Hello, this is Ryuta Hamamoto from TIMEWELL.
"We pitched our SaaS to a major US pharma company, and procurement asked whether we have CSA STAR Level 2. The CTO froze." A SaaS founder told me that last week.
This pattern has spiked since early 2026. Teams have SOC 2 and ISO 27001 but have never heard of CSA STAR Level 2, or they submitted Level 1 self-assessment and assumed they were done. In overseas enterprise procurement, Level 1 vs Level 2 is the hard line between "self-declared" and "third-party verified."
CCM v4.1 shipped in January 2026; by May, STAR Registry entries passed 2,000. For Japanese cloud and SaaS providers, Level 2 is no longer a someday certificate. It is a risk that the next sales cycle will demand it and set you back six months. This piece covers Attestation vs Certification, CCM v4.1, cost ranges, and why Level 2 pays off in vendor DD, from an implementation lens.
TL;DR
- CSA STAR Level 2 is an on-site review by a CSA-approved third-party auditor. The gap from Level 1 (self-declaration) is decisive
- Two tracks: STAR Attestation (SOC 2 Type 2 + CCM) or STAR Certification (ISO/IEC 27001 + CCM)
- CCM v4.1 (January 2026): 17 domains, 207 controls; 11 new controls on AI supply chain and log monitoring
- Cost range €40k–€120k. Existing SOC 2 / ISO 27001 holders often pay only 20–40% incremental
- Common Japanese trap: "We have ISO 27001, so we are fine" is not enough. You still need the CCM overlay
- WARP SECURITY drills: pre-audit hands-on, CCM gap analysis, dialogue scenarios with CPA / certification bodies
Level 1 vs Level 2: "we said so" vs "it was verified"
First-time readers often hear that Level 1 vs Level 2 is about "audit strictness." That is only half right. The real difference is legal and contractual nature: self-declaration versus third-party verification.
Level 1 means answering CSA's CAIQ (Consensus Assessments Initiative Questionnaire) (140+ questions) yourself and registering in the STAR Registry. Cost is effectively zero; timeline is 2–4 weeks. Level 2 means a CSA-approved third-party auditor (CPA for Attestation; ISO certification body for Certification) conducts on-site review and checks evidence item by item.
That difference is decisive in enterprise vendor due diligence (DD). For major US finance, pharma, and federal sales, procurement guidelines sometimes explicitly state "Level 1 alone is not accepted; Level 2 or higher is required."
In one case I tracked, a Japanese SaaS provider decided "Level 1 should be enough," started overseas expansion, then was asked mid-deal for "a Level 2 certificate or equivalent SOC 2 Type 2 + CCM evidence." The deal slipped six months. Six months is the minimum certification lead time. You cannot catch up after the fact. That is why I treat CSA STAR as a certification where "get it when you need it" is already too late.
Level 3 (continuous auditing) sits above this and is covered in a separate article. You cannot jump to Level 3 without understanding Level 2.
STAR Attestation vs STAR Certification: choose by where your customers sit
Once you commit to Level 2, the next fork is Attestation vs Certification. They differ by base standard and auditor credentials. They are often confused but are different products.
| Item | STAR Attestation | STAR Certification |
|---|---|---|
| Base standard | SOC 2 Type 2 (AICPA Trust Service Criteria) | ISO/IEC 27001 |
| CCM role | Additional subject matter | Integrated management system requirements |
| Auditor | US CPA firm | ISO certification body (JIPDEC, BSI, DNV, etc.) |
| Validity | 12 months (re-obtain annually) | 3 years (annual surveillance; re-certification in year 3) |
| Primary customer regions | US / SaaS | Europe / Japan / APAC / global |
| Fit with existing assets | Providers that already hold SOC 2 | Providers that already hold ISO 27001 |
For Japanese companies I often recommend Certification (ISO 27001 + CCM). Three reasons: (1) ISO 27001 is already widely held domestically, so governance and documentation reuse well; (2) three-year validity stabilizes run-rate cost (annual Attestation creates audit fatigue); (3) domestic bodies such as JIPDEC can issue CSA STAR Certification, reducing communication friction.
For US-primary go-to-market, I recommend Attestation. US CFOs and risk teams are fluent in SOC 2 reports (detailed CPA-produced reports) with a CCM Mapping Appendix. A single ISO certificate often lands as "is that all?"
Either way, holding both is an advantage. Hyperscalers (AWS, Azure, Google Cloud) hold both. Mid-market SaaS rarely can afford both on day one; start with the track that matches customer DD questions.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
CCM v4.1: 17 domains, 207 controls—making "ISO 27001 gaps" visible
The core of Level 2 is the CCM (Cloud Controls Matrix). CCM v4.1, released January 28, 2026, keeps 17 domains, expands to 207 controls, and adds 11 new controls around AI supply chain and log monitoring.
Major domains by purpose:
| Code | Domain | Focus |
|---|---|---|
| A&A | Audit & Assurance | Audit and assurance programs |
| AIS | Application & Interface Security | App and API protection |
| BCR | Business Continuity & Operational Resilience | BCP and operational resilience |
| CCC | Change Control & Configuration Management | Change management |
| CEK | Cryptography, Encryption & Key Management | Crypto and key management |
| DCS | Datacenter Security | Physical data-center security |
| DSP | Data Security & Privacy Lifecycle Management | Data lifecycle |
| GRC | Governance, Risk Management & Compliance | Governance overall |
| HRS | Human Resources Security | HR and offboarding |
| IAM | Identity & Access Management | Identity and access |
| IPY | Interoperability & Portability | Interoperability |
| IVS | Infrastructure & Virtualization Security | Virtualization platform |
| LOG | Logging and Monitoring | Logs and monitoring |
| SEF | Security Incident Management, E-Discovery & Cloud Forensics | Incident response |
| STA | Supply Chain Management, Transparency & Accountability | Supply chain |
| TVM | Threat & Vulnerability Management | Vulnerability management |
| UEM | Universal Endpoint Management | Endpoints |
Against ISO 27001 Annex A (93 controls), CCM is roughly twice as granular. Japanese companies that thought "ISO 27001 is enough" usually stall in Level 2 audits on the same four domains: DCS, CEK, IPY, and STA.
STA (supply chain management, transparency, and accountability) was strengthened in CCM v4.1. Because cloud services often run on someone else's cloud (AWS, GCP, and similar), auditors push hard on "how do you understand the security of your downstream dependencies?" ISO 27001 may not force that level of specificity; first-time audits almost always flag it.
I do not treat CCM v4.1 as "ISO 27001 plus extras." Read it as the language cloud operators use to describe what they actually do day to day, and it lands cleanly.
Process and cost: six months of prep, two weeks of audit, €40k–€120k
Typical Level 2 timeline: about 6–12 months from a cold start; 3–6 months if you already hold SOC 2 / ISO 27001.
| Phase | Duration | Main work |
|---|---|---|
| Gap analysis | 4–8 weeks | Map current state to CCM's 207 controls |
| Remediation | 2–6 months | Policies, technical controls, evidence prep |
| Internal audit | 2–4 weeks | Rehearsal audit, final evidence check |
| Audit fieldwork | 1–2 weeks | On-site interviews and evidence review |
| Report issuance | 4–8 weeks | Attestation report or certificate |
| Registry listing | 2 weeks | CSA STAR Registry publication |
Cost as of May 2026: €40k–€120k (about ¥7–20 million). Rough split:
- Audit firm (CPA or certification body): €30k–€80k
- Internal prep consulting: €10k–€30k
- Tools and automation: €5k–€10k
- Internal FTE (direct and indirect): separate 3–6 person-months
If you already hold SOC 2 Type 2, adding CCM as subject matter often costs only 20–40% incremental. The same is true for ISO 27001 holders moving to Certification. Far more efficient than starting from zero.
In my experience, a two-stage rocket—SOC 2 or ISO 27001 first, CCM later—is the most cost-efficient path. Full-scratch Level 2 burns out the organization. Sometimes you have no choice: a large overseas deal is live and you must build SOC 2 and CCM in parallel. Ask the audit firm for a concurrent plan; simultaneous completion in 6–8 months is realistic.
Five traps Japanese companies hit—patterns from the field
Textbooks rarely write these. From field work with Japanese cloud and SaaS teams, Level 2 friction clusters into five patterns.
Underestimating with "we already have ISO 27001, so three months is enough." CCM is roughly twice as granular as ISO 27001. DCS, CEK, IPY, and STA need separate work. I have watched CTOs who promised leadership "three months" re-slide the schedule at month six.
Delaying English evidence. For Attestation, CPA auditors read evidence in English; international Certification bodies often do the same. Japanese-only policies can cost two weeks of translation mid-audit. I tell clients: translate the top ~20 policies at least three months before fieldwork.
Not borrowing downstream cloud evidence (AWS, Azure, GCP). In STA, if you run on AWS, you can cite AWS compliance reports (SOC 2, ISO 27001, PCI DSS, etc.) to explain that lower layers are covered by the platform. Teams that do not know this freeze on DCS with "we cannot answer physical security because we run on AWS."
Assuming "no one looks at the STAR Registry." US enterprise procurement and security teams actively search the STAR Registry. Simply being listed can clear early DD screening.
Forgetting re-certification timing. Attestation is 12 months; Certification is three years. Expired certificates make the "do you have a currently valid certification?" question unanswerable. Put the next renewal on the calendar six months out at the moment of first issuance.
Who holds Level 2 in Japan: watch the layer, not just the count
As of May 2026, Japan-based Level 2 registrants number on the order of a dozen. Far fewer than in Europe and the US. Visible names include NTT-CI (NTT Communications group) and Fujitsu cloud services.
That scarcity can look like "too early for Japan." I read it the opposite way: scarcity increases differentiation. For overseas SaaS and domestic tech startups, "Level 2 obtained" is a clear enterprise sales asset.
Since 2026 began, among companies TIMEWELL supports, three RFPs from major overseas firms asked for CSA STAR Level 2. A question that was zero a year earlier. Global cloud procurement guidelines are starting to reference CSA STAR as a baseline.
My advice to Japanese SaaS: draw a roadmap now to obtain Level 2 during 2027. Lead time is 6–12 months. Zero prep when 2027 deals ask is already late.
Why Level 2 "works" in vendor DD: quieting the questionnaire
Level 2 pays off most when enterprise customers send security questionnaires (VSAQ: Vendor Security Assessment Questionnaire). Large US buyers routinely send 100–300 custom questions. One response cycle can take a solutions engineer two weeks.
With Level 2, you can often clear 70–80% of the questionnaire by sending one package: "Please refer to our CAIQ v4.0.3 answers (CCM 207 controls) and STAR Attestation report." The remaining 20–30% are customer-specific; with the baseline aligned, turnaround can fall below one-fifth.
In numbers I have seen, post-Level 2 vendors cut DD labor by about 300–500 hours per year. One to two solutions-engineer headcount. Certification cost of €40k–€120k can pay back in two to three years.
Level 2 also tends to improve external risk scores (BitSight, SecurityScorecard, etc.), which treat certifications as positive signals.
I treat Level 2 not as "for the security team" but as infrastructure for sales and customer success. If you debate it only as "security budget," ROI disappears. Bring it to the sales ROI table to get internal alignment.
Pre-audit hands-on with WARP SECURITY
The biggest wall before Level 2 is that auditors look at operational evidence, not policy PDFs. Many SaaS teams only run a policy read-through as training, and then cannot answer live audit questions.
TIMEWELL's WARP SECURITY offers a pre-audit hands-on workshop for Level 2, in three modules:
CCM gap analysis lab — Participants pull their own evidence and classify all 207 controls as implemented / partial / not implemented over two days. Consultants do not do the work for you; participants build the muscle for instant audit answers.
Dialogue drills with CPA / certification bodies — Role-play auditor interviews: log retention, producing incident evidence in three minutes, and more. Mentors with NTT-CI or Fujitsu cloud audit experience can join.
STA domain diagramming — Whiteboard which AWS/Azure/GCP components your service uses and define responsibility boundaries per layer. Without that language, auditors' "how is the lower layer assured?" freezes the room.
When we hear "we hired an audit firm and still failed," about 80% of root cause is internal operations never being verbalized. Level 2 is not something you buy; it is something you grow inside the company. WARP walks that growth process.
Where the EU AI Act connects: get the application dates right
One adjacent regime worth pinning down is the EU AI Act (Regulation (EU) 2024/1689). Its general application date is 2 August 2026 — but that date does not switch on the high-risk AI obligations as a block. This is widely misread, so here it is by date (Regulatory framework on AI (European Commission)).
From 2 August 2026, what applies is Chapter IV transparency obligations (Art. 50), Chapter III Section 5 (Art. 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapter VI and Chapters VIII–XI, and the European Commission's power to impose fines on providers of general-purpose AI (GPAI) models (Art. 101). The substantive high-risk obligations come later: Chapter III Sections 1, 2 and 3 apply to Annex III high-risk AI (Art. 6(2)) from 2 December 2027, and to Annex I high-risk AI (product-embedded, Art. 6(1)) from 2 August 2028. Art. 22 (authorised representatives), Art. 25 (value chain), Art. 26 (deployer obligations) and Art. 27 (fundamental rights impact assessment) start on those same dates.
Parts of the Act are already in force. Chapter I (general provisions, definitions, Art. 4 AI literacy) and Chapter II (Art. 5 prohibited practices) have applied since 2 February 2025; Chapter V on GPAI models, Chapter VII on governance and Chapter XII penalties (Art. 99, 100) since 2 August 2025. Maximum fines are €35 million or 7% of worldwide annual turnover for Art. 5 prohibited practices, and €15 million or 3% for GPAI-related and other breaches — whichever is higher in each case.
This staged timetable was settled by the amending Regulation (EU) 2026/1744 (the Digital Omnibus), adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. Under that amendment, newly added prohibited practices (Art. 5(1)(ba) and (bb)) apply from 2 December 2026, and providers of synthetic-content-generating AI placed on the market before 2 August 2026 must comply with Art. 50(2) by 2 December 2026 (Art. 111(4)). For high-risk AI already on the market, the transitional rule now bites only where the design is significantly changed on or after the relevant Chapter III application date (Art. 111(2)).
For cloud providers shipping AI features, the accountability CCM v4.1 strengthens in STA and the transparency/governance GPAI rules demand are connected in practice. Building language for downstream dependencies via CSA STAR Level 2 will help AI governance demands as well. We dig deeper in Governed enterprise AI agents.
Summary: draw a 2027 roadmap now
As of May 2026, CSA STAR Level 2 moved from "we might need it someday" to "next year's deals will ask." Timeline 6–12 months; cost €40k–€120k. Starting after a deal asks is already too late.
Three actions now: (1) inventory existing assets (SOC 2 or ISO 27001) and choose Attestation vs Certification; (2) finish a gap analysis against CCM v4.1's 17 domains in one month; (3) put certification on the executive agenda as a sales ROI KPI, not only a security KPI.
Related series: ISO/IEC 27001 complete guide, ISO/IEC 42001 primer, ISMAP explained, CSA STAR Level 1 self-assessment, CSA STAR Level 3 continuous auditing. Priority order for Japanese companies is in the master guide.
I think of CSA STAR Level 2 as a cloud provider's English-language passport. At the overseas deal table, it decides whether you get a seat. Count the lead time backward. Starting today is the correct answer.






