EEA Working Group
EthTrust Security Levels
Baseline requirements for Ethereum smart contract security audits — a certification framework that lets projects and audit firms signal, in one mark, how deep an audit went.
EthTrust v4 proposed technical refresh
AI-generated initial draft for expert validation. Compare v3 → v4 changes, review candidate requirements, and see the proposed GBBC RMF relationship. Not an approved EEA specification — version 3 remains the certification baseline.
Contributors
The companies behind the standard
Version 3 was written by security practitioners from the firms below, as credited in the specification itself — together with EEA staff, independent experts, and everyone who built the previous versions it extends.
Our focus
Minimum standards for smart contract security audits
The EEA EthTrust Security Levels Working Group defines baseline requirements for Ethereum smart contract security audits. These serve as a certification framework for projects and audit firms to signal audit depth and quality.
Automated checks
Requirements that a well-configured static analysis toolchain can verify across the full contract source.
Manual audit
Human review of the contract by qualified security auditors, beyond what automated tooling can establish.
Full logic & documentation review
The deepest level — audited business logic and documentation, end to end, against the declared intent of the contract.
Audit depth increases left to right
Resources
The specification
EEA EthTrust Security Levels Specification v3
Published March 2025. This remains the current approved EEA specification and certification baseline.
- Version 2 (checklist)Published 13 Dec 2023
- Version 1Published 22 Aug 2022
How to contribute
Two open strands of work
EthTrust Security Levels
Anyone may comment on the specification — raise an issue in the public EthTrust-public repository (no EEA membership required). To contribute directly, or to learn more about the working group, email editor@entethalliance.org.
STIX for DeFi
We are developing extensions to the STIX standard for DeFi-specific incident reporting. Join the Web3 STIX Telegram channel and contribute on the DeFi for STIX GitHub repository.