CiberLATAMbywhalemate

Chile CMF sets new cybersecurity rules

The CMF consolidates duties for banks and payment issuers on operational risk, strong authentication and incident reporting.

Whalemate Labs · AI-assisted researchPublished:3 min read

Chile’s Financial Market Commission has consolidated a framework that requires regulated financial firms to strengthen governance, controls and incident reporting. NCG 454, NCG 538 and Cybersecurity Framework Law 21,663 now operate in parallel, with requirements on operational risk, strong authentication and timely notice to the CMF and the ANCI.

Chile’s Financial Market Commission has consolidated a framework that requires regulated financial firms to strengthen governance, controls and incident reporting. NCG 454 sets duties for operational, technological and cyber risk, while NCG 538 requires dual authentication for digital transfers. The Cybersecurity Framework Law 21,663 adds cross-cutting obligations for banks, financial services and payment issuers.

What does CMF rule NCG 454 require?

NCG 454 requires boards to take responsibility for risk governance and for identifying, measuring, controlling and monitoring operational, technological and cyber risks, including third-party exposure. It also requires continuity and recovery plans with periodic testing, a cybersecurity program with preventive, detective and response controls, and timely reporting to the CMF of incidents that affect stability, customers or market integrity.

The rule works alongside sector-specific standards such as the banking rule RAN 20-10 and must be read together with Cybersecurity Framework Law No. 21,663, not as a replacement for it. According to Anguita & Osorio, the CMF has built a rulebook in which sector rules operate as complements to the framework law.

How does it connect with Law 21,663?

Cybersecurity Framework Law 21,663 adds a cross-cutting layer of obligations for essential services and vital operators in the financial sector. These include implementing an information security management system, naming a cybersecurity officer, maintaining continuity and incident response plans, carrying out periodic audits and reporting compliance to the ANCI.

The regulatory rollout also includes Supreme Decree No. 295/2024 on incident reporting and General Instruction No. 1. That instruction requires essential financial-sector services, including banking, financial services and payment issuers, to register on the ANCI platform and appoint a Reportability Officer to coordinate notification to the National CSIRT within windows as short as three hours for critical incidents.

What changes for transfer authentication?

NCG 538 imposes dual authentication for digital transfers, using two independent verification methods from different categories. The CMF also clarified in its rulings that Enhanced Customer Authentication, covered by that rule, applies to all payment issuers, not just banks.

That ARC requirement is mandatory for adding and changing personal data, changing authentication passwords and managing trusted devices. Diario Financiero linked that requirement to the economic impact of payment fraud and noted that since 2023 at least one Chilean institution has paid nearly US$400 million in reimbursements and liabilities tied to the Fraud Law.

What other recent changes are pressuring the sector?

Supreme Decree No. 498, published on March 10, 2026 in Chile’s Official Gazette, says its provisions will take effect six months after publication. That creates an implementation deadline for security and incident management obligations relevant to covered entities.

In parallel, the ABIF and Microsoft signed a cooperation agreement in September 2026 to strengthen cybersecurity in Chile’s financial sector and address digital threats affecting institutions and customers, in line with CMF regulatory requirements. At the same time, a legal analysis of the future regulation on infringement prevention models in data protection anticipates specific reports to the Data Protection Agency and, when applicable, to data subjects, along with self-reporting and internal sanctions, a framework that could overlap with obligations for financial entities handling large volumes of sensitive data.

Sources

View all