CiberLATAMbywhalemate

Mexico’s CNBV loosens SMS authentication rules

CNBV now allows SMS, email and encrypted messaging for security codes in certain digital financial services. The rule took effect Sept. 2.

Whalemate Labs · AI-assisted researchPublished:3 min read

Mexico’s CNBV put a regulatory change into force on Sept. 2, 2026, allowing security codes sent by SMS as a category 3 authentication factor for certain digital financial services run by technology-based brokers. The same resolution also authorizes email and encrypted instant messaging for security code delivery.

Mexico’s National Banking and Securities Commission, or CNBV, put a regulatory change into force on Sept. 2, 2026, allowing security codes sent by SMS as a category 3 authentication factor for certain digital financial services operated by technology-based brokers. The resolution, published in the Federal Official Gazette on Sept. 1, also authorizes email and encrypted instant messaging for sending security codes.

What changed in banking authentication?

The CNBV’s new wording relaxes how security codes can be delivered for transactions carried out by technology-based brokers. It now accepts SMS, email and encrypted instant messaging as valid channels. The change applies to a category 3 authentication scheme and took effect the day after its official publication.

A cybersecurity intelligence analysis read the move as a bet on a technology with known vulnerability risks. That assessment says that if SMS is used as an authentication factor, institutions need to offset it with stronger controls in fraud monitoring, mobile channel protection and identity management.

What do banks and brokers have to do?

The new rules require customers to be able to change their category 2 authentication factor and also the contact method used to receive the category 3 factor, including SMS, through an explicit option on the broker’s website or app. That flow must redirect to the bank’s technology infrastructure.

The provision is meant to give users control over those settings from the broker’s interface, without moving authentication logic outside the bank’s technology environment. In practice, CNBV is keeping the scheme under banking supervision while opening the door to channels that had already been questioned for their exposure to mobile-channel attacks.

How does this intersect with other oversight rules?

The authentication relaxation comes as CNBV and Banxico push other rules for payments, interoperability and anti-money laundering, with requirements that raise the compliance burden for banks and fintechs. At the same time, KYC consultancies are reminding financial institutions that they must identify and verify customer identity before and throughout the business relationship.

That regulatory framework also includes joint proposals on payment rails, with rules for payment aggregators, card payment participants and electronic payment fund institutions. Among the obligations mentioned are same-day merchant settlement, segregated accounts for merchant funds and bans on withholding funds on the condition that other services be contracted.

What signals does the sanctions front send?

CNBV has been taking an active stance on sanctions. On Sept. 9, 2026, it was reported that the agency imposed 26 fines on Banco Base and Banco Mifel for anti-money laundering lapses, with penalties totaling more than 18 million pesos.

The same day, Mexico’s Finance Ministry said there was no conclusive evidence of illicit activity by Vector Casa de Bolsa, CIBanco and Intercam, and that the CNBV’s historical fines of more than 185 million pesos issued between June 25 and June 30, 2026, stemmed from administrative failures, not proven links to money laundering. The Supreme Court also confirmed on Sept. 11 the validity of a fine of about 2 million pesos against Financiera Independencia, upholding a 2024 regulatory penalty.

Sources

View all