Sooner or later a prospect asks a cloud provider to prove its security, and the honest first answer is a question: prove it to whom? There is no single cloud security certification. There are several, each built for a different buyer, and picking the wrong one means months of work that the customer you were chasing does not recognise. This guide compares the four that come up most often.
If your buyers are commercial rather than governmental, start with our SOC 2 guide — for most private-sector deals that is still the expected answer.
The four routes at a glance
| Who asks for it | Based on | How it is proven | |
|---|---|---|---|
| FedRAMP | US federal agencies | NIST SP 800-53 | Assessment by an accredited 3PAO |
| StateRAMP / TX-RAMP | US state and local government | NIST SP 800-53 | Third-party assessment, programme review |
| CSA STAR | Commercial customers, globally | Cloud Controls Matrix | Self-assessment or third-party certification |
| BSI C5 | German market, public and private | C5 criteria catalogue | ISAE 3000 audit, attestation report |
FedRAMP: selling to US federal agencies
FedRAMP is the heaviest of the four and the only one that is effectively mandatory — federal agencies cannot buy a cloud service without it. The security package is built around a System Security Plan mapping every applicable NIST SP 800-53 control to your service, supported by contingency, incident response and configuration management plans, then assessed by an accredited third-party assessment organisation.
Expect this to be measured in quarters, not weeks. The documentation burden is the reason: our FedRAMP Authorization Toolkit covers the package with 43 templates — SSP, FIPS 199 categorisation, privacy threshold and impact analyses, digital identity worksheet, rules of behaviour and the contingency plan set a 3PAO will expect to see.
StateRAMP and TX-RAMP: the same rigour, a different buyer
State and local government wanted FedRAMP-grade assurance without federal cost, so StateRAMP applies the same NIST SP 800-53 foundation to public-sector purchasing at state level, and Texas runs its own TX-RAMP programme on similar lines.
If you already hold FedRAMP, much of the evidence transfers. If you do not, this is often the cheaper entry point into public-sector sales. Our StateRAMP TX-RAMP Toolkit provides 50 templates spanning the assessment set — security assessment plan and report, plan of action and milestones, penetration testing plan, 3PAO engagement pack — plus the continuous monitoring packs both programmes require after authorisation.
CSA STAR: proving security to commercial customers
Most enterprise buyers cannot audit their cloud providers directly, so the Cloud Security Alliance publishes a shared answer. CSA STAR maps your controls to the Cloud Controls Matrix and publishes the result — either as a self-assessment or, at the higher level, as a third-party certification.
Its advantage is proportionality: a self-assessment is achievable for a small provider and still gives procurement something concrete. Our CSA STAR Toolkit covers the CCM domains with 30 templates, from audit assurance and application security through cryptography, datacentre security and governance.
BSI C5: the German market
Germany’s Federal Office for Information Security publishes the Cloud Computing Compliance Criteria Catalogue, and German buyers — public sector especially — increasingly expect it. C5 is not a certification in the ISO sense: it is assessed through an ISAE 3000 audit that produces an attestation report, which sits closer to SOC 2 in structure than to FedRAMP.
Our BSI C5:2026 Cloud Toolkit is the largest of the four at 107 templates, reflecting the breadth of the catalogue across asset management, business continuity and the rest of the criteria set.
Choosing between them
Work backwards from the contract you want. Federal work means FedRAMP and nothing else will substitute. State and local work means StateRAMP or TX-RAMP. German buyers mean C5. Commercial buyers who simply want assurance mean CSA STAR or SOC 2, and STAR is often the faster of the two to start.
The good news is that these overlap heavily. All four rest on the same security practices; what differs is the evidence format and who audits it. A provider with a mature ISMS is not starting from zero on any of them — which is why many teams build on ISO 27001 first and treat the rest as mappings.
That mapping route has its own standard. ISO 27017 adds cloud-specific controls to an ISO 27001 system — tenant segregation, virtual machine hardening, administrator operational security and shared responsibility — and ISO 27018 covers personal data where you process it on a customer’s behalf. Neither is separately certifiable; both are audited as an extension of your ISO 27001 scope.
Frequently asked questions
Which cloud security certification should a startup get first?
For commercial buyers, SOC 2 or a CSA STAR self-assessment gives the fastest credible answer. Pursue FedRAMP or StateRAMP only when you have a public-sector deal that requires it — the effort is hard to justify speculatively.
Does FedRAMP authorization cover StateRAMP?
Not automatically, but the overlap is substantial because both build on NIST SP 800-53. StateRAMP recognises FedRAMP work, so most of the evidence can be reused rather than recreated.
Is BSI C5 a certification?
Not strictly. C5 is assessed through an ISAE 3000 audit that results in an attestation report on your controls, closer in form to a SOC 2 report than to an ISO certificate.