STAR Level 2 is the point where CSA STAR stops being a self-assessment and becomes something a third party has tested. It comes in two forms, and which one you take is decided almost entirely by an audit you probably already hold: ISO 27001 leads to STAR Certification, SOC 2 leads to STAR Attestation.
This guide covers the two routes, the maturity scoring that only one of them carries, what the work actually involves, and how to choose.

The two routes through STAR Level 2
| STAR Certification | STAR Attestation | |
|---|---|---|
| Built on | ISO/IEC 27001 plus the Cloud Controls Matrix | A SOC 2 engagement plus the Cloud Controls Matrix |
| Prerequisite | You must hold, or be obtaining, ISO 27001 | None formally — it is a SOC 2 engagement extended |
| Who performs it | A certification body with STAR-qualified auditors | A CPA firm, under AICPA attestation standards |
| Output | A certificate, plus a maturity assessment | An attestation report with the auditor’s findings |
| Natural audience | Europe, Asia and anywhere ISO certification is the norm | North America, where SOC 2 is what procurement asks for |
Both STAR Level 2 routes land in the same public registry entry, and both signal the same thing to a buyer: an independent party tested your cloud controls against the CCM, rather than you filling in a questionnaire about them.
The maturity score only certification carries
STAR Certification adds an assessment against CSA’s own maturity model: the auditor scores each CCM control domain, on a scale running to 15, and the result identifies which domains are strong and which are held together by individuals. The score is not printed on the public certificate — it is management information, and it is the most useful output of the whole exercise if you intend to improve rather than just to pass.
The attestation route produces the familiar SOC 2 output instead: a report a customer’s risk team reads, including exceptions. Neither is better. They are different artifacts for different readers, which is why the choice usually follows your market rather than your preference.
What STAR Level 2 work involves
- Map your controls to the CCM. This is the bulk of the effort and it is reusable — the same mapping serves the CAIQ, customer questionnaires and your next audit. Our guide to the Cloud Controls Matrix covers the structure.
- Fix the cloud-specific gaps. ISO 27001 and SOC 2 both under-specify the things the CCM is built for: tenant isolation, virtualisation, key management responsibilities, interoperability and portability, and the shared responsibility split with your own providers.
- Settle the scope. Which service, which regions, which supporting infrastructure. A scope that does not match what customers buy will be noticed by the first one who reads carefully.
- Choose the auditor deliberately. The certification route needs a body whose auditors are STAR-qualified; the attestation route needs a CPA firm that has done cloud work. Ask for examples before signing.
- Publish the entry. The registry listing is the point — an audit nobody can look up does not answer the buyer’s question.
Level 1 first, in most cases
Level 1 is free, public and comparable, and completing the CAIQ honestly reveals most of the gaps a Level 2 audit would find. Going straight to Level 2 without it is possible and usually more expensive, because the discovery happens in front of an auditor. Our guide to CSA STAR and its levels covers the ladder, including the AI-scored route through Level 1.
Choosing between them
Follow the certificate you hold. For STAR Level 2, if ISO 27001 is in place, certification is the shorter path; if SOC 2 is your existing assurance, attestation is. Building the other underlying audit purely to reach STAR Level 2 rarely makes sense.
Follow your buyers. A European public-sector buyer reads certificates. A US enterprise procurement team reads SOC 2 reports. Where you sell decides which artifact gets used.
Consider what you want to learn. If the goal is internal improvement, the maturity scoring in the certification route gives you a scored picture per domain that no attestation produces.
Frequently asked questions
What is STAR Level 2?
The third-party audited tier of the CSA STAR programme, delivered either as STAR Certification alongside ISO 27001 or as STAR Attestation alongside a SOC 2 engagement, both assessed against the Cloud Controls Matrix.
Do we need ISO 27001 first?
For the certification route, yes — it is built on the ISO 27001 management system. The attestation route has no formal prerequisite, though in practice it runs with a SOC 2 engagement.
Is there a Level 3?
CSA has developed continuous-assurance concepts above Level 2, but Level 2 is what buyers currently ask for and what most providers hold.
How long does it take?
Mapping to the CCM and closing cloud-specific gaps is the long part — months rather than weeks. The audit itself runs alongside your existing ISO or SOC 2 cycle.
Does it replace ISO 27001 or SOC 2?
No. STAR Level 2 extends them to cloud-specific ground. It is an addition to the underlying audit, not a substitute for it.
Where this leaves you
Pick the STAR Level 2 route from what you already hold and where you sell, not from a comparison of the schemes in the abstract. Do Level 1 first so the gaps surface on your own time, put the effort into the CCM mapping because it is reusable everywhere, and scope the audit to the service customers actually buy. If you take the certification route, use the maturity scores — they are the only part of the exercise that tells you where to spend next.
References
- CSA STAR programme — the levels, the registry and the qualification requirements.
- Cloud Controls Matrix — the control framework both routes are assessed against.
More on cloud assurance
- STAR Level 2 — you are here
- CSA STAR and its levels
- The Cloud Controls Matrix and CAIQ
- SOC 2 type 1 vs type 2
CCM mappings, control documentation and the submission pack are in the CSA STAR Cloud Security Toolkit, or start with the free ISO templates.