My understanding is that formal verification is a tough goal to achieve and that it usually requires designing the program or the language to be a specific way.
The problem with transpiling C to rust is that unsafe and unverified behavior can be a key property of the behavior resulting program, so there isn’t an obvious way to spit out a sort of rustified (CRustified?) binary that matches the behavior of the C program.