PRODIST Content

BACEN Security Requirements: A Guide for Financial Institutions

BACEN's security requirements specify the controls that financial and payment institutions must implement to protect systems, data, credentials, and critical infrastructure.

In practice, this involves cybersecurity policy, access control, protection of keys and certificates, monitoring, security testing, business continuity, and management of risks associated with technology vendors and services.

With the digitization of the National Financial System (SFN), the growth of Pix, and the expansion of integrations through the National Financial System Network (RSFN), cybersecurity has come to occupy an even more strategic position in banking regulation.

For this reason, banks, fintech companies, credit unions, payment institutions, and other regulated organizations need to understand not only which regulations to follow, but also which technological controls must be in place in their operations.

What is the Central Bank's role in ensuring the security of financial institutions?

The Central Bank of Brazil (BACEN) is responsible for ensuring the soundness and efficiency of the National Financial System, as well as for supervising the institutions authorized to operate in the country. Cybersecurity is part of this role because technological failures can compromise transactions, payment infrastructures, and the very operational stability of the financial system.

The RSFN (National Financial System Network), for example, is the communications infrastructure used to support information traffic within the SFN (National Financial System). For this reason, participants who connect to this network must comply with specific security, communications, and access control requirements.

In recent years, the Central Bank and the National Monetary Council have been tightening these requirements to keep pace with the rise in digitalization and cyber risks.

In December 2025, new regulations updated the security requirements applicable to financial and payment institutions, including additional controls regarding digital certificates, system integration, traceability, network protection, and communication with critical infrastructure.

What regulations address cybersecurity in the financial market?

The regulatory framework is broad and varies depending on the type of institution and the activities it carries out. Among the main regulations are:

CMN Resolution No. 4,893/2021 and CMN Resolution No. 5,274/2025

CMN Resolution No. 4,893/2021 establishes rules regarding cybersecurity policy and the contracting of data processing, data storage, and cloud computing services by institutions authorized to operate by the Central Bank.

In December 2025, CMN Resolution No. 5,274 updated these regulations, strengthening requirements related to the security of technology and communications infrastructure.

BCB Resolution No. 85/2021 and its updates

BCB Resolution No. 85/2021 establishes cybersecurity requirements applicable to payment institutions and mandates the implementation and maintenance of a specific policy for this purpose.

The regulations were also updated in December 2025 by BCB Resolution No. 538, expanding and updating the controls applicable to payment institutions and other institutions supervised by the BCB.

BCB Resolution No. 498/2025

BCB Resolution No. 498/2025 establishes requirements for the accreditation of Information Technology Service Providers (PSTIs), which play a key role in connecting participants to the financial system’s infrastructure.

The standard was amended in 2026 to clarify and improve requirements related to governance, risk management, and cybersecurity for PSTIs.

In addition to these regulations specific to the financial sector, institutions must also comply with general laws, such as the General Data Protection Law (LGPD) and laws related to the confidentiality of financial transactions.

BACEN's Key Security Requirements

online-security-central-bank-prodist-technology-solutions-financial-market

Although specific requirements depend on the type of institution, service, and system used, certain controls appear repeatedly in the financial regulatory environment.

Cybersecurity Policy and Governance

The institution must have formal policies in place to guide the prevention, detection, and response to incidents.

This framework must define responsibilities, controls, procedures, and mechanisms for monitoring technological risks.

Governance should also cover both internally developed systems and third-party solutions, ensuring that vendors do not become vulnerabilities in the infrastructure.

Certificate and Cryptographic Key Management

Digital certificates and private keys are critical assets for authenticating, signing, and securing financial communications.

The Central Bank has strengthened requirements related to the management of digital certificates and the protection of credentials used in critical infrastructure. The current rules also place greater emphasis on access to the private keys used by institutions.

A proper architecture should include:

  • Secure key generation and storage;
  • Strict access control;
  • Segregation of duties;
  • Rotation and revocation;
  • Traceability of operations;
  • Proper custody in KMS, Vault, or HSM, depending on the level of criticality.

Access Control and Authentication

The organization needs to restrict administrative access to critical environments and applications.

Best practices include multi-factor authentication, the principle of least privilege, segregation of duties, and monitoring of the credentials used.

In environments related to RSFN, Pix, and STR, security requirements have been strengthened precisely to reduce the risk of compromised credentials and privileged access.

Isolation and Protection of Critical Environments

Environments responsible for critical transactions and communications must be properly segregated from the rest of the infrastructure.

This isolation reduces the likelihood that a vulnerability in a less sensitive system could be exploited as a pathway to compromise Pix, STR, or other critical components of the financial operation.

Monitoring, Traceability, and Safety Testing

Security must be continuously monitored.

The updated rules include requirements related to the traceability of operations, network security, vulnerability remediation, and periodic penetration testing. The Central Bank now also requires documentation of the results and the corresponding action plans.

This makes it possible to identify vulnerabilities before they are exploited and provides evidence for audit and oversight processes.

Third-Party Management and Cloud Services

Contracting for processing, storage, or cloud computing services does not fully transfer responsibility for security to the provider.

Institutions need to assess risks, establish contractual requirements, monitor their service providers, and ensure that the contracted services remain compliant with applicable regulatory requirements.

How can we meet BACEN's security requirements in practice?

The first step is to identify which standards and manuals apply to the institution and the systems in which it participates. Next, these requirements must be transformed into technical controls that are effectively incorporated into the infrastructure.

A consistent strategy typically involves four areas: governance, cryptographic protection, operational control, and continuous monitoring.

In the case of integrations with BACEN, NÚCLEA, Pix, and other SFN systems, this means using solutions capable of performing encryption and digital signing, protecting private keys, verifying identities, and generating auditable records.

The goal is not simply to “have cryptography,” but to ensure that cryptographic assets are protected throughout their entire lifecycle and used only by authorized applications and users.

How does PRODIST help institutions meet security requirements?

PRODIST develops solutions focused on cryptographic protection and the secure integration of financial institutions with regulated environments.

PRODIST STS allows you to centralize essential encryption, digital signature, and key management functions, reducing the need to develop the entire security layer used by applications in-house.

Its features include:

  • Centralized management of cryptographic keys;
  • Encryption and digital signatures;
  • Role-Based Access Control (RBAC);
  • Certificate-based authentication (mTLS);
  • Integration with certified HSMs;
  • Compatibility with Vaults and cloud-based KMS;
  • On-premises, hybrid, or cloud deployment.

For communications based on the SFN protocol, the solution can perform message and file encapsulation, encryption, digital signing, security header insertion, and validation of received packets.

This allows organizations to incorporate cryptographic controls into their applications in a standardized manner, while maintaining greater control over their security assets.

Integration with the BACEN, NÚCLEA, and Pix systems

PRODIST also offers solutions for institutions that need to integrate their applications with major financial ecosystems.

Its technology supports systems related to asset and receivables tracking, settlement, portability, and other SFN operations, in addition to offering specific features for the Pix environment.

By centralizing the cryptographic layer in a specialized solution, the institution reduces the technical complexity of its business applications and makes it easier to maintain security controls over time.

PRODIST: Experience and Support for Financial Environments 

Founded in 1987, PRODIST has been operating in the Brazilian market for four decades, with solutions in use since the launch of the Brazilian Payment System (SPB) in 2002.

The company serves more than 40 financial institutions and combines specialized encryption technology with technical support during implementation and operation.

Among its key features are an SLA of up to 99.96%, specialized technical support, the option for 24×7 service, and a response time of up to 15 minutes, depending on the service plan selected.

More than just providing an encryption tool, PRODIST specializes in the design, implementation, and support of solutions for organizations that need to balance security, regulatory compliance, availability, and integration with critical systems.

For institutions that need to assess or modernize their controls related to BACEN’s security requirements, relying on a specialized platform can reduce the complexity of implementation and strengthen the governance of crypto assets.

FAQ – BACEN Security Requirements

What are BACEN's main security requirements?

The requirements include a cybersecurity policy, protection of keys and certificates, access control, traceability, monitoring, security testing, business continuity, and supplier risk management.

Which regulation addresses cybersecurity for financial institutions?

CMN Resolution No. 4,893/2021 is one of the key regulations and was updated by CMN Resolution No. 5,274/2025, which strengthened security and protection requirements for technology infrastructure.

Do payment institutions also need to comply with BACEN's security requirements?

Yes. BCB Resolution No. 85/2021 establishes cybersecurity requirements for payment institutions and has been updated since then.

Does BACEN require the protection of cryptographic keys?

Regulatory requirements include controls over certificates, credentials, and private keys used in financial infrastructures, particularly in critical communication environments.

How does PRODIST STS help ensure safety?

PRODIST STS centralizes key management, encryption, and digital signatures, and supports integration with HSMs, vaults, and KMS, as well as mTLS authentication and RBAC access control.

Does PRODIST assist with integration with BACEN and NÚCLEA?

Yes. The company offers solutions for encryption, digital signatures, cryptographic asset management, and secure integration with various systems from BACEN, NÚCLEA, Pix, and SFN.

Photo by PRODIST
PRODIST

Technology for secure financial transactions. Prodist develops encryption and digital signature solutions for the Pix, SFN, NÚCLEA, and SPED ecosystems to meet the regulatory requirements of the financial market.

Share

More content

Talk to an expert

Fill out the form and find out how PRODIST can help your institution operate securely, in compliance, and at peak performance. We can help you with: