Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Cloud security

CSA STAR vs ISO 27001

Plenty of people treat these as alternative routes, and they are not. ISO 27001 is the foundation: the international standard that certifies your security management. CSA STAR is the cloud layer built on top of it, with controls specific to providers and their customers, and the result appears in a public registry any buyer can check. Foundation first, cloud layer second.

Explore governance and complianceGo to the comparison

In short

  • ISO 27001 certifies information security management across the company, within the scope you define.
  • CSA STAR is the Cloud Security Alliance assurance programme, built on the Cloud Controls Matrix.
  • STAR has levels: the first is a published self assessment; the second is an external audit and requires ISO 27001 alongside it.
  • STAR results sit in a public registry, so the programme doubles as a commercial shop window.

Side by side

Management foundation against cloud layer

What to compareISO/IEC 27001CSA STAR
What it isInternational standard certifying information security management.Cloud assurance programme based on the Cloud Security Alliance control matrix.
Who publishes itISO and IEC, the international standards bodies.Cloud Security Alliance, a nonprofit focused on cloud.
ReachAll information security within the declared scope.Cloud specifically, with 197 control objectives across 17 domains.
How you get itCertification audit by an accredited body.Level 1 by self assessment; Level 2 by external audit alongside ISO 27001.
Depends on the otherNo. It stands alone.Yes, at Level 2: ISO 27001 must be in place or running in parallel.
Where it shows upOn the certificate you show customers.In the public STAR registry, which anyone can search.
Cost of entryPaid standard and paid audit.Level 1 carries no audit cost; Level 2 adds audit work to the ISO 27001 one.
Who it suitsAny company that needs to prove security.Anyone offering cloud services or selling to buyers who demand cloud assurance.

Compared with Annex A of ISO 27001, much of the Cloud Controls Matrix is equivalent or more detailed, and a smaller slice is cloud specific. That slice is what STAR adds.

The foundation everything sits on

ISO/IEC 27001

It certifies that your company manages information security in an organised, verifiable way: defined scope, assessed risk, controls chosen with justification and improvement tracked over time. It applies to any sector and it is the credential that opens the most doors worldwide. If you are only going to invest in one thing, start here, not least because STAR Level 2 depends on it.

  • Recognised in any market and sector
  • Scope you define, not cloud specific
  • Certificate valid for three years
  • Prerequisite for CSA STAR Level 2
The cloud specific layer

CSA STAR

The Cloud Security Alliance maintains the Cloud Controls Matrix, with 197 control objectives across 17 domains, designed to answer what changes when the service runs in the cloud: who is responsible for what between provider and customer, how tenants stay separated, what happens to the data on the way out. Level 1 is a self assessment published in the registry. Level 2 is an external audit carried out alongside the ISO 27001 one. There is also a continuous option, for organisations that want to show ongoing monitoring.

  • 197 control objectives across 17 cloud domains
  • Level 1 by self assessment, published in the registry
  • Level 2 by external audit alongside ISO 27001
  • Public registry that works as a commercial shop window

How they fit together

The right order saves time and money

STAR Level 2 is not a separate audit: the auditor widens the scope of the ISO 27001 audit to cover the cloud controls in the matrix. Companies that understand this early get both done in a single pass, with the same body and the same evidence cycle. Along the way there is also ISO 27017, a set of cloud security guidance that builds on 27001 and covers much of what the matrix asks for. Many organisations use 27017 as a comfortable stepping stone before taking on STAR.

  • ISO 27001 first, since it is the mandatory basis for Level 2
  • ISO 27017 is a comfortable intermediate step for cloud
  • STAR Level 2 comes out of the same audit, with a wider scope

Which case is yours

Where to start

You hold no security certification at all yet

Start with ISO 27001

It is the basis for everything and the most accepted credential. Without it, STAR Level 2 never leaves the ground.

You need to show up quickly as a trustworthy cloud vendor

Publish STAR Level 1

The self assessment enters the public registry with no audit and already answers much of the customer questionnaire.

Your customer demands audited cloud assurance

ISO 27001 plus STAR Level 2

The complete route, and cheaper when both audits run together rather than separately.

Numbers that matter

197

control objectives in the Cloud Controls Matrix

17

cloud security domains

Level 2

only issued with ISO 27001 in place or in parallel

How DM11 solves it

ISO 27001, ISO 27017 and CSA STAR in the order that saves an audit

We build the ISO 27001 foundation with cloud already in mind, use ISO 27017 as the bridge and take you to the STAR registry without rewriting evidence. One plan, one set of documents serving all three fronts.

  • One audit instead of two: wider scope in the same cycle
  • Your company appears in the public STAR registry, where buyers look
  • We translate the control matrix to your actual environment, never a copied template
  • Customer security questionnaires start coming with answers already written
Talk about cloud certification

Common questions

What people ask before deciding

Answers checked against the Cloud Security Alliance STAR programme and control matrix, and ISO/IEC 27001:2022.

It does not replace it, and at Level 2 it depends on it. STAR Level 2 certification is granted on top of a management system already certified to ISO 27001, with the audit scope widened to the cloud controls in the matrix. Companies that try to skip ISO 27001 tend to discover this after spending the time.

More questions? Talk to DM11

Prove cloud security without paying for two audits

A short conversation shows the right order for your case and how much fits into a single cycle.

Talk to a specialistExplore governance and compliance