---
title: "Zanarc resources: digital asset cybersecurity advisories"
description: "Free publications from Zanarc on digital asset cybersecurity: the CCSS v9 handbook and advisories on service provider management, nested exchanges, RWA tokenisation and AI risk."
image: https://resources.zanarc.com/hubfs/Zanarc_Social_Card_General_1200x628.png
---

[![Zanarc Limited](https://resources.zanarc.com/hs-fs/hubfs/Zanarc%20Logo_Lockup_Landscape_Colour_RGB.png?width=250&height=33&name=Zanarc%20Logo_Lockup_Landscape_Colour_RGB.png "Zanarc Limited")](https://zanarc.com)

Resource library

# Zanarc resources

**Research and advisories on digital asset cybersecurity.**

Written for platform operators, issuers, custodians, and the supervisors and assurance providers who assess them.

Each publication is free to download; register your email address on the publication page to receive your copy. Organisations developing, operating, investing in or overseeing digital asset infrastructure may also contact Zanarc to request a confidential briefing on the research behind these publications.

## Publications

One book and four advisories are currently available. Select a title to read more and register for your copy.

![Zanarc book: CCSS v9, The Practitioner’s Handbook. Implementation, Audit and Certification. First Edition, 355 pages.](https://resources.zanarc.com/hubfs/Zanarc_CCSS_v9_Handbook_Cover_1200x1683.png)

## CCSS v9: The Practitioner’s Handbook

Book · First Edition · August 2026 · 355 pages

**Implementation, Audit & Certification.** The practitioner’s guide to the CryptoCurrency Security Standard: all 59 CCSS v9 requirements across the three compliance levels, the certification journey from scoping to annual recertification, mapping tables to ISO/IEC 27001:2022, NIST CSF 2.0 and PCI DSS v4.0.1, and regulatory analysis across more than ten jurisdictions. Includes a foreword by the Executive Director of C4.

[View and download](https://resources.zanarc.com/ccss-v9-practitioners-handbook?hsLang=en)

![Zanarc advisory: Service provider management, cybersecurity due diligence and ongoing monitoring. Advisory, 16 September 2026, 38 pages.](https://resources.zanarc.com/hubfs/Zanarc_Advisory_Service_Provider_Management_Cover_NoButton_1200x.png)

## Service provider management

Advisory · 16 September 2026 · 38 pages · with Excel toolkit

**Cybersecurity due diligence and ongoing monitoring.** Explains how to assess a service provider before approval, examine the relevant controls and monitor the service throughout the relationship: six evidence priorities for critical services, five breach case studies (Bybit and Safe, Brevo, SolarWinds, Target and CalPERS), a due diligence method, a monitoring schedule and response criteria for a compromised provider. Delivered with a workbook for the service register, assessment, evidence, risks, monitoring and exit tests.

[View and download](https://resources.zanarc.com/service-provider-management-advisory?hsLang=en)

![Zanarc advisory: Nested exchange cybersecurity, securing the operator-host chain. Advisory, 24 August 2026, 30 pages.](https://resources.zanarc.com/hubfs/Zanarc_Advisory_Nested_Exchange_Cover_NoButton_1200x1600.png)

## Nested exchange cybersecurity

Advisory · 24 August 2026 · 30 pages

**Securing the operator-host chain.** Examines the risks where control and evidence divide between a nested operator and its host exchange: a three-party control chain, nine risk domains, control lessons from published incidents, a ten-objective minimum control baseline, and assurance questions for boards, regulators and host exchanges.

[View and download](https://resources.zanarc.com/nested-exchange-cybersecurity-advisory?hsLang=en)

![Zanarc advisory: RWA tokenisation cybersecurity, protecting the claim, the asset and the token. Advisory, 11 August 2026, 31 pages.](https://resources.zanarc.com/hubfs/Zanarc_RWA_Advisory_Cover_NoButton_1200x1600.png)

## RWA tokenisation cybersecurity

Advisory · 11 August 2026 · 31 pages

**Protecting the claim, the asset and the token.** Examines threats across the full token lifecycle: a model for testing that the legal claim, asset record, ledger and settlement records continue to agree, nine risk domains, incident lessons, and a five-stage control model for high-impact actions.

[View and download](https://resources.zanarc.com/rwa-tokenisation-cybersecurity-advisory?hsLang=en)

![Zanarc advisory: AI cybersecurity risk in Web3, development, operations, and third-party exposure. Advisory, 23 July 2026, 28 pages.](https://resources.zanarc.com/hubfs/zanarc-web3_ai_advisory_banner.png)

## AI cybersecurity risk in Web3

Advisory · 23 July 2026 · 28 pages

**Development, operations, and third-party exposure.** Examines how AI use across Web3 development and live operations creates risk that conventional enterprise controls do not address, mapped to the seven control areas in the draft C4 AI Security Requirements for Cryptocurrency Systems standard. Independently reviewed before release.

[View and download](https://resources.zanarc.com/ai-web3-cybersecurity-risk-advisory?hsLang=en)

# Request a briefing

Zanarc offers confidential briefings on selected findings from the research behind these publications, for organisations developing, operating, investing in or overseeing digital asset infrastructure.

[Contact Zanarc](https://zanarc.com/contact/)

[![Zanarc Logo\_Lockup\_Landscape\_Reverse\_White\_RGB](https://resources.zanarc.com/hs-fs/hubfs/Zanarc%20Logo_Lockup_Landscape_Reverse_White_RGB.png?width=300&height=40&name=Zanarc%20Logo_Lockup_Landscape_Reverse_White_RGB.png "Zanarc Logo_Lockup_Landscape_Reverse_White_RGB")](https://zanarc.com)

© 2026 Zanarc. All rights reserved.