Pular para o conteúdo principal
Close
Security

BACEN Resolution 5.274: 14 Mandatory Controls, Deadline Passed, Auditor in the Field

Gabriel Ferraresi· CEO | Tech86July 20, 20264 min
securitybacencmn-5274compliancepixmfapentestdark-webisolationstr

The deadline expired on March 1, 2026. Almost five months ago. Any institution not yet compliant with Resolução CMN nº 5.274/2025 operates in an irregular situation. Banco Central requires it. There is no negotiation.

Gabriel Muricca Galípolo signed the resolution on December 18, 2025. It was published in the DOU on December 22, 2025, and entered into force upon publication. Resolution 5.274 amends CMN 4.893/2021, details 14 mandatory controls in Art. 3º, § 2º, and adds three new articles: 3º-A (Pix and STR), 22-A (annual pentest), and 22-B (RSFN as a relevant service). The sister norm BCB 538/2025 mirrors the same deadline for payment institutions, currency exchanges, and securities distributors. There has been no official extension.

The four requirements that take down an institution

The auditor's checklist has four demands that, alone, are enough to flag non-compliance.

1. MFA is mandatory. External access to the corporate network requires MFA. Administrative access to the Pix and STR environments also requires MFA, now codified in Art. 3º-A. Without MFA, the institution is in direct non-compliance — there is no interpretation, no compensating control.

2. Pix and STR isolation. Physical and logical. In the cloud, a dedicated and separated instance. Service provider companies cannot touch the private keys of signing certificates. This is an express prohibition — the institution retains custody, the provider does not.

3. Cyber intelligence (inciso XIV, new). Monitoring of the internet, Deep Web, Dark Web, and private groups. Without this monitoring, the auditor marks it as a gap. The control is new in Art. 3º, § 2º, inciso XIV, and reflects the reality that credential theft is the primary vector in financial incidents.

4. Annual independent pentest (Art. 22-A). Performed by a natural person or a specialized company. Results documented with action plans. Evidence retained for 5 years, per Art. 23, X. A report without an action plan does not satisfy the requirement.

The other 12 controls of Art. 3º, § 2º

The remaining 12 controls of Art. 3º, § 2º cover the full surface of cyber resilience: encryption, IDS/IPS, DLP, antimalware, audit trails, backup, vulnerability management, third-party access review, hardening, network segmentation, certificate management, and requirements for APIs and Open Finance.

Each control must be documented, evidenced, and reviewable. The auditor does not accept "we have something like that." The auditor expects policy, evidence of execution, and a review cycle. Audit trails must be end-to-end. Backup must be tested. Vulnerability management must show a cadence, not a one-off scan. Third-party access review must happen on a defined frequency. Certificate management must include private key custody. APIs and Open Finance endpoints must meet the documented requirements.

The penalty framework: Lei 4.595/1964

The penalty framework is Lei 4.595/1964: fine, administrative sanctioning proceeding (PAS), and revocation of authorization. Historical precedent cases range between 50 thousand reais and 2 million reais. There is no official public table — the values come from published case history, and the actual fine depends on the institution's capital, the severity of the violation, and the recidivism.

The sister norm BCB 538/2025 mirrors the same deadline for payment institutions, currency exchanges, and securities distributors. The scope differs — CMN 5.274 covers banking institutions, BCB 538/2025 covers the payment ecosystem — but the deadline and the controls are aligned. No official extension has been granted for either.

What Tech86 implements

We implement the full control surface required by Resolução CMN nº 5.274/2025:

  1. SOC 24/7 with MDR. Dwell time collapsed to hours. Covers IDS/IPS, antimalware, and audit trails end-to-end.
  2. Corporate MFA and hardening of endpoints and servers. Documented secure configuration profiles.
  3. Annual independent pentest with report and action plans. 5-year evidence retention, per Art. 23, X.
  4. Digital certificate management with private key custody in a vault with physical and logical control. Service providers never touch the private keys of signing certificates.
  5. Dark Web monitoring and cyber intelligence. Monitoring of SPI credentials and certificates across internet, Deep Web, Dark Web, and private groups.
  6. Network segmentation with Pix environment isolation. Incident response with evidence preservation.

Conclusion

The BACEN auditor is already in the field. The question is whether he finds you compliant.

The deadline expired on March 1, 2026. Almost five months ago. Resolução CMN nº 5.274/2025 is not a roadmap — it is a requirement in force. The 14 mandatory controls of Art. 3º, § 2º, the Pix and STR isolation of Art. 3º-A, the annual pentest of Art. 22-A, and the RSFN classification of Art. 22-B are all enforceable today. The penalty framework of Lei 4.595/1964 — fine, PAS, revocation — is not theoretical. The precedent range of 50 thousand to 2 million reais is historical case data, not a published table, but it is the range the auditor works with.

At Tech86, we help financial institutions reach and maintain compliance with BACEN Resolution 5.274 — from MFA deployment to Pix isolation, from cyber intelligence to the annual independent pentest. The auditor is in the field. The question is whether he finds you compliant.

blog.cta_consulting_title

blog.cta_consulting_subtitle

BACEN Compliance and Financial Cybersecurity

Frequently Asked Questions

Resolução CMN nº 5.274/2025 amends CMN 4.893/2021 and details 14 mandatory controls in Art. 3º, § 2º, plus three new articles: 3º-A (Pix and STR), 22-A (annual pentest), and 22-B (RSFN as a relevant service). It was signed by Gabriel Muricca Galípolo on December 18, 2025, published in the DOU on December 22, 2025, and entered into force upon publication. The compliance deadline expired on March 1, 2026 — almost five months ago.

Art. 3º, § 2º lists 14 controls: MFA, encryption, IDS/IPS, DLP, antimalware, audit trails, backup, vulnerability management, third-party access review, hardening, network segmentation, certificate management, requirements for APIs and Open Finance, and cyber intelligence (inciso XIV, the new addition). The four that most often take down an institution are MFA, Pix/STR isolation, cyber intelligence, and the annual independent pentest.

The penalty framework is Lei 4.595/1964: fine, administrative sanctioning proceeding (PAS), and revocation of authorization. Historical precedent cases range between 50 thousand reais and 2 million reais. There is no official public table — the values come from published case history. The sister norm BCB 538/2025 mirrors the same deadline for payment institutions, currency exchanges, and securities distributors.

Art. 3º-A requires physical and logical isolation of the Pix and STR environments. In the cloud, this means a dedicated and separated instance. Service provider companies cannot touch the private keys of signing certificates — this is an express prohibition. Administrative access to these environments also requires MFA. Without isolation and MFA, the institution is in direct non-compliance.

Art. 22-A requires an annual independent pentest performed by a natural person or a specialized company. Results must be documented with action plans, and evidence must be retained for 5 years, per Art. 23, X. The pentest must cover the Pix and STR environments, the external perimeter, and privileged access paths. A report without an action plan does not satisfy the requirement.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.