Skip to content
10/14FrameworkOn roadmap

CSA Cloud Controls Matrix (CCM)

A cloud-specific control matrix for assessing cloud security.

What it is

From the Cloud Security Alliance, the CCM is a cybersecurity control framework tailored to cloud computing, organized into domains and mapped to other standards. It underlies the CSA STAR program for cloud-provider assurance.

Certifiable?

Self-assessment (STAR Level 1) up to third-party (STAR Level 2).

Where it's used

Evaluating cloud providers and cloud implementations.

Effort level

Medium; overlaps heavily with existing cloud controls.

Typical trigger

You are a cloud provider proving assurance, or a customer assessing one.

Related frameworks

Maps to ISO 27001, SOC 2, NIST — a cloud-lens overlay.

Why it matters

CSA CCM provides a cloud-specific lens over security controls. For cloud providers, it's the basis of STAR certification that customers use to evaluate you. For cloud consumers, it helps assess whether a provider's controls meet your needs.

When is it needed?

When you're a cloud provider demonstrating security to customers, when evaluating cloud vendors, or when your existing controls need a cloud-specific mapping layer.

Use cases

  • Cloud service providers seeking STAR certification
  • Enterprises evaluating cloud vendor security
  • Multi-cloud environments needing consistent controls
  • SaaS companies supplementing SOC 2 with cloud detail
  • Organizations building cloud security governance

Who asks for it?

  • Cloud Security Alliance (CSA) STAR program
  • Enterprise cloud security teams evaluating providers
  • Procurement teams comparing cloud vendors
  • Industry groups requiring cloud assurance
  • Internal audit teams reviewing cloud adoption

Benefits

  • Purpose-built for cloud — no adapting generic controls
  • STAR registry provides public transparency
  • Maps to ISO 27001, SOC 2, NIST — bridges frameworks
  • Covers IaaS, PaaS, and SaaS models
  • Free self-assessment option (STAR Level 1)
  • Continuous monitoring option (STAR Continuous)

Legal requirements

Not legally required, but increasingly expected by enterprise customers when evaluating cloud providers. STAR Level 2 certification is a differentiator in competitive cloud markets.

Key control areas

Application and Interface Security
Audit Assurance and Compliance
Data Security and Privacy
Encryption and Key Management
Identity and Access Management
Infrastructure and Virtualization Security
Supply Chain Management and Transparency

Want to see how Compscan maps your environment to CSA Cloud Controls Matrix (CCM)?