
Siemens AG Issues €330M Tokenised Bond on Blockchain — Audited by Softstack
Softstack audited the smart contracts for Siemens AG’s €330M tokenised bond, settled via central bank money on institutional blockchain rails.
Everyone can talk. We prefer to let our work and our clients speak for us. Get to know us and see the difference.
All of our team members are full-time employees — no freelancers, no outsourcing, no uncontrolled risks.
No hidden fees or vague estimates. We mostly work on fixed-price projects and deliver what we promise, without excuses.
Since 2017, we have been building cutting-edge solutions in Web3, AI, and enterprise-grade digital solutions.
Headquartered and operating fully in Germany, ensuring high standards, data protection, and reliability.
Clear updates, short response times, and full transparency throughout the project.
You work directly with our leadership. The CEO is personally involved, and we operate with a lean, effective scrum-based approach for speed and clarity.
Rated by clients on
You'll find the following service aspects in our offer.
Identify critical or important business functions, the ICT systems that support them, and third-party providers that must sit inside testing scope.
Review logging, monitoring, access control, incident response, and change management so offensive tests produce usable resilience evidence instead of avoidable noise.
Clean up known high-risk gaps before formal testing: exposed services, wallet/key handling, API auth, privilege paths, and undocumented dependencies.
Define what belongs in annual penetration testing versus advanced TLPT, who owns white-team governance, and which artefacts supervisors will expect.
Produce a readiness report with residual risks, recommended test types, and a sequenced plan into pentest, DORA/VARA programmes, or threat-led exercises.
ICT preparation is the work you do before formal resilience testing so scope, controls, and evidence are ready. It covers mapping critical functions, knowing which systems and vendors are in scope, closing obvious gaps, and deciding whether you need a standard pentest programme or advanced threat-led testing.
DORA expects financial entities to maintain ICT risk management and a digital operational resilience testing programme. VARA expects Dubai VASPs to run annual independent vulnerability assessments, pentests, and relevant smart contract audits, with TLPT when notified. ICT preparation gets your inventory, controls, and documentation ready so those engagements are efficient and supervisor-credible.
No. Preparation reduces blind spots and organises scope. Penetration testing and TLPT are the offensive exercises that follow. Doing preparation first usually shortens test cycles and improves the quality of findings and remediation evidence.
CASPs, banks, payment firms, custodians, exchanges, and VASPs that expect DORA scrutiny, VARA inspections, client due diligence, or a first TLPT notification. It is also useful before a major product launch that will trigger mandatory retesting.
A readiness report with scoped critical functions, priority gaps, recommended test types, and a practical sequence into pentest, smart contract audit, DORA/VARA compliance work, or threat-led penetration testing.