If you work in risk, compliance, or strategy at a bank, you've probably already had this conversation. A digital currency project arrives on your desk. The business case is written, the board has a date, and somewhere near the end of the plan, after the build, sits a line item for a security review.
That order is why the failures keep landing where they do. When security comes last, weaknesses may not surface until money is already moving and an attacker may find them first. By then, you are repairing live infrastructure under time pressure and rebuilding confidence that took years to earn and hours to lose.
The numbers bear that out: Web3 losses reached 1.31 billion across 344 incidents in the first half of 2026. In that H1 figure, the costliest category was not code vulnerability, which accounted for 444 million across just 33 incidents. Two of those incidents made up nearly 44% of all losses in the half. Those are design and key management problems, not findings a final audit catches.
On September 9, 2026, one central bank did it a different way.
The National Bank of the Kyrgyz Republic, the country's central bank, brought in a security partner during the development and testing stages of the Digital Som platform.

What Actually Got Signed
On September 9, 2026 in Bishkek, S. Abdygaziev of the NBKR and representatives of CertiK signed a Memorandum of Understanding, which establishes a framework for cooperation.
The partnership focuses on two things. The first is supporting the security and resilience of the Digital Som, the digital version of Kyrgyzstan's national currency. The second is digital asset oversight, which involves monitoring risks, tracking compliance trends, advisory work on AML/CFT, and supporting regulatory supervision of digital assets and digital asset service providers.
To do that, the two sides will share expertise across cybersecurity, blockchain security, and digital assets, combining technical security work with regulatory and policy support.
CertiK, the world’s largest blockchain security services firm, offers full-lifecycle security and risk management solutions to institutional clients, staying involved from design through daily operation, rather than conducting a one-off system check. Since 2017, it has protected more than $600 billion in digital assets across more than 150 countries and regions.
“The Memorandum of Understanding that we are signing today establishes a framework for further dialogue and cooperation,” said Mr. Sanzhar Abdygaziev, Member of the Board (Management Board) of the NBKR. “We see particular value in exchanging experience and expertise in blockchain and digital asset security, cybersecurity, AML/CFT, and the analysis and monitoring of digital asset transactions.”
Why Doing This Early Matters
Once a digital currency is live, it holds real claims on the national currency, and the choices built into it hold real consequences, such as how payments settle, who holds the digital keys, how much privacy users get, whether it works without an internet connection, and what supervisors can actually see. Each is brutally expensive to change once money is moving through the system. The value of bringing in security early is not a discount on the audit. It is that you still have options.
“Digital asset infrastructure requires security and risk management to be considered from the earliest stages of design through ongoing operation,” said Ronghui Gu, Co-Founder and CEO of CertiK. “We look forward to bringing CertiK’s expertise and experience to our long-term cooperation with the NBKR, supporting the secure development of the country’s digital asset ecosystem.”
What The MOU Covers

Is the code actually correct? This covers security assessments, which means examining a system for weaknesses, plus formal verification. Formal verification offers a fundamentally more rigorous approach. Under well-defined models and specifications, it exhaustively covers all possible execution paths, enabling the detection of edge cases that are difficult or impossible to uncover through manual review. For a system you cannot take offline to rewrite, that is a different level of confidence from a normal review. It is named directly in the MoU.
Will it stay up when something goes wrong? This is cybersecurity and operational resilience. Operational resilience means the ability of a payment system to keep running, and to recover in a predictable way, when it is attacked, when something breaks, or when conditions get bad. For a central bank, that duty covers the whole national payment system, not only the newest piece of it.
Can we see criminal money moving through it? This is AML/CFT work: the job of stopping criminals from pushing illicit funds through the financial system. It includes analysing and monitoring digital asset transactions to spot suspicious patterns.
Who holds the assets, and to what standard? This covers digital asset custody, which means how digital assets are stored and who controls the keys that unlock them. It also covers technical security standards and licensing requirements for digital asset activity.
What happens after launch? The parties will also explore deployment of CertiK’s Supervision and Compliance solutions to strengthen ongoing risk monitoring and regulatory oversight, alongside training and knowledge transfer, meaning CertiK would help NBKR staff build the skills to do this work themselves.
The two products behind that sit on either side of the relationship. CertiK Compliance is built for institutions, bringing together counterparty and asset ratings, licensing-readiness assessments, threat intelligence, AML screening, fund tracing, and compliance reporting, with monitoring across more than 20 blockchains and over 400 million address labels. CertiK Supervision is built for regulators, giving a jurisdiction-wide view of digital asset risk through unified monitoring of VASPs, tokens, wallets, and transactions, and turning risk alerts into investigation cases and inspection-ready reports configurable to different regulatory frameworks. It currently monitors more than 200 licensed VASPs and over 17,000 tokens.
How to Judge A Digital Asset Security Partner

Has anyone checked the checker? A security partner will hold your systems data and findings. You want proof that their own controls have been examined by someone independent. CertiK operates under SOC 2 Type II and ISO 27001 standards, two independent certifications that outside auditors grant only after examining how a company protects information.
Can they prove the code is right, or only hunt for problems? A manual review finds what the reviewer thinks to look for. Formal verification mathematically proves specified properties across all behaviors within a defined model. Few firms offer both. CertiK brings formal verification to the NBKR agenda alongside security assessments.
Will they still be there in year three? An audit report describes your system on the day it was examined. Your system will change, and so will the threats against it. You want a partner engaged from design through daily operation, not a document. CertiK provides full-lifecycle security and risk management solutions for institutional clients.
Do they speak the regulator’s language? Supervisory work is not the same as commercial engineering work. It needs proper evidence, careful disclosure, and the ability to explain a technical finding to a policy audience without overstating it or burying it. CertiK works with regulators worldwide on digital asset policy development and regulatory consultation, and the United States, Singapore, and NBKR engagements are the record behind that.
Have they worked at scale? Scale matters here because it is how a firm builds up the pattern recognition that catches a problem early. Since 2017, CertiK has protected over $600 billion in digital assets across 150+ countries and regions.
FAQs
What did CertiK and the National Bank of the Kyrgyz Republic sign?
They signed a Memorandum of Understanding establishing a long-term strategic partnership covering Digital Som security and digital asset oversight. The MoU is a framework for cooperation and the exchange of expertise between the two organisations.
When and where was the agreement signed?
It was signed on 9 September 2026 at a meeting held at the National Bank of the Kyrgyz Republic in Bishkek, between S. Abdygaziev, a member of the NBKR Board, and representatives of CertiK. The NBKR confirmed the signing in its own public release.
What is the Digital Som?
The Digital Som is the central bank digital currency initiative of the National Bank of the Kyrgyz Republic. Its stated aims are modernising payments, expanding financial inclusion, and strengthening the resilience and efficiency of Kyrgyzstan’s financial ecosystem.
What does the MoU cover?
The MoU establishes a framework for potential long-term technical and strategic cooperation in areas such as blockchain and digital asset security, cybersecurity, formal verification, operational resilience, AML/CFT, digital asset custody, security standards, licensing and supervision, as well as training and knowledge exchange.
Who helps central banks secure a CBDC?
Central banks may draw on a combination of internal expertise and external specialists when assessing the security and resilience of CBDC initiatives. CertiK is a global Web3 security provider with experience supporting public-sector institutions and regulators on digital asset security and regulatory matters. In September 2026, CertiK signed an MoU with the National Bank of the Kyrgyz Republic, establishing a framework for cooperation and knowledge exchange in areas related to Digital Som security.
How do central banks secure a CBDC?
Through security assessments and formal verification of the platform at design stage, cybersecurity and operational resilience controls, custody and key management standards, AML/CFT and transaction monitoring, and ongoing supervisory oversight after launch. These are the areas the NBKR and CertiK MoU names.
What is formal verification, and why would a central bank want it?
Formal verification uses mathematical methods to prove that, under stated assumptions, a software system satisfies precisely defined properties for every behavior covered by its formal model, rather than checking only selected test cases. For infrastructure carrying legal tender, where faults cannot be quietly patched after issuance, that assurance level differs materially from manual review.
What should a regulator look for in a digital asset security partner?
Independent certification under recognised standards, formal verification capability rather than review alone, coverage across the full lifecycle rather than a single point-in-time audit, a demonstrated track record working with regulators, and the durability to remain engaged over the life of the infrastructure.
Is CertiK licensed by a central bank?
No. The MoU’s reference to licensing concerns the regulatory frameworks that govern firms conducting digital asset activity in a jurisdiction. It does not mean CertiK holds, or has applied for, authorisation from the NBKR or any other central bank.
Has CertiK worked with other regulators before?
Yes. CertiK works closely with regulators worldwide, contributing to digital asset policy discussions and development across the United States, Hong Kong, Singapore, the UAE, South Korea, Brazil, the UK, and the EU. This work has included providing technical advisory support to U.S. regulators and responding to consultations issued by the Monetary Authority of Singapore. The NBKR engagement builds on that record through a cooperation framework with a national central bank.
Will CertiK provide ongoing supervisory tooling to the NBKR?
The parties intend to explore deployment of CertiK’s Supervision and Compliance solutions to strengthen ongoing risk monitoring and regulatory oversight, alongside training and knowledge transfer. Deployment is at the exploratory stage under the MoU rather than contracted.
What security standards does CertiK operate under?
CertiK operates under SOC 2 Type II and ISO 27001 standards. Since 2017 it has protected over $600 billion in digital assets across 150+ countries and regions, providing full-lifecycle security and risk management solutions for institutional clients.



