CiberLATAMbywhalemate

Argentina BCRA Tightens Cyberresilience Rules

Argentina’s central bank has tightened rules for banks, PSPs and key payment systems, adding incident reporting and root-cause analysis in five days.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Argentina’s central bank formalized Communication A 8457, and together with the updated guidance in A 8280, it set a stricter framework for banks, payment service providers and systemically important payment systems. The rules require mandatory incident reporting and a final root-cause report within five calendar days.

The Central Bank of Argentina formalized Communication A 8457 in the Official Gazette on July 29, 2026. The rule builds on the guidelines updated through Communication A 8280 and applies to banks, PSPs and systemically important payment systems, with new operational and cyber resilience requirements.

What does the BCRA framework require?

According to a regulatory monitoring report on Argentina, the rules include mandatory incident notification and a final root-cause report within five calendar days. The framework is part of a broader regime aimed at operational continuity and the response capability of supervised entities.

The regulatory logic did not appear in isolation. A news report on Argentina said Communications A 7199, A 7319 and A 7370 had already strengthened obligations tied to digital fraud prevention. The measures mentioned include stronger authentication, monitoring of unusual transactions, controls for risky transactions, early fraud detection, comprehensive technology risk management and rapid incident response.

What is the recent context?

The regulatory debate is unfolding as the BCRA itself has been warning about scams that use its image. Infobae reported on August 5, 2026, that the central bank said banks and public agencies do not ask users to download external apps as part of procedures, in the context of a virtual scheme that used the institution’s identity to try to steal savings.

With that public warning and the release of Communication A 8457, the Argentine regulator is keeping its focus on two fronts at once, technical controls at supervised entities and fraud prevention aimed at users.

Sources

View all