Every IOnclad finding already carries a CWE id. This report groups your findings by the OWASP ASVS v4.0 control area a Google CASA assessment looks at and exports it as a Markdown document you can act on. It exists to help you find and fix the mapped issues before an assessment. It is a readiness aid, not a certification, and it says so on the report. Part of IOnclad Pro.
A raw scan is a flat list of findings. A CASA assessment is organized around ASVS control areas. This feature bridges the two: it tags each finding with its CWE id and its primary ASVS v4.0 control chapter, groups the scan by that chapter with severity counts, and writes a Markdown report to your Desktop. It runs entirely offline on your existing scan results and skips anything you have suppressed.
Google CASA (Cloud Application Security Assessment), run by the App Defense Alliance, is the security review path for apps that request sensitive or restricted Google API scopes. CASA Tier 2 is aligned to the OWASP Application Security Verification Standard (ASVS) v4.0, and its acceptance criteria are expressed as CWEs that must not appear in scan results.
Two facts shape how any scanner can honestly help here. First, ASVS 5.0 (released May 2025) dropped its direct CWE and NIST mappings, so v4.0 is the version CASA still uses and the one with a maintained CWE cross-reference. IOnclad maps to v4.0 on purpose. Second, Google deprecated the CASA Tier 2 self-scan: verification now runs through an authorized lab. That makes the only legitimate role for a static tool the one this feature fills, preparing you before the assessment.
This is readiness, not certification. IOnclad is not an App Defense Alliance authorized assessor, static analysis cannot verify every ASVS control (many need manual review or dynamic testing), and a clean scan is not, by itself, a CASA pass. Use the report to prepare, then follow the CASA process in your Google notification with an authorized assessor. Never read this report as "CASA compliant" or "CASA certified."
The exported Markdown opens with your project, the IOnclad engine version, and the readiness disclaimer, then two things an assessor-minded reader wants:
The mapping reuses the CWE that every finding already carries, so nothing is guessed at report time:
IOnclad finds known patterns and common misconfigurations. It is not a guarantee, a full penetration test, or a compliance certification, and this report does not determine or predict a CASA outcome.
Scan your code in under a minute, then export the readiness report from IOnclad Pro. Nothing leaves your machine.