Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert
Financial Sector

Cybersecurity for financial institutions, under CMN 5,274.

CMN Resolution 5,274/2025 turned the cybersecurity policy into verifiable controls, with a deadline that ended on March 1, 2026. We help banks, payment institutions, credit unions and brokerages comply and prove it.

What changed

From stated policy to demonstrated control

CMN Resolution 5,274, published on December 18, 2025, updates CMN Resolution 4,893/2021 and details 14 mandatory minimum controls for institutions authorized to operate by the Brazilian Central Bank. For payment institutions, brokerage firms and securities distributors, the corresponding instrument is BCB Resolution No. 538/2025.

The previous framework was more principles-based. Now the institution must show, control by control, what it does and with what evidence.

Where we help

The minimum controls and the service that addresses each one

Pentest

Annual penetration tests by independent professionals in environments connected to Pix, RSFN and STR.

24×7 SOC and MDR

Intrusion prevention and detection, traceability and cyber intelligence, with continuous monitoring.

Vulnerability Management

Continuous vulnerability assessment, with risk-based prioritization and remediation tracking.

Identities and access

Authentication, access controls and multi-factor authentication for administrative access.

Cloud security

Data loss prevention (DLP) and protection of applications and APIs with WAF.

GRC

Cybersecurity policy, mapping of each requirement to internal controls, and organization of evidence.

Pix, RSFN and STR

Stricter requirements for critical environments

For environments connected to Pix, the Brazilian National Financial System Network (RSFN) and the Reserves Transfer System, the resolution imposes additional requirements:

Multi-factor authenticationFor all administrative access.
IsolationPhysical and logical separation of these environments.
MonitoringOf credentials and digital certificates.
Annual independent pentestConducted by professionals independent of the internal team.
Third parties and cloud

Outsourcing execution does not outsource responsibility

Under CMN Resolution 4,893/2021, an institution that contracts data processing or cloud computing remains accountable for the service. Contracting relevant services must be reported to the Brazilian Central Bank within ten days, and the contract must include clauses such as data location, segregation and regulator access.

We support vendor assessment and the organization of the evidence the regulation requires you to demand and retain. Read the guide to third-party risk and CMN 4,893.

“
Since the SOC was deployed at FitBank, with operations monitoring, there has been a significant reduction in the number of incidents.
Gustavo Ramos Head of infrastructure and security, FitBank
Read the FitBank case study →
Frequently asked questions

Frequently asked questions about CMN 5,274

No. The resolution does not require certification. But the 14 minimum controls map closely to Annex A of ISO/IEC 27001:2022, and an institution with a management system in place already produces much of the required evidence.

Not for environments connected to Pix, RSFN and STR: the resolution requires annual penetration tests conducted by independent professionals.

For payment institutions, brokerage firms and securities distributors, the corresponding instrument is BCB Resolution No. 538/2025.

No. The deadline for full compliance with CMN Resolution 5,274/2025 ended on March 1, 2026. The question now is what the institution can demonstrate.

What can your institution demonstrate today?

Talk to a specialist and see where the gaps are between CMN 5,274 and your controls.

Talk to an expert →