Digital Asset Risk & Compliance Standard

The Trust
Standard for
Digital Assets

DARC certifies the security, operational integrity, and control effectiveness of digital asset systems across the full stack—including DeFi protocols, L1s, L2s, wallets, custodians, and centralized exchanges. It covers key management, infrastructure, governance, and incident response: the systems and processes that determine real-world reliability beyond code.

View the Standard
17
Audit Domains
3
Certification Tiers
240+
Control Requirements

Capital Flows Without a Standard

01 —

No Common Reference

TradFi institutions allocating to digital assets have no equivalent of SOC 2 or ISO 27001 to evaluate operational risk. Every due diligence engagement starts from zero.

02 —

Code Audits Miss the Stack

Smart contract audits do not assess multisig controls, key management procedures, infrastructure security, incident response readiness, or the human and operational layer.

03 —

No Public Accountability

Without a public registry of certified entities, there is no mechanism for the market to distinguish operationally sound protocols from those that represent concentrated risk.

Three Tiers of Certification

DARC-1 · Foundational

Core Controls

Establishes the minimum operational baseline. Required as a prerequisite for DARC-2.

  • Multisig and key management procedures
  • Infrastructure access controls and hardening
  • On-chain governance configuration
  • Incident response plan and escalation paths
  • Admin key lifecycle management
  • Basic operational security (OpSec) standards
DARC-2 · Advanced

Verified Integrity

Demonstrates mature operational controls and third-party verification readiness. Requires DARC-1.

  • Active bug bounty program (Immunefi or equivalent)
  • Dependency and supply chain risk management
  • Frontend security and DNS hygiene
  • Financial transparency and reserve reporting
  • Business continuity planning and tested recovery
  • Third-party risk management for integrations
DARC-3 · Institutional

Full Assurance

The highest level of certification. Designed for entities seeking regulatory recognition and institutional capital. Requires DARC-2.

  • DORA-aligned digital operational resilience testing
  • Regulatory compliance readiness (MiCA, Travel Rule)
  • Independent board and governance oversight
  • Continuous monitoring and real-time alerting
  • Annual re-certification by accredited third-party auditor
  • Full audit trail and evidence package

17 Categories Across the Stack

Key Management
DARC-1
Multisig Controls
DARC-1
Infrastructure Security
DARC-1
Governance Configuration
DARC-1
Incident Response
DARC-1
Operational Security
DARC-1
Bug Bounty Program
DARC-2
Dependency Risk
DARC-2
Frontend Security
DARC-2
Financial Reporting
DARC-2
Business Continuity
DARC-2
Third-party Risk
DARC-2
Resilience Testing
DARC-3
Regulatory Readiness
DARC-3
Oversight & Independence
DARC-3
Continuous Monitoring
DARC-3
Audit Evidence Package
DARC-3

Built for All Market Participants

TradFi Institutions

Asset managers, banks, and family offices allocating to digital assets need a standardised operational risk signal. DARC provides the due diligence shorthand that reduces friction and accelerates capital deployment.

Crypto-Native Investors

DAOs, foundations, and on-chain treasuries use DARC certification as a filter when evaluating integration partners, liquidity deployments, and protocol risk.

Protocols & Operators

DeFi protocols, L1/L2 chains, custodians, wallets, and exchanges use DARC to demonstrate operational maturity to the market and attract institutional liquidity.

Regulators

DARC-3 is designed to align with DORA and MiCA, giving supervisory authorities a recognised private-sector standard to reference in licensing and supervisory frameworks.

Verifiable, Real-Time

Every certified entity is listed in the DARC Public Registry — a machine-readable, continuously updated database of certification status, tier level, audit date, and expiry. Certification badges are cryptographically signed and verifiable on-chain.

The registry enables institutional investors, aggregators, and risk platforms to integrate DARC status directly into their due diligence workflows.

View Registry
Entity Tier Expires Status
Protocol Alpha DARC-3 Dec 2025 Active
Chain Beta DARC-2 Mar 2026 Active
Wallet Gamma DARC-1 Aug 2025 Active
Exchange Delta DARC-3 Jan 2026 Active

Free to Use. Built for the Industry.

The DARC methodology, control framework, and audit criteria are fully open source and available to anyone at no cost. We believe that operational trust standards for digital assets should be a public good — not a proprietary product.

Any organisation can read the standard, self-assess against it, or build tooling on top of it. Certification by an accredited auditor is optional, and is intended for entities that want independent, verifiable attestation.

View on GitHub
Open Methodology

The full control framework, audit procedures, and scoring criteria are published publicly under a Creative Commons licence.

No Licensing Fees

There is no cost to read, implement, or reference DARC. Certification fees cover auditor time only — DARC itself charges nothing.

Community Governed

Updates to the standard are proposed publicly, reviewed by the independent standards board, and ratified through an open comment process.

Ready to
Certify Your
Operations?

Download the Standard