Scrutineer.ai

Scrutineer · By framework

CSA STAR certification and CAIQ questionnaire software

The CAIQ your team filled in last year is on a clock. CCM v4.1 landed in January 2026, and the v4.0 questionnaire is withdrawn in January 2028.

Scrutineer holds your controls and evidence once, then drafts CAIQ answers from them, so a STAR Registry listing becomes a review pass rather than a rebuild.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with CSA STAR

The three STAR levels you have read about are really two

Almost every published guide tables CSA STAR as Level 1, Level 2 and Level 3, and invites you to pick one. Level 3, the Continuous Auditing Certification, has been described as forthcoming for years and there is still no certification you can actually obtain. AWS says plainly that CSA is still defining the Level 3 requirements, so there is nothing to assess against. If a roadmap or a board deck at your company has Level 3 on it as a target date, that date is not real. What does exist is STAR Continuous, a cadence commitment layered on Level 1 or Level 2 where you refresh your documentation every thirty days. That is a maintenance discipline, not a third tier, and it is the thing most teams actually meant when they asked for continuous assurance.

Your CAIQ has a deadline now, and most vendors have not put it on a calendar

CCM v4.1 and CAIQ v4.1 were released on January 27, 2026, superseding CCM v4.0.13. This is a dated migration rather than a suggestion. CSA began accepting both v4.1 and v4.0 submissions for Level 1 and Level 2 in March 2026; from December 2027 only v4.1 submissions are accepted at either level; and in January 2028 CCM v4.0.x and CAIQ v4.0.x are withdrawn entirely. Some assessors report an earlier cutoff of July 2027 for brand new applicants, so confirm your own date against the timeline CSA currently publishes rather than against a blog. The practical consequence is that every organization already listed in the STAR Registry has a migration to schedule, and a listing left on a withdrawn version stops being credible to a buyer well before it formally lapses.

STAR grew an AI branch, and Level 2 there runs through ISO 42001

CSA launched STAR for AI on October 23, 2025, and it is a parallel program rather than an extra question in the cloud one. It runs on the AI Controls Matrix and the AI-CAIQ instead of the CCM and the CAIQ. AICM v1.1, released June 23, 2026, carries 247 control objectives across 18 domains and added a Model Development Security domain. The part that catches teams out is the Level 2 requirement: a STAR for AI Level 2 listing pairs a Valid-AI-ted AI-CAIQ with an ISO/IEC 42001 certification, a route CSA opened on November 20, 2025. Your ISO 27001 certificate does not open that door. If you sell an AI product and want the AI listing, ISO 42001 is the prerequisite to plan around.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Drafts CAIQ v4.1 answers from your existing control library, so the work shifts from writing to reviewing and approving
  • Maps your controls to the Cloud Controls Matrix once, then reuses that mapping for every CAIQ refresh instead of restarting each year
  • Tracks the CCM v4.1 migration against your current listing, so the December 2027 cutoff is a scheduled task rather than a surprise
  • Reuses the same control evidence across CAIQ, SIG, HECVAT, SOC 2 and ISO 27001, because they ask the same underlying questions in different words
  • Holds the ISO 27001 or SOC 2 evidence that a STAR Level 2 Certification or Attestation is built on top of
  • Keeps an AI system inventory with documented purpose, limitations and human oversight, which the AI-CAIQ and AICM require
  • Flags answers that have gone stale before a buyer reading your registry entry does
  • Keeps a reusable response history, so the CAIQ refresh costs a fraction of the first submission
CSA STAR readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

STAR path reference

Which STAR path is open to you, based on the audit you already hold

Every CSA STAR comparison table published today runs on the same axis: Level 1 versus Level 2 versus Level 3, pick your level. That axis misleads twice. Level 3 is not obtainable, and Level 2 is not a level you choose, it is a consequence of which audit you already hold. The axis that decides what you can list this quarter is what is already in your evidence room.

What you already hold STAR path this opens What the listing is built on How long it stays valid What it costs you
Nothing formal yet STAR Level 1, Security Self-Assessment A completed CAIQ v4.1 answered against the Cloud Controls Matrix One year, then refresh Complimentary to submit. The cost is internal time across security, engineering and legal.
Nothing formal yet, but you want the stronger badge STAR Level 1, Valid-AI-ted The same CAIQ, scored automatically by CSA for completeness and consistency One year, then refresh Reported at 595 USD with up to ten scoring attempts, and no cost for CSA corporate members. Confirm current fees with CSA.
An ISO/IEC 27001 certificate STAR Level 2, STAR Certification Your ISO 27001 certification assessed together with the CCM Three years, matching the ISO cycle Scoped as an extension of the ISO 27001 audit rather than as a separate program
A SOC 2 report STAR Level 2, STAR Attestation Your SOC 2 engagement assessed together with the CCM One year, matching the SOC 2 reporting period Scoped as an extension of the SOC 2 engagement with the same firm
An ISO/IEC 42001 certificate and an AI product STAR for AI Level 2 A Valid-AI-ted AI-CAIQ combined with the ISO 42001 certificate Follows the ISO 42001 certificate The newest path, opened November 20, 2025. ISO 27001 does not substitute for the ISO 42001 prerequisite.
An AI product but no ISO 42001 yet STAR for AI Level 1 A self-assessed AI-CAIQ v1.1 answered against AICM v1.1 One year, then refresh Self-assessment. The real work is producing an AI inventory and human oversight records that do not exist yet.
A mature monitoring program and a continuous assurance mandate STAR Level 3, Continuous Auditing Certification Nothing. CSA has not finished defining the requirements. Not applicable Cannot be bought today. Teams wanting this generally want STAR Continuous, a thirty day refresh cadence layered on Level 1 or Level 2.

Levels and validity periods reflect the STAR program as CSA describes it in 2026, running on CCM v4.1 and CAIQ v4.1 released January 27, 2026, and AICM v1.1 released June 23, 2026. C-STAR, a third Level 2 route built on Chinese GB/T standards, is excluded here because it addresses the Greater China market rather than US buyers. Fees change, so treat any figure here as reported and confirm it with CSA before you budget.

Good questions

Questions about CSA STAR

CSA STAR is the Cloud Security Alliance assurance program for cloud and SaaS providers, built around the Security, Trust, Assurance and Risk Registry. You document your security controls against the Cloud Controls Matrix, publish the result in the public STAR Registry, and buyers check that entry during procurement instead of sending you their own questionnaire. It runs at two obtainable levels: a self-assessment and a third party audit.
Two levels are available today. Level 1 is a self-assessment where you submit a completed CAIQ, either free or through the paid Valid-AI-ted scoring option. Level 2 is a third party audit, delivered as STAR Certification on top of ISO/IEC 27001 or as STAR Attestation on top of SOC 2. A Level 3 continuous auditing certification has been discussed for years but is still not available to buy.
Level 1 is self-reported and Level 2 is independently audited. At Level 1 you answer the CAIQ yourself and publish it, which costs nothing but carries the weight of a self-assessment. At Level 2 an accredited firm assesses you against the Cloud Controls Matrix alongside an ISO 27001 or SOC 2 engagement. Level 1 is a prerequisite for Level 2, so nobody skips it.
They are the same Level 2 tier reached through different audits. STAR Certification is built on ISO/IEC 27001 and the resulting listing runs for three years in line with the ISO cycle. STAR Attestation is built on SOC 2 and runs for one year in line with the SOC 2 reporting period. Which one you pursue is usually decided by which audit you already hold rather than by preference.
Level 1 self-assessment is complimentary to submit, and the optional Valid-AI-ted scoring is reported at 595 USD with no charge for CSA corporate members. Level 2 has no list price because it is scoped as part of an ISO 27001 or SOC 2 engagement, so the drivers are your audit scope, the number of systems and locations, and the firm you use. Published Level 2 estimates vary so widely that quoting one would mislead you. Get a scoped quote from an accredited assessor.
The CAIQ, or Consensus Assessments Initiative Questionnaire, is the standardized question set that documents how a cloud provider implements each control in the Cloud Controls Matrix. It is what you actually fill in to achieve a STAR Level 1 listing, and enterprise buyers also send it directly as a vendor security questionnaire. Answering it once well means you can hand it over rather than start fresh with each buyer.
CAIQ v4.1 is current, released alongside CCM v4.1 on January 27, 2026 and superseding CCM v4.0.13. CAIQ v4.1 carries 283 questions. If you find a guide describing the CAIQ as roughly 140 questions, it is describing a superseded version, and the gap between those two numbers is the single most common planning error teams make before starting.
CSA started accepting both v4.1 and v4.0 submissions in March 2026. From December 2027 only v4.1 submissions are accepted at Level 1 and Level 2, and in January 2028 CCM v4.0.x and CAIQ v4.0.x are withdrawn. Some assessors report an earlier July 2027 cutoff for new applicants, so confirm your specific date against the timeline CSA publishes today. Organizations already in the registry get roughly a two year window from the release to migrate.
Yes. The CAIQ is published by the Cloud Security Alliance at no cost, and submitting a completed CAIQ for a STAR Level 1 self-assessment listing is complimentary. What you pay for is either the optional Valid-AI-ted scoring or, far more significantly, the internal hours it takes to answer 283 questions accurately across security, engineering, legal and privacy.
Valid-AI-ted is an optional upgrade to STAR Level 1 in which CSA uses AI to score your submitted CAIQ v4 answers automatically for completeness and consistency, gives you near instant feedback, and awards a Valid-AI-ted badge on your registry entry if you pass. It is reported at 595 USD with up to ten scoring attempts, and CSA corporate members can submit at no cost. It does not make a self-assessment into an audit.
The STAR Registry is the free public directory where completed CSA STAR submissions are published. Buyers, security teams and procurement use it to check a cloud provider before purchase, which is the whole commercial point of listing: your answers are already sitting where a prospect looks, so the assessment starts from your published entry rather than from a blank questionnaire.
STAR for AI is the AI assurance branch of the STAR program, launched October 23, 2025. It runs on the AI Controls Matrix and the AI-CAIQ rather than the CCM and the CAIQ. Level 1 is an AI-CAIQ self-assessment. Level 2, available since November 20, 2025, requires a Valid-AI-ted AI-CAIQ combined with an ISO/IEC 42001 certification.
No. The Continuous Auditing Certification often labelled Level 3 has been anticipated since 2023 and CSA is still defining the requirements, so there is no assessment to undergo and no listing to earn. AWS states this directly in its own compliance documentation. If your team wants continuous assurance today, the real option is STAR Continuous, where you refresh your documentation every thirty days on top of a Level 1 or Level 2 listing.
No, it sits on top of them. STAR Level 2 is not a standalone audit: STAR Certification is assessed alongside ISO/IEC 27001 and STAR Attestation alongside SOC 2. So the sequence runs the other way round from how people often plan it. You earn the underlying certification or report first, then extend that engagement to cover the Cloud Controls Matrix and publish the result.
A first CAIQ is commonly reported at 40 to 80 hours of internal work spread across security, engineering and operations, because 283 questions need answers that match what your systems actually do rather than what your policies aspire to. The range depends almost entirely on whether your evidence already exists in a usable form. Later refreshes cost a fraction of the first if you kept the control mapping.
Cloud and SaaS providers selling to security conscious buyers, most usefully at two points. Early stage companies use a Level 1 listing to show a documented security posture before they can fund a full audit. Established providers use Level 2 to satisfy enterprise procurement without answering the same questionnaire fifty times a year. If your buyers keep sending you cloud security questionnaires, a published listing shortens that loop.
No. Buying a tool per questionnaire format is how compliance budgets get wasted. A CAIQ from a cloud buyer, a SIG from a bank and a HECVAT from a university ask the same underlying questions in different words: how you authenticate, what you log, how you encrypt, who has access, what your subprocessors do. When those answers live in one evidence backed control library, a new format is a mapping exercise rather than a rewrite.
No. Scrutineer is readiness and response software, not a certifying body, an accredited assessor or an auditor. Only CSA accredited firms deliver STAR Certification and STAR Attestation. What Scrutineer does is hold the controls and evidence behind each CAIQ answer, draft the questionnaire from them, track the CCM v4.1 migration, and keep the listing accurate so what a buyer reads in the registry is defensible.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification