CSA STAR
The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.
STAR Level 1 and Level 2 · Cloud Security Alliance
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
CSA STAR is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Use the applicable CSA submission, certification, attestation, and CCM licensing terms. Product embedding of CCM or CAIQ requires separate confirmation from registry participation.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Level 1 self-assessment · Level 2 certification · Level 2 attestation · STAR Registry · STAR for AI
- Applies to
- cloud services · SaaS · AI · technology · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| STAR Level 1 and Level 2 | Current edition | date not published |
06Related frameworks
Also applies to AI · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.
- CSA CCM and CAIQv4.1
Also applies to cloud services · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
- ISO/IEC 270172026
Also applies to cloud services · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.
- AIUC-1Q3 2026 (2026-07-15 release)
Also applies to AI · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.