Book an Appointment

CSA Cloud Controls Matrix & CAIQ

The Cloud Security Alliance's Cloud Controls Matrix structures cloud security into 17 domains with 207 controls — the CAIQ translates them into a standardized question catalog for provider assessment.

The Cloud Controls Matrix (CCM) is a cybersecurity control framework from the Cloud Security Alliance (CSA) that translates security and privacy requirements for cloud computing into structured, standardized controls. The current version 4.1, released on January 28, 2026, comprises 207 control objectives across 17 security domains — from Audit & Assurance and Identity & Access Management to Universal Endpoint Management. The CCM is regarded as the de facto standard for cloud security assurance and forms the backbone of the CSA STAR program for assessing and comparing cloud service providers. It is complemented by the Consensus Assessment Initiative Questionnaire (CAIQ), implementation and audit guidelines, and mappings to established standards. The framework addresses cloud providers (CSPs) and cloud customers (CSCs) alike — including a clear allocation of shared security responsibility.

The Essentials at a Glance

01

The CCM: 17 domains, 207 controls

CCM v4.1 organizes cloud security into 17 domains with a total of 207 control objectives — including Audit & Assurance, Application & Interface Security, Cryptography and Key Management, Identity & Access Management, Logging & Monitoring, and Supply Chain Management. The domain structure deliberately aligns with established frameworks such as ISO 27001:2022 so that existing knowledge can be put to use. For each control, the matrix additionally indicates its applicability to the IaaS, PaaS, and SaaS service models.

02

CAIQ: 283 questions for vendor assessment

The Consensus Assessment Initiative Questionnaire (CAIQ) translates the CCM controls into 283 yes/no questions that cloud customers and auditors can use to systematically examine the security posture of a cloud service provider. It serves as a standardized instrument for provider assessment — both before contracting and in ongoing supplier management. The v4.1 structure also includes dedicated columns for documenting responsibilities under the Shared Security Responsibility Model.

03

Shared Security Responsibility Model (SSRM)

The CCM assigns each control a responsibility under the Shared Security Responsibility Model: CSP-Owned, CSC-Owned, Shared (Independent), or Shared (Dependent). The framework thereby answers the central question of who is responsible for what in a cloud project. Responsibility handovers between provider and customer become transparent at the level of individual controls — and can be cleanly anchored in contracts as well as in operations.

04

STAR program and STAR Registry

The CAIQ is the basis for STAR Level 1: cloud providers submit their completed security questionnaire to the public CSA STAR Registry, creating transparency about their control landscape. STAR Continuous extends the approach with continuous assessment — with the goal of enabling compliance statements on a monthly, daily, or even hourly basis. The CCM is thus the foundation on which CSPs are compared and evaluated.

05

Implementation and standard mappings

The CCM Implementation Guidelines (v2.1) provide implementation recommendations for each control specification along the SSRM role allocation — deliberately without rigid how-to prescriptions, since implementation depends on architecture, technology, and risk profile. Mappings link the CCM to ISO/IEC 27001/27002/27017/27018, AICPA TSC, CIS Controls, NIST CSF, NIST 800-53, and PCI DSS. This makes it possible to identify gaps and overlaps between frameworks and to reduce duplicated compliance effort.

06

Continuous audit metrics

The Continuous Audit Metrics Catalog (v1.1) defines 34 cloud security metrics that tie directly into CCM controls and can largely be measured automatically — the foundation for continuous auditing instead of annual point-in-time assessments. The terminology follows ISO/IEC 19086-1, the standard framework for cloud SLAs. The accompanying Code of Practice describes eight requirements for viable key metrics, from strategic alignment and clear RACI responsibility to tamper resistance.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2026

Guide to the CCM and CAIQ — Understanding the Key Components and their Applications

Explains the components of the CCM/CAIQ v4.1 package, their purpose and use — from the 207 controls across 17 domains to mappings, guidelines, and STAR submission.

Cloud Security Alliance · 2026

Cloud Controls Matrix (CCM) Version 4.1 (Präsentation)

Overview of the structure (17 domains, 207 controls), framework components such as SSRM, CAIQ, mappings, and CCM-Lite, as well as target audiences and file formats of CCM v4.1.

Cloud Security Alliance · 2026

CCM v4.1 Implementation Guidelines v2.1

Implementation guidance for each CCM control with SSRM allocation (CSP-Owned, CSC-Owned, Shared Independent/Dependent) and a description of all 17 domains.

Cloud Security Alliance · 2026

The Continuous Audit Metrics Catalog v1.1

Catalog of 34 cloud security metrics for continuous auditing, terminologically based on ISO/IEC 19086-1 and aligned with the CCM v4.1 controls.

Cloud Security Alliance · 2026

Code of Practice for Implementing and Maintaining Key Metrics

Eight requirements for effective key metrics — from strategic alignment and RACI responsibility to timeliness, accuracy, and tamper resistance.

Embedding the CCM and CAIQ in your cloud compliance program

VamiSec supports you with consulting, assessments, and audits around cloud security — from CCM-based gap analysis to the structured assessment of your cloud providers using the CAIQ. Get in touch.