Skip to content
Home / Industries / Financial Services / BACEN Compliance
Regulatory compliance · Central Bank of Brazil

BACEN 5.274 and BCB 538 compliance: penetration testing for Brazilian financial institutions

CMN Resolution 5,274/2025 and BCB Resolution 538/2025 raised the cybersecurity bar for every institution authorised by the Central Bank of Brazil — including an annual penetration test performed by independent professionals, with evidence kept available to the supervisor.

What BACEN cybersecurity compliance means

BACEN cybersecurity compliance is the set of policies, technical controls and evidence a Central Bank of Brazil–authorised institution must maintain under CMN Resolution 5,274/2025 — which amends CMN Resolution 4,893/2021 — and BCB Resolution 538/2025: an annual independent penetration test, incident response, third-party risk management and cloud computing requirements.

In practice, having a policy on file is no longer enough. Supervision looks for evidence: test reports, identified vulnerabilities, an action plan with owners and deadlines, and proof that remediation was applied and revalidated.

The framework in force

CMN Resolution 5,274 of 18 December 2025 — amends CMN Resolution 4,893/2021 and applies to financial institutions.
BCB Resolution 538 of 18 December 2025 — equivalent content for payment institutions, brokers and dealers.
Compliance deadline for institutions already operating: 1 March 2026.
Annual penetration test, performed by independent professionals, with documented results.
Reports and remediation evidence kept available to the Central Bank for at least 5 years.
Always check the official text and any updates directly in the BCB regulatory database.
The numbers
01/03/2026
compliance deadline for institutions already operating
Annual
minimum frequency of the required penetration test
5 years
minimum retention of reports and evidence for the Central Bank
20+
years of Berghem offensive security in financial services
Deliverables

What the penetration test must produce

A generic report will not survive an inspection. Supervision expects a complete trail, from scope to proof of remediation.

Demonstrable independence

Performed by professionals independent from the teams that build and operate the systems assessed, with that separation on record.

Justified scope

Systems, environments and interfaces covered, with an explicit technical rationale for what was in and out of scope.

Findings and action plan

Vulnerabilities classified by risk, with reproduction, business impact, recommendation, owner and remediation deadline.

Proof of fix and retest

Evidence that remediation was applied and revalidated, in a format that survives an inspection years later.

Why Berghem

Two decades inside Brazilian financial services

Berghem was founded in 2003 and built most of its history inside banks, acquirers, processors and fintechs.

Offensive specialisation

Offensive security is the core of the practice, not a side line: pentest, red team, EMV, POS, ATM, Pix and Open Finance.

Audit-proof evidence

Reports written for two audiences at once: the people who fix the system and the people who answer to the regulator.

LATAM and Europe

Operating from São Paulo and, through Berilo, from Bergamo — covering institutions with regulatory exposure in Brazil and Europe.

FAQ

BACEN compliance: common questions

What does CMN Resolution 5,274/2025 require?
CMN Resolution 5,274/2025 amends CMN Resolution 4,893/2021 and tightens the cybersecurity framework for institutions authorised by the Central Bank of Brazil. The highest-impact requirement is an annual penetration test performed by independent professionals, with documented results, a remediation action plan and evidence kept available to the BCB for at least five years, alongside minimum controls such as multi-factor authentication for administrative access, encryption, data leak prevention, traceability, vulnerability management, API security and threat intelligence. Consult the BCB regulatory database for the full text.
What is the difference between CMN 5,274 and BCB 538?
Both are dated 18 December 2025 and their technical content is equivalent. The difference is scope of application: CMN Resolution 5,274/2025 applies to financial institutions, while BCB Resolution 538/2025 covers payment institutions, brokers and dealers. The security programme and the required evidence are the same; what changes is the regulatory basis cited in the documentation.
Did CMN 5,274 revoke CMN Resolution 4,893/2021?
No. CMN Resolution 5,274/2025 amends CMN Resolution 4,893/2021, which remains the reference rule with an updated text. Internal documentation should therefore cite 4,893/2021 as currently worded rather than the original 2021 version. Validate the consolidated wording directly in the BCB regulatory database.
How often must the penetration test be performed?
At least once a year. The requirement is an annual penetration test with documented results, identified vulnerabilities and an action plan. Institutions with fast release cycles usually adopt a higher cadence — a full annual pentest plus targeted testing on each significant release — so the evidence tracks the real risk of the environment.
Who is allowed to perform the penetration test?
The rule requires independent professionals, meaning no ties to the teams that develop, maintain or operate the systems assessed. An internal security team reporting to the same technology executive who owns the tested system will generally not satisfy that criterion. Engaging a specialised external firm is the most direct way to demonstrate independence during an inspection.
How long must pentest reports be retained?
Reports and remediation evidence must be kept available to the Central Bank for at least five years. That means retaining not only the final report but also the agreed scope, methodology, risk-classified findings, the action plan with owners and deadlines, and proof that the fix was applied and revalidated in a retest.
Is BCB Circular 3,909/2018 still in force?
No. Circular 3,909/2018, which covered cybersecurity policy and cloud contracting for payment institutions, was revoked by BCB Resolution 85/2021. Payment institutions today follow BCB Resolution 85/2021 and the requirements introduced by BCB Resolution 538/2025. References to Circular 3,909 in internal policies signal outdated documentation.
What was the compliance deadline?
Institutions already operating when the rules took effect had until 1 March 2026 to complete their adaptations. Institutions that have not closed the cycle — independent penetration test executed, action plan under way and evidence archived — are behind on a regulatory obligation and should prioritise remediation, documenting the plan and the effective dates.
How do I prepare for a Central Bank inspection?
Assemble the documentation trail before it is requested: the cybersecurity policy as currently worded, an inventory of critical systems, the scope and report of the annual penetration test, evidence of the tester's independence, an action plan with owners and deadlines, proof of retest, an incident response plan with exercise records, third-party assessments and cloud contracts. Berghem runs the test and delivers the evidence pack already organised in that format.
Get started

Need to close your BACEN compliance cycle?

Talk to a senior consultant about the annual independent penetration test, the evidence pack and the remediation plan required by CMN 5,274 and BCB 538.