CSA STAR (Security, Trust, Assurance, and Risk)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CSA STAR: Assurance Quality and Lifecycle
The provider performs internal audit or self-assessment of the CCM controls in the STAR scope between external assessments, to maintain readiness and detect drift.
- Internal audit/self-assessment results covering the STAR scope
- Remediation tracking from internal findings
- No internal assurance between external assessments
Nonconformities identified during assessment or surveillance are recorded, root-caused, and remediated through corrective action within the timeframes required by the scheme.
- Nonconformity register and corrective-action records
- Evidence of timely closure of findings
- Open nonconformities past their deadline
- No corrective-action process
Where the provider no longer meets the requirements, or on request, its STAR status is suspended or withdrawn and the registry updated, so published assurance is not misleading.
- Process for suspension/withdrawal of STAR status
- Registry reflecting any withdrawal
- Continuing to claim STAR status after it lapses or is withdrawn
The provider's risk treatment decisions for the assessed service are aligned with the CCM control objectives, with residual risks documented and accepted at an appropriate level.
- Risk register linking treatments to CCM control objectives
- Documented residual-risk acceptance
- Risk treatment disconnected from the CCM controls assessed
CSA STAR: Level 1 Self-Assessment (CAIQ)
Each CAIQ response must accurately and completely reflect the provider's implementation of the corresponding CCM control, with no misleading or unsupported answers.
- Internal review confirming CAIQ answers are evidenced
- Mapping of CAIQ answers to supporting controls/evidence
- Yes answers unsupported by implemented controls
- Responses copied without verification
The assessment covers the full set of applicable CCM control domains, with any not-applicable controls justified, so the assurance reflects the complete CCM control set rather than a subset.
- Coverage matrix of CCM domains assessed
- Justification for any controls marked not applicable
- CCM domains silently omitted
- Unjustified not-applicable determinations
At Level 1 the provider completes the Consensus Assessments Initiative Questionnaire (CAIQ) self-assessment against the CCM and submits it to the publicly accessible STAR Registry.
- Completed CAIQ self-assessment against the current CCM version
- Evidence of submission to the STAR Registry
- Incomplete CAIQ responses
- Self-assessment not published to the registry
The provider refreshes and resubmits its Level 1 self-assessment on a regular basis so that the published assurance reflects the current state of the service.
- Dated self-assessment showing periodic refresh
- Change log of material updates between submissions
- Stale self-assessment no longer reflecting the service
- No refresh cadence defined
CSA STAR: Level 2 Third-Party Assurance
STAR Certification is a third-party independent assessment that integrates the requirements of ISO/IEC 27001 with the CCM, including a maturity assessment, performed by an accredited certification body.
- Valid STAR Certification certificate and report
- Underlying ISO/IEC 27001 certification covering the service
- Maturity assessment results
- Claiming certification without an accredited body
- ISO 27001 scope not covering the assessed service
STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.
- SOC 2 + CCM STAR Attestation report from a licensed CPA firm
- Mapping of CCM criteria into the SOC 2 examination
- SOC 2 report without the CCM mapping
- Attestation by an unqualified provider
C-STAR is a third-party independent assessment of a cloud service provider for the Greater China market, harmonising the CCM with applicable Chinese national standards.
- C-STAR assessment evidence where the provider serves the Greater China market
- Using C-STAR claims outside its assessed scope
Level 2 assessments must be performed by assessors that are appropriately accredited or qualified (certification body, licensed CPA firm, or CSA-qualified auditor) for the relevant STAR scheme.
- Evidence of the assessor's accreditation/qualification for the STAR scheme used
- Assessor lacking the required accreditation
STAR Certification includes a maturity capability assessment that scores the management of CCM control areas beyond a pass/fail basis, giving customers insight into control maturity.
- Maturity scoring results per CCM control area
- Methodology used for the maturity assessment
- No maturity assessment where the scheme requires it
STAR Certification and Attestation are maintained through periodic surveillance and recertification activities, consistent with the underlying ISO 27001 or SOC 2 cycle.
- Surveillance audit and recertification records
- Currency of the certificate/report
- Lapsed certificate presented as current
- No surveillance activity between certifications
CSA STAR: Level 3 Continuous
STAR Continuous provides ongoing, automated validation of security controls between point-in-time assessments, enabling near-real-time assurance of the cloud service.
- Continuous control-monitoring tooling and outputs
- Evidence of automated validation against CCM controls
- Only point-in-time assurance where continuous is claimed
Continuous assurance evidence (such as STARWatch / STAR Continuous outputs) is maintained and made available to support the published continuous assurance status.
- Continuous-assurance evidence records and publication
- Linkage of continuous evidence to CCM controls
- Continuous status without supporting evidence
CSA STAR: Program, Scope and Shared Responsibility
The cloud service provider determines its eligibility for the STAR program and selects the appropriate assurance level (Level 1 self-assessment, Level 2 third-party certification or attestation, or Level 3 continuous), based on the assurance its customers require.
- Documented decision on the STAR assurance level pursued and rationale
- Evidence the offered cloud service is in scope of the STAR program
- No defined STAR assurance objective
- Claiming a STAR level not actually achieved
The provider defines the boundary of the cloud service(s) covered by the STAR self-assessment or certification, including the service models and components in scope, so that the assurance statement accurately reflects what was assessed.
- Documented scope statement of the assessed service and its boundaries
- Architecture/service description supporting the scope
- Ambiguous or overstated assessment scope
- Scope excluding components customers rely on
The provider documents and discloses the shared security responsibility model for the service, identifying which CCM controls are the responsibility of the provider, the customer, or shared, consistent with the CCM Shared Security Responsibility Model.
- Shared responsibility matrix mapping CCM controls to provider/customer/shared
- Customer-facing responsibility guidance
- No shared responsibility model published
- Responsibilities for key controls left undefined
The provider identifies subservice organisations and supply chain dependencies relevant to the assessed service, and reflects their treatment (inclusive or carve-out) in the assurance statement.
- List of subservice organisations and the inclusive/carve-out treatment
- Assurance over relevant subservice controls
- Undisclosed subservice dependencies
- Carve-out subservices with no complementary controls stated
CSA STAR: Registry and Customer Transparency
The provider communicates its STAR assurance status and the associated reports/certificates to customers and prospects in a clear and non-misleading way.
- Customer-facing assurance documentation (reports, certificates, CAIQ)
- Process for sharing assurance artefacts under NDA where needed
- Overstating the assurance level to customers
Where the program or customer commitments require, the provider notifies affected customers/registry users of security incidents affecting the assessed service in a timely manner.
- Customer incident-notification procedure
- Records of notifications made
- No customer notification path for incidents affecting assured services
The provider's assurance status (Level 1 self-assessment, Level 2 certification/attestation, or continuous) is published in the publicly accessible CSA STAR Registry so customers can verify it.
- STAR Registry entry for the assessed service
- Accuracy of the level and status shown
- Assurance not published to the registry
- Registry entry inconsistent with actual status
The provider keeps its STAR Registry entry current, updating it on reassessment, recertification, scope change, or withdrawal.
- Process for updating the registry entry on material change
- History of registry updates
- Outdated registry entry after scope or status change
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.