CMN Resolution No. 5,274, published on 18 December 2025, updates CMN Resolution No. 4,893/2021 and redesigns cybersecurity requirements for institutions authorised to operate by the Central Bank of Brazil. The deadline for full compliance was 1 March 2026 — it is already in force.
For payment institutions, brokerages and securities distributors, the corresponding instrument is BCB Resolution No. 538/2025.
The regulatory timeline
It helps to place the change, because a lot of material available online still describes the previous regime:
- CMN Resolution 4,658/2018 — the first cybersecurity policy and cloud contracting framework.
- CMN Resolution 4,893/2021 — consolidated and replaced 4,658.
- CMN Resolution 5,274/2025 — updates 4,893, with a March 2026 deadline.
If your compliance matrix still cites 4,658 or 4,893 as the reference standard, it is out of date.
The mandatory minimum controls
The main change in character is the level of specification. The previous regime was more principles-based; 5,274 details a set of 14 mandatory minimum controls, among them:
- Authentication
- Encryption mechanisms
- Intrusion prevention and detection
- Information leakage prevention
- Protection against malicious software
- Traceability
- Backup management
- Vulnerability assessment
- Access controls
- Hardening
- Network protection
- Certificate management
- API security
- Cyber intelligence
Note what appears on that list and did not feature so prominently before: API security, certificate management and cyber intelligence. All three reflect the design of the Brazilian financial system after Pix and Open Finance, where inter-institutional integration is the exposure point.
Enhanced requirements for Pix, RSFN and STR
For environments connecting to Pix, to the National Financial System Network and to the Reserves Transfer System, the resolution imposes additional requirements:
- Multi-factor authentication for administrative access
- Physical and logical isolation of those environments
- Monitoring of credentials and digital certificates
- Annual penetration testing conducted by independent professionals
That last item deserves attention from anyone treating penetration testing as a negotiable annual expense: the independence requirement rules out testing performed by the internal team.
Where ISO 27001 helps
The resolution does not require ISO 27001 certification, and it is important not to sell one as the other. But the overlap is substantial: the 14 minimum controls map almost directly onto ISO 27001:2022 Annex A controls — including several of the eleven controls new to the revision, such as threat intelligence, data leakage prevention and configuration management.
In practice, an institution with an implemented ISMS and a current Statement of Applicability already produces much of the evidence the regulator asks for. What is usually missing is the specific layer: the explicit mapping between each regulatory requirement and the corresponding internal control, with the evidence pointed to. Without that mapping, the organisation has the controls but cannot demonstrate them in the format the question is asked.
What to do now
With the deadline already past, the question is no longer "how do we prepare" but "what can we demonstrate today". Three quick checks show where you stand:
- Is there a document mapping each of the 14 minimum controls to an internal control, with an owner and evidence? If the answer is an outdated spreadsheet, that is the first item.
- Was the last penetration test of the Pix/RSFN/STR environments performed by an independent party, with a report dated within the last twelve months?
- Has the cybersecurity policy been reviewed and approved by senior management after December 2025?
Source consulted: Grant Thornton Brazil — Cybersecurity: what changes with CMN Resolution No. 5,274/2025. This article is informational and does not constitute legal advice; consult the official text on the Central Bank of Brazil website.