Cloud Controls Matrix

The Cloud Controls Matrix,
explained plainly

The Cloud Controls Matrix (CCM) is the Cloud Security Alliance’s control framework for cloud computing. Here is what it actually is, from the 17 domains and their controls to the CAIQ questionnaire and the CSA STAR program you use to demonstrate it, plus how a cloud provider runs the whole thing in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The framework

What the Cloud Controls Matrix actually is.

The CCM is a cloud-security control framework published by the Cloud Security Alliance (CSA), not a law and not a certificate of its own. The current version, CCM v4, is a matrix of control objectives organized into 17 domains, shipped alongside the CAIQ questionnaire.

The control matrix

Around 197 control objectives covering the controls a cloud provider and its customers each need — the substance you implement and evidence.

17 domains

From identity and access management to data security, application security, logging and monitoring, and governance, risk and compliance.

The CAIQ

The Consensus Assessment Initiative Questionnaire — yes/no questions mapped to the CCM that cloud customers use to evaluate a provider.

The CSA STAR program

How you demonstrate the CCM: a Level 1 self-assessment published to the STAR Registry, or a Level 2 third-party assessment.

The full picture

Cloud Controls Matrix, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What is the Cloud Controls Matrix?

The Cloud Controls Matrix (CCM) is a cybersecurity control framework built specifically for cloud computing, published and maintained by the Cloud Security Alliance (CSA). It is not a law you have to comply with, and it is not a certification you hold on its own — it is a structured set of security controls, written for the realities of cloud service delivery, that a provider implements and that a customer can assess against.

That framing matters. The CCM does not ask "is your product secure?" in the abstract. It lays out specific control objectives across the areas that matter for cloud (access, data, applications, infrastructure, supply chain, incident response and governance) and asks you to show, control by control, how you meet them and who owns each one. Because cloud responsibility is shared between provider and customer, the matrix is explicit about that split rather than leaving it implied.

The current version is CCM v4. If you read older material referring to a different domain count or control numbering, it is likely describing an earlier release — the framework is revised periodically as cloud practice moves, and v4 is the version to map against today.

A framework, not a certificate

It is worth being precise, because the language gets muddled. The CCM is the control set. There is no standalone "CCM certificate" you can earn or display. When people say a provider has "done the CCM", they almost always mean the provider has completed an assessment against the CCM (a self-assessment or a third-party one) through the CSA STAR program, which is covered further down. The matrix is what you measure against; STAR is how you demonstrate the result.

02

The 17 domains and the control set

The CCM organizes its controls into 17 domains, each covering a distinct area of cloud security. Across those domains sit roughly 197 control objectives — the individual things you are expected to be doing. The domains include identity and access management, data security and privacy lifecycle management, application and interface security, governance, risk and compliance, logging and monitoring, threat and vulnerability management, business continuity and operational resilience, and supply-chain and third-party management, among others.

Reading the matrix domain by domain is the fastest way to understand where your cloud security stands. Each control objective is concrete enough to answer plainly (you either do the thing, or you have a gap to close) which is exactly why customers find the CCM more useful than a generic policy statement. It turns "are you secure?" into a list of specific, checkable questions.

You are not expected to treat all 197 controls as equally relevant in every situation. The matrix is built to be applied to your service, with the shared-responsibility split making clear which controls fall to the provider and which to the customer. Working through the domains, deciding what applies, and recording your position on each is the core of using the CCM well.

03

The CAIQ: answering a customer’s security review

The CCM ships alongside the CAIQ — the Consensus Assessment Initiative Questionnaire. The CAIQ is a set of yes/no questions, each mapped to a CCM control, designed for a cloud customer to evaluate a provider’s security posture without having to invent their own questionnaire from scratch. A provider completes the CAIQ once and can hand it to any customer who asks how they handle a given control.

This is, in practice, where the CCM earns its keep day to day. Every cloud and SaaS vendor knows the pain of bespoke security questionnaires arriving from each prospect, all asking the same things in different words. A completed CAIQ is the recognized answer to most of them: instead of re-answering a hundred custom forms, you point to your CAIQ, which already maps your controls to a format procurement teams recognize.

Keeping the CAIQ honest and current is the work. The questionnaire is only as good as the controls behind it, so the answers have to track what you actually do — not what you intended to do at the start of last year. A CAIQ that drifts out of date is worse than none, because it gets caught the moment a customer probes a control in depth.

04

The CSA STAR program: how you demonstrate the CCM

The CCM is the control set; the CSA STAR program (Security, Trust, Assurance and Risk) is how you demonstrate it to the outside world. STAR runs on two levels of assurance, and choosing between them is one of the first real decisions a provider makes.

STAR Level 1 is a self-assessment. You complete a CAIQ (or a CCM-based assessment) describing how you meet each control and publish it to the public STAR Registry, where customers can find and read it. It is unverified by a third party — its value is transparency and speed: you are putting your security position on record, in a standard format, for anyone evaluating you to see.

STAR Level 2 is a third-party assessment, and it comes in two forms that build on standards you may already hold. STAR Certification is built on top of an ISO/IEC 27001 certification: an accredited assessor evaluates your cloud controls against the CCM in conjunction with your ISMS. STAR Attestation is built on a SOC 2 examination — it pairs the CCM with a SOC 2 report. Either way, Level 2 means an independent party has checked your cloud controls, which carries more weight with customers than a self-assessment alone.

The STAR Registry

Both levels can be published to the CSA STAR Registry, a public listing of cloud providers and their assessments. For many customers, checking the registry is the first step in evaluating a provider — a Level 1 entry signals you are willing to be transparent, and a Level 2 entry signals an independent assessor has been through your controls. Being listed is part of the point: it is where prospects look before they send you a questionnaire.

05

Who needs the CCM, and why

The CCM is aimed squarely at cloud service providers (including SaaS vendors) who face security reviews from their customers. If you sell software that runs in the cloud to organizations that care how you handle their data, you will eventually be asked to evidence your cloud security, and the CCM is the most widely recognized, cloud-native way to do it.

It is rarely pursued for its own sake. Most teams adopt it because a customer’s procurement or security team asked for a CAIQ, or because a prospect checked the STAR Registry and did not find them. The CCM has become a common language for cloud security between buyers and sellers, which is precisely why a completed assessment unblocks deals that a vague security page does not.

The practical test is the same as for any security framework: are you losing or slowing deals because you cannot demonstrate, control by control, how you secure the cloud service you sell? If customer security reviews are a recurring tax on your sales cycle, a current CAIQ and a STAR listing are usually the most efficient answer — and most of the work is simply running cloud security well, written down in a format buyers already trust.

06

How the CCM maps to ISO 27001, SOC 2 and beyond

One of the CCM’s genuine strengths is that it ships with mappings to many other standards and frameworks — ISO/IEC 27001, SOC 2, NIST, PCI DSS and others. Each CCM control points to the corresponding requirements elsewhere, so the work you do for one framework is visible against the others rather than starting from zero each time.

This is why the CCM fits naturally alongside frameworks a cloud provider often already holds. If you are certified to ISO/IEC 27001, much of your ISMS evidence maps directly onto CCM controls — and STAR Certification is literally built on top of an ISO 27001 certification. If you have a SOC 2 report, STAR Attestation builds on that examination. The CCM does not replace these; it extends them into cloud-specific territory and gives customers a cloud-shaped lens on the same underlying controls.

The CCM also overlaps with ISO/IEC 27017, the code of practice for information security controls for cloud services. A team working toward cloud-specific assurance often touches all of these at once, and the value compounds when the same control evidence answers several of them rather than living in a separate binder per framework.

07

Demonstrating the CCM without a standalone certificate

Because there is no "CCM certificate", teams sometimes ask how, concretely, they prove they meet the framework. The answer runs through the artifacts the CCM and STAR define: a completed CAIQ that records your position on each control, a published entry in the STAR Registry, and, if you go to Level 2, a third-party assessment riding on your ISO 27001 certification or SOC 2 report.

For many providers, the right first step is STAR Level 1: complete the CAIQ honestly, publish it, and use it to answer customer reviews. It is fast, it is transparent, and it puts a recognized document in front of buyers immediately. Level 2 is the move when customers want independent verification (typically larger or more regulated buyers) and it is most efficient when you already hold the ISO 27001 or SOC 2 foundation it builds on.

In all cases, what you are really demonstrating is a running set of controls, not a one-time document. The CAIQ and the assessment are snapshots of a system; their credibility depends on the controls behind them being real and current. Treating the CCM as a living record rather than a form you fill in once is what keeps it convincing when a customer looks closely.

08

Keeping the CAIQ and controls current

The hardest part of the CCM is not completing it the first time — it is keeping it true afterwards. Your cloud service changes constantly: new subprocessors, new regions, a re-architected access model, a different logging stack. Every one of those can move your answer to a CCM control, and a CAIQ that no longer matches reality is a liability the moment a customer audits a claim.

This is where most teams quietly lose ground. The CAIQ gets assembled from spreadsheets and shared drives for one big customer review, then drifts as the product moves, so the next review means reconstructing it from scratch. The cost is paid again and again, in the time it takes to rebuild evidence that was never kept in one place and linked to the controls it supports.

Maintaining the CCM continuously, by keeping each control’s status, owner and evidence current as the service evolves, is what turns the framework from a recurring fire drill into a standing asset. A current CAIQ answers the next customer review in a click, and a maintained control set carries straight into a STAR Level 2 assessment when you decide to take that step.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your CCM program, in one workspace.

Everything the framework asks you to maintain, from controls and the CAIQ to evidence and reviews, connected and review-ready between customer audits. Pick one to see it.

Every CCM domain, in one view

See all 17 domains and their controls, what applies to your service, and where you stand — each mapped to the policies, risks and assets that satisfy it, so your CAIQ stays live instead of being rebuilt before each customer review.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

The CCM ships with mappings to ISO 27001, SOC 2 and ISO/IEC 27017, and STAR Level 2 is built on top of an ISO 27001 certification or a SOC 2 report. Map a control once in devguard and the same policy and evidence satisfy it everywhere it appears — so the next framework is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already running the CCM? Move your work across.

If you already maintain a CAIQ or a STAR assessment, you do not want to rebuild it from a blank page. In a scoped conversation we agree exactly what moves (your controls, policies, CAIQ answers, risk register and assessment history) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
Cloud Controls Matrix FAQ

Cloud Controls Matrix, answered plainly.

What is the Cloud Controls Matrix (CCM)?

The CCM is a cloud-security control framework published by the Cloud Security Alliance (CSA). It organizes around 197 control objectives into 17 domains covering cloud security, and ships with the CAIQ questionnaire. It is a control framework, not a law or a certificate of its own — you demonstrate it through the CSA STAR program.

Is there a CCM certification?

Not on its own. The CCM is the control set; you demonstrate it through the CSA STAR program. STAR Level 1 is a self-assessment you publish to the STAR Registry. STAR Level 2 is a third-party assessment — either STAR Certification, built on an ISO 27001 certification, or STAR Attestation, built on a SOC 2 examination.

What is the CAIQ?

The Consensus Assessment Initiative Questionnaire is a set of yes/no questions, each mapped to a CCM control, that cloud customers use to evaluate a provider’s security. A provider completes it once and uses it to answer the security reviews that arrive from prospects, instead of re-answering bespoke questionnaires every time.

What is the difference between STAR Level 1 and Level 2?

Level 1 is a self-assessment: you complete a CAIQ and publish it to the STAR Registry, unverified by a third party. Level 2 is an independent assessment (STAR Certification built on ISO 27001, or STAR Attestation built on SOC 2) where an accredited assessor checks your cloud controls. Level 2 carries more weight with customers than a self-assessment alone.

How does the CCM relate to ISO 27001 and SOC 2?

The CCM ships with mappings to both, and STAR Level 2 is built on top of them — STAR Certification on an ISO 27001 certification, STAR Attestation on a SOC 2 report. If you already hold either, much of that evidence maps onto CCM controls, so the CCM extends what you have into cloud-specific territory rather than replacing it.

Can I reuse CCM evidence for other frameworks?

Largely, yes. The CCM maps onto ISO 27001, SOC 2 and ISO/IEC 27017, so most of the evidence you maintain for one carries over. The work is mapping it once and keeping a single source current rather than running a separate binder per framework — which is most of what staying credible across customer reviews involves.

See how your CCM program would look in devguard.

The fastest way to know if this fits is a short conversation about how you run the CCM today — what you maintain, where the customer-review effort goes, and what moving it would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free