CMN Resolution 5,274/2025 turned the cybersecurity policy into verifiable controls, with a deadline that ended on March 1, 2026. We help banks, payment institutions, credit unions and brokerages comply and prove it.
CMN Resolution 5,274, published on December 18, 2025, updates CMN Resolution 4,893/2021 and details 14 mandatory minimum controls for institutions authorized to operate by the Brazilian Central Bank. For payment institutions, brokerage firms and securities distributors, the corresponding instrument is BCB Resolution No. 538/2025.
The previous framework was more principles-based. Now the institution must show, control by control, what it does and with what evidence.
Annual penetration tests by independent professionals in environments connected to Pix, RSFN and STR.
Intrusion prevention and detection, traceability and cyber intelligence, with continuous monitoring.
Continuous vulnerability assessment, with risk-based prioritization and remediation tracking.
Authentication, access controls and multi-factor authentication for administrative access.
Data loss prevention (DLP) and protection of applications and APIs with WAF.
Cybersecurity policy, mapping of each requirement to internal controls, and organization of evidence.
For environments connected to Pix, the Brazilian National Financial System Network (RSFN) and the Reserves Transfer System, the resolution imposes additional requirements:
Under CMN Resolution 4,893/2021, an institution that contracts data processing or cloud computing remains accountable for the service. Contracting relevant services must be reported to the Brazilian Central Bank within ten days, and the contract must include clauses such as data location, segregation and regulator access.
We support vendor assessment and the organization of the evidence the regulation requires you to demand and retain. Read the guide to third-party risk and CMN 4,893.
Since the SOC was deployed at FitBank, with operations monitoring, there has been a significant reduction in the number of incidents.
No. The resolution does not require certification. But the 14 minimum controls map closely to Annex A of ISO/IEC 27001:2022, and an institution with a management system in place already produces much of the required evidence.
Not for environments connected to Pix, RSFN and STR: the resolution requires annual penetration tests conducted by independent professionals.
For payment institutions, brokerage firms and securities distributors, the corresponding instrument is BCB Resolution No. 538/2025.
No. The deadline for full compliance with CMN Resolution 5,274/2025 ended on March 1, 2026. The question now is what the institution can demonstrate.
Talk to a specialist and see where the gaps are between CMN 5,274 and your controls.