Geography
LGPD vs Bacen: mandate and diligence
What the LGPD actually requires and what Bacen requires of licensed institutions. Pentest is not named in the statute; the annual intrusion test is, in CMN Resolution 5.274/2025.
There are two distinct conversations and the market conflates them. One is the LGPD: personal-data protection for whoever processes data in Brazil. The other is Bacen: a cybersecurity policy for institutions within the scope of CMN 4,893/2021. A pentest is not the same thing in both.
Straight answers
Does the LGPD name pentesting?
- No. Law 13.709/2018, compiled text at planalto.gov.br, accessed 2026-09-17: pentest, penetration testing and intrusion testing do not appear. Chapter VII (arts. 46–50) covers security measures, incidents and good practice — not a named offensive test.
What changed with CMN Resolution 5.274/2025?
- It inserted art. 22-A into CMN Resolution 4.893/2021: intrusion tests in art. 3 §8(IV) must be at least annual; performed with independence and impartiality by a contracted natural person or specialised firm, without prejudice to in-house tests; and have results, vulnerabilities and remediation plans documented. Text in the BCB normative viewer, accessed 2026-09-17. Adaptation deadline stated by the BCB: 1 March 2026.
Did 4.893/2021 already require an annual independent pentest?
- No. The original 4.893 text (26 Feb 2021) required, among minimum controls, periodic tests and scans to detect vulnerabilities. It did not set an annual cadence or third-party independence for intrusion tests. That arrives with 5.274/2025.
Time to test your doors?
Tell us what needs validating. We answer with proposed scope, not a brochure.