EEA EthTrust Security WG

EEA Working Group

EthTrust Security Levels

Baseline requirements for Ethereum smart contract security audits — a certification framework that lets projects and audit firms signal, in one mark, how deep an audit went.

Specification Version 3 · March 2025 Three certification levels · [S] [M] [Q] Also developing · STIX for DeFi
Now in public review — Version 4 draft

EthTrust v4 proposed technical refresh

AI-generated initial draft for expert validation. Compare v3 → v4 changes, review candidate requirements, and see the proposed GBBC RMF relationship. Not an approved EEA specification — version 3 remains the certification baseline.

Contributors

The companies behind the standard

Version 3 was written by security practitioners from the firms below, as credited in the specification itself — together with EEA staff, independent experts, and everyone who built the previous versions it extends.

Our focus

Minimum standards for smart contract security audits

The EEA EthTrust Security Levels Working Group defines baseline requirements for Ethereum smart contract security audits. These serve as a certification framework for projects and audit firms to signal audit depth and quality.

Automated checks

Requirements that a well-configured static analysis toolchain can verify across the full contract source.

Manual audit

Human review of the contract by qualified security auditors, beyond what automated tooling can establish.

Full logic & documentation review

The deepest level — audited business logic and documentation, end to end, against the declared intent of the contract.

Audit depth increases left to right

Resources

The specification

Current — Version 3

EEA EthTrust Security Levels Specification v3

Published March 2025. This remains the current approved EEA specification and certification baseline.

How to contribute

Two open strands of work

EthTrust Security Levels

Anyone may comment on the specification — raise an issue in the public EthTrust-public repository (no EEA membership required). To contribute directly, or to learn more about the working group, email editor@entethalliance.org.

STIX for DeFi

We are developing extensions to the STIX standard for DeFi-specific incident reporting. Join the Web3 STIX Telegram channel and contribute on the DeFi for STIX GitHub repository.