주요 콘텐츠로 건너뛰기
블로그로 돌아가기 업계 관점

Skyhigh Security Achieves CSA STAR Level 2 Certification, Raising the Bar for Independent Cloud Security Assurance

By Stuart Bayliss and Sarang Warudkar -

June 25, 2026 6 Minute Read

In an era where cloud security is subject to increasing regulatory scrutiny and enterprise procurement demands, the difference between self-declared and independently verified security assurance has never mattered more. Today, we are proud to announce that Skyhigh Security has achieved CSA STAR Level 2 certification, issued by the Cloud Security Alliance (CSA); the world’s leading organization dedicated to defining best practices for secure cloud computing.

This milestone represents a significant step forward from our existing CSA STAR Level 1 registration, moving from a self-assessment model to independently audited, third-party verified assurance of our cloud security controls. For our customers and partners, it means a higher and more rigorous standard of confidence in Skyhigh Security’s security posture.

What is CSA STAR Level 2?

The Cloud Security Alliance’s Security, Trust, Assurance, and Registry (STAR) program is the industry’s most widely recognized assurance program for cloud security. STAR operates across two levels of assurance, each designed to meet the needs of organizations at different stages of their cloud security maturity:

  • CSA STAR Level 1 — A self-assessment based on the CSA Cloud Controls Matrix (CCM) and the Consensus Assessments Initiative Questionnaire (CAIQ), providing transparency into an organization’s security controls
  • CSA STAR Level 2 — A third-party audit conducted by a certified STAR auditor, extending either a SOC 2 examination (resulting in a STAR Attestation) or an ISO/IEC 27001 audit (resulting in a STAR Certification), providing independently verified assurance of security controls

The distinction is significant. Where Level 1 communicates an organization’s own assessment of its controls, Level 2 provides independent, audited confirmation; verified by a certified third-party assessor against the Cloud Controls Matrix (CCM), the most comprehensive and globally recognized control framework specifically designed for cloud environments.

What the CSA Cloud Controls Matrix Covers

The Cloud Controls Matrix (CCM) underpins the CSA STAR Level 2 assessment. It is a cybersecurity control framework specifically designed to address the unique security, risk, and compliance challenges of cloud environments. The CCM covers 17 security domains, including:

  • Application and interface security
  • Audit assurance and compliance
  • Business continuity management and operational resilience
  • Change control and configuration management
  • Data security and information lifecycle management
  • Encryption and key management
  • Governance, risk, and compliance
  • Identity and access management
  • Infrastructure and virtualization security
  • Supply chain management, transparency, and accountability

By achieving Level 2 certification against the CCM, Skyhigh Security has demonstrated to an independent auditor that its security controls across these domains are not only designed appropriately but are operating effectively in practice.

Achieving CSA STAR Level 2 is a direct response to what our enterprise customers in regulated industries require. Not a vendor’s word on its own security, but independently verified evidence from a certified third-party auditor. As cloud security becomes a procurement prerequisite across financial services, healthcare, and the public sector globally, our customers need assurance they can present to their own boards, regulators, and auditors with confidence. CSA STAR Level 2 gives them exactly that.
Thyaga Vasudevan, EVP of Product at Skyhigh Security

From Level 1 to Level 2: What Changes for Our Customers

Skyhigh Security’s progression from CSA STAR Level 1 to Level 2 reflects a deliberate commitment to raising the standard of security assurance we provide to our customers. The practical implications of this upgrade are meaningful:

    • Independent verification — Security controls are no longer self-attested; they have been examined and confirmed by a certified third-party auditor
    • Greater procurement confidence — Enterprise and regulated-industry procurement teams can rely on audited evidence rather than vendor declarations when evaluating Skyhigh Security
    • Regulatory alignment — Level 2 provides stronger support for compliance with NIS2 supply chain security requirements, DORA for financial services, and GDPR vendor due diligence obligations across the EU
    • Reduced assessment overhead — Customers conducting their own vendor security reviews can leverage the CSA STAR Level 2 audit findings, reducing duplication of effort

Why CSA STAR Level 2 Matters in 2026

The cloud security landscape is evolving rapidly. Across Europe, North America, and the Asia Pacific region, enterprise procurement teams and regulatory bodies are raising the bar on what constitutes acceptable evidence of cloud security maturity. Self-assessments, while valuable as a starting point, are increasingly insufficient for organizations operating in regulated environments or handling sensitive data at scale.

CSA STAR Level 2 certification addresses this directly. It provides a globally recognized, independently audited benchmark that gives enterprises, government agencies, and regulated-industry organizations the assurance they need to onboard Skyhigh Security as a trusted cloud security partner with documented evidence to support their own compliance and risk management obligations.

For organizations subject to NIS2, DORA, GDPR, or sector-specific frameworks, a vendor holding CSA STAR Level 2 certification simplifies third-party risk assessments and strengthens supply chain security documentation.

Building on a Strong Foundation

CSA STAR Level 2 is the latest addition to a comprehensive and continuously growing compliance portfolio at Skyhigh Security. It builds directly on our existing CSA STAR Level 1 registration and complements the suite of certifications and frameworks we maintain globally:

  • FedRAMP High 인증 — 미국 정부 (CASB, SWG, 고급 DLP)
  • DoD Impact Level 2 (IL2) — U.S. Department of Defense
  • ISO/IEC 27001 — International information security management
  • SOC 2 Type II — AICPA Trust Services Criteria (complete SSE Cloud Platform)
  • BSI C5 (2026) — 독일 연방정보보안청
  • IRAP 인증 (2026) — 호주 정부 클라우드 보안
  • GDPR — 유럽연합 개인정보 보호 규정
  • DORA — EU Digital Operational Resilience Act
  • DPDPA — 인도의 데이터 보호 및 디지털 개인정보 보호법
  • CSA STAR Level 1 — Cloud Security Alliance self-assessment (prerequisite)

For a full view of our certifications and compliance posture, visit the Skyhigh Security Trust Center: skyhighsecurity.com/about/certification.html

About CSA STAR

The Cloud Security Alliance’s Security, Trust, Assurance, and Registry (STAR) program is the industry standard for security assurance in the cloud. STAR encompasses the key principles of transparency, rigorous auditing, and harmonization of standards, providing organizations with a globally recognized framework to evaluate and communicate their cloud security posture. The publicly accessible STAR registry documents the security and privacy controls used by cloud computing providers, enabling customers to assess vendors with confidence.

For more information about the CSA STAR program, visit: cloudsecurityalliance.org/star

About the CSA Cloud Controls Matrix

The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing developed and maintained by the Cloud Security Alliance. Aligned with leading security standards including ISO 27001, NIST, PCI DSS, HIPAA, and others, the CCM provides a detailed understanding of security concepts and principles that are aligned to the cloud industry. It is widely recognized as the de facto standard for cloud security control frameworks.

Skyhigh Security was recognized in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE), published May 20, 2025, which evaluates vendors based on their Ability to Execute and Completeness of Vision. This report, which evaluates industry leaders based on their Ability to Execute and Completeness of Vision, serves as a testament to our ongoing innovation and market leadership. In the companion 2025 Gartner® Critical Capabilities for Security Service Edge report, Skyhigh Security achieved the highest score in the Data Security Use Case, once again reaffirming our multi-year leadership in data protection as a core differentiator of the Skyhigh SSE Portfolio. This recognition reflects our sustained investment in a unified, data-first SSE platform purpose-built for highly regulated industries, combining Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA) through a single cloud-native console, with advanced Data Loss Prevention (DLP) at its core.

The information contained in this document reflects Skyhigh Security’s views and opinions on the subject matter and is provided for informational purposes only. Nothing in this document constitutes or should be construed as legal advice. Customers are solely responsible for assessing their own compliance obligations under applicable laws and regulations. The use of Skyhigh Security products or services does not guarantee, warrant, or ensure that customers will achieve or maintain compliance with any local, national, or international legal or regulatory requirements. We recommend consulting qualified legal counsel for guidance specific to your organization’s compliance needs.

저자 소개

스튜어트 베일리스, Skyhigh Security 제품 관리 이사

스튜어트 베일리스

제품 관리 이사

스튜어트는 20년 넘게 제품 관리 분야에서 근무하며 세계 최고 수준의 수상 경력에 빛나는 클라우드 기반 보안 솔루션을 제공해 왔습니다. 현재 스튜어트는 Skyhigh Security )의 Skyhigh Security 관리 팀을 이끌며, Secure Security Edge(SSE) 클라우드 보안 플랫폼을 제공하는 글로벌 인프라를 총괄하고 있습니다.

사랑 와루드카르

사랑 와루드카르

수석 기술 제품 마케팅 매니저

Sarang Warudkar는 사이버 보안 분야에서 10년 이상 경력을 쌓은 노련한 제품 마케팅 관리자로, 기술 혁신을 시장의 요구사항에 맞추는 데 능숙합니다. 그는 CASB, DLP, AI 기반 위협 탐지와 같은 솔루션에 대한 깊은 전문 지식을 바탕으로 영향력 있는 시장 진출 전략과 고객 참여를 주도합니다. Sarang은 IIM 방갈로르에서 MBA를, 푸네 대학교에서 공학 학위를 취득하여 기술 및 전략적 통찰력을 겸비하고 있습니다.

블로그로 돌아가기

인기 블로그

업계 관점

Skyhigh Security , 2026년 IRAP 평가에서 ‘PROTECTED’ 등급 Skyhigh Security

사랑 와루드카르와 스튜어트 베일리스 2026년 5월 21일

업계 관점

AI Tools Created a Security Gap Your Network Cannot See. Browser Controls Close it.

사랑 와루드카르 2026년 5월 19일

업계 관점

현대 기업의 분산화 대응: 데이터 호스팅의 딜레마

스테 나딘 2026년 5월 14일