CCSS™ Audit Process | How to Start It?

Certified CCSS Systems have been independently evaluated and audited against aspect the CryptoCurrency Security Standard. Systems that earn Level 1, Level 2, or Level 3 designations have proven they are robust, resilient, and rooted in best practices. Learn more about the CCSS and how to get your system(s) certified below.


The first step to getting audited is to select a CCSSI or a CCSSA.

An entity may choose to begin its CCSS journey by engaging either a CCSS Implementer (CCSSI) or a CCSS Auditor (CCSSA).

A CCSSI can assist with preparing a system for certification by helping define the audit scope, identify gaps, interpret CCSS requirements, and implement appropriate controls. Working with a CCSSI is optional but can help entities improve their readiness before undergoing an audit.

When the entity is ready to pursue certification, it selects and negotiates directly with the CCSSA of its choosing. While CCSSAs have demonstrated their knowledge of the CCSS, C4 does not endorse or recommend specific auditors. Entities are encouraged to follow best practices when selecting an auditor.

CCSS audits evaluate the operating effectiveness of controls over a period of time prior to audit completion. Audits are typically performed annually and assess the preceding 12-month period. Before a Certificate of Compliance (CoC) is issued, every audit undergoes an independent peer review conducted by a CCSS Peer Reviewer (CCSSA-PR). Any dispute arising from the peer review process is resolved through arbitration by the CCSS Steering Committee.

The CCSSA is responsible for securely transmitting and retaining all audit-related evidence for the duration of the Certificate of Compliance (CoC) and for any additional period required by applicable law. C4 does not review audit evidence beyond the Summary Report on Compliance (SRoC), except when evidentiary documentation is required to resolve a peer review dispute.

c4 guide

*Text version of this image can be found in the Auditor’s Guide.

What is a CCSSA?

A CryptoCurrency Security Standard Auditor is an expert in the CCSS. CCSSAs are able to apply the CCSS standard to any information system that uses cryptocurrencies, calculating a grade for the system according to the CCSS.

CCSSAs must avoid any potential conflict of interest. This may include current or previous employment, familial relationships, financial interest (such as tokens or equity held), or any other matters that may constitute a conflict of interest.

Learn how to become a CCSSA here.

What is the cost of a CCSS Audit?

Audit fees will be determined between the CCSSA and the entity. It is the responsibility of the CCSSA to ensure sufficient time to complete the audit is reflected in the agreed upon fees.

Audit fees must also include the Listing Fee and the CCSSA-PR’s fee, as determined between the CCSSA and the CCSSA-PR. The CCSSA-PR’s fee will be forwarded to the CCSSA-PR by the CCSSA. C4 will send an invoice for the Listing Fee to the CCSSA after approving the SRoC.

The listing fee, paid by the audited system’s entity to the CCSSA, is based on Table 1.

When multiple systems (up to 3) are covered in the same audit, C4 only charges the listing fee of the most expensive system. When auditing 4-6 systems, C4 only charges the listing fee of the two most expensive systems, and so on.

Systems that maintain a Certificate of Compliance without letting it lapse receive a 25% discount on the listing fee.

Can a QSP Certified to v8.1 be used for Full System v9.0 Compliance?

Yes. Read more in the Transitions Guidelines document.