Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CSA STAR cloud security assurance levels and the STAR for AI track

CSA STAR: The Levels, Valid-AI-ted and STAR for AI

CSA STAR is the cloud industry’s answer to the security questionnaire — a public registry where a provider publishes its security posture once, in a format buyers already trust, instead of answering the same 200 questions in a different spreadsheet every quarter.

It is also the assurance programme that has moved fastest in the last two years, because the Cloud Security Alliance extended it to cover AI.

What CSA STAR is

The CSA STAR name stands for Security, Trust, Assurance and Risk. The STAR Registry is publicly accessible: anyone can look up a cloud service and read what its provider says about its controls, and at higher levels what an auditor has confirmed.

Underneath sits the Cloud Controls Matrix197 control objectives across 17 domains, aligned to CSA’s cloud security guidance and treated across the industry as the de facto cloud control framework. The CCM’s companion is the Consensus Assessments Initiative Questionnaire, the CAIQ, which turns those objectives into questions a provider answers. As of v4.1 the two are published combined.

The CCM does something most control frameworks do not: it says which actor in the cloud supply chain should implement each control. That single feature is why it resolves shared-responsibility arguments better than a generic checklist.

The levels of CSA STAR

The CSA STAR registry levels, including the STAR for AI track

Level 1 is a self-assessment and it is free. You complete the CAIQ v4 and submit it; it becomes public and is updated annually. For a startup or SME the CCM Lite and CAIQ Lite variants trim it to something achievable without a compliance team.

Self-assessed does not mean worthless. It is published, attributable and comparable — which is more than most vendor security pages offer.

Level 2 is a third-party audit, and its design is the clever part: it builds on certifications you may already hold rather than duplicating them. If you have ISO 27001, SOC 2, GB/T 22080-2008 or a GDPR-based position, Level 2 makes it cloud-specific instead of starting again. It is aimed at medium-to-high risk environments, and it carries fees, reduced for CSA corporate members.

Valid-AI-ted: the newer route through CSA STAR Level 1

Valid-AI-ted is an optional enhancement to Level 1 in which CSA’s own AI scores your CAIQ v4 submission against a standardised model derived from the CCM.

  • $595, including up to ten scoring attempts — and free to CSA corporate members.
  • Near-instant feedback, with revision guidance whether you pass or fail.
  • A distinct badge on the registry, which is the point: it separates a scored submission from an unscored one.

The ten attempts matter more than the price, and they make CSA STAR unusual among assurance schemes. This is a scoring loop, not an exam — you are meant to submit, read the feedback, fix the answers and resubmit.

STAR for AI: the part most buyers have not caught up with

CSA has extended the programme to AI systems, built on three things: the AI Controls Matrix (AICM), the AI-CAIQ, and ISO/IEC 42001.

STAR for AI Level 1 works like the cloud equivalent — submit an AI-CAIQ self-assessment against the AICM.

STAR for AI Level 2 is the interesting one. Since 20 November 2025, an organisation can combine a Valid-AI-ted AI-CAIQ with an ISO/IEC 42001 certification to earn it.

That combination is worth understanding before you plan an AI assurance roadmap. ISO 42001 gives you a certifiable management system; the AI-CAIQ gives you public, control-level transparency. Level 2 requires both, which means an organisation already pursuing ISO 42001 is most of the way to a STAR for AI designation it may not know exists.

How CSA STAR sits against other certifications

Standard Relationship
ISO 27001 The management system underneath. Level 2 explicitly builds on it, so the sequence is ISO 27001 first, then STAR — not in parallel
ISO 27017 Cloud-specific security controls. Substantial conceptual overlap with the CCM, but ISO 27017 is guidance attached to an ISO certificate while the CCM drives a public registry entry
SOC 2 Another accepted Level 2 basis. Useful where your buyers are North American and already ask for SOC 2 reports
ISO 42001 Required for STAR for AI Level 2 alongside a Valid-AI-ted AI-CAIQ

The pattern across all four: CSA STAR is not a replacement for a certification, it is a way of publishing one in cloud terms where buyers can find it.

What a CSA STAR submission actually takes

  • A completed CAIQ v4 using the submission version — the bundled CCM+CAIQ spreadsheet is a reference copy and cannot be submitted.
  • Honest answers. The registry is public and permanent; a generous self-assessment is a discoverable liability.
  • Clarity on shared responsibility, because the CCM asks which actor implements each control.
  • An annual refresh for Level 1 — a lapsed entry looks worse than no entry.
  • An underlying certification if you are targeting Level 2, plus an approved assessment firm.

Where to start

  1. Do Level 1 now. It is free, it is public, and it answers the questionnaire problem immediately.
  2. Use CAIQ Lite if the full one stalls you — a submitted Lite entry beats an unfinished full one.
  3. Consider Valid-AI-ted for the badge and the feedback loop, especially if you are already a corporate member and it costs nothing.
  4. Reach Level 2 through a certification you already hold, rather than treating it as a separate programme.
  5. If you ship AI features, look at STAR for AI now — the Level 2 route through ISO 42001 is new enough to be a genuine differentiator.
  6. Diarise the annual update.

This guide reflects cloudsecurityalliance.org at 15 August 2026. The AI track is moving quickly; check the submission guides before committing to a route.

The CSA STAR Cloud Security Toolkit provides 30 editable templates covering the control mapping, the shared responsibility documentation, the self-assessment evidence and the registry submission records — the working papers behind a CAIQ that stands up to a customer reading it.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.