CiberLATAMbywhalemate

Brazil Tightens Pix Controls

Brazil’s central bank is weighing Pix restrictions for institutions with cyber weaknesses while moving ahead with new rules for PSAVs.

Whalemate Labs · AI-assisted researchJul 22, 20263 min read

Brazil’s central bank is considering restricting Pix access for banks and fintechs with cyber weaknesses. Reported measures would include transaction limits, time restrictions, suspension of new Pix keys, and, in serious or repeated cases, a full cut off from the Instant Payment System, or SPI. At the same time, new resolutions are pushing banks, fintechs and virtual asset service providers toward tougher authorization, capital and governance requirements.

The Central Bank of Brazil is weighing restrictions on Pix access for banks and fintechs that show weaknesses in their cyber defenses. According to reporting cited by Destak News Brasil, the measures under review would include caps on transaction values and operating hours, suspension of new Pix key registrations, and, in severe or repeated cases, a full suspension of access to the Instant Payment System, or SPI.

Tougher controls on payments and security

The discussion comes as the regulator has already been broadening its requirements for financial institutions and payment system players. The research material also points to controls the Central Bank can demand during inspections, new security and verification measures for online advertising of financial products, and a regulatory framework that raises the compliance bar for banks, fintechs and providers tied to virtual assets.

In the case of any future Pix restrictions, the focus would be on institutions with cybersecurity vulnerabilities. The regulatory response would not be one size fits all, but layered, first by narrowing operating parameters, then by blocking new Pix keys and, if warranted, by cutting off access to the SPI. The exact scope of those measures is still under review, according to the available coverage.

The crypto front and authorization deadlines

In parallel, an analysis attributed to PtyCoin of Central Bank Resolution No. 580/2026 outlines a regulatory timeline for virtual asset service providers, or PSAVs. Under that reading, the circulars and resolutions linked to authorization as SPSAVs, including minimum capital, governance and custody segregation requirements, would give incumbent providers until October 30, 2026 to file their authorization request with the Central Bank.

The same analysis says that after that deadline, banks and authorized payment institutions would generally be barred from doing business with unauthorized PSAVs. It also says that as of January 1, 2027, a broad set of prudential circulars and resolutions would apply in full to virtual asset service companies classified as Type 3 institutions.

Taken together, the possible tightening around Pix and the new compliance requirements would leave Brazil’s market under a stricter oversight framework, with direct effects on operational security, authorization and prudential supervision.

Sources

View all