Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

STAR Registry explained

STAR Registry: The Clear Guide to CSA’s 2,765 Listings (2026)

The STAR Registry is the public database at the centre of the Cloud Security Alliance’s STAR programme — the place a cloud provider publishes its self-assessment, certification or attestation once so that every buyer can read it, and the place a buyer goes to compare providers control by control before the first sales call. On 19 September 2026 it held roughly 2,765 listings: about 2,479 CAIQ self-assessments and 62 CAIQ Lite entries at Level 1, 268 STAR Certifications, 46 STAR Attestations and 43 C-STAR certifications at Level 2, around 60 AI-CAIQ submissions under STAR for AI, and partner entries under the EU Cloud Code of Conduct, ISO/IEC 42001 and AIUC-1.

Each entry shows the listing date, the schemes held and, for self-assessments, the questionnaire itself. This guide sets out what the registry contains and how it is organised, the filters buyers use, what each scheme label means and how long it lasts, how to submit and keep an entry current, how to read a competitor’s or a supplier’s listing, and the five ways an entry works against the provider that published it.

STAR Registry: ~2,765 listings on 19 September 2026, by programme
Level 1: CAIQ ~2,479 · CAIQ Lite 62 · Valid-AI-ted badge · Continuous · Level 2: Certification 268 · Attestation 46 · C-STAR 43 · STAR for AI: AI-CAIQ ~60, ValidAIted + 42001 · partner entries: EU Cloud CoC, ISO/IEC 42001, AIUC-1.

How the STAR Registry is organised

Programme Scheme labels on the registry What the label means Duration
STAR Level 1 CAIQ; CAIQ Lite; Continuous; ValidAIted CAIQ A published self-assessment against the Cloud Controls Matrix; Lite is the SME subset; ValidAIted means CSA’s AI tool scored it and awarded the badge; Continuous is CSA’s continuous-assessment variation Updated annually
STAR Level 2 Certification; Attestation; C-STAR Certification: ISO 27001 plus the CCM, by a STAR-qualified body; Attestation: a SOC 2 engagement using CCM criteria, by a CPA firm; C-STAR: GB/T 22080-2008 plus the CCM for Greater China Certification and C-STAR expire after three years unless updated; Attestation after one year
STAR for AI Level 1 AI CAIQ; ValidAIted AI CAIQ A self-assessment against the AI Controls Matrix, optionally AI-scored Annually
STAR for AI Level 2 AI Attestation; AI Certification; ValidAIted + 42001 Third-party AI assurance, or since 20 November 2025 a Valid-AI-ted AI-CAIQ combined with ISO/IEC 42001 certification Per the underlying certificate
Partner entries AIUC-1; EU Cloud CoC; ISO/IEC 42001 Listings recognised from partner schemes Per the scheme

The registry also carries three “view only” filters — CSA Trusted Cloud Providers, STAR Enabled Solutions and AI Solutions — which are membership and programme designations rather than assurance levels. Our guide to CSA STAR covers the levels; this guide covers the database they land in.

What a STAR Registry entry shows

Every STAR Registry listing carries the provider’s name and description, the date it was first listed, and one label per scheme held — a provider can hold a CAIQ and a Certification, or a CAIQ and an Attestation, on the same entry. Clicking through gives the service in scope and, for Level 1, the completed questionnaire: every CCM objective, the yes/no/N/A answer, the justification and the shared-responsibility allocation. For Level 2 the entry shows the scheme and the assessor; the certificate or attestation report is obtained from the provider. The Level 1 questionnaire is therefore the most information-dense object on the registry, and the one a buyer’s security team actually reads.

Reading a listing as a buyer

  1. Check the date and the version. A listing from 2023 on CCM v4.0 that has not been refreshed since v4.1 arrived in January 2026 is a signal about maintenance.
  2. Read the justifications, not the answers. A column of “yes” with no explanation is a declaration; a justification that names the control and the evidence is a company that has done the work.
  3. Look at the N/A pattern. Datacentre controls marked N/A with the hosting provider named are normal; N/A across security domains the provider plainly operates is not.
  4. Use the shared-responsibility column to fill in your own side — it is the input your compliance team needs.
  5. Prefer scored or audited entries for higher-risk services: ValidAIted for a scored self-assessment, Certification or Attestation for independent testing.

Submitting and maintaining a STAR Registry entry

  • Level 1: complete the submission version of CAIQ v4.1 — the CCM + CAIQ bundle cannot be submitted — and upload through the registry’s submission route; refresh annually. Our guide to STAR Level 1 covers the process.
  • Valid-AI-ted: submit the CAIQ for AI scoring, $595 for up to ten attempts, free to corporate members; the badge appears on the entry on passing.
  • Level 2: the certification body or CPA firm completes the audit; the entry is listed with the scheme; certifications expire after three years and attestations after one unless updated. Our guide to STAR Level 2 covers the routes.
  • STAR for AI: submit the AI-CAIQ from the AICM package; add Valid-AI-ted and ISO/IEC 42001 for Level 2.
  • Keep the scope honest: the entry describes a service; if the product changes, the entry changes.

Five ways a STAR Registry entry works against you

  1. Lapsed. An entry past its annual refresh is visible as stale, and stale reads as abandoned.
  2. Overclaimed. The questionnaire is public and permanent; a customer’s auditor comparing it with a SOC 2 report will find the difference.
  3. Wrong scope. An entry for a service customers do not buy, or that omits the region they use.
  4. Reference workbook uploaded. Rejected at submission, weeks lost.
  5. Silent on shared responsibility. The column the CCM was built for, left blank.

Frequently asked questions

What is the STAR Registry?
The Cloud Security Alliance’s public database of cloud providers’ security and privacy assurance: Level 1 self-assessments (CAIQ, CAIQ Lite, Valid-AI-ted, Continuous), Level 2 certifications and attestations, STAR for AI entries and partner-scheme listings. It held roughly 2,765 listings on 19 September 2026.

How many providers are on it?
Around 2,765 listings on 19 September 2026, the large majority CAIQ self-assessments, with 268 STAR Certifications and 46 STAR Attestations.

How long does a listing last?
Self-assessments are updated annually; STAR Certification and C-STAR certificates expire after three years unless updated; STAR Attestation listings expire after one year.

Can I see a provider’s actual answers?
For Level 1, yes — the completed CAIQ with justifications is on the entry. For Level 2 the entry shows the scheme and assessor; the report or certificate comes from the provider.

Is there a fee to be listed?
Level 1 is free; Valid-AI-ted is $595 for up to ten attempts (free to corporate members); Level 2 carries CSA fees, reduced for corporate members, on top of the audit.

Where this leaves you

Use the STAR Registry in both directions: as a buyer, read the date, the version, the justifications and the shared-responsibility column before the first call; as a provider, publish an honest Level 1 entry on the submission version of CAIQ v4.1, score it if you want a badge, add Level 2 when buyers ask for independent testing, and refresh every year. Two thousand seven hundred listings are the questionnaire answered in public; the ones that get read are the ones that are current and true.

References

More on CSA STAR

The Registry Submission Pack, the CAIQ v4.1 Self-Assessment Workbook, the Cloud Service Scope Statement, the SSRM Matrix Workbook and the Customer Trust Page Content Pack are in the CSA STAR Cloud Security Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.