We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. CSA STAR certification
CSA STAR, UAE

STAR Level 1 puts your security posture in a public registry. That is the point and the risk.

The STAR Registry is publicly accessible and documents the security and privacy controls provided by cloud offerings. Level 1 is a self-assessment against 197 control objectives across 17 domains. Level 2 brings in a third party.

Book a STAR readiness reviewSee the two levels
CSA STAR certification readiness for UAE cloud providers
  • 197 objectivesIn the Cloud Controls Matrix
  • 17 domainsCovering key aspects of cloud technology
  • 2 levelsSelf-assessment, then third-party assurance
  • Public registryWhere the submission is published
Before you submit

A Level 1 submission is a public document that customers will read closely.

Self-assessment is the accessible entry point and it carries an obvious hazard, because nobody checks it before it is published.

  • The registry is publicly accessible. A prospective customer, a competitor, a journalist or a researcher can read exactly what you claimed about each control, at any time, without asking your permission or telling you they looked.
  • Overstated answers do not stay hidden. They surface during a customer security review, during an incident, or when a later Level 2 assessment tests the same controls independently and reaches a different conclusion about them.
  • Understated answers cost you deals. Providers frequently answer conservatively where a control is partially met, when the CAIQ format allows a considered explanation that would satisfy a buyer perfectly well if written properly.
  • The useful discipline is to treat the self-assessment as if an assessor were coming, because at Level 2 one eventually will. Answering the 197 control objectives honestly the first time makes the second time an update rather than a correction.
Ask us to review your CAIQ before you publish
What STAR involves

Eight things a UAE cloud provider should establish first.

STAR exists because cloud customers kept asking the same security questions and getting different answers. The programme gives providers a standard way to answer once, publicly, in a form buyers already know how to read.

The registry is public by design

The STAR Registry is a publicly accessible registry documenting the security and privacy controls provided by cloud computing offerings. Publishing to it lets organisations show current and potential customers their security and compliance posture.

Level 1 is a structured self-assessment

At level one, organisations submit the Consensus Assessments Initiative Questionnaire, based on the Cloud Controls Matrix, to evaluate and document their security controls. It is self-attested, which makes accuracy a matter of self discipline.

Level 2 brings in independent assurance

Level 2 allows organisations to build off other industry certifications and standards and make them specific for the cloud. That is the route to a claim a customer procurement team is likely to accept without further questioning.

Two different Level 2 routes

STAR Attestation provides guidelines for accountants to conduct SOC 2 engagements. STAR Certification is a rigorous third-party independent assessment that leverages the requirements of ISO/IEC 27001. Which one suits depends on which framework your customers ask for.

197 control objectives across 17 domains

The Cloud Controls Matrix is a cybersecurity control framework for cloud computing composed of 197 control objectives structured in 17 domains covering all key aspects of cloud technology. That scope is why preparation is a programme rather than a form.

It settles the shared responsibility question

The CCM defines the security roles between cloud service providers and customers, helping both sides understand and assign responsibilities. That clarity is often the most immediately useful output for a provider, regardless of which level is pursued.

Version 4.1 combines CCM and CAIQ

The current material combines the Cloud Controls Matrix with the Consensus Assessments Initiative Questionnaire, so the control framework and the questionnaire used to evidence it are aligned rather than maintained as separate documents.

It reuses work you may already have

Level 2 builds on other industry certifications and standards, so an organisation already holding ISO/IEC 27001 or already through a SOC 2 engagement is materially closer to STAR than one starting from nothing.

The levels

What each level involves and what it signals.

Taken from the published programme description. The right choice depends on what your customers are actually asking for rather than on which is more impressive.
AspectLevel 1 self-assessmentLevel 2 third-party
BasisCAIQ based on the Cloud Controls MatrixBuilds on other certifications and standards
IndependenceSelf-attestedIndependent assessment
Underlying frameworkCloud Controls MatrixISO/IEC 27001 or SOC 2, made cloud specific
Published to the registryYesYes
EffortSubstantial but internalSubstantial plus an audit
Typical buyer reactionA starting pointAccepted assurance
Reuses existing certificationNot requiredYes, that is the design
Control objectives in scope197 across 17 domains197 across 17 domains
Shared responsibility clarityDocumentedDocumented and tested
Suits a provider with no certificationYes, as a first stepNot until the base certification exists
How we approach it

Four things that make STAR worth the effort.

The registry entry is the visible output. The internal clarity produced along the way is often the more durable benefit.

We use it to settle shared responsibility properly

The CCM defines the security roles between providers and customers. Working through that boundary explicitly resolves arguments that otherwise surface during incidents and contract negotiations, and it is useful whether or not you ever publish anything.

We review answers as a buyer would read them

Registry entries are public and prospective customers read them as procurement input. An answer that is technically accurate but reads as evasive costs deals, and one that overstates creates an exposure that surfaces at the worst moment.

We route you through what you already hold

Level 2 builds on other industry certifications and standards, made specific for the cloud. Where ISO/IEC 27001 or a SOC 2 engagement already exists, the sensible path leverages it rather than treating STAR as an independent programme.

We treat the 197 objectives as a gap assessment

Working through them produces a genuine picture of where a cloud offering is weak, independent of whether you submit anything. Several clients have found the internal output more valuable than the registry entry itself.

How an engagement runs

Four phases across roughly ten to twenty weeks.

Level 1 sits at the shorter end. Level 2 depends heavily on whether the underlying ISO/IEC 27001 or SOC 2 position already exists.
  1. 01
    Weeks 1 to 3

    Scope and shared responsibility

    Which service offering is being assessed, since STAR entries describe offerings rather than companies, and where the boundary sits between what you provide and what the customer is responsible for. The CCM defines those roles explicitly.

    • Service offering scope defined precisely
    • Shared responsibility boundary documented
    • Level 1 or Level 2 route chosen with reasoning
    • Existing certifications assessed for reuse
  2. 02
    Weeks 4 to 9

    Work through the control objectives

    All 197 control objectives across the 17 domains, answered honestly with evidence identified for each. This is the substantial phase, and the output is useful internally even for organisations that never submit anything to the registry.

    • Control objectives answered with supporting evidence
    • Partial and not applicable answers justified in writing
    • Gaps identified and separated from documentation gaps
    • Remediation plan for anything material
  3. 03
    Weeks 10 to 15

    Remediate and prepare the submission

    Closing the gaps that would embarrass you in a public document, then preparing the CAIQ itself. The wording matters, because prospective customers read these entries as procurement input rather than as marketing material.

    • Priority gaps remediated with evidence
    • CAIQ responses drafted and reviewed
    • Internal sign off obtained before publication
    • Customer facing summary prepared alongside
  4. 04
    Weeks 16 to 20

    Assessment or publication

    For Level 1, publication to the registry and integration into the sales and procurement process. For Level 2, supporting the independent assessment that builds on your ISO/IEC 27001 or SOC 2 position and makes it cloud specific.

    • Registry submission published or assessment supported
    • Sales team briefed on how to use the entry
    • Maintenance owner assigned for future updates
    • Reassessment cadence agreed
Where this comes up

Six situations where STAR earns its place.

The pattern is a provider whose sales cycle keeps stalling at the security review stage.

A UAE SaaS company selling to enterprise buyers

Every prospect sends a different security questionnaire and each one takes days. A published registry entry answers most of them in advance, and being publicly discoverable means some buyers find the answer before they even ask the question.

A provider serving financial services customers

Financial buyers ask for independent assurance rather than self-attestation. STAR Certification leverages ISO/IEC 27001 requirements while STAR Attestation follows the SOC 2 route, so the choice follows what those customers already recognise.

A managed service provider clarifying its boundary

Disputes about who was responsible for a control almost always predate the incident that exposed them. The CCM defines the security roles between provider and customer, which turns an implicit assumption into a documented position.

A regional provider competing with global platforms

Global providers publish registry entries. A regional competitor without one looks less mature in a side by side comparison, regardless of how good its actual controls are, because the buyer has nothing standard to compare against.

A company preparing for ISO/IEC 27001 anyway

Where certification is already planned, sequencing STAR alongside it captures most of the incremental benefit for a fraction of the incremental cost, since Level 2 is designed to build on exactly that foundation.

A provider whose questionnaire answers vary by author

When different people answer the same question differently across deals, the organisation has no agreed security position. Working through 197 control objectives once produces that position and makes every future answer consistent.

Three positions

How UAE cloud providers answer security questions from buyers.

The right column is where most providers start, and it consumes far more time over a year than either of the alternatives.
Standard answer buyers recognise
STAR entry publishedYes
Certification without a STAR entryPartly
Answering each questionnaire individuallyNo
Publicly discoverable
STAR entry publishedYes
Certification without a STAR entryCertificate only
Answering each questionnaire individuallyNo
Cloud specific control coverage
STAR entry published197 objectives, 17 domains
Certification without a STAR entryGeneric
Answering each questionnaire individuallyAd hoc
Shared responsibility documented
STAR entry publishedExplicitly
Certification without a STAR entrySometimes
Answering each questionnaire individuallyRarely
Effort per new prospect
STAR entry publishedMinimal
Certification without a STAR entryModerate
Answering each questionnaire individuallyHigh and repeated
Independent assurance
STAR entry publishedAt Level 2
Certification without a STAR entryYes
Answering each questionnaire individuallyNone
Reuses existing certification
STAR entry publishedYes, by design
Certification without a STAR entryNot applicable
Answering each questionnaire individuallyNo
Risk of inconsistent answers
STAR entry publishedLow
Certification without a STAR entryModerate
Answering each questionnaire individuallyHigh
Setup effort
STAR entry publishedWeeks
Certification without a STAR entryAlready done
Answering each questionnaire individuallyNone
Ongoing burden
STAR entry publishedMaintenance only
Certification without a STAR entryRecertification
Answering each questionnaire individuallyContinuous
Feature
STAR entry published
Certification without a STAR entry
Answering each questionnaire individually
Standard answer buyers recognise
YesPartlyNo
Publicly discoverable
YesCertificate onlyNo
Cloud specific control coverage
197 objectives, 17 domainsGenericAd hoc
Shared responsibility documented
ExplicitlySometimesRarely
Effort per new prospect
MinimalModerateHigh and repeated
Independent assurance
At Level 2YesNone
Reuses existing certification
Yes, by designNot applicableNo
Risk of inconsistent answers
LowModerateHigh
Setup effort
WeeksAlready doneNone
Ongoing burden
Maintenance onlyRecertificationContinuous
The internal benefit

Working through 197 control objectives is a gap assessment whether or not you publish.

Several organisations we have worked with valued the internal output more than the registry entry, and that is a legitimate reason to do the work.

  • The Cloud Controls Matrix is a cybersecurity control framework for cloud computing composed of 197 control objectives structured in 17 domains covering all key aspects of cloud technology. Answering all of them honestly produces a genuine picture of a cloud offering.
  • It is cloud specific in a way general frameworks are not. Questions about tenant isolation, shared responsibility, virtualisation, interoperability and portability are asked directly rather than being inferred from controls written for on premises environments.
  • The shared responsibility work is immediately useful. Defining the security roles between provider and customer, control objective by control objective, resolves ambiguity that otherwise surfaces during incidents and contract negotiations at considerable cost.
  • And it makes future questionnaires cheaper. Once each objective has a documented answer with evidence behind it, a customer security review becomes a retrieval exercise rather than a project that pulls engineers off delivery for a week.
How an engagement runs

Five steps, and the first is a commercial question.

The right level is determined by what your customers ask for, not by which sounds strongest. Getting that wrong costs months.
  1. 1

    Decide the level from customer demand

    Level 1 is a self-assessment submitted as a CAIQ based on the Cloud Controls Matrix. Level 2 is independent, building on other certifications and standards made cloud specific. Which one closes deals for you is a sales question before it is a compliance one.

  2. 2

    Define the offering and the responsibility boundary

    Registry entries describe cloud offerings rather than companies, so scope has to be precise. Then the shared responsibility split, which the CCM exists in part to make explicit between provider and customer.

  3. 3

    Work through all 197 control objectives

    Across the 17 domains, with evidence identified for each and honest treatment of partial or not applicable answers. This phase is the bulk of the work and produces the gap list that drives everything after it.

  4. 4

    Remediate what would not survive scrutiny

    Prioritised by what a buyer would notice and what an assessor would test. The registry is public, so anything overstated becomes a durable exposure rather than a private compliance debt you can quietly settle later.

  5. 5

    Publish or be assessed, then maintain

    Level 1 entries are published, Level 2 involves supporting an independent assessment. Either way somebody has to own the entry afterwards, because an out of date registry entry is read as an out of date security programme.

Straight answers

What UAE providers ask about CSA STAR.

A publicly accessible registry that documents the security and privacy controls provided by cloud computing offerings. Publishing to it allows organisations to show current and potential customers their security and compliance posture in a standard format.

At Level 1 organisations submit the Consensus Assessments Initiative Questionnaire based on the Cloud Controls Matrix to evaluate and document their controls. Level 2 allows organisations to build off other industry certifications and standards and make them cloud specific.

A cybersecurity control framework for cloud computing, composed of 197 control objectives structured in 17 domains covering all key aspects of cloud technology. It is the basis for the questionnaire used in the STAR programme.

Attestation provides guidelines for accountants to conduct SOC 2 engagements. Certification is a rigorous third-party independent assessment that leverages the requirements of ISO/IEC 27001. The right one follows whichever framework your customers already recognise.

For STAR Certification it is the foundation, since the assessment leverages ISO/IEC 27001 requirements. Level 1 does not require it, which is why self-assessment is the accessible entry point for providers without an existing certification.

As a starting point rather than as assurance. It demonstrates that you have worked through a recognised cloud control framework and published the result. Buyers with stronger requirements will ask for the independent route, and they will say so.

It becomes a public document that a customer security review, an incident or a later independent assessment can contradict. Since the registry is openly accessible, an overstatement is durable in a way that a private questionnaire answer is not.

Yes, and this is one of its most practically useful features. The CCM defines the security roles between cloud service providers and customers, helping both sides understand and assign responsibilities before an incident forces the question.

The CAIQ is the questionnaire used to evidence the CCM control objectives, and the current version combines the two. That alignment means the framework and the assessment instrument stay consistent rather than drifting apart between releases.

The offering. Registry entries document the controls provided by cloud computing offerings, so scope needs defining precisely, particularly for providers with several products at different levels of maturity.

Usually yes, because the effort per prospect drops considerably and the answers become consistent. Organisations answering each questionnaire individually often spend more across a year than the whole preparation programme would have cost.

For many providers it is the internal gap picture rather than the published entry. Working through 197 control objectives honestly produces a clear view of where a cloud offering is weak, which is useful whether or not you submit anything.

A named person, because the entry is public and dated. An out of date registry entry is read by prospective customers as a signal about the security programme behind it, which is the opposite of the intended effect.

That is the efficient path. Level 2 is designed to build on other industry certifications and standards, so sequencing STAR alongside a certification programme captures most of the benefit at a fraction of the incremental effort.

We scope by the number of offerings and whether an underlying certification already exists. The free first step: count how many security questionnaires your team completed in the last six months and how long each took.

Typically eight to twelve weeks for a single offering, driven by working through 197 control objectives and gathering evidence rather than by the submission itself. Organisations with an existing certification move considerably faster.

Yes, and you should be precise about it. Registry entries document the controls provided by cloud computing offerings, so the scope statement matters, particularly where a provider has several products at different levels of maturity.

The entry needs updating, which is why a named owner matters. A public entry that describes a configuration you no longer run is worse than no entry, because it is a dated public statement contradicted by your current position.

Enterprise procurement and security teams do, and increasingly they check before making contact. Publishing to the registry allows organisations to show current and potential customers their security and compliance posture without waiting to be asked.

Usually yes. The control work is largely the same, so Level 1 captures the benefit early while the underlying certification is being pursued, and the transition to independent assurance then builds on an inventory that already exists.

It answers most of one. The questionnaire format is derived from the same control framework, so an organisation that has completed the assessment can respond to most questionnaire items by reference rather than by drafting fresh answers each time.

By the offering rather than by the infrastructure. Where several products share a platform, decide whether they are assessed together or separately, and be explicit in the scope statement, because customers read it to understand what the entry covers.

Record it as not applicable with a written justification rather than leaving it blank or answering yes. A justified exclusion is defensible in an assessment, and an unexplained gap invites exactly the questions the entry exists to prevent.

Somebody with visibility of the platform, supported by the owners of each domain. Completion by one person without domain input produces optimistic answers, and completion by committee without an owner produces an entry nobody finishes.

Yes. Architecture changes, new subprocessors, new regions and new certifications all affect answers, and a public entry describing a previous configuration is a dated statement contradicted by your current position.

It is best known among buyers who procure cloud services regularly, which is exactly the audience that sends security questionnaires. For those buyers a registry entry is a familiar and quick way to assess a provider before engaging.
Readiness check

Twelve questions to answer before starting.

The first group determines which level makes sense. Answering it honestly saves a lot of effort spent pursuing the wrong route.

Route

  • What do customers actually ask for?
    It decides the level.
  • Do we hold ISO/IEC 27001?
    The base for STAR Certification.
  • Have we done a SOC 2?
    The base for STAR Attestation.
  • Are we ready to publish publicly?
    The registry is open.

Scope

  • Which offering are we assessing?
    Entries describe offerings.
  • Where is the responsibility boundary?
    The CCM defines the roles.
  • Do we use subprocessors?
    They affect several domains.
  • Is the scope stable this year?
    Changes complicate assessment.

Evidence

  • Can we evidence each control objective?
    All 197 of them.
  • Who owns each domain?
    Seventeen domains, named owners.
  • Are our answers defensible in public?
    Assume they are read.
  • Who maintains the entry afterwards?
    It goes stale otherwise.
Related reading

The pages around this one.

ISO 27001 certification

The foundation STAR Certification builds on.

Learn more

SOC 2 readiness

The foundation STAR Attestation builds on.

Learn more

Cloud security posture audit

The technical picture behind the control answers.

Learn more
Next step

Count the security questionnaires your team completed in the last six months.

Then add up the hours. For most UAE cloud providers that figure alone decides whether working through the control objectives once is worth doing.

Book a STAR readiness reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

SOC 2 Readiness UAE

Type II preparation, and when ISO 27001 fits better

Learn more

Cloud Security Posture Audit

The real inventory, then configuration and identity

Learn more

Third Party Risk Audit

Who can actually reach your systems, and what to do about it

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

Gap Assessment

Distance to a target you actually have to meet

Learn more

Audit Readiness Assessment

Run the audit before the auditor does

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy