ISO 27017 vs CSA STAR is a comparison between two things that are often sold as alternatives and are actually different kinds of object. ISO/IEC 27017:2026 is a standard — cloud-specific guidance on the ISO/IEC 27002 controls, audited as an extension of an ISO 27001 certificate and evidenced by a line in that certificate’s scope statement. CSA STAR is a programme — a public registry run by the Cloud Security Alliance in which a provider publishes its answers to the Consensus Assessments Initiative Questionnaire against the Cloud Controls Matrix, at Level 1 by self-assessment and at Level 2 by third-party audit built on a certification it already holds, including ISO 27001. One produces an audited scope; the other produces a public, control-by-control entry buyers can read. This guide sets out the six differences that matter, how the Cloud Controls Matrix relates to the ISO 27017 controls, what each costs and how long it takes, the sequence in which a provider should do them, and the buyer situations where one or the other wins.

ISO 27017 vs CSA STAR at a glance
| Dimension | ISO/IEC 27017:2026 | CSA STAR |
|---|---|---|
| What it is | An ISO standard: implementation guidance and dedicated cloud controls built on ISO/IEC 27002:2022 | An assurance programme and public registry run by the Cloud Security Alliance |
| Control set | ISO/IEC 27002:2022 controls with cloud guidance, plus dedicated cloud controls | The Cloud Controls Matrix — 207 control objectives in 17 domains in CCM v4.1 (January 2026) — answered through the CAIQ |
| Who it addresses | Cloud service providers and cloud service customers | Cloud service providers; the CCM states which actor in the supply chain implements each control |
| Assessment | Audited by an accredited certification body as an extension of ISO 27001 | Level 1: self-assessment (optionally scored by CSA’s Valid-AI-ted); Level 2: third-party audit or attestation building on ISO 27001, SOC 2 or equivalent |
| Evidence produced | The ISO 27001 certificate with ISO 27017 named in the scope; the Statement of Applicability | A public registry entry: the completed CAIQ, and at Level 2 the certification or attestation |
| Cost and cadence | Extra audit days on each ISO 27001 audit; annual surveillance | Level 1 free, refreshed annually; Valid-AI-ted $595 with up to ten scoring attempts; Level 2 fees plus the underlying certification |
Difference 1: a standard against a registry
ISO 27017 tells a provider how to implement security controls for cloud services. CSA STAR tells a buyer what a provider says — and at Level 2, what an auditor has confirmed — about the controls it operates. A provider can implement ISO 27017 and tell nobody; a STAR entry exists to be read. That is the first ISO 27017 vs CSA STAR distinction and the one that decides which a sales team asks for: the standard closes a security review that asks “are you certified”, the registry pre-empts the questionnaire that asks “how do you do X”. Our guides to ISO 27017 and CSA STAR cover each on its own.
Difference 2: the control sets
The second ISO 27017 vs CSA STAR difference is the control set. ISO 27017 keeps the ISO/IEC 27002:2022 structure — the 93 controls in four themes — and adds cloud guidance to them plus a small number of dedicated cloud controls, so a provider that already runs an ISMS extends what it has. The Cloud Controls Matrix is a cloud-native framework: 207 control objectives across 17 domains, with mappings to ISO 27001 and 27017, NIST, PCI and others published by CSA. The overlap is large in substance — both cover tenancy separation, shared responsibility, administrator access, monitoring, data location and deletion — and different in form: the CCM is more granular and says, per control, which actor implements it, which is why it resolves shared-responsibility arguments a control list cannot. Our guide to the shared responsibility matrix covers the ISO 27017 artefact that does the same job.
Difference 3: how each is assessed
Assessment is where ISO 27017 vs CSA STAR diverges most. ISO 27017 is never assessed alone. The cloud controls go into the Statement of Applicability, the certification body audits them during the ISO 27001 Stage 2 and surveillance audits, and the certificate scope names the extension; there is no ISO 27017 certificate. CSA STAR Level 1 is a self-assessment: the provider completes the CAIQ v4.1 and CSA publishes it. Level 2 is a third-party assessment that builds on a certification the provider holds — STAR Certification on ISO 27001, STAR Attestation on SOC 2 — with the CCM as the additional criteria. In other words, Level 2 does not replace ISO 27001; it publishes it in cloud terms.
Difference 4: what the buyer sees
An ISO 27017 extension is visible as a phrase on a certificate and, if the provider shares it, a Statement of Applicability. A STAR entry is a public document, updated annually, that a buyer’s security team can read before the first call. For a buyer running a procurement, the registry answers most of the questionnaire; for a buyer’s auditor, the accredited certificate is the evidence that counts. The two satisfy different people in the same procurement.
Difference 5: cost and cadence
ISO 27017 costs extra audit days on every ISO 27001 audit — typically half a day to two days — plus the implementation of the cloud controls; our guide to ISO 27017 certification cost works the figures. CSA STAR Level 1 is free and refreshed annually; Valid-AI-ted scoring is $595 with up to ten attempts and free to CSA corporate members; Level 2 carries CSA fees, reduced for members, on top of the underlying ISO 27001 or SOC 2 engagement and an approved assessment firm’s time.
Difference 6: what each proves
The final ISO 27017 vs CSA STAR difference is what each proves. ISO 27017 proves that an accredited auditor examined the cloud controls inside a certified management system. STAR Level 1 proves that the provider was willing to answer 200-plus questions in public and be held to them; Valid-AI-ted adds that the answers scored against a model; Level 2 adds an auditor’s confirmation on top of a certification. Neither proves the other’s claim, which is why mature providers hold both and why the sequence matters.
ISO 27017 vs CSA STAR: the sequence
- ISO 27001 first. Both ISO 27017 and STAR Level 2 build on it; nothing else has a base without it.
- ISO 27017 as the extension at Stage 2 or the next surveillance. The shared responsibility matrix and the cloud controls are the work; the certificate scope is the output.
- STAR Level 1 now, in parallel. It is free, it is public, and completing the CAIQ against the CCM is a gap analysis in itself — most of the answers come from the ISO 27017 work.
- STAR Level 2 when buyers ask for it. With ISO 27001 and 27017 in place the CCM criteria are largely met; the Level 2 engagement publishes that in the registry.
Which wins where
| Buyer situation | What carries weight | Why |
|---|---|---|
| European enterprise procurement with an ISO-based supplier policy | ISO 27017 in the ISO 27001 scope | The certificate is what the policy names |
| North American enterprise already asking for SOC 2 | STAR Attestation (Level 2 on SOC 2) | Builds on the report they already read |
| Buyer sending a 300-question security questionnaire | STAR Level 1 or Valid-AI-ted | The CAIQ is the questionnaire, answered once in public |
| Regulated buyer whose auditor needs accredited evidence | ISO 27017 extension | Accredited certification is the form auditors accept |
| Buyer comparing several cloud providers quickly | STAR registry entries | Comparable, public, control by control |
Frequently asked questions
What is the difference between ISO 27017 vs CSA STAR?
ISO 27017 is an ISO standard of cloud security guidance audited as an extension of an ISO 27001 certificate; CSA STAR is a Cloud Security Alliance programme and public registry in which providers publish their CAIQ answers against the Cloud Controls Matrix, self-assessed at Level 1 and third-party assessed at Level 2 on top of ISO 27001 or SOC 2.
Do I need both?
Mature cloud providers usually hold both: ISO 27017 for accredited evidence inside the ISO 27001 certificate, STAR for a public, comparable entry buyers read before the first call. Level 2 explicitly builds on ISO 27001, so the two are sequential rather than alternative.
Is CSA STAR a certification?
Level 1 is a published self-assessment. STAR Certification and STAR Attestation at Level 2 are third-party assessments that build on ISO 27001 and SOC 2 respectively with the CCM as additional criteria.
How do the control sets relate?
The Cloud Controls Matrix (207 objectives, 17 domains in v4.1) maps to ISO 27001 and ISO 27017 among others and overlaps them heavily in substance; it is more granular and names which actor implements each control.
Which should a small SaaS provider do first?
ISO 27001 with the ISO 27017 extension, and STAR Level 1 in parallel because it is free and the CAIQ doubles as a gap analysis.
Where this leaves you
Read ISO 27017 vs CSA STAR as standard against registry, not rival against rival: implement ISO 27017 inside your ISO 27001 scope for the accredited evidence auditors accept, publish a STAR Level 1 entry now because it is free and answers the questionnaire, and add Level 2 when buyers who read the registry ask for an auditor’s confirmation. The control work is done once; the two programmes present it to two different audiences.
References
- ISO/IEC 27017:2026 — Information security controls based on ISO/IEC 27002 for cloud services — Second edition, July 2026.
- Cloud Security Alliance: STAR programme — Levels, the registry, Valid-AI-ted and STAR Certification and Attestation.
- Cloud Security Alliance: Cloud Controls Matrix — CCM v4.1 and the CAIQ, with mappings to ISO 27001 and 27017.
More on ISO 27017 and ISO 27018
- ISO 27017 vs CSA STAR — you are here
- ISO 27017: cloud security controls and the 2026 edition
- CSA STAR: the levels, Valid-AI-ted and STAR for AI
- ISO 27017 vs ISO 27018
- ISO 27017 certification cost
- Cloud security certification: 4 routes compared
The Shared Responsibility Matrix Template, the Shared Roles and Responsibilities Policy, the cloud control procedures mapped to the 2026 edition and the Cloud Service Agreement Security Schedule are in the ISO 27017 & ISO 27018 Cloud Toolkit, or start with the free templates.