Is this an audit or an assessment?+
It is an independent third-party assessment. EONTA delivers an assurance/audit pillar (evidence-based evaluation of governance, controls and conformity) and a technical validation pillar (hands-on review of smart contracts, key management, infrastructure and cloud). The deliverable is an independent EONTA assessment report — not an accredited certification and not a substitute for statutory audit or due diligence.
What standards do you assess against?+
Recognised security, resilience, blockchain and regulatory standards — including ISO/IEC 27001 · 27017 · 27018, ISO 22301, the ISO/TC 307 blockchain series (ISO 22739, ISO 23257, ISO/TS 23635, ISO/TR 23576, 23455, 23642), CCSS for key management and custody, OWASP Smart Contract Top 10 & SCSVS and EEA EthTrust for smart contracts, NIST CSF / NISTIR 8202, and the regulatory frameworks MiCA, DORA, GDPR, AMLD, NIS2 and FATF.
Can you assess only one pillar?+
Yes. Engagements can apply the assurance/audit pillar, the technical validation pillar, or both in a single coordinated engagement, scoped to your platform and objectives.
What do you deliver?+
An independent EONTA assessment: an assurance/audit report and/or a technical validation report, with control-level and technical findings, severity, supporting evidence, prioritised remediation guidance, and a board- and counterparty-ready executive summary.
How does this differ from a SOC 2 report or an audit opinion?+
A SOC 2 report and an audit opinion are produced under their own frameworks by their respective providers. EONTA produces an independent assessment of digital-trust and blockchain controls and implementation against the standards above. It complements — and does not replace — statutory audit, SOC 2 or regulatory authorisation.
Do you cover the cloud infrastructure behind the platform?+
Yes. Where a tokenisation or digital-asset environment runs on cloud, EONTA assesses the cloud foundation across IaaS, PaaS and SaaS — governance and data protection (ISO/IEC 27017/27018) and configuration, isolation and access controls (CSA CCM / SOC 2).