Developer docs
API playgroundTry for free, no card

Search company profiles

Cloud Security Alliance

Full company profile

uuid0003z7h

Namestring
Cloud Security Alliance
Legal namestring
Cloud Security Alliance
Company typeenum
Private
Founded yearint
2008
Descriptiontext

Cloud Security Alliance (CSA) is a not-for-profit organization founded in 2009 and headquartered in Seattle, with regional operations in Berlin, serving as a vendor-neutral body for cloud, AI, and Zero Trust security standards, assurance, and practitioner credentialing. It serves a global community of 150,000+ members organized through 150+ chapters across 60+ countries, alongside enterprise members including hyperscalers, regulated financial institutions, and security vendors. The organization develops and stewards the de-facto industry frameworks used by cloud service providers, their customers, and third-party auditors to document and attest security controls.

CSA's technology portfolio centers on a stack of interlocking standards: the Cloud Controls Matrix (CCM) and Consensus Assessments Initiative Questionnaire (CAIQ v4) form the foundation of the STAR Program — a multi-level assurance registry (Level 1 self-assessment, Level 2 third-party certification) that lists 2,500+ cloud and AI service providers. More recent additions include the AI Controls Matrix (AICM v1.1) with 247 control objectives across 18 security domains aligned to ISO 42001, NIST AI RMF, and the EU AI Act; the Software Defined Perimeter (SDP) zero trust specification; the RiskRubric AI scoring methodology; the NIST AI RMF Agentic Profile; and the AAGATE reference architecture for agentic AI. The CSAI Foundation, launched at RSAC 2026 and authorized as a CVE Numbering Authority through MITRE, extends CSA into agentic-AI threat intelligence, the Catastrophic Risk Annex of STAR for AI, and stewardship of the Autonomous Action Runtime Management and Agentic Trust Framework specifications.

CSA's revenue is generated through six streams: recurring corporate membership dues, per-seat certification fees (CCSK, CCZT, TAISE, CCAK, ACSP, plus STAR Auditor Training), STAR Registry listing and audit fees, event sponsorships and conference fees for in-person and virtual events, framework and research artifact licensing, and commissioned survey and research partnerships with technology vendors. Distribution runs through direct enterprise sales for corporate memberships, a self-serve training and exams platform for individual practitioners, a global chapter network that hosts local events and translates research, and a channel ecosystem of Certified STAR Auditors, Training Partners, and authorized instructors. Pricing for individual certifications, corporate membership tiers, and STAR submissions is not publicly disclosed.

Short descriptiontext

Cloud Security Alliance is a Seattle-based not-for-profit that develops vendor-neutral cloud, AI, and Zero Trust security frameworks, runs the STAR assurance registry with 2,500+ entries, and offers industry-recognized certifications (CCSK, CCZT, TAISE) to a 150,000+ member community across 60+ countries.

Ownership categoryenum
Headcount rangeband
501–1,000
akta.pro rankint
HeadquartersSeattle, United States
HQ citystring
Seattle
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cloud security frameworks, AI governance standards, zero trust certification, cloud assurance registry, security compliance training
Industry2 codes
1Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC)
CodeHDABAHAIPrimaryYes
2Cloud & SaaS Security Awareness (e.g., M365/Google Workspace)
CodeEDABAGAGPrimaryNo
NAICS code1 code
  • Software Publishers5132
SIC code1 code
  • Services-Prepackaged Software7372
Product category
Cloud Security Standards and Certification
Social media profiles2 records
GTM motion5 records

Each record includes

Type, Description, Source

Revenue model6 records
1Corporate Membership Fees
TypeSubscription Recurring
Description

Recurring corporate membership dues across tiers for solution providers, cloud solution providers, and other organizations, granting market visibility, brand awareness, trusted security expertise access, member-exclusive programs (STAR Enabled Solutions, Trusted Cloud Provider, Trusted AI & Cloud Consultant), and partnership benefits.

cloudsecurityalliance.org
2Certification and Training Fees
TypeSubscription Recurring
Description

Per-seat and per-course fees for industry-recognized certifications including Certificate of Cloud Security Knowledge (CCSK), Certificate of Cloud Auditing Knowledge (CCAK), Certificate of Competence in Zero Trust (CCZT), Trusted AI Safety Expert (TAISE), Advanced Cloud Security Practitioner (ACSP), and STAR Auditor Training. Revenue also generated through CCSK Train the Trainer, instructor certification, and the Training Partner Network.

cloudsecurityalliance.org
3STAR Registry and Assurance Program Fees
TypeLicensing Royalties
Description

Listing, assessment, and certification fees for cloud and AI service providers publishing to CSA's STAR Registry (2,500+ entries). Includes STAR Level 1 self-assessment, STAR Level 2 third-party audits through Certified STAR Auditors, and STAR for AI Catastrophic Risk Annex attestation.

cloudsecurityalliance.org
4Event Sponsorships and Conference Fees
TypeAdvertising
Description

Sponsorship packages and attendee fees for in-person conferences (GITEX AI Europe, Boston Leadership Exchange, CSA Japan Summit, XCON) and virtual events/webinars including CloudBytes Webinar Series and Research Webinar Series.

cloudsecurityalliance.org
5Research and Artifact Licensing
TypeLicensing Royalties
Description

Distribution and licensing of CSA research publications, framework downloads (CCM, AICM, CAIQ, EU Cloud Code of Conduct, top threats reports, guidance documents), and CSA Startup Showcase registry listing for emerging vendors.

cloudsecurityalliance.org
6Commissioned Survey and Research Partnerships
TypeProfessional Services
Description

Joint research and survey programs commissioned by technology vendors (Thales, Strata Identity, Aembit, Anjuna, Token Security, Miggo Security, FranklinCovey, Dropzone AI, Zenity), which fund research execution while providing sponsors with branded insights and benchmark data.

cloudsecurityalliance.org
Marketing channels10 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels7 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components6 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Pricing details5 tiers
1Corporate Membership (Solution Providers / Cloud Solution Providers / Enterprises)
ModelSubscriptionBilling cadenceAnnual
Notes

Membership benefits and tiers not publicly listed; engaged via Become a Member contact flow. Includes STAR Enabled Solutions, Trusted Cloud Provider, Trusted AI & Cloud Consultant, CSA Startup Showcase listing, and event sponsorships.

cloudsecurityalliance.org
2Individual Certifications (CCSK, CCZT, TAISE, CCAK, ACSP)
ModelPer seatBilling cadencePay-as-you-go
Notes

Vendor-neutral cloud, Zero Trust, AI safety, auditing, and practitioner credentials priced per candidate; exam registration hosted on exams.cloudsecurityalliance.org. Pricing not publicly disclosed.

cloudsecurityalliance.org
3Team and Government Training
ModelPer seatBilling cadencePay-as-you-go
Notes

Train-my-entire-team and Training for Government Agencies (GSA Schedule) available; STAR Auditor Training offered. Pricing not publicly disclosed.

cloudsecurityalliance.org
4STAR Registry Listing and Audits
ModelOtherBilling cadenceAnnual
Notes

STAR Level 1 (self-assessment), STAR Level 2 (third-party audit/certification via Certified STAR Auditors), and STAR for AI Catastrophic Risk Annex certification fees structured per submission and attestation scope. Pricing not publicly disclosed.

cloudsecurityalliance.org
5Event Sponsorships
ModelOtherBilling cadencePay-as-you-go
Notes

Sponsorship tiers available for in-person conferences (GITEX AI Europe, Boston Leadership Exchange, CSA Japan Summit, XCON) and Virtual Events/Webinars. Pricing not publicly disclosed.

cloudsecurityalliance.org
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

CSA develops and operates vendor-neutral security frameworks, control matrices, certification programs, and a public assurance registry for cloud, AI, and Zero Trust environments. The flagship deliverable is the STAR (Security, Trust, Assurance and Risk) Program with 2,500+ registry entries built on the Cloud Controls Matrix (CCM) and CAIQ, complemented by industry-recognized individual certifications (CCSK, CCZT, TAISE, CCAK, ACSP) and the AI Controls Matrix (AICM). Revenue is generated through corporate memberships, certification and training fees, STAR Registry listing/audit fees, event sponsorships, and research licensing.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 8 values shown
  • 2,500+ entries in CSA STAR Registry
+7 more records
Product overview1 text field

CSA delivers a portfolio-centric, not single-product, architecture centered on the STAR Program as the public-facing assurance registry (with 2,500+ entries and STAR Level 1, Level 2, and STAR for AI variants built on the Cloud Controls Matrix and CAIQ). Surrounding the STAR core are governance frameworks (CCM, CAIQ, AI Controls Matrix v1.1, EU Cloud Code of Conduct), industry-recognized training certificates (CCSK, CCZT, TAISE, CCAK, ACSP), and a set of strategic initiatives — AI Safety Initiative, Zero Trust Advancement Center, Compliance Automation Revolution, FinCloud Security, CxO Trust, Trusted AI & Cloud Consultant, and Trusted Cloud Provider. The CSAI Foundation (launched 2026) and the RiskRubric v2 ecosystem extend CSA into agentic AI governance and AI risk scoring; Circle and CSA Chapters (150+ chapters in 60+ countries with 150k+ members) anchor the community layer. Research artifacts (Cloud Threat Modeling Guide v2.0, NIST AI RMF Agentic Profile, MythosReady draft report) and CCAK-complementing certifications round out the offering.

Product and service20 records
1STAR (Security, Trust, Assurance and Risk) Program
Categorycloud security assurance program
2Cloud Controls Matrix (CCM)
Categorycloud security control framework
3Consensus Assessments Initiative Questionnaire (CAIQ) v4
Categorysecurity assessment questionnaire
4AI Controls Matrix (AICM) v1.1
CategoryAI governance framework
5Certificate of Cloud Security Knowledge (CCSK)
Categorycloud security certification
6Certificate of Competence in Zero Trust (CCZT)
Categoryzero trust certification
7Trusted AI Safety Expert (TAISE) Certificate
CategoryAI safety certification
8Certificate of Cloud Auditing Knowledge (CCAK)
Categorycloud auditing certification
9Advanced Cloud Security Practitioner (ACSP) Training
Categorycloud security training
10EU Cloud Code of Conduct
Categorycompliance code of conduct
11STAR Auditor Training
Categoryauditor training program
12Corporate Membership (Solution Providers, Cloud Solution Providers, Enterprises)
Categorycorporate membership subscription
13CSAI Foundation
Categorynon-profit foundation / AI safety stewardship
14STAR for AI Certification Program
CategoryAI assurance program
15Trusted AI & Cloud Consultant (TAICC)
Categoryconsultant referral program
16Trusted Cloud Provider (TCP)
Categorycloud provider member program
17CSA Startup Showcase Registry
Categorystartup registry program
18STAR Enabled Solutions
Categorymember listing program
19CSA Training Platform
Categoryonline training platform
20CSA Exams Platform
Categoryonline certification exam platform
Scale indicator11 records

Each record includes

Type, Value, Description, Source

Partnership19 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-09
Description

Joint CSA-Thales survey found that 68% of 210 organizations surveyed have significant unprotected unstructured data, yet 75% describe themselves as moderately or highly confident in their security posture. The discussion identifies AI tools as a forcing function that has exposed the risks of unmanaged unstructured data.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-09
Description

Anjuna commissioned the CSA survey of 340 global IT and security professionals (January-March 2026) showing 62% of financial services organizations have deployed AI agents, 93% of which grant agents some autonomy, and 20% experienced known AI-security incidents.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-09
Description

Joint CSA-FranklinCovey surveys found significant gaps in AI governance across financial organizations, with 62% using AI agents but 41% unaware whether their company experienced AI security incidents and 80% of managers taking a hands-off approach to AI oversight. Only 14% of employees received formal AI training.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-06-08
Description

Tumeryk joined CSA's RiskRubric ecosystem as an official AI risk assessment and scoring provider. Tumeryk CEO Rohit Valia co-authored the RiskRubric v2 Concept Paper and contributed to the framework's updated scoring methodology. The company also launched the beta of its AI Trust Score assessment service designed to help enterprises quantify the trustworthiness of AI models, agents, and MCP servers, with the scanner covering prompt injection, jailbreak resistance, privacy leakage, bias, hallucinations, transparency, reliability, and agentic boundary violations.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-03
Description

CSA-Miggo Security survey of 902 IT and security professionals found 80% of organizations experienced at least one application security incident in the past 12 months, with 35% taking four to seven days to identify critical vulnerabilities in production environments. 42% expect to increase spending on runtime security over 12-24 months.

Strategic tierCoreTypeOEM/ Whitelabel/ Licensing PartnerAnnounced on2026-04-30
Description

CSAI Foundation acquired the Autonomous Action Runtime Management specification from Vanta as part of expanding its capacity to secure the agentic AI control plane and extending CSA's AI Controls Matrix with the Catastrophic Risk Annex.

Strategic tierCoreTypeOEM/ Whitelabel/ Licensing PartnerAnnounced on2026-04-30
Description

CSAI Foundation acquired stewardship of the Agentic Trust Framework from MassiveScale.AI founder Josh Woodruff as part of expanding its capacity to secure the agentic AI control plane and supporting AI governance frameworks.

Strategic tierFlagshipTypeTechnology or IntegrationAnnounced on2026-04-30
Description

CSAI Foundation was authorized as a CVE Numbering Authority through MITRE, enabling the foundation to assign official CVE identifiers for AI security vulnerabilities as part of its mission to secure the agentic AI control plane.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-26
Description

CSA report commissioned by Token Security found 82% of enterprises have unknown AI agents running in their IT infrastructure, with 65% experiencing AI agent-related incidents. 61% suffered data exposure, 43% operational disruption, and only 21% have formal decommissioning processes.

Strategic tierMinorTypeGTM or Marketing PartnerAnnounced on2026-04-20
Description

CSA participating as an industry body speaker alongside Capital One, Chase, Varo Bank, Wintrust Financial Corp, Proof, and Secure Technology Alliance at Identity Week America 2026 covering digital identity and payment innovation in the financial sector.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-04-18
Description

Zenity joined the Coalition for Secure AI and released a joint report with CSA revealing that nearly half of organizations have experienced at least one AI agent-related security incident. Zenity exhibits at Black Hat Asia and ServiceNow Knowledge 2026, building enterprise brand visibility with CSA research as anchor content.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-04-17
Description

Joint industry report The 'AI Vulnerability Storm': Building a 'Mythos-Ready' Security Program developed by SANS Institute, CSA, [un]prompted, and OWASP GenAI with contributions from over 250 CISOs, providing a risk register, priority actions, and board briefing materials.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-03-26
Description

CSA survey commissioned by Aembit found that 68% of organizations cannot clearly distinguish between human and AI agent activity, while 74% say AI agents receive more access than necessary and 79% believe agents create new access pathways difficult to monitor. CSA Chief Scientific Officer John Yeoh also presented at NHIcon 2026 alongside Aembit CEO David Goldschlag on non-human identity challenges.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-02-05
Description

CSA survey commissioned by Strata Identity found 84% of organizations doubted they could pass a compliance audit focused on agent behavior or access controls, with only 18% expressing high confidence in current IAM systems' ability to manage agent identities. Survey covered 285 IT and security professionals and identified static API key use as a top vulnerability.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-01-28
Description

MITRE CTID, in partnership with CSA, Citigroup, CrowdStrike, Fortinet, and JPMorgan Chase, released research mapping cloud security controls to the MITRE ATT&CK framework to help organizations improve cloud security by identifying and addressing vulnerabilities based on real-world attack behaviors.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-01-15
Description

CSA benchmark study with Dropzone AI showed 22-29% better investigation accuracy and 45-61% faster completion times for AI SOC analysts. A separate study involving 148 security professionals validated faster decision-making, more detailed investigations, and reduced fatigue with AI assistance.

Strategic tierMinorTypeOthersAnnounced on2025-12-02
Description

Sign In Solutions joined CSA to reinforce its cybersecurity standards as part of expanded GRC capabilities supporting secure visitor management at global facilities, including progress toward FedRAMP Moderate authorization.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2025-10-03
Description

ISACA and CSA jointly administered the Certificate of Cloud Auditing Knowledge (CCAK) credential. As of October 3, 2025, CCAK is no longer available on the ISACA website; CSA has expressed hope to bring the certification back or assist the community in finding alternatives.

Strategic tierCoreTypeOthersAnnounced on2024-11-01
Description

CSA SA Chapter established November 2024 with Ayanda Peta as president and chairperson. Membership process opened in 2026 and the chapter endorsed the ITWeb Security Summit JHB 2026, aiming to educate on cloud security best practices, develop skills, and strengthen industry collaboration in South Africa.

Recent move9 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight8 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

Global professional association for IT governance, risk, audit, and cybersecurity. Directly comparable as a membership- and certification-driven non-profit that co-managed the CCAK credential with CSA until October 2025 and competes in cloud auditing certifications, COBIT, and CISA-level training.

TypeDirect peer
Description

Premier cybersecurity professional certification body (CISSP, CCSP, CSSLP). Direct peer as a non-profit that monetizes vendor-neutral credentials, member dues, and training — comparable to CSA's CCSK, CCZT, and TAISE certification portfolio.

TypeBroad incumbent
Description

Largest cybersecurity training and certification provider with deep GIAC credential portfolio. Comparable to CSA in practitioner training, certification, and research output (SANS co-authored the MythosReady report with CSA) and competes in the same enterprise training wallet.

TypeDirect peer
Description

Open-source, non-profit security community producing widely adopted frameworks (OWASP Top 10, ASVS, SAMM) and standards. Direct peer as a vendor-neutral, community-led standards body with similar governance model and a comparable role for OWASP GenAI in AI security.

TypeBroad incumbent
Description

Federally funded research body operating the CVE program and MITRE ATT&CK framework. Direct strategic partner (joint research with CSA on cloud-ATT&CK mapping) and comparable as an authoritative security standards publisher that grants the CVE Numbering Authority authorization CSAI Foundation now holds.

TypeBroad incumbent
Description

U.S. government standards body publishing the AI Risk Management Framework and CSF that CSA's AICM and STAR for AI explicitly map to. Comparable as a free, authoritative source of security frameworks and certifications that enterprises and government buyers adopt.

TypeDirect peer
Description

Non-profit professional association for privacy practitioners offering certifications (CIPP, CIPM, CIPT), training, and research. Direct peer with similar non-profit, certification-led, conference-and-membership monetization model.

TypeRegional player
Description

Linux Foundation sub-foundation for cloud-native open-source projects with certification programs (CKA, CKAD, KCNA). Comparable as a non-profit running Kubernetes/Cloud security certifications and working groups that overlap with CSA's cloud and AI security scope.

TypeEmerging player
Description

ISACA subsidiary offering process-maturity assessments and certifications. Comparable as a standards-body-adjacent assurance and certification program in the same cybersecurity governance category as CSA's STAR and CCZT.

TypeBroad incumbent
Description

Foundational open-source foundation hosting CNCF, OpenSSF, and LF AI & Data. Comparable as a large non-profit that operates working groups, certification programs (Linux Foundation Certified), and global events with a similar community-led governance model.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat8 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers10 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability7 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles22 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance6 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Cloud Security Alliance

Cloud Security Standards and Certificationcloudsecurityalliance.org

Cloud Security Alliance is a Seattle-based not-for-profit that develops vendor-neutral cloud, AI, and Zero Trust security frameworks, runs the STAR assurance registry with 2,500+ entries, and offers industry-recognized certifications (CCSK, CCZT, TAISE) to a 150,000+ member community across 60+ countries.

What Cloud Security Alliance does

Cloud Security Alliance (CSA) is a not-for-profit organization founded in 2009 and headquartered in Seattle, with regional operations in Berlin, serving as a vendor-neutral body for cloud, AI, and Zero Trust security standards, assurance, and practitioner credentialing. It serves a global community of 150,000+ members organized through 150+ chapters across 60+ countries, alongside enterprise members including hyperscalers, regulated financial institutions, and security vendors. The organization develops and stewards the de-facto industry frameworks used by cloud service providers, their customers, and third-party auditors to document and attest security controls.

CSA's technology portfolio centers on a stack of interlocking standards: the Cloud Controls Matrix (CCM) and Consensus Assessments Initiative Questionnaire (CAIQ v4) form the foundation of the STAR Program — a multi-level assurance registry (Level 1 self-assessment, Level 2 third-party certification) that lists 2,500+ cloud and AI service providers. More recent additions include the AI Controls Matrix (AICM v1.1) with 247 control objectives across 18 security domains aligned to ISO 42001, NIST AI RMF, and the EU AI Act; the Software Defined Perimeter (SDP) zero trust specification; the RiskRubric AI scoring methodology; the NIST AI RMF Agentic Profile; and the AAGATE reference architecture for agentic AI. The CSAI Foundation, launched at RSAC 2026 and authorized as a CVE Numbering Authority through MITRE, extends CSA into agentic-AI threat intelligence, the Catastrophic Risk Annex of STAR for AI, and stewardship of the Autonomous Action Runtime Management and Agentic Trust Framework specifications.

CSA's revenue is generated through six streams: recurring corporate membership dues, per-seat certification fees (CCSK, CCZT, TAISE, CCAK, ACSP, plus STAR Auditor Training), STAR Registry listing and audit fees, event sponsorships and conference fees for in-person and virtual events, framework and research artifact licensing, and commissioned survey and research partnerships with technology vendors. Distribution runs through direct enterprise sales for corporate memberships, a self-serve training and exams platform for individual practitioners, a global chapter network that hosts local events and translates research, and a channel ecosystem of Certified STAR Auditors, Training Partners, and authorized instructors. Pricing for individual certifications, corporate membership tiers, and STAR submissions is not publicly disclosed.

Cloud Security Alliance firmographics

Firmographics
Name
Cloud Security Alliance
Legal name
Cloud Security Alliance
Website
https://cloudsecurityalliance.org
Company type
Private
Founded year
2008
Headcount range
501–1,000 employees
Short description
Cloud Security Alliance is a Seattle-based not-for-profit that develops vendor-neutral cloud, AI, and Zero Trust security frameworks, runs the STAR assurance registry with 2,500+ entries, and offers industry-recognized certifications (CCSK, CCZT, TAISE) to a 150,000+ member community across 60+ countries.
Ownership category
akta.pro rank

Cloud Security Alliance industry classification

Industry
Product category
Cloud Security Standards and Certification
NAICS
Software Publishers (5132)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
akta.pro secondary industry
Cloud & SaaS Security Awareness (e.g., M365/Google Workspace) (EDABAGAG)

Keywords

  • Cloud security frameworks
  • AI governance standards
  • Zero trust certification
  • Cloud assurance registry
  • Security compliance training

Where Cloud Security Alliance is headquartered

Location

Headquarters

HQ city
Seattle
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Cloud Security Alliance business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others

Revenue model

  1. Corporate Membership Fees: Recurring corporate membership dues across tiers for solution providers, cloud solution providers, and other organizations, granting market visibility, brand awareness, trusted security expertise access, member-exclusive programs (STAR Enabled Solutions, Trusted Cloud Provider, Trusted AI & Cloud Consultant), and partnership benefits.
  2. Certification and Training Fees: Per-seat and per-course fees for industry-recognized certifications including Certificate of Cloud Security Knowledge (CCSK), Certificate of Cloud Auditing Knowledge (CCAK), Certificate of Competence in Zero Trust (CCZT), Trusted AI Safety Expert (TAISE), Advanced Cloud Security Practitioner (ACSP), and STAR Auditor Training. Revenue also generated through CCSK Train the Trainer, instructor certification, and the Training Partner Network.
  3. STAR Registry and Assurance Program Fees: Listing, assessment, and certification fees for cloud and AI service providers publishing to CSA's STAR Registry (2,500+ entries). Includes STAR Level 1 self-assessment, STAR Level 2 third-party audits through Certified STAR Auditors, and STAR for AI Catastrophic Risk Annex attestation.
  4. Event Sponsorships and Conference Fees: Sponsorship packages and attendee fees for in-person conferences (GITEX AI Europe, Boston Leadership Exchange, CSA Japan Summit, XCON) and virtual events/webinars including CloudBytes Webinar Series and Research Webinar Series.
  5. Research and Artifact Licensing: Distribution and licensing of CSA research publications, framework downloads (CCM, AICM, CAIQ, EU Cloud Code of Conduct, top threats reports, guidance documents), and CSA Startup Showcase registry listing for emerging vendors.
  6. Commissioned Survey and Research Partnerships: Joint research and survey programs commissioned by technology vendors (Thales, Strata Identity, Aembit, Anjuna, Token Security, Miggo Security, FranklinCovey, Dropzone AI, Zenity), which fund research execution while providing sponsors with branded insights and benchmark data.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualCorporate Membership (Solution Providers / Cloud Solution Providers / Enterprises)
Per seatPay-as-you-goIndividual Certifications (CCSK, CCZT, TAISE, CCAK, ACSP)
Per seatPay-as-you-goTeam and Government Training
OtherAnnualSTAR Registry Listing and Audits
OtherPay-as-you-goEvent Sponsorships

Go-to-market motion5 records

Distribution channels7 records

Marketing channels10 records

Cloud Security Alliance product offering

Product offering

Core offering

CSA develops and operates vendor-neutral security frameworks, control matrices, certification programs, and a public assurance registry for cloud, AI, and Zero Trust environments. The flagship deliverable is the STAR (Security, Trust, Assurance and Risk) Program with 2,500+ registry entries built on the Cloud Controls Matrix (CCM) and CAIQ, complemented by industry-recognized individual certifications (CCSK, CCZT, TAISE, CCAK, ACSP) and the AI Controls Matrix (AICM). Revenue is generated through corporate memberships, certification and training fees, STAR Registry listing/audit fees, event sponsorships, and research licensing.

Product overview

CSA delivers a portfolio-centric, not single-product, architecture centered on the STAR Program as the public-facing assurance registry (with 2,500+ entries and STAR Level 1, Level 2, and STAR for AI variants built on the Cloud Controls Matrix and CAIQ). Surrounding the STAR core are governance frameworks (CCM, CAIQ, AI Controls Matrix v1.1, EU Cloud Code of Conduct), industry-recognized training certificates (CCSK, CCZT, TAISE, CCAK, ACSP), and a set of strategic initiatives — AI Safety Initiative, Zero Trust Advancement Center, Compliance Automation Revolution, FinCloud Security, CxO Trust, Trusted AI & Cloud Consultant, and Trusted Cloud Provider. The CSAI Foundation (launched 2026) and the RiskRubric v2 ecosystem extend CSA into agentic AI governance and AI risk scoring; Circle and CSA Chapters (150+ chapters in 60+ countries with 150k+ members) anchor the community layer. Research artifacts (Cloud Threat Modeling Guide v2.0, NIST AI RMF Agentic Profile, MythosReady draft report) and CCAK-complementing certifications round out the offering.

Differentiator

Problem solved

Functional benefit

Products and services

  • STAR (Security, Trust, Assurance and Risk) Program
  • Cloud Controls Matrix (CCM)
  • Consensus Assessments Initiative Questionnaire (CAIQ) v4
  • AI Controls Matrix (AICM) v1.1
  • Certificate of Cloud Security Knowledge (CCSK)
  • Certificate of Competence in Zero Trust (CCZT)
  • Trusted AI Safety Expert (TAISE) Certificate
  • Certificate of Cloud Auditing Knowledge (CCAK)
  • Advanced Cloud Security Practitioner (ACSP) Training
  • EU Cloud Code of Conduct
  • STAR Auditor Training
  • Corporate Membership (Solution Providers, Cloud Solution Providers, Enterprises)
  • CSAI Foundation
  • STAR for AI Certification Program
  • Trusted AI & Cloud Consultant (TAICC)
  • Trusted Cloud Provider (TCP)
  • CSA Startup Showcase Registry
  • STAR Enabled Solutions
  • CSA Training Platform
  • CSA Exams Platform

Quantifiable outcome

  • 2,500+ entries in CSA STAR Registry
  • +7 more outcomes

Companies that use Cloud Security Alliance

Customer profile

Named customers10 records

Ideal customer profiles4 records

Cloud Security Alliance technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability7 records

Feature10 records

Cloud Security Alliance partnerships and signals

Strategic signal

Partnerships

19 partnerships are on record, tiered core, flagship and minor.

  • ThalescoreStrategic or Co-development Partner · 9 June 2026Joint CSA-Thales survey found that 68% of 210 organizations surveyed have significant unprotected unstructured data, yet 75% describe themselves as moderately or highly confident in their security posture. The discussion identifies AI tools as a forcing function that has exposed the risks of unmanaged unstructured data.
  • AnjunacoreStrategic or Co-development Partner · 9 June 2026Anjuna commissioned the CSA survey of 340 global IT and security professionals (January-March 2026) showing 62% of financial services organizations have deployed AI agents, 93% of which grant agents some autonomy, and 20% experienced known AI-security incidents.
  • FranklinCoveycoreStrategic or Co-development Partner · 9 June 2026Joint CSA-FranklinCovey surveys found significant gaps in AI governance across financial organizations, with 62% using AI agents but 41% unaware whether their company experienced AI security incidents and 80% of managers taking a hands-off approach to AI oversight. Only 14% of employees received formal AI training.
  • TumerykflagshipStrategic or Co-development Partner · 8 June 2026Tumeryk joined CSA's RiskRubric ecosystem as an official AI risk assessment and scoring provider. Tumeryk CEO Rohit Valia co-authored the RiskRubric v2 Concept Paper and contributed to the framework's updated scoring methodology. The company also launched the beta of its AI Trust Score assessment service designed to help enterprises quantify the trustworthiness of AI models, agents, and MCP servers, with the scanner covering prompt injection, jailbreak resistance, privacy leakage, bias, hallucinations, transparency, reliability, and agentic boundary violations.
  • Miggo SecuritycoreStrategic or Co-development Partner · 3 June 2026CSA-Miggo Security survey of 902 IT and security professionals found 80% of organizations experienced at least one application security incident in the past 12 months, with 35% taking four to seven days to identify critical vulnerabilities in production environments. 42% expect to increase spending on runtime security over 12-24 months.
  • VantacoreOEM/ Whitelabel/ Licensing Partner · 30 April 2026CSAI Foundation acquired the Autonomous Action Runtime Management specification from Vanta as part of expanding its capacity to secure the agentic AI control plane and extending CSA's AI Controls Matrix with the Catastrophic Risk Annex.
  • MassiveScale.AI (Josh Woodruff)coreOEM/ Whitelabel/ Licensing Partner · 30 April 2026CSAI Foundation acquired stewardship of the Agentic Trust Framework from MassiveScale.AI founder Josh Woodruff as part of expanding its capacity to secure the agentic AI control plane and supporting AI governance frameworks.
  • MITRE (CVE Numbering Authority authorization)flagshipTechnology or Integration · 30 April 2026CSAI Foundation was authorized as a CVE Numbering Authority through MITRE, enabling the foundation to assign official CVE identifiers for AI security vulnerabilities as part of its mission to secure the agentic AI control plane.
  • Token SecuritycoreStrategic or Co-development Partner · 26 April 2026CSA report commissioned by Token Security found 82% of enterprises have unknown AI agents running in their IT infrastructure, with 65% experiencing AI agent-related incidents. 61% suffered data exposure, 43% operational disruption, and only 21% have formal decommissioning processes.
  • Identity Week America 2026minorGTM or Marketing Partner · 20 April 2026CSA participating as an industry body speaker alongside Capital One, Chase, Varo Bank, Wintrust Financial Corp, Proof, and Secure Technology Alliance at Identity Week America 2026 covering digital identity and payment innovation in the financial sector.
  • ZenityflagshipStrategic or Co-development Partner · 18 April 2026Zenity joined the Coalition for Secure AI and released a joint report with CSA revealing that nearly half of organizations have experienced at least one AI agent-related security incident. Zenity exhibits at Black Hat Asia and ServiceNow Knowledge 2026, building enterprise brand visibility with CSA research as anchor content.
  • SANS Institute, OWASP GenAI, [un]promptedflagshipStrategic or Co-development Partner · 17 April 2026Joint industry report The 'AI Vulnerability Storm': Building a 'Mythos-Ready' Security Program developed by SANS Institute, CSA, [un]prompted, and OWASP GenAI with contributions from over 250 CISOs, providing a risk register, priority actions, and board briefing materials.
  • AembitcoreStrategic or Co-development Partner · 26 March 2026CSA survey commissioned by Aembit found that 68% of organizations cannot clearly distinguish between human and AI agent activity, while 74% say AI agents receive more access than necessary and 79% believe agents create new access pathways difficult to monitor. CSA Chief Scientific Officer John Yeoh also presented at NHIcon 2026 alongside Aembit CEO David Goldschlag on non-human identity challenges.
  • Strata IdentitycoreStrategic or Co-development Partner · 5 February 2026CSA survey commissioned by Strata Identity found 84% of organizations doubted they could pass a compliance audit focused on agent behavior or access controls, with only 18% expressing high confidence in current IAM systems' ability to manage agent identities. Survey covered 285 IT and security professionals and identified static API key use as a top vulnerability.
  • MITRE Center for Threat-Informed Defense (CTID)flagshipStrategic or Co-development Partner · 28 January 2026MITRE CTID, in partnership with CSA, Citigroup, CrowdStrike, Fortinet, and JPMorgan Chase, released research mapping cloud security controls to the MITRE ATT&CK framework to help organizations improve cloud security by identifying and addressing vulnerabilities based on real-world attack behaviors.
  • Dropzone AIcoreStrategic or Co-development Partner · 15 January 2026CSA benchmark study with Dropzone AI showed 22-29% better investigation accuracy and 45-61% faster completion times for AI SOC analysts. A separate study involving 148 security professionals validated faster decision-making, more detailed investigations, and reduced fatigue with AI assistance.
  • Sign In SolutionsminorOthers · 2 December 2025Sign In Solutions joined CSA to reinforce its cybersecurity standards as part of expanded GRC capabilities supporting secure visitor management at global facilities, including progress toward FedRAMP Moderate authorization.
  • ISACAflagshipStrategic or Co-development Partner · 3 October 2025ISACA and CSA jointly administered the Certificate of Cloud Auditing Knowledge (CCAK) credential. As of October 3, 2025, CCAK is no longer available on the ISACA website; CSA has expressed hope to bring the certification back or assist the community in finding alternatives.
  • CSA South Africa ChaptercoreOthers · 1 November 2024CSA SA Chapter established November 2024 with Ayanda Peta as president and chairperson. Membership process opened in 2026 and the chapter endorsed the ITWeb Security Summit JHB 2026, aiming to educate on cloud security best practices, develop skills, and strengthen industry collaboration in South Africa.

Scale indicators11 records

Recent moves9 records

Expansion highlights8 records

Cloud Security Alliance competitors and assessment

Company assessment

Broad incumbents

  • ISACA: Global professional association for IT governance, risk, audit, and cybersecurity. Directly comparable as a membership- and certification-driven non-profit that co-managed the CCAK credential with CSA until October 2025 and competes in cloud auditing certifications, COBIT, and CISA-level training.
  • SANS Institute: Largest cybersecurity training and certification provider with deep GIAC credential portfolio. Comparable to CSA in practitioner training, certification, and research output (SANS co-authored the MythosReady report with CSA) and competes in the same enterprise training wallet.
  • MITRE Corporation: Federally funded research body operating the CVE program and MITRE ATT&CK framework. Direct strategic partner (joint research with CSA on cloud-ATT&CK mapping) and comparable as an authoritative security standards publisher that grants the CVE Numbering Authority authorization CSAI Foundation now holds.
  • NIST (National Institute of Standards and Technology): U.S. government standards body publishing the AI Risk Management Framework and CSF that CSA's AICM and STAR for AI explicitly map to. Comparable as a free, authoritative source of security frameworks and certifications that enterprises and government buyers adopt.
  • The Linux Foundation: Foundational open-source foundation hosting CNCF, OpenSSF, and LF AI & Data. Comparable as a large non-profit that operates working groups, certification programs (Linux Foundation Certified), and global events with a similar community-led governance model.

Direct peers

  • (ISC)²: Premier cybersecurity professional certification body (CISSP, CCSP, CSSLP). Direct peer as a non-profit that monetizes vendor-neutral credentials, member dues, and training — comparable to CSA's CCSK, CCZT, and TAISE certification portfolio.
  • OWASP Foundation: Open-source, non-profit security community producing widely adopted frameworks (OWASP Top 10, ASVS, SAMM) and standards. Direct peer as a vendor-neutral, community-led standards body with similar governance model and a comparable role for OWASP GenAI in AI security.
  • International Association of Privacy Professionals (IAPP): Non-profit professional association for privacy practitioners offering certifications (CIPP, CIPM, CIPT), training, and research. Direct peer with similar non-profit, certification-led, conference-and-membership monetization model.

Regional players

  • Cloud Native Computing Foundation (CNCF): Linux Foundation sub-foundation for cloud-native open-source projects with certification programs (CKA, CKAD, KCNA). Comparable as a non-profit running Kubernetes/Cloud security certifications and working groups that overlap with CSA's cloud and AI security scope.

Emerging players

  • ISACA's CMMI Institute: ISACA subsidiary offering process-maturity assessments and certifications. Comparable as a standards-body-adjacent assurance and certification program in the same cybersecurity governance category as CSA's STAR and CCZT.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat8 records

Key risks6 records

Key highlights7 records

Customer concentration

Cloud Security Alliance social profiles

Digital presence

Cloud Security Alliance compliance and trust

Trust signal

Compliance6 records

Cloud Security Alliance financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Cloud Security Alliance leadership team

Management profile

Number of profiles

Profiles22 records

Cloud Security Alliance subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

Cloud Security Alliance funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Cloud Security Alliance M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Cloud Security Alliance

What does Cloud Security Alliance do?

CSA develops and operates vendor-neutral security frameworks, control matrices, certification programs, and a public assurance registry for cloud, AI, and Zero Trust environments. The flagship deliverable is the STAR (Security, Trust, Assurance and Risk) Program with 2,500+ registry entries built on the Cloud Controls Matrix (CCM) and CAIQ, complemented by industry-recognized individual certifications (CCSK, CCZT, TAISE, CCAK, ACSP) and the AI Controls Matrix (AICM). Revenue is generated through corporate memberships, certification and training fees, STAR Registry listing/audit fees, event sponsorships, and research licensing.

Is Cloud Security Alliance a public or private company?

Cloud Security Alliance is a private company. It is classified as nonprofit foundation owned.

When was Cloud Security Alliance founded?

Cloud Security Alliance was founded in 2008. It employs 501 to 1,000 people.

Where is Cloud Security Alliance based?

Cloud Security Alliance is headquartered in Seattle, United States, in the North America region.

How does Cloud Security Alliance make money?

Six revenue lines are on record. Corporate Membership Fees are the primary driver. The others are certification and Training Fees, STAR Registry and Assurance Program Fees, event Sponsorships and Conference Fees, research and Artifact Licensing and commissioned Survey and Research Partnerships.

Who are Cloud Security Alliance's main competitors?

Broad incumbents on record are ISACA, SANS Institute, MITRE Corporation, NIST (National Institute of Standards and Technology) and The Linux Foundation. Direct peers are (ISC)², OWASP Foundation and International Association of Privacy Professionals (IAPP). Cloud Native Computing Foundation (CNCF) is listed as a regional player. ISACA's CMMI Institute is listed as an emerging player.

Does Cloud Security Alliance have an API?

No public API is recorded for Cloud Security Alliance.

What industry is Cloud Security Alliance in?

Cloud Security Alliance's product category is Cloud Security Standards and Certification. Its primary akta.pro industry code is HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC), with a secondary code of EDABAGAG, Cloud & SaaS Security Awareness (e.g., M365/Google Workspace). Its NAICS code is 5132 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Analytics InsightCloud Security in 2027: Risks, Threats, Challenges, & Protection StrategiesThe Cloud Security Alliance's 2026 survey ranks identity and access management as the top cloud threat, with AI-enhanced attacks and AI system compromise newly added. Misconfiguration, supply chain exposure, and credential theft remain key risks. Organizations are advised to audit non-human identities and adopt zero trust.SecuritybriefCloud Security Alliance names Troy Leach to AI bodyCloud Security Alliance appointed Troy Leach as Executive Director of its CSAI Foundation, focusing on AI security and safety. Leach brings over 25 years of cybersecurity experience and previously served as Chief Strategy Officer. The foundation aims to address risks and trust frameworks for autonomous AI systems.CIOThe need to fortify cloud integrity as cracks increaseJim Reavis, CEO of the Cloud Security Alliance, discusses cloud security gaps and AI risks in an interview. He notes that tenants often bear 80% of control responsibility, and AI adoption exposes weaknesses in identity and trust. He emphasizes zero trust and least autonomy as needed approaches.SecuritybriefEnterprises still rely on manual cloud security policiesA Cloud Security Alliance survey commissioned by AlgoSec reveals that most enterprises still rely on manual or reactive processes for managing hybrid and multi-cloud security policies. This reliance has led to significant operational issues, with 65% of organizations experiencing at least one business-critical application outage due to misconfigured policies in the past year.ITWebCloud complexity turns security policy into outage riskA survey by the Cloud Security Alliance (CSA) reveals that 65% of organizations experienced business-critical application outages due to security policy misconfigurations in hybrid and multi-cloud environments over the past year. The report highlights that reliance on manual policy management and fragmented ownership across teams are primary drivers of these operational risks, leading to delays, compliance failures, and security incidents. Consequently, the CSA advises organizations to adopt unified visibility, automated risk analysis, and continuous compliance to mitigate these structural vulnerabilities.Security BoulevardBSidesSF 2026 – The Epistemology Of TrustThe article reports on multiple cybersecurity-related events and initiatives announced or discussed at Black Hat 2026, including advances in AI security frameworks by NVIDIA and the Linux Foundation, and an initiative by the Cloud Security Alliance to address catastrophic AI risks.ForbesThreat Debt: A New Lens On Cyber DefenseJon Baker, VP at AttackIQ, argues that cybersecurity organizations should shift from reactive vulnerability patching to a proactive model focused on managing "threat debt" and adversary opportunities. The article cites data from CrowdStrike and the Cloud Security Alliance indicating significantly faster attacker speeds and reduced times between vulnerability disclosure and exploitation. It proposes a shared organizational framework where security, IT, and business units align on measuring viable attack paths rather than isolated findings.Security BoulevardCloud Security Alliance Starts Initiative to Define Controls for Catastrophic AI RisksThe Cloud Security Alliance launched the Catastrophic Risk Annex initiative to define auditable controls for catastrophic AI risks, along with the Frontier-Ready Cybersecurity Resource Center, announced at Black Hat USA 2026 in Las Vegas. The initiative will extend CSA's AI Controls Matrix with controls developed and stress-tested by professionals from AI safety, cybersecurity, and national security, to be validated through pilot audits against real AI systems. CSA also released initial research reports on AI-first security organizations, vulnerability operations, and CISO perspectives, with the VulnOps report developed in partnership with Qualys.SecuritybriefCloud Security Alliance launches AI resilience centreThe Cloud Security Alliance has launched an AI Resilience Centre of Excellence with Rubrik as its founding partner, aimed at helping government and enterprise organisations develop governance, operational resilience, and recovery capabilities for AI systems. The initiative, housed within the CSAI Foundation, will produce reference architectures, tabletop exercises, maturity models, and governance guidance as AI agents become more embedded in business and public sector operations. The launch reflects a broader shift in the cybersecurity market as vendors and standards bodies adapt to address AI-related operational failures and failures beyond conventional cyber defence.MorningstarCloud Security Alliance Expands Frontier AI Leadership with New Research and Community PartnershipsThe Cloud Security Alliance announced partnerships with UNLV's Nevada Institute of Cybersecurity and RSAC to advance AI security. UNLV will collaborate on research and education, while RSAC will help launch the AI Vulnerability Storm Summit for community chapters. The partnerships aim to connect academia, industry, and practitioners to address AI security challenges.