Demonstrable independence
Performed by professionals independent from the teams that build and operate the systems assessed, with that separation on record.
CMN Resolution 5,274/2025 and BCB Resolution 538/2025 raised the cybersecurity bar for every institution authorised by the Central Bank of Brazil — including an annual penetration test performed by independent professionals, with evidence kept available to the supervisor.
BACEN cybersecurity compliance is the set of policies, technical controls and evidence a Central Bank of Brazil–authorised institution must maintain under CMN Resolution 5,274/2025 — which amends CMN Resolution 4,893/2021 — and BCB Resolution 538/2025: an annual independent penetration test, incident response, third-party risk management and cloud computing requirements.
In practice, having a policy on file is no longer enough. Supervision looks for evidence: test reports, identified vulnerabilities, an action plan with owners and deadlines, and proof that remediation was applied and revalidated.
Each item maps a BACEN cybersecurity requirement to the Berghem service that produces the corresponding evidence.
Testing performed by a team external to the groups that build and operate the systems in scope, with documented scope, methodology and results.
Identification, risk classification, action plan with owners and deadlines, and a retest that proves the fix.
Review of the policy, the minimum controls and the documentation trail the institution must present to the supervisor.
Building, testing and exercising the response plan, with audit trail, communication and lessons learned.
Assessment of vendors and of third-party systems running on the institution's own computing resources.
API security controls, hardening, digital certificate management and security embedded in the development lifecycle.
Internet, deep web and dark web monitoring for leaked credentials, certificates and institutional data.
Phishing, vishing and social engineering simulations that test authentication, controls and response in practice.
Assessment of critical environment isolation, private key control and payment and settlement security.
A generic report will not survive an inspection. Supervision expects a complete trail, from scope to proof of remediation.
Performed by professionals independent from the teams that build and operate the systems assessed, with that separation on record.
Systems, environments and interfaces covered, with an explicit technical rationale for what was in and out of scope.
Vulnerabilities classified by risk, with reproduction, business impact, recommendation, owner and remediation deadline.
Evidence that remediation was applied and revalidated, in a format that survives an inspection years later.
Berghem was founded in 2003 and built most of its history inside banks, acquirers, processors and fintechs.
Offensive security is the core of the practice, not a side line: pentest, red team, EMV, POS, ATM, Pix and Open Finance.
Reports written for two audiences at once: the people who fix the system and the people who answer to the regulator.
Operating from São Paulo and, through Berilo, from Bergamo — covering institutions with regulatory exposure in Brazil and Europe.
Talk to a senior consultant about the annual independent penetration test, the evidence pack and the remediation plan required by CMN 5,274 and BCB 538.