The Standard for Institutional DeFi

Web3SOC empowers institutions to evaluate DeFi organizations in key areas with confidence.

Developed in collaboration with industry leaders

What is Web3SOC?

Trusted by leading institutions and DeFi organizations, Web3SOC defines what it means to be institutional-grade. This makes it easy to assess and compare organizations. It provides:

  • Classifications

    A tiered system that signals institutional readiness at a glance.

  • Detailed Scoring

    Transparent breakdowns across operational, financial, security, and regulatory dimensions.

  • Confidential Assessments

    Private reviews for internal benchmarking and improvement.

Why Use Web3SOC To Evaluate Organizations?

For Institutions

Web3SOC offers a standardized due diligence tool to assess risk. It supports informed decision-making by identifying strengths and gaps in organizational maturity across key operational and compliance domains.

For Organizations

Web3SOC provides a structured path to institutional adoption. Use it to benchmark your current standing, understand expectations, and chart a course for improvement.

How Web3SOC Works

Web3SOC scores organizations in four core areas:

  • Operational

    Team structure, governance, and risk management.

  • Financial

    Economic design, capital resilience, and financial security.

  • Security

    Smart contract, application and infrastructure robustness, attack resistance, and incident response.

  • Regulatory

    Legal compliance and jurisdictional considerations.

Each area maps to the core pillars of institutional trust and allows organizations to demonstrate progress with clarity.

Registry

See the Web3SOC scores of popular organizations.

Scores

Organizations are classified into one of four tiers to signal their level of institutional readiness:

  • A

    Enterprise

    Highest standards in governance, security, and compliance; fully transparent with strong risk mitigation.

  • B

    Established

    Structured governance, security, and compliance with regular audits and reporting.

  • C

    Emerging

    Basic security and governance; lacks consistency and regulatory clarity.

  • D

    Nascent

    Same as Emerging — basic controls, but with higher risk and lower maturity.

  • These scores make it easy for institutions to assess organizational maturity at a glance, and for organizations to know exactly where they stand and what’s next.

    How to use Web3SOC?

    For Institutions

    Incorporate Web3SOC into your investment evaluation process to assess risk with clarity, structure, and confidence.

    For Organizations

    Complete the self-assessment or work with Cantina to understand your current standing - and what’s needed to earn institutional trust.

    FAQ

    What is Web3SOC and how does it work?

    Web3SOC is a standardized classification system that evaluates DeFi organizations across four core areas: operational (team structure and governance), financial (economic design and capital resilience), security (smart contract and infrastructure robustness), and regulatory (legal compliance). Organizations receive scores ranging from Enterprise (A) to Nascent (D) based on their institutional readiness.

    Who created Web3SOC and why is it trusted?

    Web3SOC was developed by Cantina in collaboration with leading DeFi organizations including Uniswap Labs, Morpho, Maple Finance, Kiln, Steakhouse Financial, L1D, and Secureum. This collaborative approach with industry leaders ensures the framework reflects real-world institutional requirements and DeFi best practices.

    What are the Web3SOC scoring tiers and what do they mean?

    Web3SOC uses four tiers:

    A - Enterprise

    Highest standards in governance, security, and compliance; fully transparent with strong risk mitigation.

    B - Established

    Structured governance, security, and compliance with regular audits and reporting.

    C - Emerging

    Basic security and governance; lacks consistency and regulatory clarity.

    D - Nascent

    Same as Emerging — basic controls, but with higher risk and lower maturity.

    How can institutions use Web3SOC for DeFi due diligence?

    Institutions can incorporate Web3SOC into their investment evaluation process to assess DeFi organizations with the same rigor as they would a traditional organization. The framework provides a standardized framework for comparing organizations and identifying strengths and gaps in governance, security, financial stability, and regulatory compliance.

    How do DeFi organizations get Web3SOC scores?

    DeFi organizations can either complete a self-assessment or work directly with Cantina for professional evaluation. Web3SOC offers both public scores for transparency and confidential assessments for private benchmarking and improvement planning.

    What does Web3SOC Enterprise A+ rating mean for DeFi protocols?

    An Enterprise A+ rating indicates the highest standards in governance, security, and compliance with full transparency and robust risk mitigation. This rating signals to institutions that the organization meets or exceeds the standards for institutional maturity.

    How often are Web3SOC scores updated and can they change?

    Web3SOC scores can be updated as organizations improve their practices across the four evaluation domains. The framework is designed as a living document that evolves with industry standards, allowing organizations to demonstrate continuous improvement in institutional readiness.

    What makes Web3SOC different from other DeFi assessment frameworks?

    Web3SOC is specifically designed for institutional evaluation, developed collaboratively with leading industry players rather than by a single entity. It provides standardized classifications, transparent scoring breakdowns, and confidential assessment options that address the unique challenges of decentralized finance.

    How does Web3SOC help bridge traditional finance and DeFi?

    Web3SOC creates a common language between institutional investors and DeFi organizations by applying familiar due diligence standards in ways that fit decentralized protocols. This standardization helps institutions assess DeFi investments with confidence while giving DeFi projects clear improvement pathways.

    What security standards does Web3SOC evaluate in DeFi protocols?

    Web3SOC evaluates smart contract security, application robustness, infrastructure resilience, attack resistance capabilities, and incident response procedures. This comprehensive security assessment helps institutions understand the technical risks associated with different DeFi protocols.

    How does Web3SOC assess DeFi governance and operational maturity?

    The operational assessment examines team structure, governance mechanisms, risk management processes, and day-to-day operational stability. This evaluation helps institutions understand whether a DeFi organization has the structural foundation necessary for long-term partnerships.

    What regulatory compliance aspects does Web3SOC cover?

    Web3SOC evaluates legal compliance across relevant jurisdictions, regulatory frameworks adherence, and jurisdictional considerations. This assessment is crucial for institutions that must ensure their DeFi investments meet regulatory requirements in their operating regions.

    Can Web3SOC scores help DeFi protocols attract institutional investment?

    Yes, Web3SOC scores provide institutional investors with standardized metrics for evaluating DeFi protocols, making it easier for high-scoring organizations to attract institutional capital. The framework gives institutions confidence in their due diligence process while highlighting protocols that meet institutional standards.

    How does Web3SOC financial assessment work for DeFi protocols?

    The financial assessment evaluates economic design sustainability, capital resilience, treasury management, and overall financial security. This analysis helps institutions understand the long-term viability and financial stability of DeFi protocols before making investment decisions.

    Is Web3SOC assessment confidential and how does the process work?

    Web3SOC offers both public and confidential assessments. Organizations can choose private assessments for internal benchmarking and improvement without public disclosure, allowing them to understand their position and make improvements before seeking public recognition.

    How can DeFi organizations improve their Web3SOC scores?

    Organizations can improve scores by addressing identified gaps across the four evaluation domains: strengthening operational processes, enhancing security practices, improving financial standing, and ensuring regulatory compliance. Web3SOC provides actionable insights for systematic improvement.

    Does Web3SOC cover all types of DeFi protocols and services?

    Web3SOC is designed to evaluate various DeFi organizations including DEXs, lending protocols, staking services, and other decentralized financial services. The framework's four-domain approach is flexible enough to assess different types of DeFi protocols while maintaining consistent standards.

    How does Web3SOC support the institutional adoption of DeFi?

    Web3SOC accelerates institutional DeFi adoption by providing familiar evaluation standards, reducing due diligence complexity, and offering clear benchmarks for institutional readiness. This standardization helps institutions move beyond pilot programs to meaningful DeFi allocations with greater confidence.