Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
CSA CCM v4.1 (matrix release 4.1.1), the cloud control framework of the Cloud Security Alliance: 207 control objectives in 17 domains (audit and assurance, application and interface security, business continuity and operational resilience, change control and configuration, cryptography and key management, datacenter security, data security and privacy lifecycle, governance risk and compliance, human resources, identity and access management, interoperability and portability, infrastructure security, logging and monitoring, incident management and cloud forensics, supply chain management, threat and vulnerability management, universal endpoint management), the control set behind CSA STAR Level 1 self-assessment (CAIQ v4.1, 283 questions) and Level 2 certification and attestation. What changed from v4.0.1: eleven controls added (AIS-08 API security; DCS-01 physical and environmental security policy, DCS-17 datacenter metrics, DCS-18 datacenter operations resilience; LOG-08 sanitising sensitive data in logs; SEF-07 incident response by category and severity, SEF-09 incident records repository and trend review; STA-01 supply chain risk management policy, STA-09 service bill of materials; TVM-04 threat analysis and modelling, TVM-10 risk-based threat response); one removed (v4.0.1 IAM-12, safeguarding log integrity); Infrastructure and Virtualization Security (IVS) renamed Infrastructure Security (I&S); controls renumbered in DCS, IAM, LOG, SEF, STA and TVM; policy reviews now also triggered by significant change; supply chain controls reworded from cloud provider and customer to service provider and customer. Matrix 4.1.1 (October 2026) adds NIST SP 800-171 rev2, MITRE ATT&CK and DORA mappings and corrects two typographic errors. CSA keeps v4.0.x acceptable for STAR during its transition period.
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 is a compliance framework from International with 17 domains and 207 controls that map to 5 other frameworks. The largest domains are CEK - Cryptography, Encryption & Key Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (21 controls), DSP - Data Security and Privacy Lifecycle Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (19 controls), DCS - Datacenter Security – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (18 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
A&A - Audit & Assurance – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
| Code | Title |
|---|---|
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-01 | Audit and Assurance Policy and Procedures |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-02 | Independent Assessments |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-03 | Risk Based Planning Assessment |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-04 | Requirements Compliance |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-05 | Audit Management Process |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::A&A-06 | Remediation |
AIS - Application & Interface Security – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
| Code | Title |
|---|---|
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-01 | Application and Interface Security Policy and Procedures |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-02 | Application Security Baseline Requirements |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-03 | Application Security Metrics |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-04 | Secure Application Development Lifecycle |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-05 | Application Security Testing |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-06 | Secure Application Deployment |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-07 | Application Vulnerability Remediation |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::AIS-08 | API Security |
BCR - Business Continuity Management and Operational Resilience – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
CCC - Change Control and Configuration Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
| Code | Title |
|---|---|
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-01 | Change Management Policy and Procedures |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-02 | Quality Testing |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-03 | Change Management Technology |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-04 | Unauthorized Change Protection |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-05 | Change Agreements |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-06 | Change Management Baseline |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-07 | Detection of Baseline Deviation |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-08 | Exception Management |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::CCC-09 | Change Restoration |
CEK - Cryptography, Encryption & Key Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
DCS - Datacenter Security – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
DSP - Data Security and Privacy Lifecycle Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
GRC - Governance, Risk and Compliance – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
| Code | Title |
|---|---|
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-01 | Governance Program Policy and Procedures |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-02 | Risk Management Program |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-03 | Organizational Policy Reviews |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-04 | Policy Exception Process |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-05 | Information Security Program |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-06 | Governance Responsibility Model |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-07 | Information System Regulatory Mapping |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::GRC-08 | Special Interest Groups |
HRS - Human Resources – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
I&S - Infrastructure Security – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
IAM - Identity & Access Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
IPY - Interoperability & Portability – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
| Code | Title |
|---|---|
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::IPY-01 | Interoperability and Portability Policy and Procedures |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::IPY-02 | Application Interface Availability |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::IPY-03 | Secure Interoperability and Portability Management |
| cloud-security-alliance-cloud-controls-matrix-ccm-v4-1::IPY-04 | Data Portability Contractual Obligations |
LOG - Logging and Monitoring – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
SEF - Security Incident Management, E-Discovery, & Cloud Forensics – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
STA - Supply Chain Management, Transparency, and Accountability – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
TVM - Threat & Vulnerability Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
UEM - Universal Endpoint Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1
Your Compliance Coverage
If you comply with Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1, you already cover:
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
95%
196 controls mapped
Compare →ISO 27002:2022
4%
9 controls mapped
Compare →NIST SP 800-53 Rev 5
4%
9 controls mapped
Compare →+ 2 more: NIST SP 800-161 Rev 1 (1%), ISO 22301:2019 (0%)
See all 5 mapped frameworks ↓Maps to 5 other frameworks
Coverage is not the same as your position
This page shows what Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 and who does it apply to?
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 is a compliance framework from International with 17 domains and 207 controls. CSA CCM v4.1 (matrix release 4.1.1), the cloud control framework of the Cloud Security Alliance: 207 control objectives in 17 domains (audit and assurance, application and interface security, business continuity and operational resilience, change control and configuration, cryptography and key management, datacenter security, data security and privacy lifecycle, governance risk and compliance, human resources, identity and access management, interoperability and portability, infrastructure security, logging and monitoring, incident management and cloud forensics, supply chain management, threat and vulnerability management, universal endpoint management), the control set behind CSA STAR Level 1 self-assessment (CAIQ v4.1, 283 questions) and Level 2 certification and attestation. What changed from v4.0.1: eleven controls added (AIS-08 API security; DCS-01 physical and environmental security policy, DCS-17 datacenter metrics, DCS-18 datacenter operations resilience; LOG-08 sanitising sensitive data in logs; SEF-07 incident response by category and severity, SEF-09 incident records repository and trend review; STA-01 supply chain risk management policy, STA-09 service bill of materials; TVM-04 threat analysis and modelling, TVM-10 risk-based threat response); one removed (v4.0.1 IAM-12, safeguarding log integrity); Infrastructure and Virtualization Security (IVS) renamed Infrastructure Security (I&S); controls renumbered in DCS, IAM, LOG, SEF, STA and TVM; policy reviews now also triggered by significant change; supply chain controls reworded from cloud provider and customer to service provider and customer. Matrix 4.1.1 (October 2026) adds NIST SP 800-171 rev2, MITRE ATT&CK and DORA mappings and corrects two typographic errors. CSA keeps v4.0.x acceptable for STAR during its transition period. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 actually require?
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 has 207 controls organised across 17 domains. The largest domains are CEK - Cryptography, Encryption & Key Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (21 controls), DSP - Data Security and Privacy Lifecycle Management – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (19 controls), DCS - Datacenter Security – Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 (18 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 do I already cover?
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 maps to 5 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (95% coverage), ISO 27002:2022 (4% coverage), NIST SP 800-53 Rev 5 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1?
Start your Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cloud Security Alliance Cloud Controls Matrix (CCM) v4.1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 207 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 934 frameworks.
Get Started Free →Free forever — no credit card required