CCSS compliance
The CryptoCurrency Security Standard is the control set for how cryptographic keys are generated, stored, and used. Hackerbane audits your wallet and custody systems against CCSS and prepares your evidence for the certified assessment.
What CCSS is
The CryptoCurrency Security Standard is an open standard for any information system that stores, transacts, or accepts cryptocurrency. It is maintained by an independent consortium and sits alongside standards such as ISO 27001 rather than replacing them: ISO covers the organisation, CCSS covers the keys.
The standard defines three levels of assurance and a set of aspects covering the full key lifecycle: key and seed generation, wallet creation, key storage, key usage, key compromise policy, keyholder grant and revocation, third-party security audits, data sanitisation, proof of reserve, and audit logs. Certification is granted after an assessment by an accredited CCSS auditor.
Who it applies to
- Exchanges and custodians holding client assets.
- Wallet providers, payment processors, and merchant gateways.
- Treasury and staking operations that hold significant keys.
- Any system where software, including an AI agent, can reach a signing key.
What Hackerbane does
- Gap assessment: we map your key lifecycle to each CCSS aspect at the level you are targeting and list where the control or its evidence is missing.
- Key management audit: how seeds and keys are generated and backed up, how they are stored, and what must be true before a signature is allowed.
- Signing path review: whether the process that reads untrusted input also holds the key, whether software can sign without a documented policy, and how quorum and approval are enforced.
- Compromise and recovery: we test the key compromise policy, keyholder revocation, and recovery procedure against realistic scenarios.
- Logging and reconciliation: we check that audit logs capture what an assessor will ask for and that balances reconcile to the chain.
- Remediation and assessment support: fixes are retested, evidence is assembled per aspect, and we support you through the accredited assessment.
What you get
- A gap report against each CCSS aspect at your target level, with priorities and owners.
- Findings with severity, proof for the serious ones, and a fix for each.
- An evidence pack organised the way a CCSS assessor reads it.
- Verified remediation and an updated report once the fixes land.
Who signs off
A CCSS certificate is issued after an assessment by an auditor accredited under the standard. Hackerbane prepares you for that assessment and fixes what would fail it; the accredited assessor and the standard's governing body grant the certificate.
Questions
- Which CCSS level should we target?
- Level I is the baseline most custodial services should meet. Higher levels add stronger requirements for key generation, multi-party approval, and environmental controls. We recommend a level during the gap assessment based on the assets you hold and what your customers and regulators expect.
- Does CCSS cover smart contracts?
- No. CCSS covers the systems that hold and use keys, not the on-chain code those keys interact with. Most clients pair a CCSS readiness engagement with a smart contract audit so the vaults and contracts the keys control are reviewed by the same team.
- We already mapped our controls to CCSS. Can you use that?
- Yes. Your control mapping becomes the starting point for the gap assessment. We verify each control as it actually runs and record the evidence, so the assessor receives tested controls rather than a self-assessment.
Next step
Request an audit
Tell us how keys are generated, who may sign, whether software can reach those keys, and which CCSS level you are targeting. We will propose a gap assessment and audit plan with an estimate.