
Siemens AG Issues €330M Tokenised Bond on Blockchain — Audited by Softstack
Softstack audited the smart contracts for Siemens AG’s €330M tokenised bond, settled via central bank money on institutional blockchain rails.
Everyone can talk. We prefer to let our work and our clients speak for us. Get to know us and see the difference.
All of our team members are full-time employees — no freelancers, no outsourcing, no uncontrolled risks.
No hidden fees or vague estimates. We mostly work on fixed-price projects and deliver what we promise, without excuses.
Since 2017, we have been building cutting-edge solutions in Web3, AI, and enterprise-grade digital solutions.
Headquartered and operating fully in Germany, ensuring high standards, data protection, and reliability.
Clear updates, short response times, and full transparency throughout the project.
You work directly with our leadership. The CEO is personally involved, and we operate with a lean, effective scrum-based approach for speed and clarity.
Rated by clients on
You'll find the following service aspects in our offer.
Map critical or important functions, ICT systems, and third-party providers in scope of DORA. Clarify whether you need a baseline testing programme, TLPT designation support, or both.
Assess your ICT risk management, digital operational resilience testing programme, and evidence pack against DORA expectations and related RTS guidance.
Build or harden an annual resilience testing plan: vulnerability assessments, penetration tests, scenario tests, and documentation suitable for competent authority review.
Run scoped offensive and resilience tests on systems supporting critical functions, including Web3, custody, trading, and cloud-backed ICT where relevant.
Deliver ranked findings, remediation plans, and artefacts you can show supervisors. Prepare designated entities for TIBER-EU style TLPT when required.
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) sets EU rules for ICT risk management and operational resilience testing for financial entities, including many crypto-asset service providers. If you are in scope, you need a risk-based testing programme. Designated entities must also perform threat-led penetration testing (TLPT).
Article 26 covers the baseline digital operational resilience testing programme that applies broadly: vulnerability assessments, penetration tests, and related controls on ICT supporting critical or important functions. TLPT is advanced, intelligence-led red teaming on live production systems for entities identified by their competent authority, typically on a multi-year cycle and aligned with TIBER-EU or an equivalent framework.
A standard penetration test can support your Article 26 programme when scoped to critical ICT and documented properly. It does not replace TLPT if your supervisor designates you for Article 26/27 advanced testing. We help you choose the right engagement type and evidence pack.
We combine ISO 27001 practice with Web3-specific testing: smart contracts, wallets, APIs, and on-chain components that often sit inside critical functions. That matters for CASPs and digital asset platforms whose ICT stack is not only traditional banking IT.
A focused gap analysis and testing programme design often takes weeks. Full TLPT programmes for designated entities typically run many months from scoping through threat intelligence, red team execution, purple teaming, and closure. We size the engagement to your designation status and regulator timeline.