CiberLATAMbywhalemate

Mexico CNBV allows SMS bank authentication

CNBV’s rule change takes effect Sept. 2, 2026 and allows SMS as an authentication factor for banks in Mexico.

Whalemate Labs · AI-assisted researchPublished:3 min read

CNBV has amended the rules on electronic banking operations and set Sept. 2, 2026, as the effective date for a change that allows SMS as an authentication factor for certain banking transactions. The move comes amid Banxico warnings about fraud using its image, new bank alerts, and tighter KYC and cybersecurity demands on the financial sector.

CNBV has amended Articles 319 Bis 2, 319 Bis 3, and 319 Bis 5 of the rules applicable to credit institutions on electronic operations, and set a single transitional provision that puts the new rules on the sending of authentication factors and SMS use into force on Sept. 2, 2026. The change applies to banking in Mexico and requires adjustments to digital transaction verification schemes.

What changes with the CNBV reform?

The resolution authorizes the sending of security codes by SMS to authenticate certain banking transactions, according to CNBV and Expansión’s coverage, while preserving stronger schemes for higher-risk operations. Revista Flow added that the goal is to make digital banking easier to use without loosening controls where risk is higher.

That regulatory shift was also summarized by Zero Trust Consulting as an expansion of the banking authentication channel, with effects on user experience and on the risk models of institutions that rely on mobile apps and remote agents. The CNBV notice in the Diario Oficial de la Federación also sets the exact implementation date, Sept. 2, 2026.

What other obligations do financial institutions face?

Institutions must not only adapt their authentication factors, they also face ongoing customer identification and verification requirements under the LFPIORPI, according to Truora, which describes a KYC standard that applies before, during, and not only at the start of the customer relationship.

At the same time, companies focused on financial services say that complying with CNBV cybersecurity and data protection frameworks requires immutable evidence of information protection and operational continuity, in line with technical controls such as ISO 27001, according to E-dea. Scram2k’s case involving a Mexican financial group illustrates that regulatory pressure: after a CNBV audit found 47 critical vulnerabilities left unremediated, the entity implemented a 24/7 SOC, added a Fortinet-based vulnerability management platform, and fixed the issues in 90 days, while also automating regulatory reports.

How did the financial system react to fraud risk?

Banco de México said on Sept. 5, 2026 that it never asks for personal or financial information by phone calls, text messages, email, or social media, and reiterated prevention measures against fraud attempts that use its image. Expansión later reported that Banamex also reminded customers that it will not ask them to install apps through links sent by SMS or suspicious emails.

Those warnings sit alongside the authentication reform and a broader financial digitization agenda. Ámbito said the Digital CURP is emerging as a trust mechanism for remotely proving identity and that CNBV, together with the Finance Ministry and Banco de México, would have specific roles in regulating and operating payments and financial services within that framework. Pagoralia also said that N2 Bis accounts will be able to receive monthly deposits of up to 15,000 UDIS, with a maximum of 3,000 UDIS in cash, pushing the rest of the funds toward CNBV-supervised digital channels.

Sources

View all