Back to Standards
Security & Access ControlGlobal

CSA STAR Level 2: Third-Party Audit

CSA STAR

Independent third-party assessment of cloud security controls.

Issuing Body: Cloud Security AllianceCode: CSA-STAR-LEVEL2Official WebsiteDocumentation

Purpose

Demonstrates rigorous third-party validation of cloud security practices.

Requirements Overview

Third-party audit; ISO 27001 or SOC 2 based; CCM assessment; Continuous monitoring option

Overview

The Cloud Security Alliance (CSA) STAR Level 2 Third-Party Audit standard emerged in 2010 as a critical response to the growing trust deficit in cloud computing security. As organizations increasingly migrated sensitive data and critical infrastructure to shared cloud environments, there was an urgent need for a standardized, independent validation mechanism that could provide transparent and rigorous security assurance. Originally developed to address the fundamental challenges of verifying security controls in multi-tenant cloud infrastructures, CSA STAR Level 2 represents a significant evolution from earlier self-assessment models. The standard mandates comprehensive third-party audits that go beyond vendor-provided security documentation, requiring independent verification across 17 critical control domains including governance, legal compliance, physical infrastructure, network security, and incident management. For data centers, CSA STAR Level 2 is particularly significant because it provides an objective framework for demonstrating security maturity. Unlike previous compliance approaches that relied heavily on vendor self-reporting, this standard requires external auditors to technically validate control effectiveness, assess potential security vulnerabilities, and provide a comprehensive evaluation of an organization's security posture. The standard has continuously evolved to address emerging cloud security challenges, incorporating updated control frameworks and adapting to new technological landscapes. By requiring detailed control mapping, operational effectiveness testing, and comprehensive risk assessments, CSA STAR Level 2 has become a critical benchmark for enterprise-grade cloud infrastructure security.

Key Requirements

Third-Party Audit Engagement with Qualified Auditors

CSA STAR Level 2 requires engagement of independent auditors meeting specific criteria—typically Big Four accounting firms, specialized cloud audit firms, or ISO 27001 certification bodies—who must possess no financial interest in the service provider.

Auditors must conduct on-site assessments at data center facilities, perform control testing, interview relevant staff, and review evidence of control implementation spanning 6-12 month assessment periods for SOC 2 Type II or ongoing for ISO 27001.

The auditor selection itself is subject to CSA oversight when pursuing official STAR certification, ensuring no conflicts of interest compromise assessment rigor.

Cloud Controls Matrix (CCM) Alignment and Mapping

All security controls within the data center infrastructure must be explicitly mapped to the 17 CCM domains and their corresponding control objectives.

This isn't generic control documentation but rather systematic proof that each CCM requirement has a corresponding implemented control—for example, CCM AIS-1 (Audit Logging) must show that all administrative access, configuration changes, and data access events are logged with immutable timestamps, retained for audit, and regularly reviewed.

Auditors verify that control descriptions are specific to the data center environment rather than boilerplate policy statements.

ISO 27001 Certification or SOC 2 Type II Audit

Level 2 requires achievement of either active ISO 27001:2022 certification from an accredited certification body (demonstrating compliance with the international information security management systems standard) or completion of a SOC 2 Type II audit report covering at least 6 consecutive months of control operation.

For data centers, this means external auditors must validate that the ISMS (Information Security Management System) covers all facility operations, and for SOC 2, must test controls for design effectiveness and operational effectiveness throughout the audit period, not just at a point in time.

Continuous Monitoring and Reassessment Requirements

CSA STAR Level 2 introduces a continuous monitoring option (CAIQ-based ongoing assessment) that requires providers to submit control updates at least quarterly and participate in external validation audits minimally every 12 months.

For data centers, this mandates establishment of a monitoring schedule—such as quarterly access control reviews, monthly audit log sample testing, and annual cryptographic key rotation verification—with documented evidence that controls remain operationally effective between formal audit cycles.

Evidence Collection and Control Testing

Auditors must obtain physical evidence that controls operate as designed, such as: access logs showing rejected unauthorized connection attempts, firewall rule configurations preventing tenant-to-tenant traffic, disk imaging evidence showing multi-tenancy segregation, documentation of security patches applied within defined timeframes, and records of annual security awareness training for all data center personnel.

This moves beyond policy existence to demonstrable operational proof across the full assessment period.

Scope Definition and Data Center Facility Coverage

The audit scope must explicitly define which data center locations, systems, and services are included in the third-party assessment.

For geographically distributed data centers, this means Level 2 may require separate audits for each region if controls differ, or a primary audit with specific documentation that controls are consistently replicated.

The scope document must specify whether assessments include physical facility security, network infrastructure, virtualization platforms, storage systems, and backup/recovery facilities.

Public Reporting and STAR Registry Listing

Upon successful Level 2 achievement, providers must publish either their ISO 27001 certificate and audit scope details or their full SOC 2 Type II audit report (or executive summary with audit evidence available to customers) in the CSA STAR registry for public visibility.

This transparency requirement means data centers cannot conceal audit findings or maintain confidential security assessments—all Level 2 organizations are publicly listed with assessment evidence accessible to prospective customers and regulators.

Non-Conformance Remediation and Audit Response

When auditors identify control deficiencies or non-conformances during Level 2 assessment, providers must develop and implement remediation plans with defined timelines, typically requiring resolution within 90 days for critical findings.

Auditors must verify remediation effectiveness before issuing the final assessment report, and ongoing compliance maintenance requires that subsequent annual audits confirm sustained control operation.

This creates accountability where findings cannot be dismissed but must be systematically addressed.

Who Uses & Why

CSA STAR Level 2 certification becomes mandatory for data centers in several key scenarios: (1) Hosting regulated workloads such as healthcare (HIPAA), financial (PCI-DSS), or government classified information; (2) Serving enterprise customers who contractually require independent security validation; (3) Competing for government and defense sector contracts; and (4) Operating multi-tenant shared infrastructure environments. While optional for single-tenant or dedicated infrastructure providers, pursuing Level 2 certification offers significant competitive advantages. It demonstrates a commitment to rigorous security practices and can differentiate providers in increasingly security-conscious markets. Geographic considerations also play a crucial role, with different regional requirements influencing certification strategies. The decision to pursue Level 2 certification involves carefully weighing several factors: customer expectations, regulatory requirements, competitive positioning, and the ongoing resource commitment required to maintain comprehensive audit documentation. Organizations must consider not just the initial certification costs, but the long-term benefits of enhanced trust and market credibility.

Certification Levels

Level
Level 1
Level 2
Level 3