NBKR Signs CertiK to Secure Kyrgyzstan’s Digital Som Ahead of a December Pilot Deadline

Nine days ago the president of Kyrgyzstan gave his central bank a deadline: build a working digital som platform and pilot it by 31 December 2026, test it with real users in 2027, then roll it out to the country in stages. Today the National Bank of the Kyrgyz Republic signed a Memorandum of Understanding (MoU) with CertiK, the largest security firm in Web3, to help it get there without the thing that has cost the crypto industry $3.35 billion in 2025 and another $1.32 billion in the first six months of this year. The digital som is already legal tender under a constitutional law signed in April 2025, which is further than 131 of the 134 countries studying a CBDC have got. What Bishkek does not yet have is the thing every central bank discovers it needs the moment a digital currency goes from slide deck to server: someone who has watched attackers take apart live blockchain systems for nine years and knows where they get in.

What was actually signed

The memorandum sets up a framework for two kinds of work. The first is engineering, where CertiK will support the central bank on blockchain and digital asset security, security assessments, formal verification, cybersecurity and operational resilience, which in plain terms means reviewing the code and the systems the digital som will run on, proving mathematically that critical pieces behave the way they are supposed to and planning for what happens when something breaks at 3am.

The MoU extends to digital asset oversight and regulatory advisory support, covering anti-money-laundering and counter-terrorist-financing controls, custody, security standards and licensing requirements, alongside the possible deployment of CertiK’s Supervision and Compliance products so the regulator can watch risk build up in real time rather than read about it afterwards. Training and knowledge transfer run through both halves. The central bank’s board member Sanzhar Abdygaziev framed the document as a starting point for exchange rather than a finished contract, with particular value placed on blockchain security, cybersecurity, AML/CFT and the monitoring of digital asset transactions.

What the central bank gets

Central banks are good at many things. Running a distributed ledger that holds the national currency, where a stolen key means stolen money that cannot be clawed back, is not historically one of them. A CBDC forces a monetary authority to take on the operating risks of a crypto exchange with none of the crypto exchange’s tolerance for failure. Kyrgyzstan’s three-phase pilot plan, announced last October, starts by connecting commercial banks for interbank transfers, then plugs in the Central Treasury for government and social payments, then tests offline and low-connectivity transactions before any national launch.

Each phase widens the attack surface: more institutions holding keys, more integrations, more devices in the field. That is the moment to bring in a firm whose day job is finding the flaw before someone else does. The list of countries that got a CBDC to the public is short for a reason. The reason is rarely the economics.

Countries exploring a central bank digital currency, per the Atlantic Council tracker, 2020 to 2026, against the number of retail CBDCs live nationally.

The supervision half matters just as much. Kyrgyzstan is not only building a CBDC; it is building a regulated digital asset industry around it. Last October the country launched KGST, a stablecoin pegged one-to-one to the som on BNB Chain, with Changpeng Zhao advising the national crypto committee and a national digital asset reserve under discussion. The 5 September council meeting approved a single digital platform for licensing and supervising virtual asset firms, with pilot testing set for 1 January 2027. A regulator that suddenly has licensed exchanges, a stablecoin, a reserve and a CBDC to watch needs tooling that reads on-chain activity the way a bank supervisor reads a balance sheet. CertiK already sells that tooling; the MoU leaves the door open to deploying it.

What CertiK gets

A central bank is the hardest customer a security firm can win. The procurement rules are strict, the compliance bar is high, the operational requirements are unforgiving and a mistake ends up in a parliamentary hearing rather than a Discord channel. CertiK has spent nine years auditing protocols and exchanges; it reports more than $600 billion of digital assets protected across 150-plus countries and operates under SOC 2 Type II and ISO 27001 controls. What it has not had until now is a named, long-term engagement inside a monetary authority that is actively building a sovereign digital currency. That is the reference point every other regulated institution asks for. The firm has been working its way toward this for a while: it has provided technical advisory support to regulators in the United States and answered consultations from the Monetary Authority of Singapore. Bishkek is the first place where the relationship is formal, long-term and tied to a live currency programme, which is the template CertiK can now carry to the next central bank.

Annual losses to hacks, scams and exploits recorded by CertiK, US$ billions, 2022 to the first half of 2026.

There is a second reason the engagement is worth more to CertiK than its fee. The firm’s own data describes exactly the kind of threat a central bank should fear most. In 2023, private key compromises were 6.3 percent of incidents and nearly half the money lost, $881 million across 47 events. In the first half of 2026, wallet compromises were 33 incidents out of 344 and took $444.5 million, a third of everything lost, with the two largest events of the half, Kelp DAO and Drift, coming from infrastructure and operational failures rather than bugs in smart contracts.

Key and wallet compromises as a share of all incidents versus a share of all losses, 2023 and first half of 2026.

Why Kyrgyzstan is moving faster than bigger countries

Kyrgyzstan is a country of about seven million people where remittances from citizens working abroad add up to roughly 30 percent of GDP. Cheaper, faster, traceable money movement is not an abstract policy goal there; it is household income. That is why the government has been willing to move in eighteen months through steps that take larger economies a decade.

digital som timeline

Milestones on Kyrgyzstan’s digital som programme, 2021 to 2027.

The central bank drafted a digital som concept in 2021, approved it in 2022, ran a regulatory impact analysis and took prototype proposals from twelve vendors in early 2024, published draft laws that August, won a constitutional amendment in April 2025 and laid out the three-phase pilot in October. Larger economies are still debating whether to build. The eurozone is moving toward an issuance decision, the United States has banned a Federal Reserve retail CBDC by law and the three retail CBDCs actually live, in the Bahamas, Jamaica and Nigeria, are all small economies that decided to go first. Kyrgyzstan wants to be the fourth. It also wants to be the first one that treated security as a design input rather than an afterthought.

What to watch

Three things will show whether this memorandum turns into something more than a signing photo. The first is whether CertiK’s name appears on the digital som platform’s security assessment before the December pilot, which would mean the engineering half of the MoU went live inside the deadline. The second is whether the Supervision and Compliance tooling is switched on for the virtual asset licensing platform that begins pilot testing on 1 January 2027, which would mean the regulator is watching its licensed exchanges on-chain from day one. The third is who calls next. Every central bank in the research phase of that 134-country list is watching the small ones that go first. A security partnership structured around a live CBDC is the kind of thing that gets copied.

Kyrgyzstan has given itself fifteen weeks to put a digital form of its currency on a working platform. It has spent one of those weeks bringing in the firm that keeps score on how the rest of the industry gets robbed. If the pilot lands in December with an independent security assessment behind it, Bishkek will have done something no G20 central bank has managed: shipped a sovereign digital currency with the security work visible from the outside.

Don’t forget to like and share the story!

Vested Interest Disclosure: HackerNoon has reviewed the report for quality, but the claims herein belong to the author. #DYOR.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.