The Good Tech Companies - NBKR Signs CertiK to Secure Kyrgyzstan's Digital Som Ahead of a December Pilot Deadline
Episode Date: September 14, 2026This story was originally published on HackerNoon at: https://hackernoon.com/nbkr-signs-certik-to-secure-kyrgyzstans-digital-som-ahead-of-a-december-pilot-deadline. Kyrg...yzstan's central bank signs CertiK to secure the digital som CBDC and supervise digital assets, nine days after the president set a December pilot deadline. Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #certik, #nbkr, #digital-som, #kyrgyzstan-cbdc, #web3, #good-company, #blockchain, #cbdc, and more. This story was written by: @ishanpandey. Learn more about this writer by checking @ishanpandey's about page, and for more stories, please visit hackernoon.com. The National Bank of the Kyrgyz Republic and CertiK have signed a memorandum of understanding covering security for the digital som, Kyrgyzstan's central bank digital currency, plus oversight of the country's wider digital asset sector. The scope runs from code to courtroom: blockchain and digital asset security, security assessments, formal verification, cybersecurity, operational resilience, AML/CFT, custody, security standards, licensing requirements and the possible deployment of CertiK's Supervision and Compliance tooling for ongoing risk monitoring. The timing is not accidental. On 5 September President Sadyr Japarov ordered the central bank to have a basic digital som platform built and piloted by 31 December 2026, with real-world testing in 2027 and a phased national rollout after that. 134 countries are studying a CBDC and three have one live for the public. The digital som has been legal tender since April 2025, which puts Kyrgyzstan closer to the finish line than most of the 134. CertiK says it has protected more than $600 billion of digital assets across 150-plus countries since 2017; its own Hack3d data shows $3.35 billion lost to hacks and scams in 2025 and $1.32 billion in the first half of 2026, with stolen keys and wallets the single most expensive category.
Transcript
Discussion (0)
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
NBKR signs Sir Dekai to secure Kyrgyzstan's digital SOM ahead of a December pilot deadline,
by Ashan Pondi.
Nine days ago, the president of Kyrgyzstan gave his central bank a deadline,
build a working digital SOM platform and piloted by the 31st of December 2026,
tested with real users in 27, then roll it out to the country in stages.
Today, the National Bank of the Kyrgyz Republic signed a memorandum of understanding,
Mo, with Sir Decay, the largest security firm in Web 3, to help it get there without the thing
that has cost the crypto industry $3.35 billion in 2025 and another $1, $32 billion in the first
six months of this year. The digital sum is already legal tender under a constitutional law
signed in April 2025, which is further than 131 of the 134 countries studying a CBDC.
have got. What Bushkek does not Yehtave is the thing every central bank discovers it needs the moment
a digital currency goes from slide deck to server. Someone who has watched attackers take apart
live blockchain systems for nine years and knows where they get in. What was actually signed,
the memorandum sets up a framework for two kinds of work. The first is engineering, where
Serta K will support the central bank on blockchain and digital asset security, security assessments,
formal verification, cybersecurity and operational resilience, which in plain terms means
reviewing the code and THE systems the digital SOM will run on, proving mathematically that
critical pieces behave the way they are supposed to and planning for what happens when something
breaks at 3 a.m. The MO extends to digital acid oversight and regulatory advisory support,
covering anti-money laundering and counter-terrorist financing controls, custody, security standards
and licensing requirements, alongside the possible deployment of CERDIC-superiors.
provision and compliance products so the regulator can watch risk build up in real time rather than
read about it afterwards. Training and knowledge transfer run through both halves. The central
banks board member Sanger Abdigaziev framed the document as a starting point for exchange
rather than a finished contract, with particular value placed on blockchain security, cybersecurity,
AML, CFT and the monitoring of digital asset transactions. What the central bank gets,
Central banks are good at many things. Running a distributed ledger that holds the national currency,
where a stolen key means stolen money that cannot be clod back, is not historically one of them.
A CBDC forces a monetary authority to take on the operating risks of a crypto exchange with
none of the crypto exchanges tolerance for failure. Kyrgyzstan's three-phase pilot plan,
announced last October, starts by connecting commercial banks for interbank transfers,
then plugs in the central treasury for government and social payments,
then tests offline and low connectivity transactions before any national launch.
Each phase widens the attack surface, more institutions holding keys, more integrations,
more devices in the field.
That is the moment to bring in a firm whose day job is finding the flaw before someone else does.
The list of countries that got a CBDC to the public is short for a reason.
The reason Israeli the economics, the supervision half matters,
just as much. Kyrgyzstan is not only building ACBDC, it is building a regulated digital
asset industry around it. Last Octoberth country launched KGST, a stable coin pegged one-to-one
to the Somme on B&B chain, with Chongpung Zhao advising the National Crypto Committee
and a National Digital Asset Reserve under discussion. The 5th of September Council meeting
approved a single digital platform for licensing and supervising virtual asset firms,
with pilot testing set for the first of January, 27. A regulator that suddenly has licensed
exchanges, a stable coin, a reserve and a CBDC to watch needs tooling that reads on chain
activity the way a bank supervisor reads a balance sheet. Serta K already sells that tooling.
The Mo leaves the door open to deploying it. What Serta K gets, a central bank is the hardest
customer a security firm can win. The procurement rules are strict, the compliance bar is high,
the operational requirements are unforgiving and a mistake ends up in a parliamentary hearing rather than a Discord channel.
Serta K has spent nine years auditing protocols and exchanges. It reports more than $600 billion of digital assets protected across 150 plus countries and operates under SOC 2 Type 2 and ISO 27,01 controls.
What it has not had until now is ennamed, long-term engagement inside a monetary authority that is actively building a sovereign digital currency.
That is the reference point every other regulated institution asks for.
The firm has been working its way toward this for a while.
It has provided technical advisory support to regulators in the United States
and answered consultations from the Monetary Authority of Singapore.
Bishkek is the first place where the relationship is formal, long-term and tied to a live currency program, which is the template Sertic can now carry to the next central bank.
There is a second reason the engagement is worth more to Sertica than its fee.
The firm's own data describes exactly the kind of threat a central bank should fear most.
In 2023, private key compromises were 6.3% of incidents and nearly half the money lost,
$881 million across 47 events.
In the first half of 26, wallet compromises were 33 incidents out of 344 and took $444.
5 million, a third of everything lost, with the two largest events of the half, Kelp Dow and
drift, coming from infrastructure and operational failures rather than bugs in smart contracts.
Key and wallet compromises is a share of all incidents versus a share of a losses, 23 and first
half of 26. Why Kyrgyzstan is moving faster than bigger countries. Kyrgyzstan is a country
of about 7 million people where remittances from citizens working abroad add up to roughly 30%
of GDP. Cheaper, faster, traceable money movement is not an abstract policy goal there. It is
household income. That is why the government has been willing to move in 18 months through steps
that take larger economies a decade. Milestones on Kyrgyzstan's Digital SOM program,
2021 to 27. The Central Bank drafted a Digital SOM concept in 2021, approved it in 2022,
run a regulatory impact analysis and took prototype proposals from 12 vendors in yearly
2024, published draft laws that August, won a constitutional amendment in April 2025 and laid out
the three-phase pilot in October. Larger economies are still debating whether to build. The Eurozone
is moving toward an issuance decision. The United States has banned a Federal Reserve Retail CBDC by law
and THE3 retail CBDCs actually live in the Bahamas, Jamaica and Nigeria, aerial small economies
that decided to go first. Kyrgyzstan wants to be the fourth. It also wants to
to be the first one that treated security as a design input rather than an afterthought.
What to watch, three things will show whether this memorandum turns into something more than a signing
photo. The first is whether Sertic's name appears on the digital SOM platform's security assessment
before the December pilot, which would mean the engineering half of the Mo went live inside the deadline.
The second is whether the supervision and compliance tooling is switched on for the virtual
asset licensing platform that begins pilot testing on the first of January 2027, which would mean
regulator is watching its licensed exchanges on chain from day one. The third is who calls next.
Every central bank in the research phase of that 134 country list is watching the small ones
that go first. A security partnership structured around a live CBDC is the kind of thing that
gets copied. Kyrgyzstan has given itself 15 weeks to put a digital form of its currency on a
working platform. It has spent one of those weeks bringing in the firm that keeps score on how
the rest of the industry gets robbed. If the pilot lands in December with an independent security
assessment behind it, Bushkech will have it own something no G20 central bank has managed.
Shipped a sovereign digital currency with the security work visible from the outside.
Don't forget to like and share the story, vested interest disclosure. Hacker Noon has reviewed
the report for quality, but the claims herein belong to the author.
Hashtag D-YOR. Thank you for listening to this hackernoon story, read by artificial intelligence.
Visit hackernoon.com to read, write, learn and publish.
