Cloud Security Alliance
Cloud Security Alliance is a Seattle-based not-for-profit that develops vendor-neutral cloud, AI, and Zero Trust security frameworks, runs the STAR assurance registry with 2,500+ entries, and offers industry-recognized certifications (CCSK, CCZT, TAISE) to a 150,000+ member community across 60+ countries.
- Company typePrivate
- Founded2008
- HeadquartersSeattle, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingServices
What Cloud Security Alliance does
Cloud Security Alliance (CSA) is a not-for-profit organization founded in 2009 and headquartered in Seattle, with regional operations in Berlin, serving as a vendor-neutral body for cloud, AI, and Zero Trust security standards, assurance, and practitioner credentialing. It serves a global community of 150,000+ members organized through 150+ chapters across 60+ countries, alongside enterprise members including hyperscalers, regulated financial institutions, and security vendors. The organization develops and stewards the de-facto industry frameworks used by cloud service providers, their customers, and third-party auditors to document and attest security controls.
CSA's technology portfolio centers on a stack of interlocking standards: the Cloud Controls Matrix (CCM) and Consensus Assessments Initiative Questionnaire (CAIQ v4) form the foundation of the STAR Program — a multi-level assurance registry (Level 1 self-assessment, Level 2 third-party certification) that lists 2,500+ cloud and AI service providers. More recent additions include the AI Controls Matrix (AICM v1.1) with 247 control objectives across 18 security domains aligned to ISO 42001, NIST AI RMF, and the EU AI Act; the Software Defined Perimeter (SDP) zero trust specification; the RiskRubric AI scoring methodology; the NIST AI RMF Agentic Profile; and the AAGATE reference architecture for agentic AI. The CSAI Foundation, launched at RSAC 2026 and authorized as a CVE Numbering Authority through MITRE, extends CSA into agentic-AI threat intelligence, the Catastrophic Risk Annex of STAR for AI, and stewardship of the Autonomous Action Runtime Management and Agentic Trust Framework specifications.
CSA's revenue is generated through six streams: recurring corporate membership dues, per-seat certification fees (CCSK, CCZT, TAISE, CCAK, ACSP, plus STAR Auditor Training), STAR Registry listing and audit fees, event sponsorships and conference fees for in-person and virtual events, framework and research artifact licensing, and commissioned survey and research partnerships with technology vendors. Distribution runs through direct enterprise sales for corporate memberships, a self-serve training and exams platform for individual practitioners, a global chapter network that hosts local events and translates research, and a channel ecosystem of Certified STAR Auditors, Training Partners, and authorized instructors. Pricing for individual certifications, corporate membership tiers, and STAR submissions is not publicly disclosed.
Cloud Security Alliance firmographics
Firmographics- Name
- Cloud Security Alliance
- Legal name
- Cloud Security Alliance
- Website
- https://cloudsecurityalliance.org
- Company type
- Private
- Founded year
- 2008
- Headcount range
- 501–1,000 employees
- Short description
- Cloud Security Alliance is a Seattle-based not-for-profit that develops vendor-neutral cloud, AI, and Zero Trust security frameworks, runs the STAR assurance registry with 2,500+ entries, and offers industry-recognized certifications (CCSK, CCZT, TAISE) to a 150,000+ member community across 60+ countries.
- Ownership category
- akta.pro rank
Cloud Security Alliance industry classification
Industry- Product category
- Cloud Security Standards and Certification
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
- akta.pro secondary industry
- Cloud & SaaS Security Awareness (e.g., M365/Google Workspace) (EDABAGAG)
Keywords
Where Cloud Security Alliance is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cloud Security Alliance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Revenue model
- Corporate Membership Fees: Recurring corporate membership dues across tiers for solution providers, cloud solution providers, and other organizations, granting market visibility, brand awareness, trusted security expertise access, member-exclusive programs (STAR Enabled Solutions, Trusted Cloud Provider, Trusted AI & Cloud Consultant), and partnership benefits.
- Certification and Training Fees: Per-seat and per-course fees for industry-recognized certifications including Certificate of Cloud Security Knowledge (CCSK), Certificate of Cloud Auditing Knowledge (CCAK), Certificate of Competence in Zero Trust (CCZT), Trusted AI Safety Expert (TAISE), Advanced Cloud Security Practitioner (ACSP), and STAR Auditor Training. Revenue also generated through CCSK Train the Trainer, instructor certification, and the Training Partner Network.
- STAR Registry and Assurance Program Fees: Listing, assessment, and certification fees for cloud and AI service providers publishing to CSA's STAR Registry (2,500+ entries). Includes STAR Level 1 self-assessment, STAR Level 2 third-party audits through Certified STAR Auditors, and STAR for AI Catastrophic Risk Annex attestation.
- Event Sponsorships and Conference Fees: Sponsorship packages and attendee fees for in-person conferences (GITEX AI Europe, Boston Leadership Exchange, CSA Japan Summit, XCON) and virtual events/webinars including CloudBytes Webinar Series and Research Webinar Series.
- Research and Artifact Licensing: Distribution and licensing of CSA research publications, framework downloads (CCM, AICM, CAIQ, EU Cloud Code of Conduct, top threats reports, guidance documents), and CSA Startup Showcase registry listing for emerging vendors.
- Commissioned Survey and Research Partnerships: Joint research and survey programs commissioned by technology vendors (Thales, Strata Identity, Aembit, Anjuna, Token Security, Miggo Security, FranklinCovey, Dropzone AI, Zenity), which fund research execution while providing sponsors with branded insights and benchmark data.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Corporate Membership (Solution Providers / Cloud Solution Providers / Enterprises) |
| Per seat | Pay-as-you-go | Individual Certifications (CCSK, CCZT, TAISE, CCAK, ACSP) |
| Per seat | Pay-as-you-go | Team and Government Training |
| Other | Annual | STAR Registry Listing and Audits |
| Other | Pay-as-you-go | Event Sponsorships |
Go-to-market motion5 records
Distribution channels7 records
Marketing channels10 records
Cloud Security Alliance product offering
Product offeringCore offering
CSA develops and operates vendor-neutral security frameworks, control matrices, certification programs, and a public assurance registry for cloud, AI, and Zero Trust environments. The flagship deliverable is the STAR (Security, Trust, Assurance and Risk) Program with 2,500+ registry entries built on the Cloud Controls Matrix (CCM) and CAIQ, complemented by industry-recognized individual certifications (CCSK, CCZT, TAISE, CCAK, ACSP) and the AI Controls Matrix (AICM). Revenue is generated through corporate memberships, certification and training fees, STAR Registry listing/audit fees, event sponsorships, and research licensing.
Product overview
CSA delivers a portfolio-centric, not single-product, architecture centered on the STAR Program as the public-facing assurance registry (with 2,500+ entries and STAR Level 1, Level 2, and STAR for AI variants built on the Cloud Controls Matrix and CAIQ). Surrounding the STAR core are governance frameworks (CCM, CAIQ, AI Controls Matrix v1.1, EU Cloud Code of Conduct), industry-recognized training certificates (CCSK, CCZT, TAISE, CCAK, ACSP), and a set of strategic initiatives — AI Safety Initiative, Zero Trust Advancement Center, Compliance Automation Revolution, FinCloud Security, CxO Trust, Trusted AI & Cloud Consultant, and Trusted Cloud Provider. The CSAI Foundation (launched 2026) and the RiskRubric v2 ecosystem extend CSA into agentic AI governance and AI risk scoring; Circle and CSA Chapters (150+ chapters in 60+ countries with 150k+ members) anchor the community layer. Research artifacts (Cloud Threat Modeling Guide v2.0, NIST AI RMF Agentic Profile, MythosReady draft report) and CCAK-complementing certifications round out the offering.
Differentiator
Problem solved
Functional benefit
Products and services
- STAR (Security, Trust, Assurance and Risk) Program
- Cloud Controls Matrix (CCM)
- Consensus Assessments Initiative Questionnaire (CAIQ) v4
- AI Controls Matrix (AICM) v1.1
- Certificate of Cloud Security Knowledge (CCSK)
- Certificate of Competence in Zero Trust (CCZT)
- Trusted AI Safety Expert (TAISE) Certificate
- Certificate of Cloud Auditing Knowledge (CCAK)
- Advanced Cloud Security Practitioner (ACSP) Training
- EU Cloud Code of Conduct
- STAR Auditor Training
- Corporate Membership (Solution Providers, Cloud Solution Providers, Enterprises)
- CSAI Foundation
- STAR for AI Certification Program
- Trusted AI & Cloud Consultant (TAICC)
- Trusted Cloud Provider (TCP)
- CSA Startup Showcase Registry
- STAR Enabled Solutions
- CSA Training Platform
- CSA Exams Platform
Quantifiable outcome
- 2,500+ entries in CSA STAR Registry
- +7 more outcomes
Companies that use Cloud Security Alliance
Customer profileNamed customers10 records
Ideal customer profiles4 records
Cloud Security Alliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature10 records
Cloud Security Alliance partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered core, flagship and minor.
- ThalescoreJoint CSA-Thales survey found that 68% of 210 organizations surveyed have significant unprotected unstructured data, yet 75% describe themselves as moderately or highly confident in their security posture. The discussion identifies AI tools as a forcing function that has exposed the risks of unmanaged unstructured data.
- AnjunacoreAnjuna commissioned the CSA survey of 340 global IT and security professionals (January-March 2026) showing 62% of financial services organizations have deployed AI agents, 93% of which grant agents some autonomy, and 20% experienced known AI-security incidents.
- FranklinCoveycoreJoint CSA-FranklinCovey surveys found significant gaps in AI governance across financial organizations, with 62% using AI agents but 41% unaware whether their company experienced AI security incidents and 80% of managers taking a hands-off approach to AI oversight. Only 14% of employees received formal AI training.
- TumerykflagshipTumeryk joined CSA's RiskRubric ecosystem as an official AI risk assessment and scoring provider. Tumeryk CEO Rohit Valia co-authored the RiskRubric v2 Concept Paper and contributed to the framework's updated scoring methodology. The company also launched the beta of its AI Trust Score assessment service designed to help enterprises quantify the trustworthiness of AI models, agents, and MCP servers, with the scanner covering prompt injection, jailbreak resistance, privacy leakage, bias, hallucinations, transparency, reliability, and agentic boundary violations.
- Miggo SecuritycoreCSA-Miggo Security survey of 902 IT and security professionals found 80% of organizations experienced at least one application security incident in the past 12 months, with 35% taking four to seven days to identify critical vulnerabilities in production environments. 42% expect to increase spending on runtime security over 12-24 months.
- VantacoreCSAI Foundation acquired the Autonomous Action Runtime Management specification from Vanta as part of expanding its capacity to secure the agentic AI control plane and extending CSA's AI Controls Matrix with the Catastrophic Risk Annex.
- MassiveScale.AI (Josh Woodruff)coreCSAI Foundation acquired stewardship of the Agentic Trust Framework from MassiveScale.AI founder Josh Woodruff as part of expanding its capacity to secure the agentic AI control plane and supporting AI governance frameworks.
- MITRE (CVE Numbering Authority authorization)flagshipCSAI Foundation was authorized as a CVE Numbering Authority through MITRE, enabling the foundation to assign official CVE identifiers for AI security vulnerabilities as part of its mission to secure the agentic AI control plane.
- Token SecuritycoreCSA report commissioned by Token Security found 82% of enterprises have unknown AI agents running in their IT infrastructure, with 65% experiencing AI agent-related incidents. 61% suffered data exposure, 43% operational disruption, and only 21% have formal decommissioning processes.
- Identity Week America 2026minorCSA participating as an industry body speaker alongside Capital One, Chase, Varo Bank, Wintrust Financial Corp, Proof, and Secure Technology Alliance at Identity Week America 2026 covering digital identity and payment innovation in the financial sector.
- ZenityflagshipZenity joined the Coalition for Secure AI and released a joint report with CSA revealing that nearly half of organizations have experienced at least one AI agent-related security incident. Zenity exhibits at Black Hat Asia and ServiceNow Knowledge 2026, building enterprise brand visibility with CSA research as anchor content.
- SANS Institute, OWASP GenAI, [un]promptedflagshipJoint industry report The 'AI Vulnerability Storm': Building a 'Mythos-Ready' Security Program developed by SANS Institute, CSA, [un]prompted, and OWASP GenAI with contributions from over 250 CISOs, providing a risk register, priority actions, and board briefing materials.
- AembitcoreCSA survey commissioned by Aembit found that 68% of organizations cannot clearly distinguish between human and AI agent activity, while 74% say AI agents receive more access than necessary and 79% believe agents create new access pathways difficult to monitor. CSA Chief Scientific Officer John Yeoh also presented at NHIcon 2026 alongside Aembit CEO David Goldschlag on non-human identity challenges.
- Strata IdentitycoreCSA survey commissioned by Strata Identity found 84% of organizations doubted they could pass a compliance audit focused on agent behavior or access controls, with only 18% expressing high confidence in current IAM systems' ability to manage agent identities. Survey covered 285 IT and security professionals and identified static API key use as a top vulnerability.
- MITRE Center for Threat-Informed Defense (CTID)flagshipMITRE CTID, in partnership with CSA, Citigroup, CrowdStrike, Fortinet, and JPMorgan Chase, released research mapping cloud security controls to the MITRE ATT&CK framework to help organizations improve cloud security by identifying and addressing vulnerabilities based on real-world attack behaviors.
- Dropzone AIcoreCSA benchmark study with Dropzone AI showed 22-29% better investigation accuracy and 45-61% faster completion times for AI SOC analysts. A separate study involving 148 security professionals validated faster decision-making, more detailed investigations, and reduced fatigue with AI assistance.
- Sign In SolutionsminorSign In Solutions joined CSA to reinforce its cybersecurity standards as part of expanded GRC capabilities supporting secure visitor management at global facilities, including progress toward FedRAMP Moderate authorization.
- ISACAflagshipISACA and CSA jointly administered the Certificate of Cloud Auditing Knowledge (CCAK) credential. As of October 3, 2025, CCAK is no longer available on the ISACA website; CSA has expressed hope to bring the certification back or assist the community in finding alternatives.
- CSA South Africa ChaptercoreCSA SA Chapter established November 2024 with Ayanda Peta as president and chairperson. Membership process opened in 2026 and the chapter endorsed the ITWeb Security Summit JHB 2026, aiming to educate on cloud security best practices, develop skills, and strengthen industry collaboration in South Africa.
Scale indicators11 records
Recent moves9 records
Expansion highlights8 records
Cloud Security Alliance competitors and assessment
Company assessmentBroad incumbents
- ISACA: Global professional association for IT governance, risk, audit, and cybersecurity. Directly comparable as a membership- and certification-driven non-profit that co-managed the CCAK credential with CSA until October 2025 and competes in cloud auditing certifications, COBIT, and CISA-level training.
- SANS Institute: Largest cybersecurity training and certification provider with deep GIAC credential portfolio. Comparable to CSA in practitioner training, certification, and research output (SANS co-authored the MythosReady report with CSA) and competes in the same enterprise training wallet.
- MITRE Corporation: Federally funded research body operating the CVE program and MITRE ATT&CK framework. Direct strategic partner (joint research with CSA on cloud-ATT&CK mapping) and comparable as an authoritative security standards publisher that grants the CVE Numbering Authority authorization CSAI Foundation now holds.
- NIST (National Institute of Standards and Technology): U.S. government standards body publishing the AI Risk Management Framework and CSF that CSA's AICM and STAR for AI explicitly map to. Comparable as a free, authoritative source of security frameworks and certifications that enterprises and government buyers adopt.
- The Linux Foundation: Foundational open-source foundation hosting CNCF, OpenSSF, and LF AI & Data. Comparable as a large non-profit that operates working groups, certification programs (Linux Foundation Certified), and global events with a similar community-led governance model.
Direct peers
- (ISC)²: Premier cybersecurity professional certification body (CISSP, CCSP, CSSLP). Direct peer as a non-profit that monetizes vendor-neutral credentials, member dues, and training — comparable to CSA's CCSK, CCZT, and TAISE certification portfolio.
- OWASP Foundation: Open-source, non-profit security community producing widely adopted frameworks (OWASP Top 10, ASVS, SAMM) and standards. Direct peer as a vendor-neutral, community-led standards body with similar governance model and a comparable role for OWASP GenAI in AI security.
- International Association of Privacy Professionals (IAPP): Non-profit professional association for privacy practitioners offering certifications (CIPP, CIPM, CIPT), training, and research. Direct peer with similar non-profit, certification-led, conference-and-membership monetization model.
Regional players
- Cloud Native Computing Foundation (CNCF): Linux Foundation sub-foundation for cloud-native open-source projects with certification programs (CKA, CKAD, KCNA). Comparable as a non-profit running Kubernetes/Cloud security certifications and working groups that overlap with CSA's cloud and AI security scope.
Emerging players
- ISACA's CMMI Institute: ISACA subsidiary offering process-maturity assessments and certifications. Comparable as a standards-body-adjacent assurance and certification program in the same cybersecurity governance category as CSA's STAR and CCZT.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat8 records
Key risks6 records
Key highlights7 records
Customer concentration
Cloud Security Alliance social profiles
Digital presenceCloud Security Alliance compliance and trust
Trust signalCompliance6 records
Cloud Security Alliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cloud Security Alliance leadership team
Management profileNumber of profiles
Profiles22 records
Cloud Security Alliance subsidiaries and ownership
Company hierarchySubsidiaries1 record
Cloud Security Alliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cloud Security Alliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cloud Security Alliance
What does Cloud Security Alliance do?
CSA develops and operates vendor-neutral security frameworks, control matrices, certification programs, and a public assurance registry for cloud, AI, and Zero Trust environments. The flagship deliverable is the STAR (Security, Trust, Assurance and Risk) Program with 2,500+ registry entries built on the Cloud Controls Matrix (CCM) and CAIQ, complemented by industry-recognized individual certifications (CCSK, CCZT, TAISE, CCAK, ACSP) and the AI Controls Matrix (AICM). Revenue is generated through corporate memberships, certification and training fees, STAR Registry listing/audit fees, event sponsorships, and research licensing.
Is Cloud Security Alliance a public or private company?
Cloud Security Alliance is a private company. It is classified as nonprofit foundation owned.
When was Cloud Security Alliance founded?
Cloud Security Alliance was founded in 2008. It employs 501 to 1,000 people.
Where is Cloud Security Alliance based?
Cloud Security Alliance is headquartered in Seattle, United States, in the North America region.
How does Cloud Security Alliance make money?
Six revenue lines are on record. Corporate Membership Fees are the primary driver. The others are certification and Training Fees, STAR Registry and Assurance Program Fees, event Sponsorships and Conference Fees, research and Artifact Licensing and commissioned Survey and Research Partnerships.
Who are Cloud Security Alliance's main competitors?
Broad incumbents on record are ISACA, SANS Institute, MITRE Corporation, NIST (National Institute of Standards and Technology) and The Linux Foundation. Direct peers are (ISC)², OWASP Foundation and International Association of Privacy Professionals (IAPP). Cloud Native Computing Foundation (CNCF) is listed as a regional player. ISACA's CMMI Institute is listed as an emerging player.
Does Cloud Security Alliance have an API?
No public API is recorded for Cloud Security Alliance.
What industry is Cloud Security Alliance in?
Cloud Security Alliance's product category is Cloud Security Standards and Certification. Its primary akta.pro industry code is HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC), with a secondary code of EDABAGAG, Cloud & SaaS Security Awareness (e.g., M365/Google Workspace). Its NAICS code is 5132 and its SIC code is 7372.