Google CASA Assessment

CASA Assessment Tool & Platform

Prepare your Cloud Application Security Assessment by linking its requirements to your existing controls, on a platform built in France.

What Google CASA is and why it matters

The Cloud Application Security Assessment (CASA) is Google's security evaluation framework, based on the OWASP ASVS, required of applications that access certain sensitive data through Google APIs. Any application requesting restricted API scopes must demonstrate compliance to retain its access. For software vendors, it is a mandatory, recurring step that directly conditions service continuity. Rigorous preparation avoids validation delays and interruptions to data access.

How Vailor helps you prepare your CASA assessment

CASA is not part of Vailor's catalogue of ready-to-use frameworks: the Vailor team adds its OWASP ASVS requirements on request to the Vailor Control Framework (VCF). Each requirement is linked to a control, each control to its evidence, and each gap becomes an action tracked in the action plan, with an owner and a priority. Evidence already collected for your other frameworks, a penetration test for instance, is reused without re-entry. You approach the assessment with your evidence gathered and a clear view of where you stand.

Why keep control of your technical evidence

Preparing a CASA assessment involves sensitive information about your application architecture and vulnerabilities. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice. Data is encrypted at rest and in transit, and every action is recorded in an audit log with no delete function. Your technical evidence stays under your control, from one assessment cycle to the next.

A platform built for security assessment

Requirements linked to controls

The CASA OWASP ASVS requirements linked to the controls you already maintain, with no double entry.

Faster preparation

Reuse the evidence already collected for your other frameworks rather than starting from scratch.

Centralized evidence

Gather your application security evidence, each piece tied to its control, ready to present to the CASA assessor.

Data sovereignty

As SaaS, your evidence and sensitive technical information are stored in France (AWS Paris region), or on your premises.

What you gain with Vailor

OWASP ASVS requirements added on request by the Vailor team to your controls
A structured, complete CASA assessment file
Gaps prioritized from P1 to P4 in the action plan
Remediation tracking through to validation
Sustained compliance from one cycle to the next
Continuity of your access to Google APIs

Frequently asked questions about CASA

Which applications need a CASA assessment?

The trigger is the type of OAuth permission your application asks Google users for, not the size of your organisation. An application requesting sensitive scopes goes through OAuth verification; one requesting restricted scopes, those covering the most protected content such as mail or files, must also demonstrate its application security level through CASA. An application used only by accounts inside your own organisation sits outside that verification. Scope is therefore settled application by application.

What are the CASA assessment levels?

CASA is tiered. At the lighter end sits a self-assessment backed by evidence and by automated scanning of the application; at the most demanding end, an assessment run by an authorised laboratory that adds its own testing and a documentation review. The tier is not a comfort setting a vendor picks: it follows from the verification Google asks for and from the risk carried by the data the application reaches. The preparation work is the same either way; only the standard of proof changes.

Is CASA a certification?

Not in the sense of ISO 27001: there is no accredited scheme and no certificate covering the organisation as a whole. CASA is the App Defense Alliance framework Google uses in its OAuth verification; an assessment run by an authorised laboratory ends in a letter of validation, tied to one application and to the permissions it requests, which you pass on to Google. It is not settled once and for all: while the application keeps restricted scopes the assessment has to be redone each year, and changing the scopes you request restarts the verification.

What does the OWASP ASVS check in a CASA review?

The ASVS is the application security verification standard published by OWASP, and CASA builds its requirements on it. It covers authentication and session management, access control, input validation, cryptography and secrets handling, logging, dependency management and the security of the development lifecycle. The logic throughout is evidential: for each requirement, show not an intention but a control that is in place and can be checked.

Does ISO 27001 certification exempt you from CASA?

No. An ISO/IEC 27001 certificate covers an information security management system at organisation level; CASA looks at one application and its code. Neither replaces the other. That said, much of the evidence already produced for your ISMS, a SOC 2 report or a recent penetration test feeds straight into the CASA file. The common mistake is starting from scratch when the material already exists, scattered across several teams.

What happens if the assessment does not pass?

The gaps found have to be fixed and submitted again: an assessment is not a one-shot exam. The real risk is not a single failure, it is the calendar. Until the file is validated, Google can restrict the application's access to the scopes concerned, which breaks functionality for your users. That is the argument for handling remediation continuously rather than discovering the gaps a few weeks before the deadline.

Why use a dedicated tool rather than a spreadsheet for CASA?

Because a CASA file is not a list of ticked boxes but a set of links: which requirement, which control covers it, which evidence supports it, who owns it and when it was last reviewed. A spreadsheet loses those links from one cycle to the next, so the work is redone identically the following year. A platform keeps them, flags evidence that has gone stale between assessments and reuses what is still valid, including for your other frameworks.

Prepare your CASA assessment

Book 30 minutes with us: we listen to your context and tell you concretely how Vailor can support your CASA preparation.

Book a demo