Skip to content
Back to all articles
Analysis
Verified against the Bank of Russia source

New Digital Ruble Cryptographic-Key Rules: A Participant Readiness Checklist

The Bank of Russia's third edition requires separate test and production key sets, 36-month subordinate CA capability reporting, and updated administrator procedures.

Published: 6 September 2026

Last updated: 6 September 2026

Effective: No separate commencement date stated

6 min

New cryptographic-key management rules for the Digital Ruble Platform

Article

On 2 September 2026, the Bank of Russia listed the third edition of its regulation governing interaction between a financial intermediary and the Bank of Russia when managing cryptographic keys for the Digital Ruble Platform.

The document is not directed at ordinary consumers or merchants. Its primary audience is banks and other financial intermediaries, their information-security functions, key-system administrators, and integration teams.

Three operational changes

Before initial key generation, a financial intermediary must report whether it can create production subordinate certification-authority keys with a 36-month validity period and write them to its key media. A change in that technical capability requires another notification.

The regulation also expressly requires two separate key sets in the relevant key systems for test and production interaction. A test set should not be treated as a standby production set: environment separation is now an explicit readiness control.

Email interaction with the Bank of Russia must use addresses recorded in the administrator's power of attorney. “Send on behalf of another user” is permitted only when sending on behalf of the authorised financial-intermediary key-system administrator, and the intermediary must ensure that Bank of Russia messages can reach that address.

Participant checklist

  • Confirm the authorised key-system administrator and current power of attorney.
  • Reconcile the authorised email address with the actual communication workflow.
  • Record whether 36-month production subordinate-CA keys can be created and stored on the selected media.
  • Document the notification process for a change in that capability.
  • Separate test and production keys, media, stores, access rights, and logs.
  • Control certificate lifecycles, revocation lists, compromise response, and key destruction.
  • Validate standby control- and processing-contour keys without using them for normal production operations.

What did not change

This edition does not establish Digital Ruble tariffs, change the individual account top-up limit, or introduce a new Digital Ruble acceptance duty for ordinary merchants. It concerns platform-participant cryptographic-key operations.

The register is dated 2 September. We found no separate commencement date in the register entry or the regulation and therefore do not present the listing date as an effective date.

DigitalRUR provides the verified editorial explanation. RURChain can help operational teams turn the change into controlled requirements and evidence:

This material is informational and does not replace organisation-specific legal or technical advice.

  • RURChain Regulatory Monitoring — https://rurchain.ru/en/services/regulatory-monitoring/
  • Digital Ruble Readiness Assessment — https://rurchain.ru/en/services/readiness-assessment/
  • Security & Integration Review — https://rurchain.ru/en/services/security-review/

Official sources

  • Bank of Russia — Digital Ruble Platform regulation register — https://www.cbr.ru/PSystem/dr/doc_dr/reglaments/
  • Bank of Russia — third edition of the cryptographic-key management regulation — https://www.cbr.ru/Content/Document/File/150168/reglament_dr_20260902_1.pdf

Correction history

No material corrections have been made.

This material is informational and analytical and does not constitute individual legal advice.