The National Bank of the Kyrgyz Republic and CertiK have formally entered into a Memorandum of Understanding focused on security cooperation for the Digital Som alongside broader digital asset oversight. This framework encompasses cybersecurity, formal verification, AML/CFT measures, operational resilience, regulatory supervision, and knowledge sharing.
On September 9, 2026, the National Bank of the Kyrgyz Republic (NBKR) and CertiK executed a Memorandum of Understanding (MoU) in Bishkek, setting up a structured partnership for Digital Som security and digital asset supervision.
Sanzhar Abdygaziev, a Member of the Board of the NBKR, signed the pact alongside representatives from CertiK.
Through this agreement, both entities intend to trade insights concerning cybersecurity, blockchain security, digital assets, regulatory supervision, and risk management.
Supporting Digital Som Security
A primary focus of the partnership centers on the Digital Som, which is the central bank digital currency initiative spearheaded by the NBKR.
Both organizations plan to investigate security assessments, formal verification procedures, cybersecurity controls, and operational resilience strategies throughout the creation and testing phases of the platform.
Formal verification employs mathematical methods to test if software satisfies predefined properties under a specific model. This practice aids traditional security reviews by checking system behavior against explicitly defined specifications.
Operational resilience forms another key component of the MoU. It addresses the capacity of digital financial systems to sustain operations and recover predictably after experiencing technical failures or cybersecurity attacks.
“Digital asset infrastructure requires security and risk management to be considered from the earliest stages of design through ongoing operation,” said Ronghui Gu, Co-Founder and CEO of CertiK. “We look forward to bringing CertiK’s expertise and experience to our long-term cooperation with the NBKR, supporting the secure development of the country’s digital asset ecosystem.”
Digital Asset Oversight and AML/CFT
The collaborative framework extends beyond the Digital Som initiative itself.
Based on the text of the MoU, CertiK and the NBKR aim to share knowledge regarding the supervision of digital assets as well as digital asset service providers.
This includes anti-money laundering and countering the financing of terrorism (AML/CFT) practices, transaction monitoring, digital asset custody, technical security standards, and licensing criteria.
“The Memorandum of Understanding that we are signing today establishes a framework for further dialogue and cooperation,” said Sanzhar Abdygaziev, Member of the Board of the NBKR. “We see particular value in exchanging experience and expertise in blockchain and digital asset security, cybersecurity, AML/CFT, and the analysis and monitoring of digital asset transactions.”
The participants also intend to work together on examining risks and compliance trends linked to digital assets.
Security Monitoring and Regulatory Supervision
As part of this arrangement, the NBKR and CertiK will look into potentially utilizing CertiK’s Supervision and Compliance tools for continuous risk tracking and regulatory oversight.
CertiK Compliance merges capabilities such as AML screening, fund tracing, threat intelligence, compliance reporting, and counterparty and asset assessments.
CertiK Supervision is built for regulators, enabling the tracking of virtual asset service providers, tokens, wallets, and transactions.
Implementing these tools remains strictly exploratory under the current MoU and has not been announced as a finalized, contracted deployment.
The cooperation framework additionally provides for training programs and knowledge sharing between the two institutions.
Security During CBDC Development
This agreement arrives while central banks and financial institutions continue to investigate digital currency infrastructure alongside its operational requirements.
CBDC security considerations encompass software integrity, key management, payment settlement, transaction monitoring, privacy, system uptime, and operational resilience.
The MoU bridges several of these concerns for the ongoing development of the Digital Som.
According to CertiK’s Hack3D reports, Web3-related losses totaled $3.35 billion throughout 2025. The firm documented an additional $1.31 billion in losses spanning 344 incidents during the first six months of 2026.
Wallet compromises accounted for more than $444 million in losses during the first half of 2026, whereas code vulnerabilities contributed $152 million.
These figures underscore the diverse threat landscape impacting digital asset infrastructure, featuring risks that go beyond mere software bugs.
Broader Cooperation on Digital Assets
Aside from the Digital Som, the MoU outlines a blueprint for technical and strategic cooperation covering the wider digital asset environment.
Specific areas noted in the agreement consist of:
- Blockchain and digital asset security
- Cybersecurity
- Formal verification
- Operational resilience
- AML/CFT
- Digital asset custody
- Technical security standards
- Licensing and supervision
- Risk monitoring
- Training and knowledge exchange
The agreement does not grant CertiK any license or authorization status from the NBKR.
References to licensing within the MoU pertain exclusively to the regulatory standards governing organizations engaged in digital asset activities.
Both parties stated their intention to maintain ongoing dialogue and exchange expertise as the NBKR shapes its strategy for digital currency architecture and digital asset supervision.
About CertiK
CertiK functions as a blockchain and Web3 security firm that offers security assessments, formal verification, monitoring, compliance, and risk management solutions.
Established in 2017, the enterprise collaborates with blockchain projects, financial institutions, and government agencies to secure digital assets and manage related risks.
Its offerings comprise smart contract and blockchain audits, formal verification, AML screening, transaction monitoring, threat intelligence, and regulatory oversight utilities.
CertiK operates in alignment with SOC 2 Type II and ISO 27001 standards.
Frequently Asked Questions
What is the purpose of the MoU between CertiK and NBKR?
The Memorandum of Understanding establishes a framework for cooperation on the security of the Digital Som and the broader digital asset oversight, focusing on cybersecurity, formal verification, AML/CFT, and operational resilience.
When was the agreement signed?
The MoU was signed on September 9, 2026, in Bishkek by Sanzhar Abdygaziev and representatives from CertiK.
Does the MoU mean CertiK is licensed by the NBKR?
No, the agreement does not constitute a license or authorization of CertiK by the NBKR. Licensing references in the MoU relate strictly to regulatory frameworks governing entities that conduct digital asset activities.
Are CertiK’s Supervision and Compliance tools currently deployed for the NBKR?
No, any deployment of these tools remains purely exploratory under the MoU and has not been announced as a contracted implementation.


