2025-12-18 | Resolução CMN 5274

Central Bank Resolution No. 5,274 of December 18, 2025, Amending Resolution CMN No. 4,893 on Cybersecurity Policy and Cloud Services

The Central Bank of Brazil issued Resolution No. 5,274 to amend Resolution CMN No. 4,893, imposing stricter cybersecurity requirements on financial institutions regarding data processing, storage, and cloud services. The regulation mandates enhanced controls for cyber threat intelligence, including monitoring the Deep and Dark Web, and establishes rigorous standards for vulnerability management, access control, and network protection. Additionally, it introduces specific security mandates for critical systems such as Pix and STR, requires annual independent penetration testing, and sets a compliance deadline of March 1, 2026.

Banco Central do Brasil logo

Brazil

Banco Central do Brasil

Click to view full text