Book · First Edition · August 2026
CCSS v9: The Practitioner’s Handbook
Implementation, Audit & Certification.
The practitioner’s guide to the CryptoCurrency Security Standard, written by Marc Krisjanous, the first auditor in the world accredited under CCSS and a member of the CCSS Steering Committee. Across more than 350 pages, the handbook follows the certification journey from scoping your CCSS Trusted Environment through governance, risk management, technical controls, audit preparation, certification and ongoing compliance, and includes a foreword by Jessica Levesque, Executive Director of C4.
The handbook covers all 59 CCSS v9 requirements, maps them to ISO/IEC 27001:2022, NIST CSF 2.0 and PCI DSS v4.0.1, and examines the regulatory expectations emerging across more than ten jurisdictions. Entities seeking certification, auditors, implementers and regulators may also contact Zanarc to request a confidential briefing on how CCSS applies to their systems.
Register your email address to download the book.
Register to download
What the handbook covers
Written for entities seeking certification, CCSSAs, CCSSIs, regulators and security teams building on ISO/IEC 27001. Inside the handbook:

All 59 requirements
Every CCSS v9 requirement across the three compliance levels, with implementation guidance, checklists and requirement tables in each chapter.
The full certification journey
From scoping the CCSS Trusted Environment through governance, risk, technical controls, audit preparation, certification and annual recertification.
Cross-framework mappings
Detailed mapping tables to ISO/IEC 27001:2022, NIST CSF 2.0 and PCI DSS v4.0.1, with coverage summaries and interpretation guidance.
Regulatory context
Analysis across more than ten jurisdictions, including MiCA and DORA, the GENIUS Act, and frameworks from the FCA, SFC, VARA, MAS, JFSA and the Commonwealth.
Current threats
Zero trust architecture, AI risks to the Trusted Environment, supply chain risk, and key material beyond transaction signing.
Working tools
A key material inventory template with worked example, a readiness assessment checklist, a requirement quick reference and a glossary.
Frequently asked questions
About the handbook, the registration process, and Zanarc.
Who is the handbook written for?
Entities preparing for CCSS certification, current and aspiring CCSSAs and CCSSIs, regulators and supervisory authorities, and security teams with ISO/IEC 27001 certification who want to understand what CCSS adds. The “How to Use This Book” section sets out a reading pathway for each role.
Is the handbook free?
Yes. Register your email address and your copy of the PDF will be sent to your inbox. The handbook is licensed under Creative Commons BY-NC-ND 4.0, so you are also welcome to share it with colleagues, unmodified and with attribution.
How will my email address be used?
To deliver the handbook and, where you have opted in, occasional updates from Zanarc on digital asset cybersecurity. You can unsubscribe at any time.
What is CCSS?
The CryptoCurrency Security Standard (CCSS) is an information security standard for systems that provide cryptocurrency functions, focused on the generation, storage, access, usage and destruction of key material. It is maintained by the CryptoCurrency Certification Consortium (C4) and supported by an independent audit and certification process across three compliance levels.
Does the handbook replace the CCSS standard or C4 guidance?
No. The handbook is practitioner guidance to be used alongside the current CCSS standard and official C4 guidance. It distinguishes between what CCSS requires and what the author considers good security and audit practice, and it does not constitute a gap assessment, readiness assessment or audit.
Who is Zanarc?
Zanarc is a specialist blockchain and digital asset cybersecurity consultancy. It advises virtual asset platforms and their supervisors, conducts CryptoCurrency Security Standard (CCSS) readiness assessments and audits, and assesses cybersecurity risks arising from artificial intelligence, real-world asset tokenisation and nested exchange arrangements.
Register to download the handbook
Certification is evidence-based: the entities that reach it efficiently are the ones that scope well, plan early and know what their auditor will ask for. The handbook sets out that path for all three compliance levels, drawing on the experience of the world’s first accredited CCSS auditor.