The Cloud Controls Matrix is the control framework behind every CSA STAR entry, and it moved in January 2026. CCM v4.1 succeeded the v4.0 line, the CAIQ moved with it, and a submission built on the older version now has a transition timeline attached to it.
This guide covers what the Cloud Controls Matrix is, what the CAIQ does with it, what the v4.1 release changes for a STAR submission, and how to answer it without producing a document your own customers can disprove.

What the Cloud Controls Matrix is
The Cloud Controls Matrix is the Cloud Security Alliance’s cybersecurity control framework for cloud computing, organized into seventeen security domains covering everything from identity and access management to interoperability, logging and supply chain. Its distinguishing feature is not the control text but the shared responsibility dimension: the framework asks which actor — cloud service provider or cloud service customer — implements each control.
Its companion is the Consensus Assessments Initiative Questionnaire. The CAIQ turns the control objectives into yes/no questions a provider answers, and a completed CAIQ is what gets submitted to the public STAR Registry. The two ship together, and the version numbers move together: CCM v4.1 and CAIQ v4.1.
The reference copy is not the submission copy
A trap worth naming early, because it costs weeks. The bundled CCM and CAIQ spreadsheet is a reference document. STAR submissions use the submission version of the CAIQ. Teams that complete the reference workbook discover this at the point of upload, having answered several hundred questions in the wrong file.
What changed with v4.1
CCM v4.1 was released in late January 2026 as the successor to the v4.0 line, and CSA published a transition timeline alongside it. Three practical consequences:
- New submissions move to v4.1. If you are starting now, start on v4.1 rather than completing a v4.0 workbook you will have to redo.
- Existing registry entries have a window. An entry submitted on the previous version remains visible, but the transition timeline is what determines how long it can be refreshed on that basis. Check the current dates on CSA’s own transition page before planning your annual refresh.
- Mappings need re-checking. If you maintain a crosswalk from the CCM to ISO 27001, SOC 2 or your internal control set, the version change is exactly the point at which control identifiers shift and a stale mapping starts producing wrong answers.
The version you answered against is part of your public position. When a customer’s due-diligence team reads your registry entry, “CAIQ v4.1, submitted March 2026” tells them something; “CAIQ” alone does not.
Answering the CAIQ so it survives a customer reading it
The registry is public and permanent, which changes the incentives. Four rules keep an entry defensible:
- Answer for the service, not the company. Scope the entry to a named offering. A generous answer that is true of your flagship platform and false of the product a customer is buying is the worst outcome available.
- Be explicit about shared responsibility. The framework asks which actor implements each control; “yes” where the customer actually implements it is the single most common inaccuracy, and it is the one that surfaces during an incident.
- Write the notes. A bare yes is weaker than a yes with a sentence naming the mechanism. Assessors and customers both read the notes column first.
- Refresh annually. A lapsed entry reads worse than no entry, because it suggests the position was true once and nobody has checked since.
Where the full questionnaire is stalling a small team, the Lite variants exist for exactly that reason — a submitted Lite entry beats an unfinished full one, and it can be upgraded later.
How the Cloud Controls Matrix relates to what you already hold
The CCM overlaps heavily with frameworks most cloud providers already run, and the overlap is the point rather than duplication:
- ISO 27001 and ISO 27017 — substantial conceptual overlap, but ISO 27017 is guidance attached to an ISO certificate while the CCM drives a public registry entry. Our guide to ISO 27017 cloud controls covers that side.
- SOC 2 — an accepted basis for STAR Level 2, so an existing report shortens the path considerably.
- BSI C5 — different criteria and a different report format, but the same underlying control estate; see the C5 attestation guide.
The efficient pattern is one control library mapped outward to each of these, with the CCM version recorded in the mapping. Then a version change is a mapping update rather than a re-answer.
Frequently asked questions
What is the current version of the Cloud Controls Matrix?
CCM v4.1, released in late January 2026, with CAIQ v4.1 as its companion questionnaire. CSA publishes a transition timeline for entries on earlier versions.
What is the difference between the CCM and the CAIQ?
The CCM is the control framework; the CAIQ turns those controls into questions a provider answers. You submit the CAIQ, not the CCM.
How many domains does the CCM cover?
Seventeen security domains, spanning governance, technical and supply chain areas of cloud service delivery.
Is a STAR Level 1 submission free?
Level 1 is a self-assessment and is free to submit. Level 2 involves an assessment by an approved firm against an underlying certification.
Do we have to redo everything for v4.1?
Not everything, but the mapping and the identifiers need checking, and new submissions should be built on the current version rather than the one you started drafting.
Where this leaves you
Treat the Cloud Controls Matrix as the control framework and the CAIQ as its public face. Start new work on v4.1, check CSA’s transition timeline against your refresh date, scope the entry to a named service, and answer the shared-responsibility question honestly — the registry is permanent and a generous answer becomes a discoverable liability. Then map the CCM to the certifications you already hold once, with the version recorded, so the next release is an afternoon rather than a project.
References
- CSA — Cloud Controls Matrix and CAIQ v4.1 — the current release of the framework and questionnaire.
- CSA — Cloud Controls Matrix research — domain structure, transition guidance and supporting material.
More on cloud assurance
- The Cloud Controls Matrix — you are here
- CSA STAR: the levels and STAR for AI
- ISO 27017 cloud security controls
- The BSI C5 attestation
Control mappings, shared responsibility documentation and submission records are in the CSA STAR Cloud Security Toolkit, or start with the free ISO templates.