| Field | Detail |
|---|---|
| Jurisdiction | Federative Republic of Brazil |
| Regulation | Resolução No. 4.658 (April 26, 2018) |
| Enacted | April 26, 2018 |
| Effective | May 6, 2019 (phased implementation) |
| Regulator | Banco Central do Brasil (BCB / BACEN) |
| Status | Superseded by Resolução BCB No. 4.893 (February 26, 2021) |
| Official Text | bcb.gov.br |
Resolution 4.658/2018 (Resolução No. 4.658) was the Banco Central do Brasil's first comprehensive cybersecurity regulation for financial institutions. Enacted in April 2018 and phased in through May 2019, it established the foundational framework for cybersecurity policy and cloud computing governance in Brazil's financial sector — a framework that Resolution 4.893/2021 later strengthened and expanded.
Understanding 4.658 remains relevant because:
- Legacy contracts signed between 2018 and mid-2021 often reference it
- Audit findings from that period cite its article numbers
- Transition assessments compare old vs. new requirements
- Some smaller credit unions (cooperativas) and payment institutions are still completing gap remediation from 4.658 to 4.893
The regulation required all BCB-supervised institutions to adopt a formal, Board-approved cybersecurity policy addressing:
- Objectives and scope of the cybersecurity program
- Information security procedures and controls
- Roles and responsibilities
- Incident response procedures
- Employee training and awareness
- Annual reporting to senior management
This was the first time BCB mandated board-level ownership of cybersecurity for all institution types — not just systemically important banks.
Resolution 4.658 introduced Brazil's first regulatory framework specifically governing cloud computing use in financial services:
| Principle | Detail |
|---|---|
| Cloud is permitted | Institutions could use third-party cloud infrastructure for data processing and storage |
| Risk equivalence | Controls applied to cloud-hosted data must be equivalent to on-premises controls |
| BCB audit rights | Cloud providers must contractually grant BCB inspection rights over data and systems |
| Data location | Data could be stored abroad if BCB access rights were preserved |
| Due diligence | Institutions required to assess cloud providers before engagement |
This framework was groundbreaking for the region — it gave regulated institutions a clear path to cloud adoption while establishing the audit-rights principle that 4.893 later reinforced.
4.658 established that institutions must assess and manage risk from material service providers (prestadores de serviços relevantes), including:
- Data processing companies
- Core banking system vendors
- Cloud infrastructure providers
- IT outsourcing firms with privileged access
Contracts with these providers were required to include security standards, incident notification obligations, and audit rights.
| Weakness in 4.658 | How 4.893 Addressed It |
|---|---|
| No specific incident notification deadline | 72-hour hard deadline to BCB |
| Cloud rules were principles-based | Specific controls, exit plans, concentration risk |
| Third-party risk was high-level | Detailed due diligence, subcontractor visibility |
| No structured board reporting template | More prescriptive annual report content |
| Concentration risk not explicitly addressed | Explicit single-provider dependency assessment |
Vendor contracts and outsourcing agreements executed between 2018 and mid-2021 often contain clauses like:
"The parties agree to comply with the requirements of Banco Central Resolution 4.658/2018 and any successor regulations."
These contracts are typically valid until renegotiated or renewed. During audits, examiners may review whether the institution's arrangements with vendors effectively meet 4.893, even if the contract text references 4.658. The key question is whether substantive compliance (72h notification, audit rights, exit plans) has been achieved — not whether the contract number has been updated.
Any security audits, penetration test reports, or board presentations prepared under 4.658 form part of the institution's ongoing compliance history. BACEN examiners reviewing the transition to 4.893 will look at this history as evidence of the institution's cybersecurity maturity trajectory.
| Date | Event |
|---|---|
| April 26, 2018 | Resolution 4.658 enacted |
| May 6, 2019 | Full implementation deadline for all institutions |
| February 26, 2021 | Resolution 4.893 enacted, superseding 4.658 |
| July 1, 2021 | Resolution 4.893 effective date |
Institutions had a 5-month window (February–June 2021) to assess gaps between their 4.658-compliant programs and the new 4.893 requirements.
- 4.658 is superseded — no institution should cite it as their current compliance baseline; 4.893 is the operative standard
- Legacy contract language is common — when reviewing vendor agreements, look for substantive compliance with 4.893 requirements even if the contract cites 4.658
- The cloud permissions it established remain in 4.893 — BCB has consistently supported cloud adoption, with audit rights as the key condition
- Security products sold under 4.658-era contracts may need formal re-assessment under 4.893's more stringent third-party risk requirements
- Audit history matters — your 4.658-era documentation (board reports, pen test results) is still relevant evidence of your cybersecurity program maturity