Resource library

Zanarc resources

Research and advisories on digital asset cybersecurity.

Written for platform operators, issuers, custodians, and the supervisors and assurance providers who assess them.

Each publication is free to download; register your email address on the publication page to receive your copy. Organisations developing, operating, investing in or overseeing digital asset infrastructure may also contact Zanarc to request a confidential briefing on the research behind these publications.

Publications

One book and three advisories are currently available. Select a title to read more and register for your copy.

Zanarc book: CCSS v9, The Practitioner’s Handbook. Implementation, Audit and Certification. First Edition, 355 pages.

CCSS v9: The Practitioner’s Handbook

Book · First Edition · August 2026 · 355 pages

Implementation, Audit & Certification. The practitioner’s guide to the CryptoCurrency Security Standard: all 59 CCSS v9 requirements across the three compliance levels, the certification journey from scoping to annual recertification, mapping tables to ISO/IEC 27001:2022, NIST CSF 2.0 and PCI DSS v4.0.1, and regulatory analysis across more than ten jurisdictions. Includes a foreword by the Executive Director of C4.

Zanarc advisory: Nested exchange cybersecurity, securing the operator-host chain. Advisory, 24 August 2026, 30 pages.

Nested exchange cybersecurity

Advisory · 24 August 2026 · 30 pages

Securing the operator-host chain. Examines the risks where control and evidence divide between a nested operator and its host exchange: a three-party control chain, nine risk domains, control lessons from published incidents, a ten-objective minimum control baseline, and assurance questions for boards, regulators and host exchanges.

Zanarc advisory: RWA tokenisation cybersecurity, protecting the claim, the asset and the token. Advisory, 11 August 2026, 31 pages.

RWA tokenisation cybersecurity

Advisory · 11 August 2026 · 31 pages

Protecting the claim, the asset and the token. Examines threats across the full token lifecycle: a model for testing that the legal claim, asset record, ledger and settlement records continue to agree, nine risk domains, incident lessons, and a five-stage control model for high-impact actions.

Zanarc advisory: AI cybersecurity risk in Web3, development, operations, and third-party exposure. Advisory, 23 July 2026, 28 pages.

AI cybersecurity risk in Web3

Advisory · 23 July 2026 · 28 pages

Development, operations, and third-party exposure. Examines how AI use across Web3 development and live operations creates risk that conventional enterprise controls do not address, mapped to the seven control areas in the draft C4 AI Security Requirements for Cryptocurrency Systems standard. Independently reviewed before release.

Request a briefing

Zanarc offers confidential briefings on selected findings from the research behind these publications, for organisations developing, operating, investing in or overseeing digital asset infrastructure.