Phase 1
Scoping and Onboarding
Confirm the application, assessment objective, CASA profile, assurance level, application URLs, APIs, components, applicable OAuth details, timelines, and required access.
Phase 2
Evidence and Readiness Review
Review the onboarding questionnaire, supporting documentation, architecture and data-flow information, existing testing outputs, test accounts, and other prerequisites required for the selected assurance level.
Phase 3
Assessment and Validation
For AL1, evaluate submitted evidence and testing outputs and perform additional verification where required. For AL2, perform applicable lab-led testing directly against the application in accordance with the CASA Specification, Test Guide, and agreed scope.
Phase 4
Remediation and Revalidation
Document findings, explain security impact, provide remediation guidance, and revalidate failed requirements and identified vulnerabilities after corrective actions are completed.
Phase 5
Reporting and Validation Support
Prepare applicable assessment reports, validation records, Developer Test Report, Compliance Report, and Letter of Validation support materials where applicable to the assessment path.