Gain a competitive advantage with CSA Star certification
CSA STAR (Cloud Security Alliance Security Trust Assurance and Risk Registry) assessments use an assurance framework that enables cloud service providers (CSP) to assess cloud-specific controls within their existing compliance program.
Get started
Demonstrate cloud service security
Demonstrates your organization’s capabilities and maturity relative to the security controls of its cloud service offering.
Differentiation in a saturated market
Validates that your organization takes measures to demonstrate your security capabilities.
Accelerates sales cycles
Enterprise buyers often require vendors to meet a stringent set of cloud security requirements before procurement. CSA STAR Level 2 accelerates these sales cycles by providing third-party validation and establishing trust upfront.
CSA STAR services
As a CSA STAR assessor, A-LIGN can help ensure your organization is included on the CSA STAR registry with an attestation or certification.
Contact usSOC 2 + CSA STAR Attestation
A-LIGN performs a SOC 2 assessment using Trust Service Criteria outlined by AICPA in combination with the CSA Cloud Controls Matrix. The CSA STAR Attestation will result in either a Type 1 or Type 2 SOC 2 + CSA STAR Attestation report which is valid for six months or one year, respectively, from the date of completion.
ISO 27001 + CSA STAR Certification
A-LIGN conduct a rigorous third-party independent assessment of CSPs who are undergoing ISO 27001 certification using a combination of the ISO/IEC 27001:2022 management standards and the CSA Cloud Controls Matrix. This approach will result in an ISO 27001 + CSA STAR Certification which is valid for three years from completion.
A-LIGN by the numbers
Why security leaders trust A-LIGN
Support for your compliance journey
From guides to whitepapers, we've got the resources to move your compliance program forward.
View resourcesFrequently asked questions
What is CSA STAR and why is it relevant for cloud providers?
CSA STAR (Security, Trust, Assurance, and Risk) is a program developed by the Cloud Security Alliance to help cloud service providers demonstrate their security posture to customers. It uses the CSA Cloud Controls Matrix as its underlying framework and is recognized internationally as a key benchmark for cloud security assurance.
What are the three levels of CSA STAR?
Level 1 is a self-assessment that CSPs can publish into the STAR Registry. Level 2 involves a third-party assessment that results in a STAR Certification or STAR Attestation. Level 3 is a continuous monitoring-based program. A-LIGN delivers Level 2 assessments via both the SOC 2 and ISO 27001 pathways.
How long does a CSA STAR assessment take?
The timeline for a CSA STAR Level 2 assessment depends on which base assessment it is paired with (SOC 2 or ISO 27001), the scope and complexity of your cloud service environment, and the maturity of your existing cloud security controls. Organizations combining CSA STAR with an existing SOC 2 or ISO 27001 engagement typically benefit from a significantly more efficient process.
Is CSA STAR mandatory for cloud service providers?
CSA STAR is voluntary, but it is increasingly expected by enterprise customers conducting vendor security assessments. Being listed in the CSA STAR Registry demonstrates transparency and provides stakeholders with a standardized view of your cloud security controls.



