<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is CSA and CCM?"
title: "What Is CSA and CCM"
seoTitle: "What Is the CSA Cloud Controls Matrix (CCM)?"
summary: "CSA is the Cloud Security Alliance, a nonprofit that publishes security best practices for cloud computing. CCM is its Cloud Controls Matrix, a cybersecurity control framework for cloud services; version 4.1 contains 207 controls across 17 domains and maps to standards including ISO 27001, NIST SP 800-53, and PCI DSS. CSA also runs the STAR program: Level 1 is a published self-assessment using the CAIQ questionnaire, and Level 2 is third-party validation, delivered either as STAR Certification alongside ISO 27001 or as STAR Attestation alongside a SOC 2 examination. Cloud vendors use STAR to answer customer security questions in a public registry."
publishedAt: "2026-09-14"
keywords:
  - "what is CSA CCM"
  - "Cloud Controls Matrix"
  - "CSA STAR certification"
  - "CAIQ questionnaire"
pillar: "Beyond SOC 2"
faqs:
  - question: "What is the CAIQ?"
    answer: "The CAIQ, or Consensus Assessments Initiative Questionnaire, is CSA's standard security questionnaire built from the Cloud Controls Matrix. A cloud vendor answers it yes or no per control, with comments, and can publish the completed CAIQ in the CSA STAR Registry as a Level 1 self-assessment, which many customers accept in place of their own questionnaire."
  - question: "Is CSA STAR the same as SOC 2?"
    answer: "No, but they combine. STAR Level 2 Attestation is issued by a CPA firm performing a SOC 2 examination that also covers the Cloud Controls Matrix criteria. A company with SOC 2 can add the CCM to scope rather than run a separate audit, and a company with ISO 27001 can do the same through STAR Certification."
  - question: "Does a SaaS startup need CSA STAR?"
    answer: "Usually not as a first step. SOC 2 and ISO 27001 are what enterprise buyers ask for by name. Publishing a free STAR Level 1 self-assessment is a low-cost way to answer cloud-specific questionnaires, and Level 2 becomes worthwhile when customers or regulated buyers specifically request it."
---

## What is CSA and CCM?

**CSA is the Cloud Security Alliance**, a nonprofit organization that publishes security best practices for cloud computing. **CCM is its Cloud Controls Matrix**, a control framework written specifically for cloud services. Version 4.1 of the CCM contains 207 controls across 17 domains and maps to ISO 27001, NIST SP 800-53, PCI DSS, and other standards. CSA also runs the STAR program, which lets cloud providers publish self-assessments or third-party validation against the CCM.

## What the Cloud Controls Matrix covers

The CCM's 17 domains cover the ground of a general security framework, with more attention to how responsibility splits between a cloud provider and its customer.

| Area | Domains include | What is cloud-specific |
|---|---|---|
| Governance and risk | Governance, Risk and Compliance; Audit and Assurance | Shared responsibility defined per control |
| Identity and access | Identity and Access Management | Customer versus provider administrative access |
| Data | Data Security and Privacy Lifecycle Management; Cryptography, Encryption and Key Management | Data location, tenant separation, customer-managed keys |
| Infrastructure | Infrastructure and Virtualization Security; Datacenter Security | Hypervisor and multi-tenant isolation |
| Operations | Logging and Monitoring; Threat and Vulnerability Management; Change Control and Configuration Management | Visibility customers can get into provider operations |
| Supply chain | Supply Chain Management, Transparency, and Accountability | Controls on the provider's own cloud subprocessors |
| Resilience | Business Continuity Management and Operational Resilience; Security Incident Management, E-Discovery, and Cloud Forensics | Provider versus customer recovery obligations |

Since version 4, the CCM includes shared security responsibility guidance that assigns each control to the cloud provider, the customer, or both. That split is the main thing the CCM adds over a general catalog such as ISO 27001 Annex A.

## CSA STAR levels

| Level | What it is | Who performs it |
|---|---|---|
| Level 1: Self-Assessment | Completed CAIQ questionnaire published in the STAR Registry | The provider itself |
| Level 2: Certification | ISO 27001 certification audit extended to cover the CCM | An accredited certification body |
| Level 2: Attestation | SOC 2 examination extended to cover the CCM criteria | A licensed CPA firm |

The STAR Registry is public, so a buyer can look up a provider's submission without asking for it. Level 1 costs nothing to publish, which is why many SaaS vendors use it to answer cloud-specific questionnaires before pursuing a formal audit.

## Where the CCM fits for a SaaS company

For most B2B SaaS companies, the CCM is a complement to SOC 2 or ISO 27001 rather than a replacement. Buyers ask for those two by name. The CCM becomes useful in two situations: when a customer sends the CAIQ as its security questionnaire, and when a company already running SOC 2 or ISO 27001 wants STAR Level 2 by adding the CCM to an existing audit instead of starting a new one. Because the CCM maps to both, much of the evidence is already collected. For how the underlying frameworks overlap, see [the controls shared by SOC 2, ISO 27001, and HIPAA](/resources/answers/what-controls-overlap-between-soc-2-iso-27001-and-hipaa).
