How I would run strategic ecosystem accounts from kickoff to renewal, and a working engagement desk that scopes a repo, plans the audit, seeds the RAID log and tests scope changes against a change-order rule.
The default contracts library on EVM, ported to 10+ stacks, sold to foundations as an Ecosystem Stack. S&P Global agreed to acquire the company on 17 September 2026.
Foundation terms are milestone-paid and committee-accepted, and newer ones are partly adoption-gated. Clean governance and a written value case decide the renewal.
An engagement desk: scope any repo at a pinned commit, estimate effort, run the readiness gate, seed the RAID log, size a scope change, and read each ecosystem library's pulse.
| Takeaway | Why it matters for the role |
|---|---|
| Renewals are due now | TRON's 12-month term ends September 2026 and Stellar's two-year term ends December 2026. Polkadot's 2025 one-year proposal has run its term. |
| Adoption is part of the invoice | Canton's grant pays half on adoption: 3 independent integrators by milestone 4, 20 projects by milestone 8. Adoption needs tracking from day one. |
| Scope control protects the brand | After the November 2025 Balancer exploit, OpenZeppelin's public statement rested on the audited scope. Frozen commits and change orders are a reputational control. |
| Turnaround is what gets compared | Public renewal debates at large DAOs focus on cost, turnaround and parallel delivery. Utilisation and on-time metrics feed the renewal case directly. |
| The buyer is getting more institutional | DTCC, Fidelity, CACEIS and WisdomTree on the client list, a Technical Risk Assessment service for networks, and an S&P Ratings parent. Reporting has to read well for a CFO and a risk committee. |
A library company that sells security services, with a growing institutional book.
| Area | What is public | Read for Customer Success |
|---|---|---|
| Ownership | S&P Global agreed to acquire OpenZeppelin on 17 September 2026. It will run as its own business unit under S&P Global Ratings. Audits, engineering and ecosystem programs continue with the same team. | Expect institutional procurement, SOC 2 and ISO 27001 questions in client diligence. |
| Contracts | Solidity v5.7 (July 2026). Libraries for Cairo, Stylus, Soroban, Compact, Move, Daml and TVM. Community Contracts as a staging library. | Each port is an account with its own release cadence. |
| Services | Audits (every line by at least two researchers, then fix review), Secure Development, ZK practice, operational security, Technical Risk Assessment of networks (May 2026). | Delivery spans researchers, engineers and DevRel. The PM keeps them on one plan. |
| Continuous Security Program | Subscription with reserved researcher capacity and the AI Auditor on every engagement (May 2026). | Recurring revenue, and a natural path from a one-off audit. |
| Tooling | Defender sunset on 1 July 2026. Relayer and Monitor open source in Rust. Contracts Wizard, UI Builder, Contracts MCP, Role Manager. | Migration questions from former Defender users may land on CS. |
| Scale | 900+ audits, 200+ active customers, 95%+ re-engagement, NPS 71, 140+ people (company figures). | The retention bar is already high. The work is keeping it through growth. |
The Ecosystem Stack bundles a library port, audit researcher-weeks, tooling, a bug bounty, developer enablement and a dedicated technical account manager. Public terms below; the account list is larger.
| Account | What OpenZeppelin delivers | Term | What CS watches |
|---|---|---|---|
| Canton | Daml library, reference implementations, 55 researcher-weeks, bounty, TAM | 24 months from May 2026, 8 quarterly milestones | Adoption-gated payments. Timeline amended September 2026; milestone 2 falls in November. |
| Stellar | Stellar library, 40 auditor-weeks, Wizard, RWA Wizard, Relayer and Monitor | January 2025 to December 2026 | Renewal case due this quarter. stellar-contracts is on a release candidate. |
| TRON | TVM port, upgradeable variant, upgrades plugins, settlement contracts, TAM with biweekly syncs | 12 months to September 2026 | Term ends this month. Libraries audited July 2026. |
| Polkadot | Runtime templates, pallets, Hub libraries, Wizard | 2025 one-year proposal | No commits in 90 days on the runtime templates. Confirm 2026 intent. |
| Arbitrum Stylus | Rust contracts library, SDK audits | Since 2024 | Last release over a year old, 1 commit in 90 days. |
| Uniswap | v4 security partner, Hooks library (Foundation grant) | Since 2024 | Library release cadence and hooks audit pipeline. |
| Zama, Midnight, Sui, Miden | Confidential contracts (ERC-7984), Compact library, Move library, Guardian | 2025 to 2026 starts | Younger accounts: first renewal narratives get written here. |
| Solana Foundation | Confidential computing track | Into 2027 | New engagement with a principal engineer hire open. |
| ZKsync, Linea, USDT0, T-REX | Continuous release audits, embedded security, compliance infrastructure | Ongoing | Continuous programs: utilisation and turnaround are the metrics. |
Sources in §08. Repo signals from the demo's Ecosystem pulse tab, public GitHub data taken 23 September 2026.
At renewal, a foundation compares OpenZeppelin with these firms. The library is the moat; price and turnaround are where the comparison happens.
| Firm | Model | Where it competes at renewal |
|---|---|---|
| Certora + ChainSecurity | Formal verification plus boutique audits | Paired bids on DAO security retainers; took Compound's 2026 to 2027 program. |
| Spearbit / Cantina | Curated researcher network and contest marketplace | Flexible capacity and contest pricing. No standard library to anchor an ecosystem. |
| Sherlock | Contests, private audits, Sherlock AI, coverage | Bundled coverage appeals to DAOs that want a payout backstop. |
| Trail of Bits | Deep research consultancy and open tooling | Chain-level and infrastructure reviews for foundations. |
| Zellic, OtterSec | Research boutiques strong on Rust, Move and Solana | Direct overlap on Sui, Solana and Stellar, where OpenZeppelin's library is newer. |
| CertiK, Halborn, Hacken | High-volume audits, pen testing, compliance angle | Lower price points; CertiK's ratings sit near where S&P is heading. |
| Octane, Almanax | AI-native continuous scanning | Same buyer as the Continuous Security Program, without a human audit brand. |
| Immunefi | Bug bounties; absorbed Code4rena's bounty clients in 2026 | Post-deploy spend. Usually a partner inside the Ecosystem Stack. |
The Engagement Desk reads public GitHub data live in the browser. Building it surfaced these.
| Finding | Evidence | What I would do with it |
|---|---|---|
| Small diffs and re-scopes look alike in a commit count | Morpho Blue v1.0.0 to main is 374 commits ahead, yet in-scope churn is 19 normalised lines (2.2%). Uniswap Hooks v1.1.0 to v1.2.0 is 236 commits with 1,180 lines of churn and 7 new files (76%). | Size change requests on normalised in-scope lines, and write the threshold into the SOW. |
| Two ecosystem libraries are quiet | rust-contracts-stylus: 1 commit in 90 days, last release 378 days old. polkadot-runtime-templates: none in 90 days. | Raise at the next account review before the client raises it at renewal. |
| Review backlog on the flagship library | openzeppelin-contracts: 140 open PRs, 108 merged in 90 days. | Track reviewer capacity against roadmap promises made to ecosystems. |
| Release candidates sit open | stellar-contracts v0.8.0-rc.3 is 99 days old during the renewal window. | A GA date plus an audit slot is a concrete item for the renewal packet. |
| Readiness gaps are visible from outside | Floating or mixed pragmas, TODOs at the frozen commit, thin NatSpec and missing specs all show up in a scan before kickoff. | Send the readiness list with the SOW, so fixes land before researcher-weeks start burning. |
| Scope size predicts audit length | Measured at their scope commits, 73 full-scope published OpenZeppelin audits fit days ∝ size0.49 (R² 0.48 on log scale, median error 34%). Doubling scope adds about 40% to the calendar. | Quote dates from the benchmark and the range, and show the closest past audits next to the quote. |
| Review-cost signals are countable | Assembly, delegatecall, proxies, cross-chain messaging, oracles, signatures, callbacks and custom math each change effort, and each is a regex away. | Give Sales a consistent first estimate and give researchers the RAID risks on day one. |
The calendar estimate is benchmarked on 93 published OpenZeppelin audit reports (73 full-scope), each re-measured at its scope commit; the dataset and fit are on the demo's Method tab. Researcher-weeks stay a planning input because reports do not state team size.
| JD duty | How I would do it | Detailed in |
|---|---|---|
| Own the engagement | One account page per ecosystem: term, milestones, sold vs used researcher-weeks, owners, open RAID items, renewal date. Reviewed weekly. | §05 |
| Drive delivery | Kickoff from a scan-based brief, frozen commit in the SOW, readiness gate a week before start, draft report, fix review, publication with client sign-off. | §05, demo |
| Administer program governance | RASCI per workstream, one milestone plan, one RAID log, a monthly executive status. Artifacts live in Notion and link to GitHub. | §05 |
| Orchestrate technical delivery | Requirements sessions become milestones with exit criteria. Go/no-go written at each stage gate. Repo access and vendor onboarding tracked as dependencies. | §05, demo |
| Coordinate third-party infrastructure | Bounty platforms, oracle and bridge providers as named dependencies with dates. Commercial questions routed to leadership with options. | §05 |
| Dependency mapping and risk | A cross-team dependency map per account, a risk and compliance register, and a monthly regulatory-readiness review for institutional clients. | §05 |
| Build account intelligence | Library pulse, governance forum activity, funding and roadmap per ecosystem, refreshed before each account review. | ★, demo |
| Grow the account | Renewal packet built from delivered value; expansion into the Continuous Security Program, new library modules and ecosystem-builder audits. | §06 |
| Engage technically | Scope estimates from the code itself: nSLOC, review-cost signals, dependency pins. Enough to talk architecture with a CTO. | demo |
| Operate with rigor | Weekly utilisation, allocation and on-time delivery per account. Automations for status reports from GitHub, Notion and HubSpot. | §05, §07 |
| Unreasonable hospitality | Same-day replies, no surprises on dates, bad news first with a plan attached. | §06 |
One set of artifacts per account, with a clear owner each and a fixed cadence.
| RASCI | CS PM | Researchers | Secure Dev | Sales / Growth | Exec | Client |
|---|---|---|---|---|---|---|
| SOW scope and frozen commit | R | C | C | A | I | S |
| Readiness gate (go/no-go) | A | R | C | I | I | S |
| Audit delivery and findings | S | A, R | C | I | I | C |
| Library milestones | A | C | R | I | I | C |
| Change orders | R | C | C | A | I | S |
| Report QA and publication | A | R | I | C | I | C |
| Milestone acceptance packet | A, R | S | S | C | I | C |
| Renewal narrative | R | S | S | A | C | I |
| Cadence | Audience | Contents |
|---|---|---|
| Biweekly sync | Client engineering, OZ leads | Milestone progress, blockers, RAID changes, next two weeks. |
| Monthly executive status | Client leadership, OZ exec | One page: milestone status, researcher-weeks used, findings resolved, adoption KPIs, decisions needed. |
| Quarterly milestone acceptance | Foundation committee | Deliverables against exit criteria, links to releases and reports, adoption evidence, next quarter's plan. |
| Renewal review (T-120 days) | Sales, Growth, Exec | Value delivered, account health, expansion options, risks to renewal. |
| Weekly internal | Delivery leads | Utilisation, allocation, on-time delivery, stage-gate calls due. |
| Stage gate | Exit criteria | Evidence |
|---|---|---|
| 1. Scoped | Frozen commit, file list, effort estimate, change-order rule signed | SOW with scope table (demo export) |
| 2. Ready | Build passes, tests run, spec received, repo access granted | Readiness checklist (demo) |
| 3. Reviewed | Draft report, readout call held | Report draft, finding tracker |
| 4. Fixed | Fix review complete, each finding resolved or acknowledged | Final report |
| 5. Published | Client approval, report live, milestone accepted | Blog post, acceptance record |
| Move | Mechanic | Why it works |
|---|---|---|
| Renewal packet at T-120 days | Releases shipped, audits delivered, findings fixed, TVL on the library, adoption KPIs, researcher-weeks used against sold. One page plus appendix. | Committees vote on evidence. Starting early leaves room for a second draft. |
| Adoption instrumentation from week one | Dependency tracking of the library in public repos, Wizard usage, docs analytics, integrator list kept current. | Canton-style adoption gates pay only on counted projects. |
| Turnaround as a published metric | Days from request to kickoff and from kickoff to draft report, reported monthly per account. | Turnaround is the most common complaint in public renewal threads. |
| Parallel delivery on retainers | Queue audits in parallel lanes by size, with the estimate from the desk deciding the lane. | Answers the "one at a time" concern before it is raised. |
| Audit to Continuous Security Program | After a clean fix review, propose reserved capacity plus the AI Auditor on every PR. | Recurring revenue built on a relationship that is already working. |
| Ecosystem builder audits | Route ecosystem teams building on the library into audit slots, with the foundation's subsidy where one exists. | Expansion inside the account, and adoption evidence for the foundation. |
| Institutional readiness pack | SOC 2 and ISO 27001 evidence, report format and publication policy prepared once for bank diligence. | Shortens procurement for regulated clients. |
Built from the public job posting (2026), OpenZeppelin's site and blog, public grant proposals and governance forums, press releases and public GitHub data, read on 2026-09-23. Company figures are labelled as company figures. The demo is my own tool, built for this application, and reads only public GitHub data. Unsolicited interview homework; happy to walk through any section.
Ownership: S&P Global release · OpenZeppelin post
TRON: Ecosystem Stack proposal · library audit
Stellar: SDF partnership · RWA Wizard
Polkadot: 2025 proposal · Arbitrum: Stylus
Services: audit process · readiness guide · Continuous Security Program
Figures: about us · security stats
Scope: Balancer v2 exploit analysis · Defender: sunset FAQ
Renewal debates: Compound 2025 thread · 2026 to 2027 providers
Competitors: Code4rena wind-down · Zellic V12 · Octane
Demo: oz-cs.leverlabs.workers.dev · Repos: github.com/OpenZeppelin
Independent homework for the OpenZeppelin Program Manager (Customer Success) role · 2026 · edwardtay.com