Chile CMF Enforces New Authentication Rule
Chile’s CMF puts NCG 583 into effect, requiring stronger authentication for payments, transfers and digital onboarding.
Chile’s Financial Market Commission said General Rule No. 583 is now in force. It requires stronger customer authentication for transfers and digital onboarding, and replaces coordinate cards as the main authentication method.
Chile’s Financial Market Commission said General Rule No. 583 is now in force, raising security requirements for electronic payments and transfers. The measure requires stronger customer authentication for transfers and digital onboarding, and removes coordinate cards from their main authentication role.
What does the CMF’s new rule require?
NCG 583 requires customer identity to be validated through stronger authentication, a scheme that uses at least two of three elements: something the user knows, something the user has, or an inherent characteristic. In the coverage cited, examples include a password, a phone or device, and a fingerprint.
That change applies to both transfers and digital onboarding processes. The rule is meant to replace coordinate cards as the main authentication mechanism, in line with the standards the CMF set for banking operations and those of other financial institutions.
What happened to the coordinate card?
The CMF had planned a gradual phaseout of the coordinate card, but it pushed back the mandatory removal by one year from the original date, set for August 1, 2025. According to Diario AS Chile, the decision came after complaints about the impact of the measure.
The same report says each bank or financial institution may decide which customer groups can keep using that mechanism. Adults older than 60 were among the groups mentioned as possibly retaining it, depending on each institution’s decision.
How does this intersect with Cybersecurity Framework Law 21.663?
The rollout of NCG 583 comes alongside other requirements in Chile’s cybersecurity regulatory framework, including the minimum controls ANCI put out for public consultation in August 2026. The proposal would make six controls mandatory for entities regulated by Framework Law 21.663, periodic updates, training, backups, device hardening, multifactor authentication, and password managers.
At the same time, an analysis of the same law repeated that providers of essential services must notify the National CSIRT within three hours of learning about an incident with significant impact, update the information within 72 hours, and deliver a final report within 15 days. For vital operators, the rule also requires ongoing security management, continuity plans, periodic exercises, training, and the appointment of a cybersecurity delegate.
What controls and deadlines are on the table?
ANCI’s public consultation set out six minimum mandatory controls for entities regulated by Law 21.663. The list includes periodic updates, training, backups, device hardening, multifactor authentication, and the use of password managers.
A technical report cited in the material added that meeting those controls faces cost and staffing challenges. That sits within a regulatory environment that now combines changes in banking authentication, incident reporting obligations, and new operational requirements for essential services and vital operators.
Sources
- Adiós a la tarjeta de coordenadas: entra en vigor el cambio para las operaciones bancariaschile.as.com· Diario AS ChileUnverified URL
- Nexa Cyber Café llega a Chile con foco en los nuevos riesgos de la inteligencia artificialitsitio.com· ITSitio Chile
- Ciberdefensa con IA: alerta de Sam Altmananda.cl· ANDA Chile
- Costos y escaso personal entre los desafíos para cumplir controles básicos de ANCIblog.nivel4.com· NIVEL4 Labs
- Guía Ley 21.663: ciberseguridad y Operadores de importancia vitalvestigiachile.com· Vestigia



