CSA Cloud Controls Matrix (CCM) v4

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The CSA Cloud Controls Matrix (CCM) v4 is a cybersecurity control framework built specifically for cloud computing. Its current release, CCM v4.1, defines control objectives across 17 security domains and pairs each control with implementation guidance, auditing guidance, a shared-responsibility view for IaaS, PaaS, and SaaS, and a companion questionnaire, the Consensus Assessments Initiative Questionnaire (CAIQ).
The Cloud Security Alliance (CSA), a nonprofit industry association, publishes and maintains the CCM through its CCM Working Group. The framework is voluntary: cloud service providers use it to document their security posture, and cloud customers, auditors, and procurement teams use it to evaluate providers. It is also the control basis for the CSA STAR assurance program, where CAIQ submissions and third-party certifications are published in the STAR Registry.
Organizations implement the CCM by mapping their existing policies and controls to the 17 domains, identifying gaps, assigning ownership, and collecting evidence for each control. Because CSA publishes mappings from the CCM to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, and the AICPA Trust Services Criteria, teams typically maintain the CCM as a cloud-specific layer on top of a broader compliance program rather than as a standalone effort.
Why it Matters
Cloud environments split security responsibility between provider and customer, and general-purpose control catalogs rarely make that split explicit. The CCM gives both parties a common, cloud-native vocabulary for what must be controlled, who owns it, and how it can be assessed, which shortens vendor due diligence and reduces duplicate audit work.
Key benefits include:
- Cloud-specific control coverage
Addresses cloud concerns such as virtualization, container security, key management, interoperability, and supply chain that generic catalogs treat only indirectly.
- Clear shared responsibility
Each control indicates whether the cloud provider, the customer, or both are responsible, so ownership is settled before an assessment begins.
- Reduced compliance fatigue
CSA publishes mappings to ISO/IEC 27001, NIST SP 800-53, PCI DSS, CIS Controls, AICPA TSC, and the NIST Cybersecurity Framework, letting one set of evidence serve many obligations.
- Recognized assurance path
The CCM is the control basis for CSA STAR, so implementing it prepares a provider for a STAR Level 1 self-assessment or a STAR Level 2 certification or attestation.
- Free and machine-readable
The CCM and CAIQ are downloadable at no cost for internal use and are available in JSON, YAML, and OSCAL formats for compliance tooling.
How it Works
CCM v4 organizes controls into 17 domains, including Audit and Assurance, Application and Interface Security, Business Continuity Management and Operational Resilience, Change Control and Configuration Management, Cryptography, Encryption and Key Management, Data Security and Privacy Lifecycle Management, Governance, Risk and Compliance, Identity and Access Management, Infrastructure and Virtualization Security, Logging and Monitoring, Security Incident Management, Supply Chain Management, Threat and Vulnerability Management, and Universal Endpoint Management. Each control carries an identifier, a control specification, implementation guidelines, auditing guidelines, and applicability flags for IaaS, PaaS, and SaaS.
Organizations start by scoping which cloud services and service models are in play, then map current policies and technical controls to each CCM control. Gaps are recorded and assigned to owners, evidence is gathered against the auditing guidelines, and the CAIQ is completed to document the answers in the yes/no format that customers and the STAR Registry expect. Providers pursuing STAR Level 2 engage an accredited auditor to certify or attest against the CCM in combination with ISO/IEC 27001 or SOC 2.
Within SmartSuite, teams load the 17 CCM domains as a control library, link each control to the policies, systems, and owners that satisfy it, and attach evidence and test results in one place. Cross-framework mappings let a single piece of evidence satisfy the CCM and the ISO/IEC 27001, NIST SP 800-53, or PCI DSS control it maps to, and dashboards track CAIQ completeness and open gaps for STAR submissions.
Key Elements
- Seventeen security domains
Group the control objectives into cloud-relevant areas from governance and identity through logging, incident management, and supply chain.
- Control specifications with guidance
Each control is accompanied by implementation guidelines and auditing guidelines so it can be built and tested consistently.
- Shared Security Responsibility Model
Flags whether the provider, the customer, or both are accountable for each control across IaaS, PaaS, and SaaS.
- Consensus Assessments Initiative Questionnaire (CAIQ)
Restates every control as yes/no questions that providers answer to document their posture for customers and the STAR Registry.
- Published framework mappings
Relate CCM controls to ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-53, NIST CSF, PCI DSS, CIS Controls, AICPA TSC, and ISF SOGP.
- Continuous auditing metrics
The v4.1 bundle adds a metrics catalog and a code of practice for measuring control performance over time.
- Machine-readable bundle
JSON, YAML, and OSCAL editions allow the CCM to be loaded directly into GRC and compliance automation tools.
Framework Scope
The CCM applies to any organization that provides or consumes cloud services. Cloud service providers use it to document and assure their controls, cloud customers use it to assess providers and define their own responsibilities, and auditors use it as the assessment basis for CSA STAR. It covers IaaS, PaaS, and SaaS delivery models and is sector-neutral, so it is used across technology, financial services, healthcare, and government supply chains.
Framework Objectives
The Cloud Controls Matrix exists to give the cloud supply chain a single, assessable definition of good security practice.
Provide a comprehensive catalog of cloud security control objectives organized by domain.
Make shared responsibility explicit for every control across cloud service models.
Enable consistent self-assessment and third-party assessment through the CAIQ and CSA STAR.
Reduce duplicate compliance effort through maintained mappings to major standards and regulations.
Support continuous assurance with auditing guidelines, metrics, and machine-readable formats.
Keep pace with cloud technology through periodic revisions maintained by the CSA community.
Framework in Context
The CCM sits alongside ISO/IEC 27001 and ISO/IEC 27017 as the cloud-specific control layer of an information security program, and it is the control basis for CSA STAR. CSA maintains mappings to NIST SP 800-53, the NIST Cybersecurity Framework, PCI DSS, CIS Controls, and the AICPA Trust Services Criteria used in SOC 2, so organizations commonly treat the CCM as the bridge between their cloud provider assessments and their wider compliance obligations, including FedRAMP and GovRAMP programs that reference it.
Common Framework Mappings
CSA publishes and maintains official mappings between the CCM and other standards so that organizations can reuse evidence and reduce assessment effort across frameworks.
Mapped frameworks include:
ISO 27001:2022
ISO 27002:2022
ISO 27017
ISO 27018
NIST 800-53 Rev. 5
NIST CSF 2.0
PCI DSS 4.0.1
SOC 2 (AICPA TSC 2017)
CIS Controls v8.1
ISF Standard of Good Practice for Information Security 2022
CSA STAR
- ClassificationCategoryCloud SecurityDomainCloud SecurityFramework FamilyCSA STAR
- Regulatory ContextTypeControl FrameworkLegal InstrumentFrameworkSectorTechnology SectorIndustryCloud & Technology Providers
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherCloud Security Alliance (CSA)
- VersioningVersion4.1Effective DateJanuary 27, 2026Issue DateJanuary 21, 2021
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The CCM v4.1 bundle, including the CAIQ, implementation guidelines, auditing guidelines, and mappings, is downloadable free of charge from the Cloud Security Alliance for internal use; commercial use requires a CSA license, and the text is not bundled with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports CSA CCM v4
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Teams manage all 17 CCM domains as a linked control library, answer the CAIQ from the same records, and reuse evidence across the ISO/IEC 27001, NIST SP 800-53, and PCI DSS controls CSA maps to each CCM control.
CCM Control Library
Load the 17 CCM domains and their controls with implementation and auditing guidance attached to each record.
Ownership, Cadence, and Accountability
Assign a control owner and review schedule for every control and flag shared-responsibility items that depend on the cloud provider.
Evidence Collection and Audit Trail
Store evidence against each control with timestamps and reviewers so CAIQ answers and STAR submissions are backed by records.
Control Testing and Metrics
Plan tests against the CCM auditing guidelines and track continuous auditing metrics over time.
Cross-Framework Mapping
Link each CCM control to its ISO/IEC 27001, NIST SP 800-53, PCI DSS, and SOC 2 equivalents so one piece of evidence satisfies several frameworks.
STAR-Ready Reporting
Report CAIQ completeness, open gaps, and remediation status for customers, auditors, and leadership.
Related frameworks

CSA STAR is a cloud security assurance program helping organizations assess and demonstrate cloud security and compliance.

CSA IoT SCF provides guidance for identifying and implementing security controls across IoT devices, networks, and data throughout their lifecycle.

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.

C5:2020 is a BSI catalogue of cloud security controls to assess and demonstrate security and compliance of cloud services.

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.
Frequently Asked Questions For CSA CCM v4
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

