CSA Cloud Controls Matrix v4.1
The Cloud Controls Matrix (CCM) v4.1 is the de facto standard for cloud security assurance. Released January 2026, it defines 207 controls across 17 security domains covering governance, data protection, infrastructure, identity management, and supply chain. CCM provides a shared responsibility framework for cloud service providers and customers.
207
Controls
17
Security Domains
v4.1
Current (Jan 2026)
All Cloud
IaaS/PaaS/SaaS
Governance, risk management, and compliance policies; security threat and vulnerability management across cloud environments.
Identity and access management, human resources security, and credential lifecycle management for cloud services.
Data security and privacy lifecycle management, encryption and key management for data at rest and in transit.
Infrastructure and virtualisation security, datacenter security, and business continuity and disaster recovery.
Supply chain management transparency, service bill of materials, logging and monitoring, and audit log sanitisation (new in v4.1).
Use the CCM Control Applicability Matrix to assign responsibilities between Cloud Service Provider and Customer.
Evaluate compliance across all 17 security domains against applicable controls.
Document unmet controls with remediation plans, priorities, and timelines.
Deploy controls prioritised by risk and domain, using CCM Implementation Guidelines.
Submit self-assessment (Level 1) or third-party audit (Level 2) to the CSA STAR Registry.
Update assessment annually; transition to v4.1 before the December 2027 deadline.