Book an Appointment

CSA Cloud Controls Matrix & CAIQ

The Cloud Security Alliance's Cloud Controls Matrix structures cloud security into 17 domains with 207 controls — the CAIQ translates them into a standardized question catalog for provider assessment.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

17security domains in CCM v4.1
207control objectives
283yes/no questions in the CAIQ
34metrics for continuous auditing

The Cloud Controls Matrix (CCM) is a cybersecurity control framework from the Cloud Security Alliance (CSA) that translates security and privacy requirements for cloud computing into structured, standardized controls. The current version 4.1, released on January 28, 2026, comprises 207 control objectives across 17 security domains — from Audit & Assurance and Identity & Access Management to Universal Endpoint Management. The CCM is regarded as the de facto standard for cloud security assurance and forms the backbone of the CSA STAR program for assessing and comparing cloud service providers. It is complemented by the Consensus Assessment Initiative Questionnaire (CAIQ), implementation and audit guidelines, and mappings to established standards. The framework addresses cloud providers (CSPs) and cloud customers (CSCs) alike — including a clear allocation of shared security responsibility.

The Essentials at a Glance

Six topic blocks — tap to expand.

CCM, CAIQ, SSRM & STAR

The framework's four building blocks — pick a tab for the key points.

v4.1
  • CCM v4.1 organizes cloud security into 17 domains with a total of 207 control objectives.
  • The domain structure deliberately aligns with established frameworks such as ISO 27001:2022 so that existing knowledge can be put to use.
  • For each control, the matrix additionally indicates its applicability to the IaaS, PaaS, and SaaS service models.
Audit & AssuranceApplication & Interface SecurityCryptography and Key ManagementIdentity & Access ManagementLogging & MonitoringSupply Chain ManagementISO 27001:2022

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2026

Guide to the CCM and CAIQ — Understanding the Key Components and their Applications

Explains the components of the CCM/CAIQ v4.1 package, their purpose and use — from the 207 controls across 17 domains to mappings, guidelines, and STAR submission.

Cloud Security Alliance · 2026

Cloud Controls Matrix (CCM) Version 4.1 (Präsentation)

Overview of the structure (17 domains, 207 controls), framework components such as SSRM, CAIQ, mappings, and CCM-Lite, as well as target audiences and file formats of CCM v4.1.

Cloud Security Alliance · 2026

CCM v4.1 Implementation Guidelines v2.1

Implementation guidance for each CCM control with SSRM allocation (CSP-Owned, CSC-Owned, Shared Independent/Dependent) and a description of all 17 domains.

Cloud Security Alliance · 2026

The Continuous Audit Metrics Catalog v1.1

Catalog of 34 cloud security metrics for continuous auditing, terminologically based on ISO/IEC 19086-1 and aligned with the CCM v4.1 controls.

Cloud Security Alliance · 2026

Code of Practice for Implementing and Maintaining Key Metrics

Eight requirements for effective key metrics — from strategic alignment and RACI responsibility to timeliness, accuracy, and tamper resistance.

Embedding the CCM and CAIQ in your cloud compliance program

VamiSec supports you with consulting, assessments, and audits around cloud security — from CCM-based gap analysis to the structured assessment of your cloud providers using the CAIQ. Get in touch.