IOnclad  /  Features  /  CASA / ASVS Readiness
Compliance Readiness Pro

Your scan, in the shape a CASA assessment reads.

Every IOnclad finding already carries a CWE id. This report groups your findings by the OWASP ASVS v4.0 control area a Google CASA assessment looks at and exports it as a Markdown document you can act on. It exists to help you find and fix the mapped issues before an assessment. It is a readiness aid, not a certification, and it says so on the report. Part of IOnclad Pro.

What it actually does

A raw scan is a flat list of findings. A CASA assessment is organized around ASVS control areas. This feature bridges the two: it tags each finding with its CWE id and its primary ASVS v4.0 control chapter, groups the scan by that chapter with severity counts, and writes a Markdown report to your Desktop. It runs entirely offline on your existing scan results and skips anything you have suppressed.

CWE id per finding OWASP ASVS v4.0 control areas Grouped by control chapter Severity roll-up Markdown export 100% offline

What CASA is, and what changed in 2025

Google CASA (Cloud Application Security Assessment), run by the App Defense Alliance, is the security review path for apps that request sensitive or restricted Google API scopes. CASA Tier 2 is aligned to the OWASP Application Security Verification Standard (ASVS) v4.0, and its acceptance criteria are expressed as CWEs that must not appear in scan results.

Two facts shape how any scanner can honestly help here. First, ASVS 5.0 (released May 2025) dropped its direct CWE and NIST mappings, so v4.0 is the version CASA still uses and the one with a maintained CWE cross-reference. IOnclad maps to v4.0 on purpose. Second, Google deprecated the CASA Tier 2 self-scan: verification now runs through an authorized lab. That makes the only legitimate role for a static tool the one this feature fills, preparing you before the assessment.

The honest line

This is readiness, not certification. IOnclad is not an App Defense Alliance authorized assessor, static analysis cannot verify every ASVS control (many need manual review or dynamic testing), and a clean scan is not, by itself, a CASA pass. Use the report to prepare, then follow the CASA process in your Google notification with an authorized assessor. Never read this report as "CASA compliant" or "CASA certified."

What the report contains

The exported Markdown opens with your project, the IOnclad engine version, and the readiness disclaimer, then two things an assessor-minded reader wants:

How IOnclad builds it

The mapping reuses the CWE that every finding already carries, so nothing is guessed at report time:

How to use it for readiness

IOnclad finds known patterns and common misconfigurations. It is not a guarantee, a full penetration test, or a compliance certification, and this report does not determine or predict a CASA outcome.

See where you stand before the assessment does.

Scan your code in under a minute, then export the readiness report from IOnclad Pro. Nothing leaves your machine.