CASA Assessment Tool & Platform
Prepare your Cloud Application Security Assessment by linking its requirements to your existing controls, on a platform built in France.
What Google CASA is and why it matters
The Cloud Application Security Assessment (CASA) is Google's security evaluation framework, based on the OWASP ASVS, required of applications that access certain sensitive data through Google APIs. Any application requesting restricted API scopes must demonstrate compliance to retain its access. For software vendors, it is a mandatory, recurring step that directly conditions service continuity. Rigorous preparation avoids validation delays and interruptions to data access.
How Vailor helps you prepare your CASA assessment
CASA is not part of Vailor's catalogue of ready-to-use frameworks: the Vailor team adds its OWASP ASVS requirements on request to the Vailor Control Framework (VCF). Each requirement is linked to a control, each control to its evidence, and each gap becomes an action tracked in the action plan, with an owner and a priority. Evidence already collected for your other frameworks, a penetration test for instance, is reused without re-entry. You approach the assessment with your evidence gathered and a clear view of where you stand.
Why keep control of your technical evidence
Preparing a CASA assessment involves sensitive information about your application architecture and vulnerabilities. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice. Data is encrypted at rest and in transit, and every action is recorded in an audit log with no delete function. Your technical evidence stays under your control, from one assessment cycle to the next.
A platform built for security assessment
Requirements linked to controls
The CASA OWASP ASVS requirements linked to the controls you already maintain, with no double entry.
Faster preparation
Reuse the evidence already collected for your other frameworks rather than starting from scratch.
Centralized evidence
Gather your application security evidence, each piece tied to its control, ready to present to the CASA assessor.
Data sovereignty
As SaaS, your evidence and sensitive technical information are stored in France (AWS Paris region), or on your premises.
What you gain with Vailor
Frequently asked questions about CASA
Which applications need a CASA assessment?
The trigger is the type of OAuth permission your application asks Google users for, not the size of your organisation. An application requesting sensitive scopes goes through OAuth verification; one requesting restricted scopes, those covering the most protected content such as mail or files, must also demonstrate its application security level through CASA. An application used only by accounts inside your own organisation sits outside that verification. Scope is therefore settled application by application.
What are the CASA assessment levels?
CASA is tiered. At the lighter end sits a self-assessment backed by evidence and by automated scanning of the application; at the most demanding end, an assessment run by an authorised laboratory that adds its own testing and a documentation review. The tier is not a comfort setting a vendor picks: it follows from the verification Google asks for and from the risk carried by the data the application reaches. The preparation work is the same either way; only the standard of proof changes.
Is CASA a certification?
Not in the sense of ISO 27001: there is no accredited scheme and no certificate covering the organisation as a whole. CASA is the App Defense Alliance framework Google uses in its OAuth verification; an assessment run by an authorised laboratory ends in a letter of validation, tied to one application and to the permissions it requests, which you pass on to Google. It is not settled once and for all: while the application keeps restricted scopes the assessment has to be redone each year, and changing the scopes you request restarts the verification.
What does the OWASP ASVS check in a CASA review?
The ASVS is the application security verification standard published by OWASP, and CASA builds its requirements on it. It covers authentication and session management, access control, input validation, cryptography and secrets handling, logging, dependency management and the security of the development lifecycle. The logic throughout is evidential: for each requirement, show not an intention but a control that is in place and can be checked.
Does ISO 27001 certification exempt you from CASA?
No. An ISO/IEC 27001 certificate covers an information security management system at organisation level; CASA looks at one application and its code. Neither replaces the other. That said, much of the evidence already produced for your ISMS, a SOC 2 report or a recent penetration test feeds straight into the CASA file. The common mistake is starting from scratch when the material already exists, scattered across several teams.
What happens if the assessment does not pass?
The gaps found have to be fixed and submitted again: an assessment is not a one-shot exam. The real risk is not a single failure, it is the calendar. Until the file is validated, Google can restrict the application's access to the scopes concerned, which breaks functionality for your users. That is the argument for handling remediation continuously rather than discovering the gaps a few weeks before the deadline.
Why use a dedicated tool rather than a spreadsheet for CASA?
Because a CASA file is not a list of ticked boxes but a set of links: which requirement, which control covers it, which evidence supports it, who owns it and when it was last reviewed. A spreadsheet loses those links from one cycle to the next, so the work is redone identically the following year. A platform keeps them, flags evidence that has gone stale between assessments and reuses what is still valid, including for your other frameworks.
Explore AI GRC with Vailor
Our resources on governance, risk and compliance assisted by artificial intelligence.
By role, and to go further
Pages to discover
Recommended articles
ANSSI-labelled EBIOS RM software: the 2026 overview
The EBIOS Risk Manager tools labelled by ANSSI as of 9 October 2026, what the label guarantees, what it does not, and how to check it.
Supply Chain Cyber Risk: How to Manage Your Suppliers
Supply chain cyber risk: what NIS2, DORA and EBIOS RM require, how to map your critical third parties, and what to ask your suppliers before and after signing.
Prepare your CASA assessment
Book 30 minutes with us: we listen to your context and tell you concretely how Vailor can support your CASA preparation.