# SP-054 CBDC and Digital Currency Infrastructure

Status: draft. Release 26.03. Modified 2026-03-10. Licence: CC BY-SA 4.0.

Scope: Security architecture for central bank digital currency (CBDC) and digital currency infrastructure covering retail and wholesale CBDC models, dual-ledger architecture with RTGS interoperability, offline payment capability with tamper-resistant hardware, tiered privacy models with privacy-enhancing technologies, programmable money and smart contract layers, anti-counterfeiting and double-spend prevention, and...
Use when: Central banks in the design, prototyping, or pilot phase of a retail or wholesale CBDC. Commercial banks designated as CBDC intermediaries by their central bank.
Not when: Private sector stablecoins (USDC, EURC) — these are commercial instruments with different threat models; see SP-051 Tokenised Asset Security Architecture.

## Controls (50, NIST SP 800-53 ids)
- Critical (27): SC-12, SC-13, SC-28, SC-07, SC-08, SC-17, AC-03, AC-04, AC-05, AC-06, AU-02, AU-03, AU-09, IA-02, IA-05, CP-07, CP-09, PE-03, CM-03, IR-04, CA-07, SA-11, RA-03, PT-01, PT-02, PT-03, PM-09
- Important (21): SC-45, AC-02, AC-17, AC-24, AU-06, AU-12, IA-08, CP-06, CP-10, PE-04, CM-02, CM-08, IR-01, IR-06, IR-08, CA-08, SA-09, RA-05, PM-12, SI-02, SI-10
- Standard (2): AC-01, IA-01

## What each critical control mitigates (27)
- SC-12 Cryptographic Key Establishment and Management: T-CBDC-001, T-CBDC-002, T-CBDC-003, T-CBDC-008, T-CBDC-010
- SC-13 Cryptographic Protection: T-CBDC-001, T-CBDC-002
- SC-28 Protection of Information at Rest: T-CBDC-003, T-CBDC-010
- SC-07 Boundary Protection: T-CBDC-007, T-CBDC-008
- SC-08 Transmission Confidentiality and Integrity: T-CBDC-008
- SC-17 Public Key Infrastructure Certificates: T-CBDC-002
- AC-03 Access Enforcement: T-CBDC-005
- AC-04 Information Flow Enforcement: T-CBDC-004, T-CBDC-009
- AC-05 Separation of Duties: T-CBDC-001, T-CBDC-002, T-CBDC-005
- AC-06 Least Privilege: T-CBDC-004, T-CBDC-006, T-CBDC-009
- AU-02 Event Logging: T-CBDC-001, T-CBDC-002, T-CBDC-004, T-CBDC-005, T-CBDC-008, T-CBDC-009
- AU-03 Content of Audit Records: T-CBDC-001, T-CBDC-003, T-CBDC-008
- AU-09 Protection of Audit Information: T-CBDC-001, T-CBDC-004
- IA-02 Identification and Authentication (Organizational Users): T-CBDC-001, T-CBDC-004, T-CBDC-005
- IA-05 Authenticator Management: T-CBDC-003
- CP-07 Alternate Processing Site: T-CBDC-006, T-CBDC-007
- CP-09 System Backup: T-CBDC-007
- PE-03 Physical Access Control: T-CBDC-002, T-CBDC-003, T-CBDC-010
- CM-03 Configuration Change Control: T-CBDC-001, T-CBDC-005
- IR-04 Incident Handling: T-CBDC-003, T-CBDC-005, T-CBDC-006, T-CBDC-007, T-CBDC-008
- CA-07 Continuous Monitoring: T-CBDC-002, T-CBDC-003, T-CBDC-006, T-CBDC-007, T-CBDC-008, T-CBDC-009
- SA-11 Developer Testing and Evaluation: T-CBDC-005
- RA-03 Risk Assessment: T-CBDC-005, T-CBDC-006, T-CBDC-009, T-CBDC-010
- PT-01 Policy and Procedures: T-CBDC-004
- PT-02 Authority to Process Personally Identifiable Information: T-CBDC-004
- PT-03 Personally Identifiable Information Processing Purposes: T-CBDC-004
- PM-09 Risk Management Strategy: T-CBDC-006, T-CBDC-009

## Threats and the controls that mitigate them (10)
- T-CBDC-001 undefined: SC-12, SC-13, AC-05, AU-02, AU-03, AU-09, IA-02, CM-03
- T-CBDC-002 undefined: SC-12, SC-13, SC-17, PE-03, AC-05, AU-02, CA-07, PM-12
- T-CBDC-003 undefined: SC-12, SC-28, PE-03, PE-04, IA-05, CA-07, AU-03, IR-04
- T-CBDC-004 undefined: PT-01, PT-02, PT-03, AC-04, AU-02, AU-09, AC-06, IA-02
- T-CBDC-005 undefined: CM-03, SA-11, AC-05, AC-03, IA-02, IR-04, AU-02, RA-03
- T-CBDC-006 undefined: AC-06, PM-09, RA-03, CA-07, IR-04, IR-08, CP-07
- T-CBDC-007 undefined: SC-07, CP-07, CP-09, CP-10, CA-07, IR-04, IR-08, CM-02
- T-CBDC-008 undefined: SC-07, SC-08, SC-12, CA-07, AU-02, AU-03, CM-08, IR-04
- T-CBDC-009 undefined: AC-04, AC-06, AU-02, CA-07, IA-08, PM-09, RA-03, IR-06
- T-CBDC-010 undefined: PE-03, PE-04, SC-12, SC-28, SA-09, CM-08, CA-08, RA-03

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-054/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-054/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 65 KB: /api/v1/patterns/SP-054
- Page for people: /patterns/sp-054/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-019 Secure Ad-Hoc File Exchange Pattern; SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-051 Tokenised Asset Security Architecture; SP-052 Decentralised Identity & Verifiable Credentials

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
