Google CASA Assessment: What to Do Next

CASA — Cloud Application Security Assessment — is a security assessment framework used when certain Google-connected applications need to demonstrate they handle user data securely. It is maintained through the App Defense Alliance and builds on OWASP ASVS requirements.

If Google asked you to complete a CASA assessment, that usually means your application needs restricted-scope access (or similar sensitive data access) and must go through a formal security review. Receiving the requirement does not by itself mean something is broken in your app — it means Google needs validated assurance before (or to continue) that access.

The formal assessment is performed by an authorized assessor. Nexio Watch is not that assessor; we help you prepare beforehand.

What is a Google CASA assessment?

CASA defines a consistent baseline of application security controls for web apps and web-accessible APIs. Google uses the framework so applications that access certain Google user data are evaluated against shared requirements rather than ad-hoc checklists.

Successful formal assessment typically results in documentation from an authorized lab (often described as a Letter of Validation) that you submit as part of Google’s verification process. Always follow the instructions Google and the lab give you for your specific case.

Why did Google ask me to complete CASA?

Google generally initiates this when an application requests access to restricted OAuth scopes or otherwise falls into a category that requires an annual security assessment. The Trust and Safety / verification process may contact you when it is time to start.

Common triggers include restricted-scope OAuth verification, growth in users or data sensitivity, or renewing an existing annual validation. Check the message you received for the assurance level, deadline, and next steps.

Which applications may require CASA?

Applications that access Google user data via restricted scopes are the most common case. Marketplace and other Google integrations can also be pulled into the same security-assessment track.

Whether your app needs CASA depends on Google’s current verification rules for your product and scopes — not on Nexio Watch’s opinion. Use Google’s documentation and the notice you received as the source of truth.

What should I do after receiving the CASA notification?

1. Read the notice carefully: note the deadline, required assurance level if stated, and any links Google provided.

2. Confirm application scope: which URLs, APIs, and data flows are in scope for the assessment.

3. Complete any other OAuth / verification prerequisites Google still requires before the security assessment step.

4. Review your app against CASA/ASVS-oriented controls (transport security, authn/authz, sessions, input handling, logging, and so on).

5. Engage an authorized assessor when Google instructs you to — or when you are ready to schedule formal testing.

6. Optionally run a readiness check first so obvious external and process gaps are visible before lab time starts.

What does the assessment examine?

CASA assessments are oriented around OWASP ASVS-derived requirements: authentication, session management, access control, input validation, cryptography, error handling and logging, communications security, and related application concerns.

Exact depth depends on the assurance level and process Google assigned. The assessor’s scope letter and the current CASA specification are authoritative — treat third-party summaries (including this page) as orientation only.

What can I check before contacting or working with the assessor?

Before formal testing, many teams verify HTTPS/TLS and certificates, security headers, cookie flags, obvious information disclosure, dependency vulnerabilities, secret hygiene, logout/session expiry, and server-side authorization on sensitive endpoints.

Also gather architecture notes and evidence for controls that scanners cannot see (e.g. how you delete user data on request, how privileged roles are granted).

Common security issues worth checking beforehand

Missing or weak transport security (no HTTPS redirect, weak TLS, expired certificates).

Absent security headers (HSTS, framing protection, content-type sniffing protections).

Session cookies without Secure, HttpOnly, or appropriate SameSite.

Client-only authorization checks with weak server enforcement.

Secrets in source control or verbose error pages that leak internals.

Stale dependencies with known CVEs on internet-facing surfaces.

What happens during formal assessment?

An authorized lab evaluates your application against the required CASA controls for your assurance level. They may combine automated testing, manual review, and evidence you provide. You typically share scoped URLs, test credentials if needed, and documentation.

Timelines and methods vary by lab. Follow their project plan; do not assume a self-scan or a third-party readiness report substitutes for their work.

What happens if issues are found?

Labs generally report findings and expect remediation (and often retesting) before issuing validation. Budget engineering time for fixes and a possible retest cycle — that is separate from the initial assessment fee.

A readiness check beforehand cannot prevent all findings, but it can reduce the chance that simple external issues consume the first assessment pass.

CASA readiness vs official CASA assessment

Official assessment: performed by an authorized assessor; can lead to formal validation recognized in Google’s process.

Nexio Watch readiness: independent preparation — automated external checks, a questionnaire, and a prioritized report. It is not certification, not a Letter of Validation, and not a substitute for an authorized lab.

Check Before Your Formal Assessment

Nexio Watch can run a pre-assessment readiness check on your application URL, map relevant findings to CASA-oriented requirements we support, and deliver a prioritized remediation report.

One-time payment. No subscription.

FAQ

  • Does getting a CASA request mean my app is insecure?

    Not necessarily. It usually means Google requires a standardized security assessment for the data access your app is requesting or already has.

  • Can Nexio Watch certify my app for Google?

    No. Only an App Defense Alliance authorized assessor can perform the formal assessment used for Google’s process.

  • Should I contact an assessor immediately?

    Follow Google’s instructions and timeline. Many teams fix obvious issues and gather evidence first so formal testing is more productive.

  • Where are the official requirements?

    Start with Google’s security assessment help article and the App Defense Alliance CASA materials linked below. Those supersede any unofficial summary.

Before you buy

Nexio Watch CASA Readiness is an independent preparation service. Nexio Watch is not an App Defense Alliance authorized assessor. The readiness report does not constitute CASA certification, verification, or an official CASA assessment.

Official documentation