Is CSA STAR Worth It for UK Cloud Providers? Where Penetration Testing Fits

Is CSA STAR Worth It for UK Cloud Providers? Where Penetration Testing Fits

By EJN Labs · 24 Aug 2026 · 8 min read

CSA STAR is worth pursuing for UK cloud providers selling to security-conscious buyers, and CSA STAR penetration testing is the evidence that makes it credible. STAR is voluntary, and it does not name a mandatory pen test, but its Cloud Controls Matrix expects risk-based technical testing. Most providers budget £4,400 to £8,400 for a focused cloud and application test at £1,100 to £1,400 per day.

Why CSA STAR penetration testing matters for UK cloud providers

CSA STAR penetration testing matters because STAR entries keep appearing in procurement questionnaires, giving enterprise buyers a single, comparable view of a cloud provider’s security posture. It is voluntary and no UK regulator requires it, yet many UK SaaS and cloud providers first meet it when a prospect asks.

The Security, Trust, Assurance and Risk (STAR) programme, run by the Cloud Security Alliance, is a public registry of cloud providers assessed against the Cloud Controls Matrix (CCM).

The commercial logic is straightforward. If your buyers run formal supplier assurance, a STAR listing shortens due diligence: you point to one published assessment instead of answering hundreds of bespoke questions per deal. The catch is that the assessment is only as convincing as the evidence behind it, and technical testing is the part buyers scrutinise hardest.

What CSA STAR actually is, and what it is not

CSA STAR is a two-level assurance scheme. Level 1 is a self-assessment published to the registry, and Level 2 adds independent assessment through STAR Certification or STAR Attestation. Level 2 carries far more weight with procurement teams because a third party has checked the claims.

At Level 1 you complete the Consensus Assessment Initiative Questionnaire (CAIQ) against the CCM and publish it, at little cost beyond your own time. STAR Certification is built on an ISO 27001 audit extended with the CCM, while STAR Attestation is built on a SOC 2 examination.

What STAR is not is a legal requirement. Its status is voluntary and contractual: nobody fines you for skipping it, but a customer or market may make it a condition of doing business. Our guide to cyber security for financial services is a useful companion read, because that sector drives many of the STAR requests we see.

Does CSA STAR require a penetration test?

No. No clause in the STAR programme says you must commission an annual penetration test, and we will not pretend otherwise. What STAR does instead is embed testing expectations through the Cloud Controls Matrix, whose domains expect vulnerabilities to be identified and controls to be verified, not merely described.

The CCM’s Threat and Vulnerability Management domain expects a defined, risk-based programme for finding those weaknesses, and its application and infrastructure domains carry the verification expectation.

In practice, penetration testing is the standard way to evidence those controls:

  • A Level 1 CAIQ asks how you find and fix vulnerabilities. “We commission an annual CREST-accredited penetration test and remediate on a defined SLA” is a defensible answer; “we run a scanner sometimes” is not.
  • A Level 2 assessor asks for evidence that vulnerability management operates. A recent independent test report, with findings and remediation records, is the cleanest artefact you can hand over.
  • The buyers who care about STAR almost always ask for a pen test summary anyway.

So the accurate position is: STAR expects risk-based technical security evidence, and penetration testing is the strongest form of it. If your Certification route runs through ISO 27001, the same test satisfies both programmes.

What to test in a cloud provider estate

Your testing scope should mirror the parts of your estate a customer actually consumes. For a typical UK SaaS or cloud provider that means four layers.

The cloud platform itself. A cloud penetration test reviews your AWS, Azure or GCP configuration: identity and access management, segmentation between tenants, storage exposure, secrets handling and logging. Misconfiguration, not exotic exploits, is where most real cloud breaches start, and it is the area the CCM probes hardest.

The application and its APIs. Multi-tenant SaaS lives or dies on tenant isolation. We test whether one customer can reach another’s data through broken object-level authorisation, predictable identifiers or over-permissive API scopes. API penetration testing matters doubly for STAR because APIs are the surface your enterprise buyers integrate with first.

The external perimeter. Everything internet-facing that is not the product: marketing sites, admin panels, VPN endpoints, CI/CD interfaces. This is the attack surface your customers inherit by trusting you.

The build and deployment pipeline. For providers, the pipeline is production. A compromised deployment credential compromises every tenant, so we examine how code moves from repository to runtime and who can touch it.

Before scoping, our penetration testing checklist covers the questions to answer first.

How a STAR-aligned engagement runs

A STAR-aligned test follows the same arc as any well-run engagement, with one difference: scoping is mapped to CCM domains from the outset so the report reads as compliance evidence rather than just a vulnerability list.

  1. Scoping. We map your architecture, tenancy model and CCM answers to a test plan, and agree rules of engagement for the cloud accounts involved.
  2. Testing. UK-based testers combine configuration review with hands-on exploitation of the application, APIs and perimeter.
  3. Reporting. Findings are risk-rated with reproduction steps and remediation guidance, noting which CCM control areas each touches.
  4. Retesting. Once fixes land we verify them and issue an updated report, the version most providers attach to their CAIQ or hand to a Level 2 assessor.

What CSA STAR penetration testing costs

Scope drives price: the number of applications, APIs and cloud accounts, and the complexity of your tenancy model. UK day rates for CREST-accredited work typically run £1,100 to £1,400, and STAR-aligned engagements usually land in these bands:

Engagement scopeTypical effortTypical UK cost
Single web app and external perimeter2 to 4 days£2,200 to £5,600
SaaS platform, APIs and cloud configuration review4 to 6 days£4,400 to £8,400
Multi-service estate across several cloud accounts6 to 9 days£6,600 to £12,600
Full estate with pipeline and internal segmentation testing8 to 12 days£8,800 to £16,800

These are typical UK ranges rather than quotes; an exact price follows a short scoping call. For what moves the number, see our guide to penetration testing costs in the UK.

How EJN Labs approaches CSA STAR testing

EJN Labs is a UK-based, CREST-accredited firm holding Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we know first-hand what an assessor or enterprise buyer expects to see. When we scope a STAR-aligned engagement we start from your tenancy model: before any testing begins we map how customers are separated at the account, network, application and data layers, because that is where a cloud provider’s real risk concentrates.

Our UK-based testers then work the estate as an attacker would: standing up multiple test tenants to attack isolation from the inside, tracing API authorisation across roles and scopes, and reviewing the cloud control plane for the misconfigurations the CCM cares about. Reporting serves engineers who need reproduction steps and the compliance lead mapping findings to CAIQ answers, with retesting and a shareable summary included.

Frequently Asked Questions

Is CSA STAR mandatory for UK cloud providers?

No. CSA STAR is a voluntary programme run by the Cloud Security Alliance, and no UK law or regulator requires it. It becomes effectively mandatory only when a customer contract or procurement process demands a STAR listing, which happens most in finance, healthcare and large enterprise deals.

For providers selling into those sectors, a STAR listing increasingly functions as a ticket to the shortlist rather than an optional extra.

Does CSA STAR require penetration testing?

Not explicitly. STAR contains no clause mandating a penetration test, but the Cloud Controls Matrix it assesses against expects a risk-based programme for finding and fixing vulnerabilities and for verifying application and infrastructure controls. In our experience it is the evidence most often accepted.

The strength of that evidence matters most at Level 2, where an assessor reviews your proof.

What does CSA STAR penetration testing cost?

Expect £2,200 to £5,600 for a single application and perimeter, £4,400 to £8,400 for a SaaS platform with APIs and cloud configuration review, and £6,600 to £12,600 for a multi-service estate, at day rates of £1,100 to £1,400. Exact pricing follows a scoping call.

Those brackets correspond to 2 to 4 days for the single application and perimeter, 4 to 6 days for the SaaS platform, and 6 to 9 days for the multi-service estate.

Should I choose STAR Level 1 or Level 2?

Choose Level 1 if buyers merely ask whether you are on the registry, since the self-assessed CAIQ costs mostly internal time. Move to Level 2 when deals stall on independent assurance, picking STAR Certification if you already hold or plan ISO 27001, or STAR Attestation if your buyers are SOC 2 oriented.

Whichever route you take, the same technical testing evidence supports both levels.

Can one penetration test cover STAR, ISO 27001 and customer due diligence?

Yes, usually, provided it is scoped deliberately. A single test covering your cloud configuration, application, APIs and external perimeter produces evidence that maps to the CCM, satisfies ISO 27001 technical control verification, and answers the pen test question on most enterprise security questionnaires.

Tell your testing partner about every framework in play at scoping so the report is written to serve all of them.

Turn your STAR listing into evidence buyers trust

If STAR is on your roadmap, or a prospect has just asked for your CAIQ, get the technical evidence in place before the questions arrive. Tell us about your platform and tenancy model and we will return a fixed scope and price. Get a CREST penetration testing quote and walk into your next security review with the answers already written.

Leave a Reply

Your email address will not be published. Required fields are marked *