Cloud Security
DETAIL

CSA Cloud Controls Matrix (CCM) v4

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The CSA Cloud Controls Matrix (CCM) v4 is a cybersecurity control framework built specifically for cloud computing. Its current release, CCM v4.1, defines control objectives across 17 security domains and pairs each control with implementation guidance, auditing guidance, a shared-responsibility view for IaaS, PaaS, and SaaS, and a companion questionnaire, the Consensus Assessments Initiative Questionnaire (CAIQ).

The Cloud Security Alliance (CSA), a nonprofit industry association, publishes and maintains the CCM through its CCM Working Group. The framework is voluntary: cloud service providers use it to document their security posture, and cloud customers, auditors, and procurement teams use it to evaluate providers. It is also the control basis for the CSA STAR assurance program, where CAIQ submissions and third-party certifications are published in the STAR Registry.

Organizations implement the CCM by mapping their existing policies and controls to the 17 domains, identifying gaps, assigning ownership, and collecting evidence for each control. Because CSA publishes mappings from the CCM to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, and the AICPA Trust Services Criteria, teams typically maintain the CCM as a cloud-specific layer on top of a broader compliance program rather than as a standalone effort.

Why it Matters

Cloud environments split security responsibility between provider and customer, and general-purpose control catalogs rarely make that split explicit. The CCM gives both parties a common, cloud-native vocabulary for what must be controlled, who owns it, and how it can be assessed, which shortens vendor due diligence and reduces duplicate audit work.

Key benefits include:

  • Cloud-specific control coverage

Addresses cloud concerns such as virtualization, container security, key management, interoperability, and supply chain that generic catalogs treat only indirectly.

  • Clear shared responsibility

Each control indicates whether the cloud provider, the customer, or both are responsible, so ownership is settled before an assessment begins.

  • Reduced compliance fatigue

CSA publishes mappings to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, AICPA TSC, and the NIST Cybersecurity Framework, letting one set of evidence serve many obligations.

  • Recognized assurance path

The CCM is the control basis for CSA STAR, so implementing it prepares a provider for a STAR Level 1 self-assessment or a STAR Level 2 certification or attestation.

  • Free and machine-readable

The CCM and CAIQ are downloadable at no cost for internal use and are available in JSON, YAML, and OSCAL formats for compliance tooling.

How it Works

CCM v4 organizes controls into 17 domains, including Audit and Assurance, Application and Interface Security, Business Continuity Management and Operational Resilience, Change Control and Configuration Management, Cryptography, Encryption and Key Management, Data Security and Privacy Lifecycle Management, Governance, Risk and Compliance, Identity and Access Management, Infrastructure and Virtualization Security, Logging and Monitoring, Security Incident Management, Supply Chain Management, Threat and Vulnerability Management, and Universal Endpoint Management. Each control carries an identifier, a control specification, implementation guidelines, auditing guidelines, and applicability flags for IaaS, PaaS, and SaaS.

Organizations start by scoping which cloud services and service models are in play, then map current policies and technical controls to each CCM control. Gaps are recorded and assigned to owners, evidence is gathered against the auditing guidelines, and the CAIQ is completed to document the answers in the yes/no format that customers and the STAR Registry expect. Providers pursuing STAR Level 2 engage an accredited auditor to certify or attest against the CCM in combination with ISO/IEC 27001 or SOC 2.

Within SmartSuite, teams load the 17 CCM domains as a control library, link each control to the policies, systems, and owners that satisfy it, and attach evidence and test results in one place. Cross-framework mappings let a single piece of evidence satisfy the CCM and the ISO/IEC 27001, NIST SP 800-53, or PCI DSS control it maps to, and dashboards track CAIQ completeness and open gaps for STAR submissions.

Key Elements

  • Seventeen security domains

Group the control objectives into cloud-relevant areas from governance and identity through logging, incident management, and supply chain.

  • Control specifications with guidance

Each control is accompanied by implementation guidelines and auditing guidelines so it can be built and tested consistently.

  • Shared Security Responsibility Model

Flags whether the provider, the customer, or both are accountable for each control across IaaS, PaaS, and SaaS.

  • Consensus Assessments Initiative Questionnaire (CAIQ)

Restates every control as yes/no questions that providers answer to document their posture for customers and the STAR Registry.

  • Published framework mappings

Relate CCM controls to ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-53, NIST CSF, PCI DSS, CIS Controls, AICPA TSC, and ISF SOGP.

  • Continuous auditing metrics

The v4.1 bundle adds a metrics catalog and a code of practice for measuring control performance over time.

  • Machine-readable bundle

JSON, YAML, and OSCAL editions allow the CCM to be loaded directly into GRC and compliance automation tools.

Framework Scope

The CCM applies to any organization that provides or consumes cloud services. Cloud service providers use it to document and assure their controls, cloud customers use it to assess providers and define their own responsibilities, and auditors use it as the assessment basis for CSA STAR. It covers IaaS, PaaS, and SaaS delivery models and is sector-neutral, so it is used across technology, financial services, healthcare, and government supply chains.

Framework Objectives

The Cloud Controls Matrix exists to give the cloud supply chain a single, assessable definition of good security practice.

Provide a comprehensive catalog of cloud security control objectives organized by domain.

Make shared responsibility explicit for every control across cloud service models.

Enable consistent self-assessment and third-party assessment through the CAIQ and CSA STAR.

Reduce duplicate compliance effort through maintained mappings to major standards and regulations.

Support continuous assurance with auditing guidelines, metrics, and machine-readable formats.

Keep pace with cloud technology through periodic revisions maintained by the CSA community.

Framework in Context

The CCM sits alongside ISO/IEC 27001 and ISO/IEC 27017 as the cloud-specific control layer of an information security program, and it is the control basis for CSA STAR. CSA maintains mappings to NIST SP 800-53, the NIST Cybersecurity Framework, PCI DSS, CIS Controls, and the AICPA Trust Services Criteria used in SOC 2, so organizations commonly treat the CCM as the bridge between their cloud provider assessments and their wider compliance obligations, including FedRAMP and GovRAMP programs that reference it.

Common Framework Mappings

CSA publishes and maintains official mappings between the CCM and other standards so that organizations can reuse evidence and reduce assessment effort across frameworks.

Mapped frameworks include:

ISO 27001:2022

ISO 27002:2022

ISO 27017

ISO 27018

NIST 800-53 Rev. 5

NIST CSF 2.0

PCI DSS 4.0.1

SOC 2 (AICPA TSC 2017)

CIS Controls v8.1

ISF Standard of Good Practice for Information Security 2022

CSA STAR

At a Glance
CSA Cloud Controls Matrix (CCM) v4
  • Classification
    Category
    Cloud Security
    Domain
    Cloud Security
    Framework Family
    CSA STAR
  • Regulatory Context
    Type
    Control Framework
    Legal Instrument
    Framework
    Sector
    Technology Sector
    Industry
    Cloud & Technology Providers
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    Cloud Security Alliance (CSA)
  • Versioning
    Version
    4.1
    Effective Date
    January 27, 2026
    Issue Date
    January 21, 2021
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

The CCM v4.1 bundle, including the CAIQ, implementation guidelines, auditing guidelines, and mappings, is downloadable free of charge from the Cloud Security Alliance for internal use; commercial use requires a CSA license, and the text is not bundled with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
CSA Cloud Controls Matrix (CCM)
Defines a controls framework aligned with CSA STAR requirements and standards.
CSA STAR Program Overview
Describes the structure and benefits of participating in the CSA STAR assurance program.
SMARTSUITE

How SmartSuite Supports CSA CCM v4

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Teams manage all 17 CCM domains as a linked control library, answer the CAIQ from the same records, and reuse evidence across the ISO/IEC 27001, NIST SP 800-53, and PCI DSS controls CSA maps to each CCM control.

CCM Control Library

Load the 17 CCM domains and their controls with implementation and auditing guidance attached to each record.

Ownership, Cadence, and Accountability

Assign a control owner and review schedule for every control and flag shared-responsibility items that depend on the cloud provider.

Evidence Collection and Audit Trail

Store evidence against each control with timestamps and reviewers so CAIQ answers and STAR submissions are backed by records.

Control Testing and Metrics

Plan tests against the CCM auditing guidelines and track continuous auditing metrics over time.

Cross-Framework Mapping

Link each CCM control to its ISO/IEC 27001, NIST SP 800-53, PCI DSS, and SOC 2 equivalents so one piece of evidence satisfies several frameworks.

STAR-Ready Reporting

Report CAIQ completeness, open gaps, and remediation status for customers, auditors, and leadership.

Related frameworks

CSA STAR

CSA STAR is a cloud security assurance program helping organizations assess and demonstrate cloud security and compliance.

CSA IoT SCF v2

CSA IoT SCF provides guidance for identifying and implementing security controls across IoT devices, networks, and data throughout their lifecycle.

ISO 27017

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

ISO 27018

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

BSI C5:2020

C5:2020 is a BSI catalogue of cloud security controls to assess and demonstrate security and compliance of cloud services.

SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

FedRAMP Rev. 5

FedRAMP standardizes security requirements to assess, authorize, and continuously monitor cloud services that handle U.S. federal data.

ONBOARDING FAQS

Frequently Asked Questions For CSA CCM v4

No items found.

Operationalize CSA CCM v4 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.