Chile Tightens Cybersecurity for Payments
Chile raised cybersecurity requirements for the STFM and widened Open Finance security rules under the CMF.
Chile’s Finance Ministry now requires cybersecurity safeguards for the provider of the Market Makers Transaction System, while Open Finance rules keep expanding under the CMF. Together, the measures show how the country is linking data protection, operational continuity and financial oversight in critical infrastructure.
Chile’s Finance Ministry has added cybersecurity requirements for the provider that operates the Market Makers Transaction System, or STFM, as part of the program for sovereign debt in local currency. The document calls for information security certifications, business continuity and disaster recovery plans, incident response procedures that include reporting to the Fiscal Agent and affected Market Makers, and safeguards to segregate and protect quotation and transaction data.
What does the Market Makers program require?
The program document requires the STFM provider to demonstrate concrete controls over security, continuity and incident handling. Those safeguards include certifications such as ISO/IEC 27001 or equivalent standards, along with mechanisms to separate and protect the data generated in quoting and trading.
The requirement is not limited to technical infrastructure. It also includes incident response procedures that require notifying the Fiscal Agent and affected Market Makers, which places those events within a formal reporting chain.
What role does the CMF play in that setup?
The trading system operated for the STFM falls under the supervision of the Financial Market Commission, according to the Finance Ministry document. That reference means the cybersecurity safeguards imposed on the provider sit within a financial regulatory framework.
In practice, the STFM is not treated as a standalone platform. It is part of an architecture subject to regulatory oversight over its operation. The text links technical operations with CMF supervision, a relevant point for any provider that must maintain availability, integrity and information protection in a sovereign debt market.
How is the scope of Open Finance expanding?
Technical guidance on the Open Finance System says CMF General Rule 514 classifies participants into groups, and that Group 2 covers actors beyond traditional banking. That group includes payment card operators, savings and credit cooperatives, insurers, mortgage loan agents, mass credit placement firms, fund managers, securities brokers and registered financial service providers.
According to Ozone API, that classification broadens the reach of the FAPI, OAuth and OpenID security framework to a wider set of financial entities and companies tied to payments and lending. The point matters because it extends technical requirements to participants with different operational profiles and risk levels.
What does this regulatory framework show together?
The combination of the Framework Cybersecurity Law, the new personal data law and CMF technical requirements creates a stricter environment for financial infrastructure and information handling. In the STFM case, the focus is on operational continuity, incidents and data segregation. In Open Finance, the scope widens to multiple categories of participants under more formal authentication and authorization rules.
Sources
- Programa de Formadores de Mercado para la deuda soberana en moneda local – Documento para recepción de comentarioshacienda.cl· Ministerio de Hacienda de Chile
- Ley de Protección de Datos Personales al congelador: gobierno de Kast escucha a gremio de grandes empresarioseldesconcierto.cl· El Desconcierto
- La CMF avanza en la implementación del SFA: sandbox 'Atena' estará disponible en octubrechocale.cl· Chócale
- Privacidad diferencial: Ley N° 21.719rvsolucioneslegales.cl· R&V Soluciones Legales
- Ley 21.719 en Chile: checklist de 90 días para SaaS LATAM antes del 1 de diciembre 2026carlos.lat· Carlos.lat
- Ley 21.719 y Ley 21.663: dos deberes distintos ante un mismo incidentealayiatrust.com· Alayiá Trust
- Dictámenes de la Comisión para el Mercado Financiero sobre Ley Marco de Ciberseguridad N°21.663cmfchile.cl· CMF Chile
- Ley de Protección de Datos: el desafío que las pymes no pueden seguir postergandodiarioestrategia.cl· Diario Estrategia
- Chile's Open Finance System: Your Guide to Get Startedozoneapi.com· Ozone API
- ¿Está preparado Chile para los ciberataques potenciados por IA?computerweekly.com· ComputerWeekly en español
- La difícil implementación de la ley de protección de datos personalesmsn.com· MSN / La Tercera
- Chile se prepara para nuevas exigencias en protección de datos que rigen desde diciembrepautacomunal.cl· Pauta Comunal



