ข้ามไปที่เนื้อหาหลัก
กลับไปที่บล็อก มุมมองอุตสาหกรรม

Skyhigh Security Achieves CSA STAR Level 2 Certification, Raising the Bar for Independent Cloud Security Assurance

By Stuart Bayliss and Sarang Warudkar -

June 25, 2026 6 Minute Read

In an era where cloud security is subject to increasing regulatory scrutiny and enterprise procurement demands, the difference between self-declared and independently verified security assurance has never mattered more. Today, we are proud to announce that Skyhigh Security has achieved CSA STAR Level 2 certification, issued by the Cloud Security Alliance (CSA); the world’s leading organization dedicated to defining best practices for secure cloud computing.

This milestone represents a significant step forward from our existing CSA STAR Level 1 registration, moving from a self-assessment model to independently audited, third-party verified assurance of our cloud security controls. For our customers and partners, it means a higher and more rigorous standard of confidence in Skyhigh Security’s security posture.

What is CSA STAR Level 2?

The Cloud Security Alliance’s Security, Trust, Assurance, and Registry (STAR) program is the industry’s most widely recognized assurance program for cloud security. STAR operates across two levels of assurance, each designed to meet the needs of organizations at different stages of their cloud security maturity:

  • CSA STAR Level 1 — A self-assessment based on the CSA Cloud Controls Matrix (CCM) and the Consensus Assessments Initiative Questionnaire (CAIQ), providing transparency into an organization’s security controls
  • CSA STAR Level 2 — A third-party audit conducted by a certified STAR auditor, extending either a SOC 2 examination (resulting in a STAR Attestation) or an ISO/IEC 27001 audit (resulting in a STAR Certification), providing independently verified assurance of security controls

The distinction is significant. Where Level 1 communicates an organization’s own assessment of its controls, Level 2 provides independent, audited confirmation; verified by a certified third-party assessor against the Cloud Controls Matrix (CCM), the most comprehensive and globally recognized control framework specifically designed for cloud environments.

What the CSA Cloud Controls Matrix Covers

The Cloud Controls Matrix (CCM) underpins the CSA STAR Level 2 assessment. It is a cybersecurity control framework specifically designed to address the unique security, risk, and compliance challenges of cloud environments. The CCM covers 17 security domains, including:

  • Application and interface security
  • Audit assurance and compliance
  • Business continuity management and operational resilience
  • Change control and configuration management
  • Data security and information lifecycle management
  • Encryption and key management
  • Governance, risk, and compliance
  • Identity and access management
  • Infrastructure and virtualization security
  • Supply chain management, transparency, and accountability

By achieving Level 2 certification against the CCM, Skyhigh Security has demonstrated to an independent auditor that its security controls across these domains are not only designed appropriately but are operating effectively in practice.

Achieving CSA STAR Level 2 is a direct response to what our enterprise customers in regulated industries require. Not a vendor’s word on its own security, but independently verified evidence from a certified third-party auditor. As cloud security becomes a procurement prerequisite across financial services, healthcare, and the public sector globally, our customers need assurance they can present to their own boards, regulators, and auditors with confidence. CSA STAR Level 2 gives them exactly that.
Thyaga Vasudevan, EVP of Product at Skyhigh Security

From Level 1 to Level 2: What Changes for Our Customers

Skyhigh Security’s progression from CSA STAR Level 1 to Level 2 reflects a deliberate commitment to raising the standard of security assurance we provide to our customers. The practical implications of this upgrade are meaningful:

    • Independent verification — Security controls are no longer self-attested; they have been examined and confirmed by a certified third-party auditor
    • Greater procurement confidence — Enterprise and regulated-industry procurement teams can rely on audited evidence rather than vendor declarations when evaluating Skyhigh Security
    • Regulatory alignment — Level 2 provides stronger support for compliance with NIS2 supply chain security requirements, DORA for financial services, and GDPR vendor due diligence obligations across the EU
    • Reduced assessment overhead — Customers conducting their own vendor security reviews can leverage the CSA STAR Level 2 audit findings, reducing duplication of effort

Why CSA STAR Level 2 Matters in 2026

The cloud security landscape is evolving rapidly. Across Europe, North America, and the Asia Pacific region, enterprise procurement teams and regulatory bodies are raising the bar on what constitutes acceptable evidence of cloud security maturity. Self-assessments, while valuable as a starting point, are increasingly insufficient for organizations operating in regulated environments or handling sensitive data at scale.

CSA STAR Level 2 certification addresses this directly. It provides a globally recognized, independently audited benchmark that gives enterprises, government agencies, and regulated-industry organizations the assurance they need to onboard Skyhigh Security as a trusted cloud security partner with documented evidence to support their own compliance and risk management obligations.

For organizations subject to NIS2, DORA, GDPR, or sector-specific frameworks, a vendor holding CSA STAR Level 2 certification simplifies third-party risk assessments and strengthens supply chain security documentation.

Building on a Strong Foundation

CSA STAR Level 2 is the latest addition to a comprehensive and continuously growing compliance portfolio at Skyhigh Security. It builds directly on our existing CSA STAR Level 1 registration and complements the suite of certifications and frameworks we maintain globally:

  • FedRAMP High Authorization — U.S. Government (CASB, SWG, Advanced DLP)
  • DoD Impact Level 2 (IL2) — U.S. Department of Defense
  • ISO/IEC 27001 — International information security management
  • SOC 2 Type II — AICPA Trust Services Criteria (complete SSE Cloud Platform)
  • BSI C5 (2026) — German Federal Office for Information Security
  • IRAP PROTECTED (2026) — Australian Government cloud security
  • GDPR — European Union data protection regulation
  • DORA — EU Digital Operational Resilience Act
  • DPDPA — India’s Data Protection and Digital Privacy Act
  • CSA STAR Level 1 — Cloud Security Alliance self-assessment (prerequisite)

For a full view of our certifications and compliance posture, visit the Skyhigh Security Trust Center: skyhighsecurity.com/about/certification.html

About CSA STAR

The Cloud Security Alliance’s Security, Trust, Assurance, and Registry (STAR) program is the industry standard for security assurance in the cloud. STAR encompasses the key principles of transparency, rigorous auditing, and harmonization of standards, providing organizations with a globally recognized framework to evaluate and communicate their cloud security posture. The publicly accessible STAR registry documents the security and privacy controls used by cloud computing providers, enabling customers to assess vendors with confidence.

For more information about the CSA STAR program, visit: cloudsecurityalliance.org/star

About the CSA Cloud Controls Matrix

The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing developed and maintained by the Cloud Security Alliance. Aligned with leading security standards including ISO 27001, NIST, PCI DSS, HIPAA, and others, the CCM provides a detailed understanding of security concepts and principles that are aligned to the cloud industry. It is widely recognized as the de facto standard for cloud security control frameworks.

Skyhigh Security was recognized in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE), published May 20, 2025, which evaluates vendors based on their Ability to Execute and Completeness of Vision. This report, which evaluates industry leaders based on their Ability to Execute and Completeness of Vision, serves as a testament to our ongoing innovation and market leadership. In the companion 2025 Gartner® Critical Capabilities for Security Service Edge report, Skyhigh Security achieved the highest score in the Data Security Use Case, once again reaffirming our multi-year leadership in data protection as a core differentiator of the Skyhigh SSE Portfolio. This recognition reflects our sustained investment in a unified, data-first SSE platform purpose-built for highly regulated industries, combining Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA) through a single cloud-native console, with advanced Data Loss Prevention (DLP) at its core.

The information contained in this document reflects Skyhigh Security’s views and opinions on the subject matter and is provided for informational purposes only. Nothing in this document constitutes or should be construed as legal advice. Customers are solely responsible for assessing their own compliance obligations under applicable laws and regulations. The use of Skyhigh Security products or services does not guarantee, warrant, or ensure that customers will achieve or maintain compliance with any local, national, or international legal or regulatory requirements. We recommend consulting qualified legal counsel for guidance specific to your organization’s compliance needs.

เกี่ยวกับผู้เขียน

Stuart Bayliss, Director, Product Management, Skyhigh Security

Stuart Bayliss

Director of Product Management

Stuart has served in product management roles for over 20 years, providing world-class, award-winning cloud-based security solutions. Today, Stuart leads the Skyhigh Security Product Management team, where is responsible for global Infrastructure delivering Secure Security Edge (SSE) cloud security platform.

ซารัง วารุดการ์

ซารัง วารุดการ์

ผู้จัดการโครงการด้านเทคนิคอาวุโส

Sarang Warudkar เป็นผู้จัดการฝ่ายการตลาดผลิตภัณฑ์ที่มีประสบการณ์มากกว่า 10 ปีในด้านความปลอดภัยทางไซเบอร์ มีความเชี่ยวชาญในการจัดแนวนวัตกรรมทางเทคนิคให้สอดคล้องกับความต้องการของตลาด เขามีความเชี่ยวชาญอย่างลึกซึ้งในโซลูชันต่างๆ เช่น CASB, DLP และการตรวจจับภัยคุกคามที่ขับเคลื่อนด้วย AI ซึ่งขับเคลื่อนกลยุทธ์การออกสู่ตลาดที่มีประสิทธิผลและการมีส่วนร่วมของลูกค้า Sarang สำเร็จการศึกษาระดับปริญญาโทสาขาบริหารธุรกิจจาก IIM Bangalore และปริญญาทางวิศวกรรมศาสตร์จาก Pune University โดยผสมผสานความรู้เชิงเทคนิคและเชิงกลยุทธ์เข้าด้วยกัน

กลับไปที่บล็อก

เนื้อหาที่เกี่ยวข้อง

บล็อกที่กำลังได้รับความนิยม

มุมมองอุตสาหกรรม

Skyhigh Security Achieves CSA STAR Level 2 Certification, Raising the Bar for Independent Cloud Security Assurance

Stuart Bayliss and Sarang Warudkar June 25, 2026

มุมมองอุตสาหกรรม

A Different Approach: Why the Answer to Browser Security Is Not a New Browser

Sarang Warudkar June 17, 2026

มุมมองอุตสาหกรรม

Skyhigh Security การประเมิน IRAP ที่ระดับ PROTECTED สำหรับปี 2026

สารัง วรุธกฤา และ สจวร์ต เบลลิส 21 พฤษภาคม 2026

มุมมองอุตสาหกรรม

AI Tools Created a Security Gap Your Network Cannot See. Browser Controls Close it.

สารัง วรุธกฤා 19 พฤษภาคม 2026