Learn more about the CCSS™ and how to get your system(s) certified.
The CryptoCurrency Security Standard (CCSS) is a set of security requirements for information systems that store, manage, or interact with cryptocurrencies, including exchanges, custodians, wallet providers, and other digital asset systems. By providing a consistent security benchmark, CCSS helps organizations assess, improve, and demonstrate the security of their cryptocurrency systems. CCSS is updated regularly to reflect changes in the cryptocurrency ecosystem and emerging security practices. The current version is 9.0.
CCSS complements established information security standards, such as ISO/IEC 27001, by adding security requirements specific to cryptocurrency systems. It is not intended to replace broader information security standards, but to build on them. Like any security standard, CCSS should be implemented and assessed by qualified security professionals and auditors to help ensure risks are identified and addressed appropriately.
CCSS certification applies to systems, not entities. Systems can be certified at CCSS Level 1, 2, or 3, with each level building on the requirements of the previous one.
There are different types of cryptocurrency systems, and an Entity can have multiple types of systems. Entities are not certified, but rather systems are certified. Systems can be certified as CCSS Level 1, 2, or 3 with increased security as the levels increase. Systems fall into 3 buckets. Self-Custody, Qualified Service Provider (QSP), and Full System.
A self-custody system has sole control of the private keys that controls that entity’s own funds. Self Custody systems do not have control over customer funds.
A CCSS Qualified Service Provider (QSP)’s system meets many of the requirements for CCSS certification with the exception of the few requirements that another system has control over. A QSP is a system that facilitates a subset of custody services to other systems and therefore is only required to meet certain requirements. This means that if a system uses a QSP, the audit focus is only on the few remaining requirements to become certified.
A CCSS Full System is a system that meets all applicable CCSS requirements in totality. In situations where a system includes a QSP system as part of their system, some CCSS requirements may be met by the QSP system, as determined by the Cryptocurrency Security Standard Auditor (CCSSA).
The lastest version of the Standard.
Guidance for conducting CCSS audits and peer review.
Definitions of terms used throughout the CCSS.
Agreement defining the roles and responsibilities of the auditor, peer reviewer, and audited entity during the CCSS audit process.
Past version of the CCSS.
Certified CCSS Systems have been independently evaluated and audited against 41 aspect controls of the CryptoCurrency Security Standard. Systems that earn Level 1, Level 2, or Level 3 designations have proven they are robust, resilient, and rooted in best practices. Learn more about the CCSS and how to get your system(s) certified below.
Before an audit takes place, entities may engage a CCSS Implementer to help design, build, and document controls in alignment with the Standard. Implementers work with the entity to assess the current state of the system, identify gaps against CCSS™ requirements, design appropriate control approaches, and produce the policies, procedures, diagrams, and evidence needed to support an audit.
Entities can find Certified CCSS Implementers on our website and contract directly with the Implementer of their choosing. Implementers are independent professionals who have demonstrated practical knowledge of how to apply the CCSS in real-world systems and have passed our CCSSI exam. While CryptoCurrency Certification Consortium (C4) certifies Implementers, it does not endorse or recommend specific individuals. Entities are responsible for following best practices when selecting and engaging an Implementer.
The first step to getting audited is to select a CCSSA. You can search our currently certified CCSSAs here. Entities then contact and negotiate with the CCSSA of their choosing. Please note that while these individuals have proven their knowledge of the CCSS, C4 does not endorse specific CCSSAs. It is imperative that entities follow best practices for selecting an auditor.
All CCSS audits cover a period of time prior to audit completion and will test the operating effectiveness of the control over this period of time. Audits are designed to be performed at least annually and cover the preceding 12 month period. All audits performed by CCSSAs are reviewed by a CCSSA-Peer Reviewer before C4 certifies an entity. Any dispute arising out of the peer review process shall be arbitrated by the CCSS Steering Committee.
The CCSSA is responsible for ensuring all data related to the audit is transmitted and stored in a secure manner for the duration of the Certificate of Compliance (CoC) and as legally required in the jurisdiction of the audit. C4 will not view documentation of evidence outside the Summary Report on Compliance (SRoC). The CCSS steering committee shall review evidentiary documentation in the case of a peer review dispute.
.
A CryptoCurrency Security Standard Implementer is an expert in applying the CCSS in real-world systems. CCSSIs help entities design, implement, and document security controls in alignment with the CryptoCurrency Security Standard, preparing systems to meet Level 1, Level 2, or Level 3 requirements.
CCSSIs work directly with entities to help identify the likely audit scope, assess gaps against CCSS requirements, and produce the practical artifacts needed to support an audit, such as policies, procedures, and diagrams. CCSSIs do not perform audits and do not issue grades or certifications.
CCSSIs must avoid any potential conflict of interest. This may include current or previous employment, familial relationships, financial interest (such as tokens or equity held), or any other matters that may constitute a conflict of interest.
Learn how to become a CCSSI here.
A CryptoCurrency Security Standard Auditor is an expert in the CCSS. CCSSAs are able to apply the CCSS standard to any information system that uses cryptocurrencies, calculating a grade for the system according to the CCSS.
CCSSAs must avoid any potential conflict of interest. This may include current or previous employment, familial relationships, financial interest (such as tokens or equity held), or any other matters that may constitute a conflict of interest.
Implementation fees will be determined between the CCSSI and the entity. It is the responsibility of the CCSSI to ensure sufficient time to complete the implementation is reflected in the agreed upon fees.
Audit fees will be determined between the CCSSA and the entity. It is the responsibility of the CCSSA to ensure sufficient time to complete the audit is reflected in the agreed upon fees.
Audit fees must also include the Listing Fee and the CCSSA-PR’s fee, as determined between the CCSSA and the CCSSA-PR. The CCSSA-PR’s fee will be forwarded to the CCSSA-PR by the CCSSA. C4 will send an invoice for the Listing Fee to the CCSSA after approving the SRoC.
The listing fee, paid by the audited system’s entity to the CCSSA, is based on Table 1.
The standard is maintained by the CCSS Steering Committee. The committee’s mission is to ensure the standard continues to remain up-to-date with industry best practices and remain neutral. Current CCSS Steering Committee members are (in alphabetical order):
Head of Audit at Provenance
Co-Founder and Chief Security Officer of Casa
President, Slow Ninja
Founder and Principal Consultant at Zanarc
Security Expert and Chairman of the Board, CryptoCurrency Certification Consortium (C4)
Head of Security at Botanix Labs
Founder & Chief Strategist at Imagine Crypto, LLC, CCSS Steering Committee Chair