Geography
Penetration testing in Brazil
Penetration testing for Brazilian companies: what the market asks, what Bacen requires of licensed institutions, and what the LGPD does not name. Proposed scope, not a brochure.
Brazil does not buy pentesting for fashion: it buys it because someone upstream demanded it — an enterprise client, a post-incident board, or the supervisor if the firm sits under Bacen. The useful question is not “do we need a test?”. It is “is this a mandate or evidence of diligence?”.
Straight answers
Does the LGPD mandate a pentest?
- No. Law 13.709/2018 arts. 6(VII) and (X), and 46 to 50 require technical and administrative security measures and proof they are observed. They do not name pentest, penetration testing or intrusion testing (text accessed 2026-09-17 at planalto.gov.br).
Does Bacen require an annual independent pentest?
- For institutions within the scope of CMN 4,893/2021, yes: CMN Resolution 5.274/2025 (18 Dec 2025) inserted art. 22-A into 4.893/2021. Intrusion tests must be at least annual, independent and impartial, performed by a contracted person or firm, with documented results. It is not a generic duty for every Brazilian company.
Does Rekon operate in Brazil?
- Yes. Rekon runs the pentest with an explicit human gate. In Brazil the cybersecurity partner is Lexart (lexart.tech). We answer with proposed scope, not a brochure.
Time to test your doors?
Tell us what needs validating. We answer with proposed scope, not a brochure.