CiberLATAMbywhalemate

Chile Tightens Cybersecurity for Payments

Chile raised cybersecurity requirements for the STFM and widened Open Finance security rules under the CMF.

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile’s Finance Ministry now requires cybersecurity safeguards for the provider of the Market Makers Transaction System, while Open Finance rules keep expanding under the CMF. Together, the measures show how the country is linking data protection, operational continuity and financial oversight in critical infrastructure.

Chile’s Finance Ministry has added cybersecurity requirements for the provider that operates the Market Makers Transaction System, or STFM, as part of the program for sovereign debt in local currency. The document calls for information security certifications, business continuity and disaster recovery plans, incident response procedures that include reporting to the Fiscal Agent and affected Market Makers, and safeguards to segregate and protect quotation and transaction data.

What does the Market Makers program require?

The program document requires the STFM provider to demonstrate concrete controls over security, continuity and incident handling. Those safeguards include certifications such as ISO/IEC 27001 or equivalent standards, along with mechanisms to separate and protect the data generated in quoting and trading.

The requirement is not limited to technical infrastructure. It also includes incident response procedures that require notifying the Fiscal Agent and affected Market Makers, which places those events within a formal reporting chain.

What role does the CMF play in that setup?

The trading system operated for the STFM falls under the supervision of the Financial Market Commission, according to the Finance Ministry document. That reference means the cybersecurity safeguards imposed on the provider sit within a financial regulatory framework.

In practice, the STFM is not treated as a standalone platform. It is part of an architecture subject to regulatory oversight over its operation. The text links technical operations with CMF supervision, a relevant point for any provider that must maintain availability, integrity and information protection in a sovereign debt market.

How is the scope of Open Finance expanding?

Technical guidance on the Open Finance System says CMF General Rule 514 classifies participants into groups, and that Group 2 covers actors beyond traditional banking. That group includes payment card operators, savings and credit cooperatives, insurers, mortgage loan agents, mass credit placement firms, fund managers, securities brokers and registered financial service providers.

According to Ozone API, that classification broadens the reach of the FAPI, OAuth and OpenID security framework to a wider set of financial entities and companies tied to payments and lending. The point matters because it extends technical requirements to participants with different operational profiles and risk levels.

What does this regulatory framework show together?

The combination of the Framework Cybersecurity Law, the new personal data law and CMF technical requirements creates a stricter environment for financial infrastructure and information handling. In the STFM case, the focus is on operational continuity, incidents and data segregation. In Open Finance, the scope widens to multiple categories of participants under more formal authentication and authorization rules.

Sources

View all