Home
» New Trends
»
Central Bank Digital Currencies (CBDCs): The Infrastructure Behind Digital Money
Central Bank Digital Currencies (CBDCs): The Infrastructure Behind Digital Money
Central bank digital currencies are often discussed as if they were simply “government cryptocurrency.” That shorthand is misleading. A CBDC is a digital form of central bank money, but the important questions are not about a coin icon or a mobile app. They are about the infrastructure underneath: who issues the liability, who keeps the ledger, how wallets connect to payment providers, how identity and privacy are handled, whether payments can work offline, and how the system remains available during outages or attacks.
There has also been a meaningful change in 2026. CBDC work in several jurisdictions has moved further from policy papers toward operational engineering. In July 2026, the European Central Bank selected 36 payment service providers for a planned digital euro pilot, while an August 2026 ECB update described work on secure hardware standards for offline payments. At the same time, the Bank for International Settlements continued testing tokenized central-bank money in wholesale cross-border infrastructure. These developments do not mean that every major economy is about to launch a retail CBDC. They do mean that the technical stack is becoming more concrete.
Useful action: When you see a CBDC headline, first identify whether it refers to research, a prototype, a limited pilot, a live production system, or an actual decision to issue. Those stages are not interchangeable.
A central-bank building beside a modern financial district, representing the public institution and payment infrastructure that sit behind a CBDC rather than a specific national implementation.
What a CBDC actually is
A central bank digital currency is a digital liability of a central bank denominated in the national unit of account. That is the defining feature. It is different from a commercial-bank deposit, which is a liability of a private bank, and from most crypto-assets, which are not liabilities of a central bank at all. The White House’s January 2025 executive order, for example, defined a CBDC as digital money that is a direct liability of the central bank even while setting a U.S. policy against establishing or promoting one. The order remains an important reminder that CBDC policy differs sharply across jurisdictions. See the official U.S. executive order on digital financial technology.
CBDCs are usually discussed in two categories. A retail CBDC is designed for households and businesses to make everyday payments. A wholesale CBDC or tokenized form of central-bank reserves is designed primarily for financial institutions and settlement in financial markets. The infrastructure requirements overlap, but the scale, access model, compliance controls, and use cases can be very different.
Useful action: Before comparing two CBDC projects, confirm whether both are retail, both are wholesale, or one is each. A consumer wallet and a bank-to-bank settlement platform should not be evaluated by the same criteria.
The infrastructure stack behind digital central-bank money
There is no single universal CBDC architecture. The Bank for International Settlements has documented several possible models, including direct, hybrid, and intermediated structures. Still, most proposals can be understood as a set of connected layers.
Infrastructure layer
What it does
What to examine
Issuance and core ledger
Creates, redeems, and records the central-bank liability
Who can update the ledger, settlement finality, capacity, recovery
Distribution
Connects the central bank to banks, fintechs, or other payment service providers
Links domestic systems or tokenized settlement platforms across currencies
Foreign access, FX, legal finality, identity recognition, data rules
The BIS Project Rosalind showed one example of a two-tier retail architecture. Its prototype separated a central-bank ledger, a ledger API, a core API, and private-sector service providers. The project built 33 API functions and tested more than 30 use cases, demonstrating that the API layer could work with different ledger designs. See the BIS Project Rosalind report.
Useful action: If you are assessing a CBDC design, draw these layers separately. It becomes much easier to see which responsibilities belong to the central bank, which belong to private intermediaries, and where operational dependencies accumulate.
Misconception: a CBDC has to run on blockchain
Verified: Blockchain or distributed ledger technology is not required for a CBDC. BIS research explicitly notes that CBDC data can be managed with a conventional centralized database, distributed ledger technology, or a combination. The core requirement is the nature of the claim and the rules governing issuance and settlement, not the use of a blockchain.
This matters because different ledger technologies make different tradeoffs. Conventional architectures can use multiple physical nodes and geographic redundancy while still having one authoritative operator. DLT can distribute validation across approved entities, but consensus introduces coordination overhead and governance questions. A central bank may therefore choose centralized technology for one layer and distributed technology for another.
Useful action: Ignore labels such as “blockchain-based” until you know what function the technology performs. Ask who validates transactions, who controls software changes, where finality occurs, and what happens during a network partition.
Misconception: every CBDC means everyone gets an account directly at the central bank
Context-dependent: A direct central-bank account is only one possible model. Many retail designs preserve a two-tier system in which the central bank issues the money and maintains core infrastructure, while commercial banks or authorized payment service providers handle wallets, customer onboarding, support, and other user-facing services.
The digital euro work is a current example. The ECB’s July 2026 pilot documentation describes payment service providers as a major part of the distribution model. The pilot is planned to begin operational testing in the second half of 2027 and run for 12 months; a final decision to issue a digital euro remains separate and depends on the legal framework. See the ECB digital euro pilot page.
Useful action: For any proposed CBDC, find the distribution model before assuming the central bank will operate consumer accounts. Look for the terms “direct,” “hybrid,” “intermediated,” or “two-tier.”
Misconception: CBDC privacy is automatically either total surveillance or total anonymity
Context-dependent: Privacy is an architectural and legal design choice. It depends on which participant sees identity information, which data the core settlement layer receives, how identifiers are pseudonymized, what intermediaries must retain for compliance, and whether offline transactions are handled differently from online ones.
The proposed digital euro illustrates the distinction. According to the ECB, online payments are being designed so that the Eurosystem would not directly identify individual users from payment data, while payment service providers would still perform legally required customer and anti-money-laundering checks. The ECB says offline transaction details would be known only to the payer and payee, with compliance checks applying during funding and defunding. These claims are specific to the digital euro design and should not be generalized to every CBDC. See the ECB’s digital euro privacy documentation.
Useful action: Do not evaluate privacy from the word “CBDC” alone. Read the jurisdiction’s data-access model and ask four questions: what the central bank sees, what the wallet provider sees, what law-enforcement access requires, and how long transaction data are retained.
Offline CBDC payments require special infrastructure
Verified: A digital currency does not become cash-like offline merely because a wallet app has been installed. Offline payments require a way to store value or credentials securely on a device, authenticate transfers without immediate server contact, prevent or bound double spending, and reconcile state when connectivity returns.
In August 2026, the ECB said its offline digital euro work was examining secure hardware in smartphones, including embedded Secure Elements and embedded SIMs. Pilot documentation also describes proximity payments using NFC between devices. These are engineering choices for a specific project, not universal CBDC requirements, but they show why offline capability is a separate infrastructure problem rather than a simple app setting. See the ECB’s August 18, 2026 update on offline digital euro standards.
Useful action: When a CBDC project advertises offline payments, check the supported device types, offline value limits, recovery rules after device loss, synchronization process, and the controls against replay or double spending.
Retail and wholesale CBDCs solve different infrastructure problems
A retail CBDC focuses on everyday access, wallet distribution, merchant acceptance, inclusion, consumer protection, and privacy. A wholesale system focuses more heavily on institutional access, settlement finality, liquidity, market infrastructure, and interoperability across asset and currency platforms.
Project Agorá, coordinated by the BIS with public- and private-sector participants, is a useful wholesale example. It has tested a shared programmable platform that combines tokenized central-bank reserves and tokenized commercial-bank deposits. The aim is to study whether cross-border settlement can become more atomic, transparent, and operationally efficient without abandoning the two-tier banking structure. The official BIS Project Agorá page reports that real-value testing took place in July 2026 across 17 scenarios involving 28 financial institutions and central banks, with transactions totaling roughly CHF 800,000.
Useful action: When reading about tokenized central-bank money, look for the eligible participants. If access is restricted to banks and financial-market institutions, the project should not be interpreted as a consumer CBDC rollout.
Live CBDCs show that deployment is more than a ledger
Some retail CBDCs are already in public use, and their official documentation shows how much the surrounding ecosystem matters. Nigeria’s eNaira is legal tender issued by the Central Bank of Nigeria and accessed through wallets. The CBN’s operating guidelines describe a Digital Currency Management System, financial-institution tools, and different wallet roles. See the Central Bank of Nigeria eNaira page.
Jamaica’s JAM-DEX is also central-bank money distributed through wallet providers rather than being treated as a conventional deposit account. Bank of Jamaica’s 2025 annual report described continued national rollout, additional wallet-provider participation, merchant enablement, and online government-payment testing. See the Bank of Jamaica JAM-DEX information.
The Bahamas provides another infrastructure lesson. The Central Bank of The Bahamas continues integrating SandDollar with the wider payment environment; in July 2026 it described a planned fast-payment system intended to be SandDollar-enabled. See the Central Bank of The Bahamas fast-payment system update.
Useful action: Judge deployment by ecosystem reach, not by launch date alone. Check active wallet providers, merchant acceptance, government-payment integration, interoperability, accessibility, and transaction reliability.
Security is an end-to-end problem
CBDC security is not limited to protecting the core ledger. The attack surface can include wallet applications, mobile operating systems, secure hardware, APIs, identity systems, payment service providers, cryptographic key management, networks, cloud or data-center infrastructure, merchant devices, and administrative access.
The BIS has warned that different CBDC architectures shift operational and information-security responsibilities between central banks and external participants. A highly centralized design may concentrate responsibilities inside the central bank, while a two-tier model increases dependencies on intermediaries and interfaces. Neither model eliminates risk; it redistributes it. See the BIS report on CBDC information-security and operational risks.
Useful action: For technical due diligence, map failure domains rather than asking whether the system is merely “secure.” Identify what happens if the core ledger fails, a major PSP goes offline, keys are compromised, a mobile device is lost, or connectivity is unavailable across a region.
What is still unknown or unresolved
Several important questions cannot be answered globally because they depend on final policy choices, local laws, user behavior, and production experience.
Adoption: A technically sound CBDC may still see limited use if existing payment methods are more convenient or widely accepted.
Bank funding effects: Holding limits, remuneration rules, and user preferences can affect whether funds move from commercial-bank deposits into CBDC, especially in periods of stress.
Privacy in practice: Technical privacy features must operate within legal requirements, fraud controls, and the actual data practices of intermediaries.
Cross-border interoperability: Linking currencies involves more than connecting ledgers; identity, sanctions rules, FX, legal settlement finality, and data-localization requirements must align.
Offline scale: Secure offline payments are possible, but broad deployment across heterogeneous phones, cards, and merchant devices remains an implementation challenge.
Long-term operating model: Cost allocation, service-level obligations, wallet-provider incentives, software upgrades, and governance need to remain workable after launch.
The IMF’s CBDC Virtual Handbook, updated in November 2025, emphasizes that countries need to evaluate design, financial stability, inclusion, cross-border effects, and product development in their own institutional context.
Useful action: Treat unresolved questions as design variables, not as evidence that all CBDCs will produce the same outcome. A credible assessment should identify which claims are demonstrated, which depend on policy, and which remain to be tested in production.
A practical checklist for reading any CBDC announcement
Is the project retail or wholesale?
Is it research, prototype, pilot, limited launch, or general availability?
What exactly is the central-bank liability, and where is settlement final?
Who operates the core ledger?
Is the ledger conventional, distributed, or hybrid?
Which tasks are delegated to commercial banks or payment service providers?
What data can the central bank, PSP, merchant, and government authorities see?
Are offline payments supported, and on which hardware?
What happens when a wallet provider or network fails?
How are wallets, merchant systems, and existing payment rails connected?
Are holdings capped or remunerated?
What legal or legislative decisions are still outstanding?
Useful action: Use the checklist before accepting claims that a CBDC is inherently decentralized, inherently surveillant, automatically inclusive, or guaranteed to replace cash. Those outcomes depend on the actual infrastructure and rules.
The real story is infrastructure, not the digital token
The most important thing to understand about CBDCs is that the visible wallet is only the edge of a much larger system. Underneath it sit central-bank issuance, settlement ledgers, intermediaries, identity services, APIs, security controls, offline hardware, merchant acceptance, resilience engineering, and legal governance.
As of September 2026, that infrastructure is becoming increasingly tangible in both retail and wholesale experiments, while national approaches remain very different. The ECB is preparing technical capacity and a future pilot rather than claiming a completed digital euro launch. The United States maintains a federal policy against establishing or promoting a CBDC. Meanwhile, countries including Nigeria, Jamaica, and The Bahamas continue operating or integrating their own digital-currency systems. The correct question is therefore not “Are CBDCs coming?” but “Which architecture, under which rules, for which users, and at what stage?”
Useful action: Follow the official central-bank project page for the jurisdiction you care about and compare each new announcement against the architecture, privacy, resilience, and deployment questions above. That is the fastest way to separate infrastructure progress from speculation.