The Cloud Controls Matrix is the control framework behind every CSA STAR entry, and it moved in January 2026. CCM v4.1 succeeded the v4.0 line, the CAIQ moved with it, and a submission built on the older version now has a transition timeline attached to it.
This guide covers what the Cloud Controls Matrix is, what the CAIQ does with it, what the v4.1 release changes for a STAR submission, and how to answer it without producing a document your own customers can disprove.

What the Cloud Controls Matrix is
The Cloud Controls Matrix is the Cloud Security Alliance’s cybersecurity control framework for cloud computing, organized into seventeen security domains covering everything from identity and access management to interoperability, logging and supply chain. Its distinguishing feature is not the control text but the shared responsibility dimension: the framework asks which actor — cloud service provider or cloud service customer — implements each control.
Its companion is the Consensus Assessments Initiative Questionnaire. The CAIQ turns the control objectives into yes/no questions a provider answers, and a completed CAIQ is what gets submitted to the public STAR Registry. The two ship together, and the version numbers move together: CCM v4.1 and CAIQ v4.1.
The reference copy is not the submission copy
A trap worth naming early, because it costs weeks. The bundled CCM and CAIQ spreadsheet is a reference document. STAR submissions use the submission version of the CAIQ. Teams that complete the reference workbook discover this at the point of upload, having answered several hundred questions in the wrong file.
What changed with v4.1
CCM v4.1 was released in late January 2026 as the successor to the v4.0 line, and CSA published a transition timeline alongside it. Three practical consequences:
- New submissions move to v4.1. If you are starting now, start on v4.1 rather than completing a v4.0 workbook you will have to redo.
- Existing registry entries have a window. An entry submitted on the previous version remains visible, but the transition timeline is what determines how long it can be refreshed on that basis. Check the current dates on CSA’s own transition page before planning your annual refresh.
- Mappings need re-checking. If you maintain a crosswalk from the CCM to ISO 27001, SOC 2 or your internal control set, the version change is exactly the point at which control identifiers shift and a stale mapping starts producing wrong answers.
The numbers behind that, taken from CSA’s own v4.1 release and its CAIQ change analysis: the control count rises from 197 to 207 across the same 17 domains, and the CAIQ from 261 to 283 question IDs. The Infrastructure & Virtualization Security domain (IVS) becomes Infrastructure Security (I&S), with its nine controls renumbered I&S-01 to I&S-09. Twenty controls are new by identifier — among them API security (AIS-08), datacentre metrics and operations resilience (DCS-17, DCS-18), audit-log sanitisation for customers (LOG-08), incident records management and points of contact (SEF-09, SEF-10), a supply-chain policy and a service bill of materials (STA-01, STA-09), and threat analysis and threat response (TVM-04, TVM-10) — and one is dropped (the old IAM-12). The trap is the renumbering that the new controls cause: in six domains (DCS, IAM, LOG, SEF, STA and TVM) the identifiers below an inserted control keep their numbers and the ones above shift, so old DCS-07 is now DCS-08, old IAM-16 is IAM-15, old LOG-08 is LOG-09, old SEF-08 is SEF-10 and old TVM-09 is TVM-11. A crosswalk that carries v4.0 identifiers into a v4.1 submission points at the wrong control roughly one time in three in those domains. On dates: new STAR assessments must use v4.1 from July 2027, and existing registrations need to be on v4.1 by January 2028.
The version you answered against is part of your public position. When a customer’s due-diligence team reads your registry entry, “CAIQ v4.1, submitted March 2026” tells them something; “CAIQ” alone does not.
Answering the CAIQ so it survives a customer reading it
The registry is public and permanent, which changes the incentives. Four rules keep an entry defensible:
- Answer for the service, not the company. Scope the entry to a named offering. A generous answer that is true of your flagship platform and false of the product a customer is buying is the worst outcome available.
- Be explicit about shared responsibility. The framework asks which actor implements each control; “yes” where the customer actually implements it is the single most common inaccuracy, and it is the one that surfaces during an incident.
- Write the notes. A bare yes is weaker than a yes with a sentence naming the mechanism. Assessors and customers both read the notes column first.
- Refresh annually. A lapsed entry reads worse than no entry, because it suggests the position was true once and nobody has checked since.
Where the full questionnaire is stalling a small team, the Lite variants exist for exactly that reason — a submitted Lite entry beats an unfinished full one, and it can be upgraded later.
How the Cloud Controls Matrix relates to what you already hold
The CCM overlaps heavily with frameworks most cloud providers already run, and the overlap is the point rather than duplication:
- ISO 27001 and ISO 27017 — substantial conceptual overlap, but ISO 27017 is guidance attached to an ISO certificate while the CCM drives a public registry entry. Our guide to ISO 27017 cloud controls covers that side.
- SOC 2 — an accepted basis for STAR Level 2, so an existing report shortens the path considerably.
- BSI C5 — different criteria and a different report format, but the same underlying control estate; see the C5 attestation guide.
The efficient pattern is one control library mapped outward to each of these, with the CCM version recorded in the mapping. Then a version change is a mapping update rather than a re-answer.
Frequently asked questions
What is the current version of the Cloud Controls Matrix?
CCM v4.1, released in late January 2026, with CAIQ v4.1 as its companion questionnaire. CSA publishes a transition timeline for entries on earlier versions.
What is the difference between the CCM and the CAIQ?
The CCM is the control framework; the CAIQ turns those controls into questions a provider answers. You submit the CAIQ, not the CCM.
How many domains does the CCM cover?
Seventeen security domains, spanning governance, technical and supply chain areas of cloud service delivery.
Is a STAR Level 1 submission free?
Level 1 is a self-assessment and is free to submit. Level 2 involves an assessment by an approved firm against an underlying certification.
Do we have to redo everything for v4.1?
Not everything. The 17 domains and most control titles are unchanged, so implementation narratives carry over. What must be redone is the identifier layer: the DCS, IAM, LOG, SEF, STA and TVM domains were renumbered, IVS became I&S, 20 controls and 22 CAIQ questions are new, and every crosswalk built on v4.0 identifiers needs re-keying before it is trusted. New submissions should be built on v4.1 rather than the version you started drafting.
Where this leaves you
Treat the Cloud Controls Matrix as the control framework and the CAIQ as its public face. Start new work on v4.1, check CSA’s transition timeline against your refresh date, scope the entry to a named service, and answer the shared-responsibility question honestly — the registry is permanent and a generous answer becomes a discoverable liability. Then map the CCM to the certifications you already hold once, with the version recorded, so the next release is an afternoon rather than a project.
Update, 11 September 2026: our own CSA STAR Cloud Security Toolkit was rebuilt for v4.1 this month — 207 controls across 17 domain implementation plans, the Infrastructure Security domain, 283 CAIQ v4.1 question IDs in the self-assessment workbook, and the renumbering above applied to every crosswalk. One design point worth stating: the CCM is CSA’s copyrighted work, licensed for non-commercial use without redistribution, so the toolkit carries CSA’s control IDs and titles with our own statement of each control’s intent, and points you to CSA’s free download for the authoritative wording. Any toolkit that reproduces the CCM text verbatim is doing something CSA’s licence does not permit.
References
- CSA — Cloud Controls Matrix and CAIQ v4.1 — the current release of the framework and questionnaire.
- CSA — Cloud Controls Matrix research — domain structure, transition guidance and supporting material.
More on cloud assurance
- The Cloud Controls Matrix — you are here
- CSA STAR: the levels and STAR for AI
- ISO 27017 cloud security controls
- The BSI C5 attestation
Control mappings, shared responsibility documentation and submission records are in the CSA STAR Cloud Security Toolkit, or start with the free ISO templates.