STAR Level 1 puts your security posture in a public registry. That is the point and the risk.
The STAR Registry is publicly accessible and documents the security and privacy controls provided by cloud offerings. Level 1 is a self-assessment against 197 control objectives across 17 domains. Level 2 brings in a third party.

- 197 objectivesIn the Cloud Controls Matrix
- 17 domainsCovering key aspects of cloud technology
- 2 levelsSelf-assessment, then third-party assurance
- Public registryWhere the submission is published
A Level 1 submission is a public document that customers will read closely.
Self-assessment is the accessible entry point and it carries an obvious hazard, because nobody checks it before it is published.
- The registry is publicly accessible. A prospective customer, a competitor, a journalist or a researcher can read exactly what you claimed about each control, at any time, without asking your permission or telling you they looked.
- Overstated answers do not stay hidden. They surface during a customer security review, during an incident, or when a later Level 2 assessment tests the same controls independently and reaches a different conclusion about them.
- Understated answers cost you deals. Providers frequently answer conservatively where a control is partially met, when the CAIQ format allows a considered explanation that would satisfy a buyer perfectly well if written properly.
- The useful discipline is to treat the self-assessment as if an assessor were coming, because at Level 2 one eventually will. Answering the 197 control objectives honestly the first time makes the second time an update rather than a correction.
Eight things a UAE cloud provider should establish first.
The registry is public by design
The STAR Registry is a publicly accessible registry documenting the security and privacy controls provided by cloud computing offerings. Publishing to it lets organisations show current and potential customers their security and compliance posture.
Level 1 is a structured self-assessment
At level one, organisations submit the Consensus Assessments Initiative Questionnaire, based on the Cloud Controls Matrix, to evaluate and document their security controls. It is self-attested, which makes accuracy a matter of self discipline.
Level 2 brings in independent assurance
Level 2 allows organisations to build off other industry certifications and standards and make them specific for the cloud. That is the route to a claim a customer procurement team is likely to accept without further questioning.
Two different Level 2 routes
STAR Attestation provides guidelines for accountants to conduct SOC 2 engagements. STAR Certification is a rigorous third-party independent assessment that leverages the requirements of ISO/IEC 27001. Which one suits depends on which framework your customers ask for.
197 control objectives across 17 domains
The Cloud Controls Matrix is a cybersecurity control framework for cloud computing composed of 197 control objectives structured in 17 domains covering all key aspects of cloud technology. That scope is why preparation is a programme rather than a form.
It settles the shared responsibility question
The CCM defines the security roles between cloud service providers and customers, helping both sides understand and assign responsibilities. That clarity is often the most immediately useful output for a provider, regardless of which level is pursued.
Version 4.1 combines CCM and CAIQ
The current material combines the Cloud Controls Matrix with the Consensus Assessments Initiative Questionnaire, so the control framework and the questionnaire used to evidence it are aligned rather than maintained as separate documents.
It reuses work you may already have
Level 2 builds on other industry certifications and standards, so an organisation already holding ISO/IEC 27001 or already through a SOC 2 engagement is materially closer to STAR than one starting from nothing.
What each level involves and what it signals.
| Aspect | Level 1 self-assessment | Level 2 third-party | |
|---|---|---|---|
| Basis | CAIQ based on the Cloud Controls Matrix | Builds on other certifications and standards | |
| Independence | Self-attested | Independent assessment | |
| Underlying framework | Cloud Controls Matrix | ISO/IEC 27001 or SOC 2, made cloud specific | |
| Published to the registry | Yes | Yes | |
| Effort | Substantial but internal | Substantial plus an audit | |
| Typical buyer reaction | A starting point | Accepted assurance | |
| Reuses existing certification | Not required | Yes, that is the design | |
| Control objectives in scope | 197 across 17 domains | 197 across 17 domains | |
| Shared responsibility clarity | Documented | Documented and tested | |
| Suits a provider with no certification | Yes, as a first step | Not until the base certification exists |
Four things that make STAR worth the effort.
We use it to settle shared responsibility properly
The CCM defines the security roles between providers and customers. Working through that boundary explicitly resolves arguments that otherwise surface during incidents and contract negotiations, and it is useful whether or not you ever publish anything.
We review answers as a buyer would read them
Registry entries are public and prospective customers read them as procurement input. An answer that is technically accurate but reads as evasive costs deals, and one that overstates creates an exposure that surfaces at the worst moment.
We route you through what you already hold
Level 2 builds on other industry certifications and standards, made specific for the cloud. Where ISO/IEC 27001 or a SOC 2 engagement already exists, the sensible path leverages it rather than treating STAR as an independent programme.
We treat the 197 objectives as a gap assessment
Working through them produces a genuine picture of where a cloud offering is weak, independent of whether you submit anything. Several clients have found the internal output more valuable than the registry entry itself.
Four phases across roughly ten to twenty weeks.
- 01Weeks 1 to 3
Scope and shared responsibility
Which service offering is being assessed, since STAR entries describe offerings rather than companies, and where the boundary sits between what you provide and what the customer is responsible for. The CCM defines those roles explicitly.
- Service offering scope defined precisely
- Shared responsibility boundary documented
- Level 1 or Level 2 route chosen with reasoning
- Existing certifications assessed for reuse
- 02Weeks 4 to 9
Work through the control objectives
All 197 control objectives across the 17 domains, answered honestly with evidence identified for each. This is the substantial phase, and the output is useful internally even for organisations that never submit anything to the registry.
- Control objectives answered with supporting evidence
- Partial and not applicable answers justified in writing
- Gaps identified and separated from documentation gaps
- Remediation plan for anything material
- 03Weeks 10 to 15
Remediate and prepare the submission
Closing the gaps that would embarrass you in a public document, then preparing the CAIQ itself. The wording matters, because prospective customers read these entries as procurement input rather than as marketing material.
- Priority gaps remediated with evidence
- CAIQ responses drafted and reviewed
- Internal sign off obtained before publication
- Customer facing summary prepared alongside
- 04Weeks 16 to 20
Assessment or publication
For Level 1, publication to the registry and integration into the sales and procurement process. For Level 2, supporting the independent assessment that builds on your ISO/IEC 27001 or SOC 2 position and makes it cloud specific.
- Registry submission published or assessment supported
- Sales team briefed on how to use the entry
- Maintenance owner assigned for future updates
- Reassessment cadence agreed
Six situations where STAR earns its place.
A UAE SaaS company selling to enterprise buyers
Every prospect sends a different security questionnaire and each one takes days. A published registry entry answers most of them in advance, and being publicly discoverable means some buyers find the answer before they even ask the question.
A provider serving financial services customers
Financial buyers ask for independent assurance rather than self-attestation. STAR Certification leverages ISO/IEC 27001 requirements while STAR Attestation follows the SOC 2 route, so the choice follows what those customers already recognise.
A managed service provider clarifying its boundary
Disputes about who was responsible for a control almost always predate the incident that exposed them. The CCM defines the security roles between provider and customer, which turns an implicit assumption into a documented position.
A regional provider competing with global platforms
Global providers publish registry entries. A regional competitor without one looks less mature in a side by side comparison, regardless of how good its actual controls are, because the buyer has nothing standard to compare against.
A company preparing for ISO/IEC 27001 anyway
Where certification is already planned, sequencing STAR alongside it captures most of the incremental benefit for a fraction of the incremental cost, since Level 2 is designed to build on exactly that foundation.
A provider whose questionnaire answers vary by author
When different people answer the same question differently across deals, the organisation has no agreed security position. Working through 197 control objectives once produces that position and makes every future answer consistent.
How UAE cloud providers answer security questions from buyers.
| Feature | STAR entry published | Certification without a STAR entry | Answering each questionnaire individually |
|---|---|---|---|
Standard answer buyers recognise | Yes | Partly | No |
Publicly discoverable | Yes | Certificate only | No |
Cloud specific control coverage | 197 objectives, 17 domains | Generic | Ad hoc |
Shared responsibility documented | Explicitly | Sometimes | Rarely |
Effort per new prospect | Minimal | Moderate | High and repeated |
Independent assurance | At Level 2 | Yes | None |
Reuses existing certification | Yes, by design | Not applicable | No |
Risk of inconsistent answers | Low | Moderate | High |
Setup effort | Weeks | Already done | None |
Ongoing burden | Maintenance only | Recertification | Continuous |
Working through 197 control objectives is a gap assessment whether or not you publish.
Several organisations we have worked with valued the internal output more than the registry entry, and that is a legitimate reason to do the work.
- The Cloud Controls Matrix is a cybersecurity control framework for cloud computing composed of 197 control objectives structured in 17 domains covering all key aspects of cloud technology. Answering all of them honestly produces a genuine picture of a cloud offering.
- It is cloud specific in a way general frameworks are not. Questions about tenant isolation, shared responsibility, virtualisation, interoperability and portability are asked directly rather than being inferred from controls written for on premises environments.
- The shared responsibility work is immediately useful. Defining the security roles between provider and customer, control objective by control objective, resolves ambiguity that otherwise surfaces during incidents and contract negotiations at considerable cost.
- And it makes future questionnaires cheaper. Once each objective has a documented answer with evidence behind it, a customer security review becomes a retrieval exercise rather than a project that pulls engineers off delivery for a week.
Five steps, and the first is a commercial question.
- 1
Decide the level from customer demand
Level 1 is a self-assessment submitted as a CAIQ based on the Cloud Controls Matrix. Level 2 is independent, building on other certifications and standards made cloud specific. Which one closes deals for you is a sales question before it is a compliance one.
- 2
Define the offering and the responsibility boundary
Registry entries describe cloud offerings rather than companies, so scope has to be precise. Then the shared responsibility split, which the CCM exists in part to make explicit between provider and customer.
- 3
Work through all 197 control objectives
Across the 17 domains, with evidence identified for each and honest treatment of partial or not applicable answers. This phase is the bulk of the work and produces the gap list that drives everything after it.
- 4
Remediate what would not survive scrutiny
Prioritised by what a buyer would notice and what an assessor would test. The registry is public, so anything overstated becomes a durable exposure rather than a private compliance debt you can quietly settle later.
- 5
Publish or be assessed, then maintain
Level 1 entries are published, Level 2 involves supporting an independent assessment. Either way somebody has to own the entry afterwards, because an out of date registry entry is read as an out of date security programme.
What UAE providers ask about CSA STAR.
Twelve questions to answer before starting.
Route
- What do customers actually ask for?It decides the level.
- Do we hold ISO/IEC 27001?The base for STAR Certification.
- Have we done a SOC 2?The base for STAR Attestation.
- Are we ready to publish publicly?The registry is open.
Scope
- Which offering are we assessing?Entries describe offerings.
- Where is the responsibility boundary?The CCM defines the roles.
- Do we use subprocessors?They affect several domains.
- Is the scope stable this year?Changes complicate assessment.
Evidence
- Can we evidence each control objective?All 197 of them.
- Who owns each domain?Seventeen domains, named owners.
- Are our answers defensible in public?Assume they are read.
- Who maintains the entry afterwards?It goes stale otherwise.
Count the security questionnaires your team completed in the last six months.
Then add up the hours. For most UAE cloud providers that figure alone decides whether working through the control objectives once is worth doing.
Related Services
Explore more solutions that work great with this service
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
Cloud Security Posture Audit
The real inventory, then configuration and identity
Third Party Risk Audit
Who can actually reach your systems, and what to do about it
Compliance as a Service
Keeping the position true between assessments
Gap Assessment
Distance to a target you actually have to meet
Audit Readiness Assessment
Run the audit before the auditor does
Virtual CISO Dubai
Security governance and accountability, not more tools