CiberLATAMbywhalemate

Argentina BCRA Tightens Cyberresilience Rules

Argentina’s central bank has tightened rules for banks, PSPs and key payment systems, adding incident reporting and root-cause analysis in five days.

Whalemate Labs · AI-assisted researchAug 7, 20262 min read

Argentina’s central bank formalized Communication A 8457, and together with the updated guidance in A 8280, it set a stricter framework for banks, payment service providers and systemically important payment systems. The rules require mandatory incident reporting and a final root-cause report within five calendar days.

The Central Bank of the Argentine Republic formalized Communication A 8457 in the Official Gazette on July 29, 2026. The rule builds on the guidance updated through Communication A 8280 and applies to banks, payment service providers, and systemically important payment systems, with new operational and cyberresilience requirements.

What the BCRA framework requires

According to a regulatory monitoring report on Argentina, the rules include mandatory incident notification and a final root-cause report within five calendar days. That framework sits within a broader approach to operational continuity and the response capabilities of supervised entities.

The regulatory logic did not emerge in isolation. A news report on Argentina said Communications A 7199, A 7319 and A 7370 had already strengthened obligations tied to digital fraud prevention. The points mentioned include stronger authentication, monitoring of unusual activity, controls for risky transactions, early fraud detection, comprehensive technology risk management and rapid incident response.

Recent context

The regulatory debate comes as the BCRA itself has been warning about scams that use its name and image. Infobae reported on August 5, 2026, that the Central Bank said banks and public agencies do not ask users to download external applications as part of procedures, amid a virtual scheme that used the institution’s identity in an attempt to steal savings.

With that public warning and the publication of Communication A 8457, the Argentine regulator is keeping its focus on two fronts at once, technical controls over regulated entities and fraud prevention aimed at users.

Sources

View all