
The National Bank of the Kyrgyz Republic and CertiK have signed a Memorandum of Understanding covering security cooperation for the Digital Som and broader digital asset oversight. The framework includes cybersecurity, formal verification, AML/CFT, operational resilience, supervision, and knowledge exchange.
On Sept. 9, 2026, the National Bank of the Kyrgyz Republic (NBKR) and CertiK signed a Memorandum of Understanding (MoU) in Bishkek, establishing a framework for cooperation on the security of the Digital Som and digital asset supervision.
The agreement was signed by Sanzhar Abdygaziev, Member of the Board of the NBKR, and representatives of CertiK.
Under the MoU, the parties plan to exchange expertise in cybersecurity, blockchain security, digital assets, regulatory supervision, and risk management.
Supporting Digital Som Security
One area of cooperation focuses on the Digital Som, the NBKR’s central bank digital currency initiative.
The parties plan to explore security assessments, formal verification, cybersecurity controls, and operational resilience measures during the development and testing of the platform.
Formal verification uses mathematical methods to assess whether software meets predefined properties under a specified model. The approach can complement traditional security reviews by examining system behavior against formally defined requirements.
Operational resilience is another area covered by the MoU. This includes the ability of digital financial infrastructure to continue operating and recover in a predictable manner following technical disruptions or cybersecurity incidents.
“Digital asset infrastructure requires security and risk management to be considered from the earliest stages of design through ongoing operation,” said Ronghui Gu, Co-Founder and CEO of CertiK. “We look forward to bringing CertiK’s expertise and experience to our long-term cooperation with the NBKR, supporting the secure development of the country’s digital asset ecosystem.”
Digital Asset Oversight and AML/CFT
The cooperation framework also covers areas beyond the Digital Som.
According to the MoU, CertiK and the NBKR intend to exchange expertise related to the supervision of digital assets and digital asset service providers.
This includes AML/CFT practices, transaction monitoring, digital asset custody, technical security standards, and licensing requirements.
“The Memorandum of Understanding that we are signing today establishes a framework for further dialogue and cooperation,” said Sanzhar Abdygaziev, Member of the Board of the NBKR. “We see particular value in exchanging experience and expertise in blockchain and digital asset security, cybersecurity, AML/CFT, and the analysis and monitoring of digital asset transactions.”
The parties also plan to cooperate on the analysis of risks and compliance trends associated with digital assets.
Security Monitoring and Regulatory Supervision
As part of the cooperation framework, the NBKR and CertiK will explore the potential use of CertiK’s Supervision and Compliance solutions for ongoing risk monitoring and regulatory oversight.
CertiK Compliance combines functions including AML screening, fund tracing, threat intelligence, compliance reporting, and assessments related to assets and counterparties.
CertiK Supervision is designed for regulatory use and supports the monitoring of virtual asset service providers, tokens, wallets, and transactions.
Any deployment of these tools remains exploratory under the MoU and has not been announced as a contracted implementation.
The cooperation framework also includes training and knowledge exchange between the organizations.
Security During CBDC Development
The agreement comes as central banks and financial institutions continue exploring digital currency infrastructure and the operational requirements associated with it.
Security considerations for a CBDC can include software integrity, key management, payment settlement, transaction monitoring, privacy, system availability, and operational resilience.
The MoU between the NBKR and CertiK establishes a framework for addressing several of these areas during the Digital Som’s development.
According to CertiK’s Hack3D reports, Web3-related losses reached $3.35 billion in 2025. The company reported a further $1.31 billion in losses across 344 incidents during the first half of 2026.
Wallet compromise accounted for more than $444 million of losses during the first half of 2026, while code vulnerabilities accounted for $152 million.
These figures highlight the range of security risks affecting digital asset infrastructure, including risks that extend beyond software vulnerabilities alone.
Broader Cooperation on Digital Assets
In addition to the Digital Som, the MoU provides a framework for technical and strategic cooperation across the broader digital asset ecosystem.
Areas identified in the agreement include:
- Blockchain and digital asset security
- Cybersecurity
- Formal verification
- Operational resilience
- AML/CFT
- Digital asset custody
- Technical security standards
- Licensing and supervision
- Risk monitoring
- Training and knowledge exchange
The agreement does not constitute a license or authorization of CertiK by the NBKR.
References to licensing within the MoU relate to regulatory frameworks governing entities conducting digital asset activities.
The parties said they intend to continue dialogue and exchange expertise as the NBKR develops its approach to digital currency infrastructure and digital asset oversight.
About CertiK
CertiK is a blockchain and Web3 security company providing security assessment, formal verification, monitoring, compliance, and risk management services.
Founded in 2017, the company works with blockchain projects, financial institutions, and public-sector organizations on digital asset security and related risk management.
Its services include smart contract and blockchain security assessments, formal verification, AML screening, transaction monitoring, threat intelligence, and regulatory supervision tools.
CertiK operates under SOC 2 Type II and ISO 27001 standards.
Source: BeInCrypto






