App Defense Alliance · CASA Authorized ADA CASA Assessment Services Cloud Application Security Assessment for Google OAuth Restricted Scope Verification NetSentries helps application providers complete Cloud Application Security Assessment — CASA — requirements for applications that access, process, transmit, or store sensitive user data through cloud and platform integrations.
CASA assessment at a glance
3 ADA assurance levels
AL0 · AL1 · AL2
OWASP ASVS Basis for CASA
requirements
Annual Validation cycle,
up to 365 days
5 Service stages from
scoping to validation
CASA is a security assessment framework developed by the App Defense Alliance and used as part of Google's restricted OAuth scope verification process. Applications requesting restricted Google OAuth scopes are required to undergo security assessment and annual revalidation. Successful completion of the applicable assessment and validation requirements may result in a Letter of Validation issued through the applicable assessment process, supporting the application's Google restricted-scope verification.
As an ADA Authorized Lab, NetSentries supports customers through scoping, onboarding, security testing, evidence review, remediation validation, reporting, and Letter of Validation support. Our assessment approach is aligned with CASA requirements, which are based on OWASP Application Security Verification Standard - OWASP ASVS - and mapped to relevant security weaknesses where applicable.
What is CASA What Is CASA? The Cloud Application Security Assessment — CASA — is a standardized security assessment framework designed to evaluate whether cloud-connected applications can securely handle user data.
Recognized security requirements CASA helps application providers demonstrate that their applications follow recognized security requirements for areas such as authentication, access control, secure data handling, application security testing, vulnerability remediation, and secure configuration.
Requirement areas
Authentication Access control Secure data handling Application security testing Vulnerability remediation Secure configuration
A consistent, risk-based approach The App Defense Alliance states that CASA is based on OWASP ASVS and follows a consistent, risk-based assessment approach. The assessment requirements apply across supported assurance levels, and applications must satisfy all applicable CASA requirements to be verified.
OWASP ASVS Application Security Verification Standard — the basis for CASA requirements.

CASA TIERS

As an ADA Authorized Lab NetSentries provides Tier 2 validation and Tier 3 assessment.

Start your Assessment Now
Your Journey with us

‍TIER 2 Assessments

Start your Assessment Now

‍TIER 3 Assessments

Start your Assessment Now
When you need it When Do You Need CASA?
You may need a CASA assessment if your application requests access to restricted Google OAuth scopes or if you have received a notification from Google or another App Defense Alliance partner requiring security validation. Google states that applications requesting restricted scopes need to undergo an annual security assessment. The assessment evaluates whether applicable CASA requirements are satisfied for the agreed scope, including how user data is handled and deleted upon request.
Customers should follow the CASA profile, assurance level, scope, and instructions specified in their current Google or App Defense Alliance notification.
Examples of applications that may require CASA include:
SaaS applications integrating with Google Workspace APIs.
Applications requesting restricted Gmail, Drive, Calendar, or other Google OAuth scopes.
Cloud applications that process, transmit, or store sensitive user data.
Applications notified by Google or another ADA partner to complete a CASA assessment.
Applications seeking continued access to restricted scopes during annual revalidation.
Assurance levels CASA Assessment Levels The App Defense Alliance certification flow identifies multiple assurance levels. The applicable level depends on the selected profile, application risk, platform instructions, and notification received by the application provider.
AL0 Self Assessment A developer-managed assessment path, where applicable based on the selected profile and platform requirements.
Developer managed
Lab reviewed AL1 Verified Self Assessment The application owner/developer completes the onboarding questionnaire and provides supporting evidence and applicable testing outputs. The ADA Authorized Lab reviews the submitted materials and performs any additional verification or testing required by the applicable profile, platform-provider instructions, and agreed assessment scope.
Questionnaire • Evidence and testing-output review • Applicable lab verification
Lab assessed AL2 Lab Assessment The ADA Authorized Lab reviews the onboarding questionnaire and relevant assessment materials, evaluates applicable audit test cases directly against the application, documents the results, and prepares the applicable assessment outputs for independent review.
Questionnaire • Automated testing • Lab testing
For AL1 assessments, applicants should follow the assessment and testing instructions provided in their Google or App Defense Alliance notification. Where the notification requires testing or verification to be performed by an authorized lab, NetSentries will perform the applicable activities within the agreed assessment scope.
Our services NetSentries CASA Assessment Services
NetSentries provides end-to-end support for CASA assessments, from initial scoping to final validation support. Our services are designed to help your team understand the applicable CASA requirements, prepare required evidence, complete security testing, remediate identified issues, and progress toward successful assessment closure.
01 Scoping and Onboarding We begin by understanding your application, assessment notification, OAuth scopes, application architecture, hosting model, and applicable CASA profile.
Key activities include:
Reviewing the Google or ADA assessment notification.
Confirming whether the assessment is platform-provider initiated or application owner/developer initiated.
Confirming the application name, project ID, OAuth client ID, and requested scopes.
Identifying application components in scope.
Reviewing application URLs, APIs, user flows, and test access requirements.
Confirming assurance level and applicable profile.
Preparing the customer for onboarding questionnaire completion.
02 Evidence and Readiness Review We help customers prepare and validate the documentation and evidence required for the assessment.
Typical evidence may include:
Completed onboarding questionnaire.
Application architecture details.
Data flow information.
OAuth scope justification.
Application URLs and API endpoints.
Test account details.
Security testing outputs, where applicable.
Existing security certifications or reports, where applicable.
Remediation evidence for previously identified vulnerabilities.
The ADA certification process refers to onboarding questionnaires, automated testing, assessment activities, Developer Test Reports, Compliance Reports, and Certification Body review as part of the assessment flow.
03 Assessment and Validation NetSentries performs the review, verification, and testing activities applicable to the selected CASA assurance level. AL1 generally focuses on review of developer-provided evidence and testing outputs, with additional verification where required. AL2 includes lab-led testing directly against the application and applicable web-accessible APIs.
The type and depth of testing performed depend on the selected assurance level, applicable profile testing requirements, platform-provider instructions, and agreed assessment scope.
Web application security testing.
API security testing.
Authentication and session management review.
Authorization and access control validation.
Input validation testing.
Secure configuration review.
Transport security validation.
Review of security headers.
Our testing approach is aligned with CASA requirements and OWASP ASVS-based expectations. CASA requirements are used across assurance levels and are mapped to OWASP ASVS assurance levels and relevant MITRE CWE categories where applicable.
04 Remediation and Revalidation Where gaps or findings are identified, NetSentries provides supporting evidence and remediation guidance. Following remediation by the application owner/developer, NetSentries revalidates failed requirements and identified vulnerabilities within the agreed assessment scope.
Our remediation support may include:
Explaining the security impact of each finding.
Prioritizing vulnerabilities based on risk.
Providing remediation recommendations.
Supporting secure design and configuration improvements.
Retesting and verification of remediation evidence.
Validating fixes after remediation.
Preparing closure evidence for assessment submission.
For applicable CASA engagements, revalidation of failed requirements and vulnerabilities identified within the agreed scope is included until completion of the current validation cycle, subject to the applicable SOW.
05 Reporting and Validation Support After testing and validation are completed, NetSentries supports the preparation of assessment outputs required for the CASA process.
Deliverables may include:
Assessment scope summary.
Security assessment report.
Findings and remediation report.
Retest and closure validation.
Evidence review summary.
Developer Test Report and Compliance Report, where applicable.
Letter of Validation or Validation Support, where applicable.
Successful completion of the applicable assessment and validation requirements may result in a Letter of Validation issued through the applicable assessment process, supporting the application's Google restricted-scope verification.
Methodology Our CASA Engagement Methodology
Phase 1 Scoping and Onboarding Confirm the application, assessment objective, CASA profile, assurance level, application URLs, APIs, components, applicable OAuth details, timelines, and required access.
Phase 2 Evidence and Readiness Review Review the onboarding questionnaire, supporting documentation, architecture and data-flow information, existing testing outputs, test accounts, and other prerequisites required for the selected assurance level.
Phase 3 Assessment and Validation For AL1, evaluate submitted evidence and testing outputs and perform additional verification where required. For AL2, perform applicable lab-led testing directly against the application in accordance with the CASA Specification, Test Guide, and agreed scope.
Phase 4 Remediation and Revalidation Document findings, explain security impact, provide remediation guidance, and revalidate failed requirements and identified vulnerabilities after corrective actions are completed.
Phase 5 Reporting and Validation Support Prepare applicable assessment reports, validation records, Developer Test Report, Compliance Report, and Letter of Validation support materials where applicable to the assessment path.
Deliverables CASA Deliverables Depending on the assessment scope and applicable requirements, NetSentries may provide the following deliverables: Deliverables depend on the selected assurance level, platform-provider instructions, agreed assessment scope, and applicable ADA/CASA process.
Deliverable Description
CASA Scoping Summary Confirms the application, assessment scope, OAuth details, URLs, and components covered during the engagement.
Evidence Checklist Lists the documentation, access details, test accounts, and supporting evidence required from the customer.
Security Assessment Report Documents the assessment activities, findings, severity, impact, and remediation recommendations.
Remediation Validation Report Confirms whether identified vulnerabilities were remediated and validated.
Developer Test Report, where applicable Supports preparation of required assessment reporting artifacts, where applicable under the ADA process.
Compliance Report, where applicable Supports preparation of compliance reporting artifacts, where applicable under the ADA process.
Letter of Validation or Validation Support, where applicable Supports the final validation process after successful completion of applicable assessment requirements.
Why NetSentries Why Choose NetSentries?
Authorized ADA Assessment Capability NetSentries supports CASA assessments as an ADA Authorized Lab. Our team helps customers navigate the assessment process, prepare evidence, complete testing, and progress toward successful validation.
Practical Experience with Google OAuth Verification We work with customers undergoing Google OAuth verification for restricted scopes and help them understand CASA requirements, assessment readiness, evidence preparation, and validation expectations.
Security-Led Assessment Approach Our CASA services are delivered by application security, cloud security, and penetration testing professionals who understand modern SaaS architectures, APIs, OAuth-based integrations, and secure data handling requirements.
Clear Remediation Guidance We do not stop at reporting findings. Our team helps customers understand the root cause, business impact, and remediation approach for identified security gaps.
Customer-Friendly Engagement Model Our process is structured to reduce assessment friction. We provide clear onboarding instructions, evidence requirements, testing expectations, remediation guidance, and reporting support throughout the engagement.
Who it's for Who Should Use This Service? NetSentries CASA Assessment Services are suitable for:
SaaS providers integrating with Google Workspace APIs.
Application providers requesting restricted Google OAuth scopes.
Product teams that have received a CASA assessment notification.
Organizations preparing for annual CASA revalidation.
Developers seeking independent security validation for cloud-connected applications.
Businesses that need a Letter of Validation to support Google restricted-scope verification.
Readiness Common CASA Readiness Requirements Before starting the assessment, customers should be prepared to provide:
11 Items to prepare
01Google, ADA partner, or other applicable assessment notification, where applicable.
02Application name and business function.
03Google Cloud project ID, where applicable.
04OAuth client ID and requested scopes, where applicable.
05Production or agreed test application URL.
06API endpoints in scope.
07Test user accounts.
08Architecture and data-flow information.
09Details of how applicable user data is collected, processed, stored, transmitted, retained, and deleted.
10Existing security reports or certifications, where available.
11Technical point of contact.
Providing complete and accurate information at the start of the engagement helps reduce delays during testing and validation. Start CASA Scoping Questionnaire
Get started Start Your CASA Assessment
If your application has received a Google or App Defense Alliance notification for CASA assessment, NetSentries can help you understand the requirement, prepare your evidence, complete security validation, and support the Letter of Validation process.
Need CASA validation for Google OAuth restricted scopes? Start your CASA assessment with NetSentries. Start CASA Scoping Questionnaire
Have questions before starting? Speak with our CASA assessment team. Contact Sales
Contact us at sales@netsentries.com or complete the CASA Scoping Questionnaire to begin your assessment.
Disclaimer CASA assurance level determination, restricted-scope approval, Google OAuth verification decisions, certification status, and final acceptance remain subject to the applicable App Defense Alliance and Google verification processes. NetSentries supports the assessment and validation process based on the scope, evidence, and requirements applicable to the customer's notification.