CiberLATAMbywhalemate

Brazil Central Bank tightens rules for VASPs

From Oct. 30, 2026, unlicensed VASPs in Brazil will lose access to regulated banking services.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The Banco Central do Brasil set Oct. 30, 2026, as the regulatory cutoff for virtual asset service providers, or VASPs. From that date, regulated institutions will not be able to provide accounts, payments, exchange, trading, or custody services to firms that are not authorized or do not have a filed authorization request.

Update September 18, 2026: the Banco Central do Brasil clarified the deadline for VASPs already operating in the country to seek authorization and confirmed that, starting on Oct. 30, 2026, regulated entities may not provide them with accounts, payments, exchange, trading, intermediation, or custody if they are not authorized or do not have a filed application. It also advanced Resolution BCB No. 580/2026, which brings them into the prudential framework starting in January 2027.

The Banco Central do Brasil set Oct. 30, 2026, as the regulatory cutoff for virtual asset service providers, or VASPs. From that date, regulated institutions under the central bank will not be allowed to provide account, payments, exchange, trading, or custody services to firms that are not authorized or do not already have a filed authorization request.

What does the new regime require for VASPs?

The authorization regime set out in BCB Resolutions No. 519, 520 and 521 requires companies covered by the transition rules to file their applications with the Banco Central do Brasil by Oct. 30, 2026. Resolution BCB No. 520/2025 set a 270-day deadline, counted from Feb. 2, 2026, for VASPs already operating in Brazil to file their request.

Those that do not comply will not be able to keep operating with support from the regulated financial system. Article 91 of Resolution BCB No. 520/2025 also says that, as of that date, banks, payment institutions and other supervised entities are barred from offering unlicensed providers, or those without a filed application, account opening and maintenance, payments, exchange, trading, intermediation and custody.

That framework also comes with a sharp increase in entry requirements. According to BTCC, the new capital rules for virtual asset service providers set requirements ranging from R$10.8 million to R$37.2 million, depending on the activity and risk profile. NDM Advogados says the minimum share capital starts at about R$9.2 million for firms that only intermediate virtual assets and can exceed R$13 million if they also offer custody.

How many companies would remain in the race?

FinanceFeeds estimates that the new framework could sharply narrow Brazil's crypto market. According to that analysis, out of about 300 active companies in Brazil, only 20 to 25 would currently meet the minimum conditions to apply for authorization, and the expectation is that only about 10 will secure a full license after the regulator's review.

BTCC adds that virtual asset service institutions that do not file their application by Oct. 30, 2026, must cease operations within an additional 30 days and formally notify clients about the shutdown and the liquidation process. The report outlines an orderly exit for operators left outside the new regime.

What changed in prudential supervision?

Resolution BCB No. 580/2026 brings virtual asset service provider companies into the prudential framework of the national financial system. According to Portal do Bitcoin, capital, risk management and disclosure requirements will start in January 2027, with a gradual transition running through June 2028.

That move brings them closer to a supervisory regime more like the one other financial actors already face. For banks and fintechs that operate with crypto or provide related services, the change requires a review of capital, internal controls and operational exposure before implementation begins.

What changed in Pix and anti-fraud controls?

The central bank also tightened operational rules tied to Pix. According to MixVale, transfers made from new smartphones and computers are capped at 200 reais per transaction and require additional checks, such as facial biometrics, electronic confirmations or document verification.

The same source says Brazilian financial institutions must consult the central bank's central fraud database at least twice a year and keep preventive mechanisms active to detect unusual account behavior. They will also have to maintain ongoing customer guidance programs.

How does cybersecurity fit into this regulatory picture?

The regulatory debate also reached digital security with a draft of a future General Cybersecurity Law presented in April 2026 by the National Cybersecurity Committee, according to TI Inside. The text proposes creating a National Cybersecurity System and a National Authority in charge of overseeing digital security, with an impact on public and private infrastructure, including the financial sector.

TI Inside says the financial sector would be treated as critical infrastructure and that the proposal uses a general 180-day deadline for companies to comply after approval. For banks, fintechs and international payment providers, that would mean reviewing controls, certifications and third-party contracts to align with a new protection standard.

What happens with closures for serious irregularities?

Serasa reported that the December 2025 resolutions already require banks and payment institutions to close accounts when they detect serious irregularities. Those entities must document the fraud or misuse indicators internally, preserve the evidence and report to the central bank and other competent agencies when applicable.

That forced closure is part of a broader fraud prevention and enforcement policy. In practice, Brazil's regulatory package combines prior authorization for VASPs, capital pressure, Pix operating limits and stronger monitoring and reporting duties for the financial system.

Sources

View all