STAR Level 1 is the free, public, self-assessed tier of the Cloud Security Alliance’s STAR programme: a provider completes the Consensus Assessments Initiative Questionnaire against the Cloud Controls Matrix, submits it to the STAR Registry, and the answers become a permanent public record that any buyer can read. It is also, by a wide margin, the most used tier — of roughly 2,765 registry listings on 19 September 2026, about 2,479 were CAIQ self-assessments and a further 62 CAIQ Lite, against 268 STAR Certifications and 46 STAR Attestations.
CSA describes it as the tier for organisations “operating in a low-risk environment”, wanting transparency about their controls, or “looking for a cost-effective way to improve trust”, and it now has two variations: CAIQ Lite for SMEs and start-ups, and Valid-AI-ted, an optional AI-scored version for $595 with up to ten attempts. This guide sets out what a Level 1 submission contains, the reference-copy trap that costs teams weeks, the Lite and Valid-AI-ted variations, the annual refresh rule, how buyers read a self-assessment, and the six mistakes that make a public entry a liability.

What a STAR Level 1 submission is
The Cloud Controls Matrix is CSA’s control framework for cloud — 207 control objectives across 17 domains in v4.1, released in January 2026 — and the CAIQ turns each objective into yes/no/not-applicable questions with space to justify the answer. A Level 1 submission is the completed CAIQ, uploaded to the registry with a description of the service in scope, and updated annually.
CSA’s own description of the entry is precise: it “offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services”, and the point is publication — the questionnaire a provider would otherwise answer privately for every customer is answered once, in public, in a format buyers already use. Our guide to the Cloud Controls Matrix covers the framework and the v4.1 changes.
The reference-copy trap
CSA publishes two versions of the CAIQ v4 and says so on the STAR page: the CCM + CAIQ bundle “is intended to be used as a reference only” and “you cannot use the spreadsheet that contains both the CAIQ and CCM to submit to the registry”; the “STAR Level 1: Security Questionnaire (CAIQ v4)” is the one to fill out and submit. Teams that complete the bundled workbook — 283 question IDs in v4.1 — discover the distinction at upload. Download the submission version first.
The two variations of STAR Level 1
| Variation | What it is | Who it is for | Cost |
|---|---|---|---|
| CAIQ Lite (with CCM Lite) | A streamlined subset of the CCM and CAIQ, described by CSA as tailored to SMEs and start-ups and an initial step towards the full self-assessment | Small providers without a compliance team; 62 registry entries on 19 September 2026 | Free |
| Valid-AI-ted | An optional enhancement in which CSA’s AI evaluates the CAIQ submission against a standardised scoring model derived from the CCM, gives near-instant feedback and revision guidance for pass and fail, and awards a Valid-AI-ted badge on the registry on passing | Providers who want a scored, badged Level 1 without a third-party audit | $595 for up to ten scoring attempts; free to CSA corporate members |
Valid-AI-ted changes the character of Level 1 from a declaration to a scored submission. The ten attempts are the design: submit, read the feedback, fix the answers, resubmit. A badge on the registry separates a scored self-assessment from an unscored one, and CSA’s registry filter lets buyers view only Valid-AI-ted listings. Our guide to Valid-AI-ted covers the scoring loop.
How buyers read a self-assessment
A Level 1 entry is not audited, and a buyer’s security team knows it; what they get is a public, attributable, comparable statement of the provider’s controls in the vocabulary of the CCM, which is more than most vendor trust pages offer. Three things carry weight. The justifications — a “yes” with no explanation reads as untested; a “yes” that names the control, the system and the evidence reads as a company that has done the work.
The not-applicable answers — a provider that marks half the datacentre domain N/A because it runs on a hyperscaler should say so and name the inherited provider. And the shared responsibility split — the CCM asks which actor implements each control, and the answer is what the buyer’s own compliance team needs to fill in its side. The entry’s public permanence is why honesty is the cheap option: a generous self-assessment is a discoverable liability the moment a customer’s auditor compares it with reality.
The annual refresh
CSA states that STAR self-assessments “are updated annually”. A lapsed entry is visible as lapsed, and reads worse than no entry, because it tells a buyer the provider stopped maintaining what it published. The refresh is also the natural point to move to the current CCM version — v4.1 since January 2026, with CSA’s transition timeline governing how long a v4.0 submission can be refreshed on the old basis.
Level 1 as the first step
CSA’s Level 2 — STAR Certification on ISO 27001 or STAR Attestation on SOC 2, both with the CCM as additional criteria — builds on the same mapping. A provider that completes a rigorous Level 1 has done the control-to-CCM mapping that Level 2 audits, and the CAIQ doubles as the gap analysis. Our guide to STAR Level 2 covers the two routes; the sensible sequence for most providers is Level 1 now, Level 2 when buyers ask for independent testing.
Six mistakes that make a STAR Level 1 entry a liability
- Answering the reference workbook. Weeks lost at upload.
- Yes without justification. The answer column is the least informative part of the entry; the justification is what buyers read.
- Overclaiming. A “yes” on a control that does not exist is public, permanent and comparable with the next audit.
- Silent inheritance. Controls the hosting provider operates should be marked as inherited, with the provider named, not claimed as the submitter’s own.
- Scope that does not match the product. An entry for a service customers cannot buy, or one that omits the region they use.
- No refresh. A 2024 entry on CCM v4.0 in late 2026 reads as abandonment.
Submitting well
- Map controls to CCM v4.1 first, reusing the ISO 27001 or SOC 2 mapping if one exists.
- Write justifications as evidence pointers: control, system, owner, artefact.
- Complete the shared responsibility column for every objective.
- Run it through Valid-AI-ted if you want a score and a badge; use the attempts.
- Diary the annual refresh and the CCM version transition.
Frequently asked questions
What is STAR Level 1?
The self-assessment tier of the CSA STAR programme: a provider completes the CAIQ against the Cloud Controls Matrix and publishes it on the STAR Registry, free, updated annually. About 2,479 of roughly 2,765 registry listings on 19 September 2026 were CAIQ self-assessments.
Is it free?
Yes. The self-assessment and CAIQ Lite are complimentary. Valid-AI-ted, the optional AI-scored variation, costs $595 for up to ten scoring attempts and is free to CSA corporate members.
Which CAIQ file do I submit?
The ‘STAR Level 1: Security Questionnaire (CAIQ v4)’ version. The CCM + CAIQ bundle is reference only and cannot be submitted.
What is CAIQ Lite?
A streamlined version of the CCM and CAIQ for SMEs and start-ups, offered by CSA as an initial step towards the full Level 1 self-assessment; 62 registry entries used it on 19 September 2026.
Does Level 1 count as certification?
No. It is a published self-assessment. Independent testing comes at Level 2 — STAR Certification on ISO 27001 or STAR Attestation on SOC 2 — which builds on the same CCM mapping.
Where this leaves you
Do STAR Level 1 now and do it honestly: the submission version of CAIQ v4.1, justifications written as evidence pointers, inheritance named, the shared responsibility column complete, a Valid-AI-ted score if you want a badge, and a refresh every year. It costs nothing, it answers the questionnaire before it arrives, and it is the mapping Level 2 will audit.
References
- Cloud Security Alliance: STAR programme — Level 1 description, the two CAIQ versions, CAIQ Lite, Valid-AI-ted pricing and the annual refresh.
- Cloud Security Alliance: STAR Registry — Listings by programme and scheme; counts read on 19 September 2026.
- Cloud Security Alliance: Cloud Controls Matrix — CCM v4.1 and the CAIQ.
More on CSA STAR
- STAR Level 1 — you are here
- CSA STAR: the levels, Valid-AI-ted and STAR for AI
- STAR Level 2: certification vs attestation
- Cloud Controls Matrix v4.1 and the CAIQ
- Valid-AI-ted: the AI-scored self-assessment
- CSA STAR certification cost
The CAIQ v4.1 Self-Assessment Workbook, the Registry Submission Pack, the SSRM Matrix Workbook, the Evidence Repository Index and the seventeen CCM domain documents are in the CSA STAR Cloud Security Toolkit, or start with the free templates.