The operational risk your audit cannot see.
An independent, evidence-based assessment of your protocol's operational maturity, mapped to 106 controls drawn from the NIST Cybersecurity Framework v2.0.
The gap
$16.6 billion has been lost across 556 DeFi exploits. Roughly 56% of it never touched the smart contracts: it came from the off-chain surface, private keys, custody, access controls, frontends, and the way a team actually operates.
A code audit is built to find bugs in the contracts. It is not built to see any of this, and this is the single largest loss domain in the market.
Case in point · July 2026
A perp protocol passed six audits and was drained of $23.7 million anyway. The attacker never touched the contract logic; they compromised a signer key. Every one of those audits scoped off-chain key management out. That is the door the PLRA closes.
What it covers
Plus the surfaces specific to onchain teams: multisig and signer hygiene, deployment and upgrade process, frontend and infrastructure security, and third-party dependency exposure.
How it works
The session runs around two hours. There is no multi-week engagement; you leave with the report in hand.
The report
A per-control PDF report with maturity scores and prioritised fixes, issued the moment the session ends. It sits in the room before the legal opinion.
EXECUTIVE SUMMARY
A two-minute executive summary: your average maturity tier, the critical and high findings, and the priority actions to close before launch.
MATURITY BY FUNCTION
Your operational maturity scored across the six NIST CSF v2.0 functions, on a defined tier scale.
FINDINGS WITH REMEDIATIONS
Every critical and high finding mapped to the exact control, each paired with a concrete remediation.
ALL 106 CONTROLS
Control-by-control detail across all 106 controls, with tier definitions and a glossary.
Who it's for
Approaching launch
Protocols shipping their first deployment that need a structured, evidenced read on operational readiness.
Expanding surface
Teams shipping a new product line or expanding to a new chain, where the prior assessment no longer covers the changed surface.
Raising institutional capital
Teams that need to prove operational maturity before an allocator will deploy.
Book the assessment