Scrutineer · By framework
CSA STAR certification and CAIQ questionnaire software
The CAIQ your team filled in last year is on a clock. CCM v4.1 landed in January 2026, and the v4.0 questionnaire is withdrawn in January 2028.
Scrutineer holds your controls and evidence once, then drafts CAIQ answers from them, so a STAR Registry listing becomes a review pass rather than a rebuild.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with CSA STAR
The three STAR levels you have read about are really two
Almost every published guide tables CSA STAR as Level 1, Level 2 and Level 3, and invites you to pick one. Level 3, the Continuous Auditing Certification, has been described as forthcoming for years and there is still no certification you can actually obtain. AWS says plainly that CSA is still defining the Level 3 requirements, so there is nothing to assess against. If a roadmap or a board deck at your company has Level 3 on it as a target date, that date is not real. What does exist is STAR Continuous, a cadence commitment layered on Level 1 or Level 2 where you refresh your documentation every thirty days. That is a maintenance discipline, not a third tier, and it is the thing most teams actually meant when they asked for continuous assurance.
Your CAIQ has a deadline now, and most vendors have not put it on a calendar
CCM v4.1 and CAIQ v4.1 were released on January 27, 2026, superseding CCM v4.0.13. This is a dated migration rather than a suggestion. CSA began accepting both v4.1 and v4.0 submissions for Level 1 and Level 2 in March 2026; from December 2027 only v4.1 submissions are accepted at either level; and in January 2028 CCM v4.0.x and CAIQ v4.0.x are withdrawn entirely. Some assessors report an earlier cutoff of July 2027 for brand new applicants, so confirm your own date against the timeline CSA currently publishes rather than against a blog. The practical consequence is that every organization already listed in the STAR Registry has a migration to schedule, and a listing left on a withdrawn version stops being credible to a buyer well before it formally lapses.
STAR grew an AI branch, and Level 2 there runs through ISO 42001
CSA launched STAR for AI on October 23, 2025, and it is a parallel program rather than an extra question in the cloud one. It runs on the AI Controls Matrix and the AI-CAIQ instead of the CCM and the CAIQ. AICM v1.1, released June 23, 2026, carries 247 control objectives across 18 domains and added a Model Development Security domain. The part that catches teams out is the Level 2 requirement: a STAR for AI Level 2 listing pairs a Valid-AI-ted AI-CAIQ with an ISO/IEC 42001 certification, a route CSA opened on November 20, 2025. Your ISO 27001 certificate does not open that door. If you sell an AI product and want the AI listing, ISO 42001 is the prerequisite to plan around.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Drafts CAIQ v4.1 answers from your existing control library, so the work shifts from writing to reviewing and approving
- Maps your controls to the Cloud Controls Matrix once, then reuses that mapping for every CAIQ refresh instead of restarting each year
- Tracks the CCM v4.1 migration against your current listing, so the December 2027 cutoff is a scheduled task rather than a surprise
- Reuses the same control evidence across CAIQ, SIG, HECVAT, SOC 2 and ISO 27001, because they ask the same underlying questions in different words
- Holds the ISO 27001 or SOC 2 evidence that a STAR Level 2 Certification or Attestation is built on top of
- Keeps an AI system inventory with documented purpose, limitations and human oversight, which the AI-CAIQ and AICM require
- Flags answers that have gone stale before a buyer reading your registry entry does
- Keeps a reusable response history, so the CAIQ refresh costs a fraction of the first submission
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
STAR path reference
Which STAR path is open to you, based on the audit you already hold
Every CSA STAR comparison table published today runs on the same axis: Level 1 versus Level 2 versus Level 3, pick your level. That axis misleads twice. Level 3 is not obtainable, and Level 2 is not a level you choose, it is a consequence of which audit you already hold. The axis that decides what you can list this quarter is what is already in your evidence room.
| What you already hold | STAR path this opens | What the listing is built on | How long it stays valid | What it costs you |
|---|---|---|---|---|
| Nothing formal yet | STAR Level 1, Security Self-Assessment | A completed CAIQ v4.1 answered against the Cloud Controls Matrix | One year, then refresh | Complimentary to submit. The cost is internal time across security, engineering and legal. |
| Nothing formal yet, but you want the stronger badge | STAR Level 1, Valid-AI-ted | The same CAIQ, scored automatically by CSA for completeness and consistency | One year, then refresh | Reported at 595 USD with up to ten scoring attempts, and no cost for CSA corporate members. Confirm current fees with CSA. |
| An ISO/IEC 27001 certificate | STAR Level 2, STAR Certification | Your ISO 27001 certification assessed together with the CCM | Three years, matching the ISO cycle | Scoped as an extension of the ISO 27001 audit rather than as a separate program |
| A SOC 2 report | STAR Level 2, STAR Attestation | Your SOC 2 engagement assessed together with the CCM | One year, matching the SOC 2 reporting period | Scoped as an extension of the SOC 2 engagement with the same firm |
| An ISO/IEC 42001 certificate and an AI product | STAR for AI Level 2 | A Valid-AI-ted AI-CAIQ combined with the ISO 42001 certificate | Follows the ISO 42001 certificate | The newest path, opened November 20, 2025. ISO 27001 does not substitute for the ISO 42001 prerequisite. |
| An AI product but no ISO 42001 yet | STAR for AI Level 1 | A self-assessed AI-CAIQ v1.1 answered against AICM v1.1 | One year, then refresh | Self-assessment. The real work is producing an AI inventory and human oversight records that do not exist yet. |
| A mature monitoring program and a continuous assurance mandate | STAR Level 3, Continuous Auditing Certification | Nothing. CSA has not finished defining the requirements. | Not applicable | Cannot be bought today. Teams wanting this generally want STAR Continuous, a thirty day refresh cadence layered on Level 1 or Level 2. |
Levels and validity periods reflect the STAR program as CSA describes it in 2026, running on CCM v4.1 and CAIQ v4.1 released January 27, 2026, and AICM v1.1 released June 23, 2026. C-STAR, a third Level 2 route built on Chinese GB/T standards, is excluded here because it addresses the Greater China market rather than US buyers. Fees change, so treat any figure here as reported and confirm it with CSA before you budget.
Good questions
Questions about CSA STAR
Keep reading
Guides that go deeper on this framework
Best CSA STAR certification software
The four categories of tooling sold against CSA STAR, what each actually does, and where every category stops short of a listing.
Read the guideBest security questionnaire automation software
How the questionnaire response tools compare on format coverage, portal support and answer accuracy, with reported pricing.
Read the guideAutomating security questionnaires
How SIG, CAIQ and bespoke questionnaires get answered from an evidence-backed control library instead of from scratch.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification