AIセキュリティ

CSA STAR Level 1 Primer: Publishing a CAIQ Self-Assessment for Market Transparency

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

CSA STAR Level 1 lets cloud providers answer CAIQ v4 (200+ questions) as a self-assessment and publish it for free.

CSA STAR Level 1 Primer: Publishing a CAIQ Self-Assessment for Market Transparency
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

"We do not have the budget or time for ISO/IEC 27001 yet. But we still need to show customers the security posture of our cloud service." SaaS startups ask us this often. My answer is: start with a CSA STAR Level 1 self-assessment.

CSA STAR (Security, Trust, Assurance and Risk) is the world's largest public cloud security repository run by the Cloud Security Alliance (CSA) (see: CSA STAR Registry). Level 1 self-assessment is free in principle: answer CAIQ v4 (200+ questions) and publish, and you appear in the CSA STAR Registry. Microsoft, AWS, Google Cloud, Box, Atlassian, and other majors are registered. It is an industry-standard transparency program.

The big picture: a four-level assurance model

CSA STAR has four levels.

Level Name Assessment method Cost (approx.) Timeline
Level 1 Self-Assessment Self-assessment Free (CSA membership separate) 1–3 months
Level 2 Third-Party Audit Third-party certification (CSA STAR Certification or Attestation) ¥3–8 million 6–12 months
Level 3 Continuous Auditing Continuous auditing TBD (pilot)
Level 4 Continuous Auditing Plus Advanced continuous auditing TBD (pilot)

Level 1 and Level 2 are in practical use; Level 3 and above are future extensions (see: CSA STAR Levels).

People often ask whether "just publishing a self-assessment" means anything. There is a concrete benefit. You can cut the labor of answering long security questionnaires from customers by pointing them to your CAIQ submission. At SaaS companies I have supported, monthly 3–5 questionnaire responses became "please refer to our CSA STAR Registry page," and sales productivity rose sharply.

CAIQ v4: breaking down the 200+ question set

The current CAIQ (Consensus Assessments Initiative Questionnaire) v4 is a 200+ question set aligned to CSA's control framework CCM (Cloud Controls Matrix) v4 (see: STAR Level 1: Security Questionnaire (CAIQ v4)).

CCM v4's 17 domains look like this:

Domain Abbrev. Example questions
Audit & Assurance A&A Third-party audit frequency, certifications held
Application & Interface Security AIS Secure coding, SAST/DAST
Business Continuity & Operational Resilience BCR RTO/RPO, disaster recovery drills
Change Control & Configuration Management CCC Production change approval process
Cryptography, Encryption & Key Management CEK Encryption at rest/in transit, key rotation
Datacenter Security DCS Physical access control
Data Security & Privacy Lifecycle Management DSP Data classification, retention
Governance, Risk Management & Compliance GRC Risk governance, compliance maintenance
Human Resources Security HRS Pre-employment screening, training
Identity & Access Management IAM MFA, privileged access management
Interoperability & Portability IPY Data export, avoiding vendor lock-in
Infrastructure & Virtualization Security IVS Hypervisor security, network isolation
Logging and Monitoring LOG Security event monitoring, SIEM
Security Incident Management, E-Discovery & Cloud Forensics SEF Incident response, forensics
Supply Chain Management, Transparency & Accountability STA Sub-processor management, third-party risk
Threat & Vulnerability Management TVM Vulnerability scanning, patch management
Universal Endpoint Management UEM Endpoint security, MDM

Each item is answered Yes / No / NA / Partial plus free-form text. For A&A-01 ("Do you undergo external compliance audits?"), you write something concrete like "Yes. ISO/IEC 27001:2022 certified; auditor XXX; valid through YYYY-MM-DD."

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Three friction points Japanese companies hit in practice

CAIQ submission looks simple, but there are common traps.

Issue 1: How to use "Partial"
There is a temptation to answer "Yes" even when implementation is incomplete. False statements can lead to CSA delisting. In my experience, "Partial" with a roadmap in the notes builds more trust. Specific language such as "full implementation planned by Q3 2026" is valued, not penalized.

Issue 2: Mapping CCM v4 to internal documents
Companies already running ISMS or SOC 2 still need to remap existing artifacts to CCM v4, and that work is heavier than expected. CSA's CCM Mapping Working Group materials map to ISO/IEC 27001, SOC 2, PCI DSS, and others; start there (see: CSA STAR Program Overview).

Issue 3: How to treat AI features
This is a post-2025 issue. CCM v4 does not yet have an AI/ML-specific domain. SaaS products with AI features usually add AI-related controls in free-form notes under AIS or DSP. CSA is developing an AI Controls Matrix (AICM), expected to integrate into CAIQ around 2026–2027.

For AI-enabled SaaS, I already recommend explicitly describing AI-related controls in CAIQ notes. Providers that voluntarily document third-party AI use (OpenAI, Anthropic, and similar), data handling, and human oversight are evaluated differently in the market.

A staged upgrade from Level 1 to Level 2

For providers who want CSA STAR Level 2 or ISO/IEC 27001 later but lack budget now, I often propose a three-year roadmap.

Year 1: Publish CSA STAR Level 1 self-assessment
Free. Complete CAIQ v4 in 1–3 months and register in the STAR Registry. Reduce sales questionnaire load while baselining internal security controls.

Year 2: Obtain ISO/IEC 27001
Reuse the Level 1 gap analysis for ISO/IEC 27001 Statement of Applicability work. Certification in 9–12 months; mid-size companies typically spend ¥3.8–6.0 million. Details: ISO/IEC 27001 Certification Complete Guide.

Year 3: Obtain CSA STAR Level 2 (CSA STAR Certification)
With ISO/IEC 27001 in place, take a third-party audit by a CSA-approved auditor. Cost ¥3–8 million. Level 2 materially improves competitiveness in global deals and government-related procurement.

The key point: documentation assets built in Year 1 fully pay off in Year 2 ISO/IEC 27001 and Year 3 CSA STAR Level 2. Starting with a free self-assessment lowers later certification cost.

How WARP SECURITY systematizes "CSA STAR benchmark research"

Providers starting Level 1 often ask TIMEWELL: "What do peers answer?" and "Can we benchmark our weak spots?" The WARP SECURITY CSA STAR track is built around benchmark research.

  • CAIQ analysis of major registrants — Domain-by-domain comparison of AWS, Microsoft, Google, Box, and other STAR Registry entries to visualize industry baseline
  • In-house CAIQ draft workshop — Participants draft answers across CCM v4's 17 domains × 200 questions in two days
  • AI control free-form templates — CAIQ still lacks explicit AI items; recommended language for voluntary disclosure
  • Path to Level 2 / ISO 27001 / SOC 2 — How Level 1 outputs feed the next certification

What I want to differentiate from generic CSA STAR training: less statute lecture, more benchmark comparison and implementation pattern discussion. Anyone can read the questions. The hard part is judging how peers write and how you differentiate.

Details: WARP SECURITY.

Public reference points for describing AI features (as of August 1, 2026)

Issue 3 (AI features) has become easier to write up now that the public guidelines have firmed up. In Japan, MIC and METI published AI Business Operator Guidelines v1.2 on March 31, 2026, expanding risk management and human oversight language for AI use. Abroad, the general date of application of the EU AI Act (European Commission) is August 2, 2026. What starts on that date is the Chapter IV transparency obligations (Article 50), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration), and Article 101 — the European Commission's power to fine providers of general-purpose AI (GPAI) models. The substantive high-risk obligations do not start then: under the amending Regulation (EU) 2026/1744 (adopted July 8, 2026; published as OJ L 2026/1744 on July 24, 2026; in force July 27, 2026), they apply from December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems. While CAIQ still lacks an AI-native domain, using these as underlays for free-form answers is the practical approach. For control design of AI features, see also Governed enterprise AI agents.

Summary: Level 1 is your security-posture business card

  • CSA STAR Level 1 is a free self-assessment: answer CAIQ v4 (200+ questions) and publish in the STAR Registry
  • It functions as a benchmark document registered by AWS, Microsoft, Google, Box, and others, and directly cuts questionnaire labor
  • Level 2 differs by third-party certification: Level 1 is 1–3 months and free; Level 2 is 6–12 months and ¥3–8 million
  • Prefer "Partial" with a roadmap over forced "Yes" answers
  • AI-enabled SaaS should voluntarily document AI controls in CAIQ notes
  • Classic roadmap: Year 1 STAR Level 1 → Year 2 ISO/IEC 27001 → Year 3 STAR Level 2

If I had to pick one first move for early-stage SaaS that cannot yet take ISMS or ISMAP, CSA STAR Level 1 is the highest ROI way to declare security posture. There is little reason not to do it.

Related: ISMS primer, ISO/IEC 27001 certification complete guide, ISO/IEC 42001 AIMS primer, ISMAP primer.

References

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles