2023-11-21 | Circular 12/2023

Added · Updated

Circular 12/2023 — Modifies Circular 14/2017

The Bank of Mexico modifies the Cybersecurity and Information Technology framework for participants in the Interbank Electronic Payments System (SPEI) by updating definitions for technological infrastructure and introducing new requirements for data centers, cyber resilience, and IT/telecommunications infrastructure. Participants with a relative market share exceeding three percent, as well as securities depository institutions, are required to execute contingency procedures within 365 days and submit compliance reports within 180 days thereafter. The regulation establishes staggered effective dates for specific security controls: December 19, 2023, for general provisions; December 19, 2024, for certain network and access controls; and December 19, 2025, for organizational and physical security measures, with securities depositories required to submit their initial reports by May 19, 2025.

Banco de Mexico logo

Mexico

Banco de Mexico

Click to view full text

More like this from BANXICO

We email you every new BANXICO publication the day it's published.

Share