The Standard for Institutional DeFi

Web3SOC empowers institutions to evaluate DeFi protocols in key areas with confidence.

  • Private diligence reports for institutions on request
  • Control-by-control evidence review
  • Public badges: In Progress and Certified
Cantina visual placeholder for upcoming content.

Developed in collaboration with industry leaders

For Institutions

Get private Web3SOC reports for protocols you are evaluating.

Cantina visual placeholder for upcoming content.

For Protocols

Receive a private scorecard and remediation priorities. Public status badges available.

Cantina visual placeholder for upcoming content.

Framework, last updated January 2026

Designed to match institutional due diligence expectations for DeFi.

How Web3soc works:

Web3SOC scores organizations in four core areas.

Operational

Financial

Security

Regulatory

What’s public, what stays private

Public

  • In Progress badge (active assessment)
  • Certified badge (binary conformance)
  • Badges display: scope, version, expiry, SoA reference

Private

  • Scorecard and maturity mapping
  • Findings and evidence review notes
  • Remediation priorities and next steps

“In Progress” indicates an active assessment.

Deliverables

Cantina visual placeholder for upcoming content.

Assessment

  • Executive summary, key risks
  • Control-level findings and evidence list
  • Remediation priorities
Cantina visual placeholder for upcoming content.

In Progress badge (public)

  • Issued when assessment begins
  • Shows scope, version, SoA reference
Cantina visual placeholder for upcoming content.

Certified badge (public)

  • Awarded only on full conformance
  • Valid for 12 months

For Institutions

Standardized DeFi due diligence

Request access to private Web3SOC reports to evaluate protocols using consistent outputs across governance, finance, security, and legal and compliance readiness.

  • Compare protocols using a consistent report format
  • Review evidence-backed findings by control area
  • Reduce diligence time and improve documentation quality
  • Support underwriting, investment, and partnership decisions

For Protocols

A clear path to institutional readiness

Complete the Web3SOC assessment to benchmark controls, prioritize remediation, and earn public status badges that signal progress and certification.

  • Define scope using a Statement of Applicability (SoA)
  • Share evidence privately via secure channels or read-only access
  • Receive a private scorecard and remediation priorities
  • Earn “In Progress” during assessment, “Certified” on conformance

Evaluation areas

Operational (30%)

Governance, team structure, risk management, change control, custody and key management.

Financial Stability (20%)

Transparency, reserves, solvency, collateral and liquidity risk management.

Security (30%)

Smart contracts, application and infrastructure security, monitoring and incident response.

Regulatory and Compliance (20%)

Legal posture, AML/CFT readiness where applicable, disclosures, enterprise commitments.

Public status badges

Cantina visual placeholder for upcoming content.

Web3SOC In Progress

  • Issued when assessment begins for a defined scope and version
  • Shows scope, version, SoA reference
  • Not a rating
Cantina visual placeholder for upcoming content.

Web3SOC Certified

  • Binary conformance award
  • Requires all applicable controls at “Good” with verifiable evidence
  • Valid for 12 months
Disclaimer

Misuse, evidence falsification, failure to report material changes, or control regression may trigger suspension or revocation.

How the assessment works

Scope and SoA

Evidence sharing (secure channel, read−only, or screenshare)

Review and verification

Report and scorecard (private)

Public status (In Progress → Certified on conformance)

Validity and renewal (12 months)

FAQ

What is Web3SOC and how does it work?

Web3SOC is a standardized classification system that evaluates DeFi organizations across four core areas: operational (team structure and governance), financial (economic design and capital resilience), security (smart contract and infrastructure robustness), and regulatory (legal compliance).

Who created Web3SOC and why is it trusted?

Web3SOC was developed by Cantina in collaboration with leading DeFi organizations including Uniswap Labs, Morpho, Maple Finance, Kiln, Steakhouse Financial, L1D, and Secureum. This collaborative approach with industry leaders ensures the framework reflects real-world institutional requirements and DeFi best practices.

How can institutions use Web3SOC for DeFi due diligence?

Institutions can incorporate Web3SOC into their investment evaluation process to assess DeFi organizations with the same rigor as they would a traditional organization. The framework provides a standardized framework for comparing organizations and identifying strengths and gaps in governance, security, financial stability, and regulatory compliance.

What makes Web3SOC different from other DeFi assessment frameworks?

Web3SOC is specifically designed for institutional evaluation, developed collaboratively with leading industry players rather than by a single entity. It provides standardized classifications, transparent scoring breakdowns, and confidential assessment options that address the unique challenges of decentralized finance.

How does Web3SOC help bridge traditional finance and DeFi?

Web3SOC creates a common language between institutional investors and DeFi organizations by applying familiar due diligence standards in ways that fit decentralized protocols. This standardization helps institutions assess DeFi investments with confidence while giving DeFi projects clear improvement pathways.

What security standards does Web3SOC evaluate in DeFi protocols?

Web3SOC evaluates smart contract security, application robustness, infrastructure resilience, attack resistance capabilities, and incident response procedures. This comprehensive security assessment helps institutions understand the technical risks associated with different DeFi protocols.

How can DeFi organizations improve their Web3SOC scores?

Organizations can improve scores by addressing identified gaps across the four evaluation domains: strengthening operational processes, enhancing security practices, improving financial standing, and ensuring regulatory compliance. Web3SOC provides actionable insights for systematic improvement.

How are organizations evaluated?

Organizations are assessed across operational, financial, security, and regulatory domains using the Web3SOC framework.

What does Web3SOC provide?

Web3SOC provides a structured assessment framework and a certification status that reflects progress and readiness.

What is shared publicly?

Organizations may display their certification status publicly, while detailed assessment outputs can be handled privately.

Can assessments be kept confidential?

Yes. Assessment details can remain confidential and shared selectively with relevant stakeholders.

How does Web3SOC support the institutional adoption of DeFi?

Web3SOC accelerates institutional DeFi adoption by providing familiar evaluation standards, reducing due diligence complexity, and offering clear benchmarks for institutional readiness. This standardization helps institutions move beyond pilot programs to meaningful DeFi allocations with greater confidence.