibility defined per control
Identity and accessIdentity and Access ManagementCustomer versus provider administrative access
DataData Security and Privacy Lifecycle Management; Cryptography, Encryption and Key ManagementData location, tenant separation, customer-managed keys
InfrastructureInfrastructure and Virtualization Security; Datacenter SecurityHypervisor and multi-tenant isolation
OperationsLogging and Monitoring; Threat and Vulnerability Management; Change Control and Configuration ManagementVisibility customers can get into provider operations
Supply chainSupply Chain Management, Transparency, and AccountabilityControls on the provider's own cloud subprocessors
ResilienceBusiness Continuity Management and Operational Resilience; Security Incident Management, E-Discovery, and Cloud ForensicsProvider versus customer recovery obligations

Since version 4, the CCM includes shared security responsibility guidance that assigns each control to the cloud provider, the customer, or both. That split is the main thing the CCM adds over a general catalog such as ISO 27001 Annex A.

CSA STAR levels

LevelWhat it isWho performs it
Level 1: Self-AssessmentCompleted CAIQ questionnaire published in the STAR RegistryThe provider itself
Level 2: CertificationISO 27001 certification audit extended to cover the CCMAn accredited certification body
Level 2: AttestationSOC 2 examination extended to cover the CCM criteriaA licensed CPA firm

The STAR Registry is public, so a buyer can look up a provider's submission without asking for it. Level 1 costs nothing to publish, which is why many SaaS vendors use it to answer cloud-specific questionnaires before pursuing a formal audit.

Where the CCM fits for a SaaS company

For most B2B SaaS companies, the CCM is a complement to SOC 2 or ISO 27001 rather than a replacement. Buyers ask for those two by name. The CCM becomes useful in two situations: when a customer sends the CAIQ as its security questionnaire, and when a company already running SOC 2 or ISO 27001 wants STAR Level 2 by adding the CCM to an existing audit instead of starting a new one. Because the CCM maps to both, much of the evidence is already collected. For how the underlying frameworks overlap, see the controls shared by SOC 2, ISO 27001, and HIPAA.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.