NBKR and CertiK Establish Long-Term Strategic Partnership on Digital Som Security and Digital Asset Oversight

Advertisement

A Central Bank Opens Its Door to a Web3 Security Firm

On September 15, 2026, the National Bank of the Kyrgyz Republic (NBKR) and blockchain security company CertiK signed a Memorandum of Understanding in Bishkek, formalizing a long-term partnership centered on Digital Som security and digital asset oversight.

Exterior of a central bank building representing institutional finance and monetary authority
Photo by Matheus Natan / Pexels

What the NBKR Is Actually Asking CertiK to Do

The agreement places CertiK in a working relationship with one of Central Asia’s sovereign monetary authorities – an environment defined by compliance obligations, operational restrictions, and regulatory accountability that most Web3 firms never encounter. That positioning matters. CertiK describes the NBKR engagement as a model for how it intends to approach other highly regulated institutions going forward.

Sanzhar Abdygaziev, a member of the NBKR’s Management Board who signed the MoU alongside CertiK Chief Business Officer Jason Jiang, framed the partnership around knowledge exchange rather than pure product delivery. “We see particular value in exchanging experience and expertise in blockchain and digital asset security, cybersecurity, AML/CFT, and the analysis and monitoring of digital asset transactions,” Abdygaziev said. The language signals that Kyrgyzstan’s central bank is treating this less as a vendor contract and more as an institutional learning arrangement.

The scope outlined in the MoU covers several distinct technical and regulatory tracks. On the technical side, the parties intend to explore blockchain security assessments, formal verification methods, cybersecurity protocols, and operational resilience planning. On the regulatory side, the work extends to AML/CFT frameworks, digital asset custody standards, licensing requirements, and the potential deployment of CertiK’s Supervision and Compliance monitoring solutions.

Ronghui Gu, CertiK’s Co-Founder and CEO, pointed to the design phase as the critical window for security intervention. “Digital asset infrastructure requires security and risk management to be considered from the earliest stages of design through ongoing operation,” Gu said. For the NBKR, which is still actively developing its Digital Som CBDC initiative, that framing arrives at a relevant moment – decisions made in infrastructure architecture now will shape how the system behaves under real-world stress later.

Abstract visualization of a blockchain security network with nodes and encrypted data connections
Photo by https://kaboompics.com/ / Pexels

The Regulatory Dimension Behind the Technical Work

The CBDC context gives this agreement weight that a standard security audit contract would not carry. The Digital Som is the NBKR’s initiative to modernize Kyrgyzstan’s payment infrastructure, expand financial inclusion, and improve system resilience across the country’s financial ecosystem. Unlike a private blockchain deployment, a CBDC failure would have direct consequences for monetary policy credibility and public trust in the banking system. That is why the MoU’s emphasis on AML/CFT and custody standards is significant – these are not optional compliance boxes. They are conditions for the system to function within the legal architecture Kyrgyzstan has built around its financial institutions.

The training and knowledge transfer component of the agreement deserves attention. Central banks typically maintain strict internal control over sensitive operational processes, so any arrangement involving external parties in training roles implies a degree of institutional openness that is not standard. The NBKR appears willing to build internal capacity in blockchain security rather than simply outsourcing the function – a distinction that shapes how durable this partnership is likely to be.

Advertisement

CertiK brings documented history with regulatory bodies into this arrangement. The firm has provided technical advisory support to regulators in the United States and submitted responses to regulatory consultations issued by the Monetary Authority of Singapore (MAS). Those engagements mean CertiK enters the NBKR relationship with some familiarity with the difference between advising innovation-focused regulators and working inside the more conservative institutional culture of a central bank.

Since its founding in 2017, CertiK has secured more than $600 billion in digital assets across clients in more than 150 countries and regions. The company operates under SOC 2 Type II and ISO 27001 certification standards – compliance frameworks that matter in central bank procurement contexts, where vendors typically face security vetting requirements that most commercial blockchain clients do not impose. That certification infrastructure likely made CertiK a viable candidate for a partnership of this nature in the first place.

The NBKR itself holds responsibilities well beyond the Digital Som project. As Kyrgyzstan’s primary monetary authority, it manages price stability, supervises the banking and payment systems, handles international reserves, and oversees the national payment infrastructure. Introducing a blockchain security firm into that institutional environment – even under a cooperative MoU framework rather than a direct operational contract – marks a notable shift in how the bank is approaching its digital asset mandate.

Person reviewing digital compliance documents on a tablet in a formal financial setting
Photo by Leeloo The First / Pexels

What Happens After an MoU Gets Signed

An MoU is a statement of intent, not a binding delivery schedule. The NBKR and CertiK have committed to a framework for dialogue and cooperation, but the specific outputs – security assessments completed, compliance tools deployed, staff training hours delivered – remain to be defined through whatever working arrangements follow the signing ceremony. Abdygaziev’s framing of the document as “a framework for further dialogue” reflects that reality accurately.

Whether the Supervision and Compliance monitoring tools CertiK builds for commercial clients can be adapted to meet a central bank’s requirements without modification is a question the partnership will need to answer in practice. Central banks operate on procurement cycles, approval chains, and data governance standards that differ fundamentally from those of private financial institutions – and CertiK’s existing product suite was not originally designed with sovereign monetary authorities as the primary customer.

Advertisement

Comments are closed, but trackbacks and pingbacks are open.