CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
Release Date: 02/13/2026 This introduction provides foundational context and practical direction for organizations using CSA’s Cloud Controls Matrix (CCM) v4.1. The CCM is a vendo... Request to download | |
The Continuous Audit Metrics Catalog Release Date: 01/28/2026 Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo... Request to download | |
Cloud Controls Matrix and CAIQ v4.1 Release Date: 01/27/2026 The Cloud Controls Matrix (CCM) is a cybersecurity control framework made up of 207 controls across 17 security domains. The CCM maps to industry best pra... Request to download | |
Release Date: 01/27/2026 The Cloud Security Alliance, in collaboration with the CCM Working Group, proudly presents the CCM-Lite and CAIQ-Lite File Bundle. These tools offer a str... Request to download | |
![]() | Release Date: 01/26/2026 This charter establishes the mission, scope and responsibilities, goals and objectives, and operational procedures for the SCC WG. The goal of the SCC WG is... Request to download |
Release Date: 11/19/2025 The AI Controls Matrix (AICM) provides a foundational security and governance framework for AI service providers and customers. It helps them securely imp... Request to download | |
Release Date: 07/09/2025 The AI Controls Matrix (AICM) is a first-of-its-kind vendor-agnostic framework for cloud-based AI systems. Organizations can use the AICM to develop, impl... Request to download | |
AICM Implementation & Auditing Guidelines (Frameworks) Release Date: 10/22/2025 The Cloud Security Alliance (CSA) AI Controls Matrix (AICM) Implementation and Auditing Guidelines Bundle provides comprehensive direction for both implem... Request to download | |
NIST CSF v2 Cloud Community Profile - Based on CCM v4 Release Date: 10/15/2024 The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equiv... Request to download | |
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2 Release Date: 10/08/2024 The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices for securing cloud... Request to download | |
![]() | CCM v4.0 Implementation Guidelines Release Date: 06/03/2024 This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM cont... Request to download |
![]() | CCM v4.0 Addendum - ECUC PP v2.1 Release Date: 02/12/2024 This document is an addendum to the 'ECUC Position Paper v2.1 (ECUC PP v2.1) that contains controls mapping between the CSA CCM v4.0 and the ECUC PPv2.1. ... Request to download |
![]() | Release Date: 08/31/2023 The CSA Security, Trust, Assurance, and Risk (STAR) program is the most complete and largest cloud assurance program in the world that constitutes an ecos... Request to download |
![]() | Release Date: 04/05/2023 The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and up... Request to download |
![]() | CSA CCM v4.0 Addendum - IBM Cloud Framework for Financial Services v1.1.0 Release Date: 02/22/2023 This document is a CSA CCM v4.0 addendum to the IBM Cloud Framework for Financial Services v1.1.0 that contains controls mapping between the CCM and the I... Request to download |
![]() | Release Date: 10/04/2022 This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and Japan's Information System Security Management and Asse... Request to download |
![]() | CSA CCM v4.0 Addendum - CRI FS Profile v1.2 Release Date: 07/15/2022 This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t... Request to download |
![]() | Release Date: 12/08/2021 This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework align... Request to download |
Cloud Controls Matrix and CAIQ v4.0 Release Date: 06/07/2021 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download | |
![]() | Enterprise Architecture to CCM v3.01 Reordered Mapping Release Date: 05/18/2021 The EA v2 to CCM v3.0.1 Mapping is a companion piece with the Enterprise Architecture Reference Guide v2. The peer review for both documents are intended to ... Request to download |





