Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how

nSLOC

Non-comment source lines of code. The standard metric audit firms use to size scope and price smart contract audits.

nSLOC (non-comment source lines of code) is the standard metric used by smart contract audit firms to size scope, estimate timelines, and produce price quotes. It measures only executable code, excluding comments, blank lines, and import statements. Because it correlates loosely with the attack surface an auditor must review, it has become the dominant sizing variable across competitive platforms (Sherlock, Code4rena, Cantina), private firms (Hacken, Zealynx, Trail of Bits), and scoping tooling like Solidity Metrics.

Why nSLOC, not SLOC

Raw SLOC (source lines of code) counts everything in the file, including comments, blank lines, and boilerplate. Two files with identical logic can have wildly different SLOC if one is heavily commented. nSLOC normalizes for this by counting only the code an auditor must actually read and reason about. It is a better proxy for review effort than SLOC, though neither metric captures logic density or integration complexity.

How audit firms use nSLOC

Sherlock publishes explicit mappings from nSLOC to contest duration: ~500 nSLOC for a 3-day window, ~3,000 for 18 days, ~6,000 for 38 days. Above 6,000, scope growth stops being linear — complexity becomes exponential, and firms typically recommend splitting scope or sequencing reviews. Private firms use similar heuristics internally; they rarely publish the exact formula, but nSLOC is consistently the first variable plugged in.

Limitations

nSLOC does not capture:

  • Logic density — 500 lines of ERC-20 boilerplate is not the same as 500 lines of cross-chain bridge math.
  • Integration complexity — a small contract that depends on Uniswap v4 PoolManager internals expands the threat model beyond what line count suggests.
  • Language premium — Rust on Solana, Cairo, Move, and ZK circuits all command 25–120% markups over equivalent Solidity nSLOC.

A competent audit firm uses nSLOC as a starting point, then applies multipliers for density, language, and integration scope before producing a final quote.

Measuring nSLOC yourself

Run Zealynx's free secure Solidity nSLOC calculator against your GitHub repository before requesting quotes. It separates first-party source and scripts from tests and vendor code, provides a non-binding planning range, and can carry the calculated scope directly into the Zealynx quote form. Knowing your nSLOC gives you a consistent baseline for comparing scope and timeline, while still leaving architecture and logic complexity for manual review.

Need expert guidance on nSLOC?

Our team at Zealynx has deep expertise in blockchain security and DeFi protocols. Whether you need an audit or consultation, we're here to help.

Get a Quote