# Central Bank of Kyrgyzstan Partners with CertiK to Strengthen Digital Som Security and Digital Asset Oversight
A landmark partnership between the National Bank of the Kyrgyz Republic (NBKR) and CertiK, a leading blockchain security firm, was formalized on September 9, 2026, through a Memorandum of Understanding (MoU) signed in Bishkek. The agreement establishes a comprehensive cooperation framework aimed at ensuring the security of the Digital Som — Kyrgyzstan’s central bank digital currency — and advancing the nation’s approach to digital asset regulation.
The signing ceremony brought together Sanzhar Abdygaziev, a Member of the Board of the NBKR, and CertiK’s leadership, marking a significant step in Kyrgyzstan’s journey toward building a secure and resilient digital financial infrastructure.
## Why This Partnership Matters
Central bank digital currencies represent a fundamental shift in how nations manage monetary policy, payments, and financial inclusion. With the Digital Som, Kyrgyzstan is entering a new chapter in its financial landscape — one that demands rigorous security measures from the ground up.
CertiK brings years of specialized experience in blockchain security, formal verification, and regulatory compliance tools. By partnering with the NBKR, the company aims to help Kyrgyzstan navigate the complex intersection of emerging digital currencies and the regulatory frameworks needed to oversee them responsibly.
## Key Areas of Cooperation
The MoU outlines a multi-faceted collaboration spanning several critical domains:
### Cybersecurity and Blockchain Security
The agreement calls for the exchange of expertise in cybersecurity practices tailored to digital financial systems. This includes identifying threats, hardening infrastructure, and implementing defense mechanisms that protect both the Digital Som platform and the broader digital asset ecosystem.
### Formal Verification
A distinctive element of this partnership is the emphasis on formal verification — a mathematical approach to software assurance. Rather than relying solely on traditional code audits, formal verification uses rigorous logic-based methods to confirm that systems behave exactly as intended under all defined conditions. For a central bank digital currency, this level of scrutiny adds a critical layer of confidence.
### Operational Resilience
Digital financial systems must remain functional even when faced with disruptions. The MoU addresses operational resilience by planning measures that ensure the Digital Som infrastructure can withstand and recover from technical failures, cyberattacks, or other unforeseen events in a predictable and timely manner.
### AML/CFT and Transaction Monitoring
Combating money laundering and the financing of terrorism remains a priority for regulators worldwide. Under the agreement, the NBKR and CertiK will collaborate on anti-money laundering (AML) and counter-terrorism financing (CFT) practices. This includes transaction monitoring, fund tracing, AML screening, and the analysis of digital asset flows to detect suspicious activity.
### Digital Asset Custody and Technical Standards
The partnership also covers best practices for digital asset custody, technical security standards, and licensing frameworks for entities operating in the digital asset space. These areas are essential for establishing a trustworthy environment where users and institutions can engage with digital assets safely.
### Supervision Tools and Risk Monitoring
The MoU explores the potential use of CertiK’s Supervision and Compliance platforms, which offer capabilities such as virtual asset service provider monitoring, wallet and transaction tracking, threat intelligence, and compliance reporting. It is important to note that any deployment of these tools remains exploratory at this stage and has not been finalized as a formal contract.
### Training and Knowledge Exchange
Recognizing that sustainable security requires institutional knowledge, the agreement includes provisions for training programs and ongoing knowledge exchange between the two organizations. This ensures that NBKR staff can build in-house expertise alongside CertiK’s advisory support.
## The Security Landscape Behind the Agreement
The urgency behind this partnership is underscored by the scale of losses in the digital asset space. CertiK’s Hack3D reports documented $3.35 billion in Web3-related losses during 2025, with an additional $1.31 billion lost across 344 incidents in the first half of 2026 alone. Wallet compromises alone accounted for more than $444 million in that period, while code vulnerabilities contributed to $152 million in losses.
These figures illustrate that digital asset security threats extend well beyond software bugs. They encompass social engineering, key management failures, infrastructure weaknesses, and evolving attack techniques. A partnership like the one between the NBKR and CertiK aims to address this spectrum of risks proactively.
## What the MoU Does Not Include
The agreement is important to clarify certain boundaries. It does not constitute a license or formal authorization of CertiK by the NBKR. Any references to licensing within the MoU relate to the broader regulatory frameworks governing digital asset activities, not to CertiK receiving official regulatory status in Kyrgyzstan.
## Broader Context: CBDCs and Global Security Trends
Kyrgyzstan’s move aligns with a growing global trend of central banks seeking specialized security partners as they develop their own digital currencies. Countries across Asia, Europe, and the Americas are grappling with similar questions: How do you build a digital currency that is secure, private, efficient, and resilient?
The Digital Som initiative places Kyrgyzstan among a growing group of nations exploring the potential of CBDCs to modernize financial systems, increase financial inclusion, and improve the efficiency of cross-border and domestic payments. However, the success of any digital currency initiative depends heavily on the strength of its security foundations — and that is exactly what this MoU aims to address.
## Frequently Asked Questions (FAQ)
**What is the Digital Som?**
The Digital Som is a central bank digital currency (CBDC) initiative launched by the National Bank of the Kyrgyz Republic. It represents a digital form of the national currency designed for use within the country’s digital financial ecosystem.
**What is a Memorandum of Understanding (MoU)?**
An MoU is a formal agreement between two or more parties that outlines the terms and scope of a cooperation framework. It is typically not legally binding in the same way as a contract but signals a mutual commitment to collaborate on specific objectives.
**What is formal verification?**
Formal verification is a mathematical method used to prove that a system or software meets its specified requirements. Unlike traditional testing, which checks a system against a set of test cases, formal verification uses logical proofs to validate behavior under all possible conditions within a given model.
**What role does CertiK play in this partnership?**
CertiK serves as the security and blockchain expertise partner, providing knowledge in areas such as cybersecurity assessments, formal verification, AML/CFT compliance, digital asset monitoring, and regulatory supervision tools.
**Will CertiK take over supervision of Kyrgyzstan’s digital assets?**
No. The MoU does not grant CertiK any regulatory authority over digital assets in Kyrgyzstan. The partnership is advisory and collaborative in nature, focused on sharing expertise and exploring tools that may support the NBKR’s regulatory efforts.
**Has the Digital Som already been launched?**
The article does not specify whether the Digital Som has been fully launched. The MoU covers both the development and testing phases as well as ongoing operational security, suggesting the project is still in progress.
**What are AML and CFT?**
AML stands for Anti-Money Laundering, and CFT stands for Countering the Financing of Terrorism. These are regulatory frameworks designed to detect, prevent, and report financial crimes, including the laundering of illicit funds and the financing of terrorist activities.
**What are CertiK’s main services?**
CertiK offers smart contract and blockchain security audits, formal verification, AML screening, transaction monitoring, threat intelligence, compliance reporting, and regulatory supervision tools. The company operates under SOC 2 Type II and ISO 27001 standards.
**What is operational resilience?**
Operational resilience refers to the ability of an organization or system to continue delivering critical functions during disruptions and to recover to normal operations in a timely and predictable manner.
## Conclusion
The partnership between the National Bank of the Kyrgyz Republic and CertiK represents a forward-looking approach to digital currency development and digital asset regulation. By combining the NBKR’s authority and institutional knowledge with CertiK’s technical expertise in blockchain security and compliance, the two organizations aim to build a digital financial ecosystem that is secure, resilient, and well-regulated.
As central bank digital currencies become an increasingly important part of the global financial landscape, the Kyrgyzstan-CertiK collaboration offers a model for how governments and specialized security firms can work together to address the unique challenges of digital monetary systems. The emphasis on formal verification, operational resilience, AML/CFT practices, and knowledge exchange demonstrates a comprehensive understanding of the risks involved.
The MoU marks the beginning of what both parties describe as a long-term cooperation. Whether the Digital Som will serve as a blueprint for other developing economies seeking to enter the digital currency space remains to be seen, but the commitment to security-first development is a promising sign.
Thank you for reading



