Brazil’s Central Bank is putting virtual asset providers under a broader compliance framework that goes beyond proof of reserves. Under rules tied to Law 14.478/2022, Decree 11.563/2023 and BCB Resolutions 519, 520 and 521, firms will have to show not only that assets exist, but also that key controls around custody, compliance and cybersecurity are working in practice.
For existing operators, the main deadline is October 30, 2026. By that date, they must submit a reasonable assurance report prepared by an auditor registered with Brazil’s securities regulator, the CVM. The Central Bank’s framework takes effect from February 2, 2026.
Proof of reserves will not be enough on its own
The new regime reflects a view that proof of reserves is only one part of customer protection. A reserve report can indicate that a platform held certain assets at a given moment, but it does not by itself address operational, legal or security weaknesses that could still put users at risk.
Brazil’s requirements therefore combine proof of reserves with checks on anti-money laundering and counter-terrorist financing controls, sanctions screening, asset segregation and cybersecurity measures. The aim is to require evidence that these safeguards are effective, rather than relying on policy statements alone.
What crypto providers must do under the new rules
Existing virtual asset service providers, also referred to as PSAVs, must file a reasonable assurance report from a CVM-registered auditor by October 30, 2026. New entrants will need prior approval to operate under the framework.
The rules also impose minimum capital requirements that range from about R$10.8 million to R$37.2 million, or roughly $2.1 million to $7.3 million, depending on the services offered. Providers must keep client wallets separate, provide proof of reserves, carry out regular penetration testing and retain evidence of incidents for five years.
The source article says the standards resemble MiCA-style requirements, with one notable difference: the required proof is to be presented at the time of filing, rather than after authorization.
Safer than before, but not risk free
The framework is presented as a material improvement on Brazil’s earlier, lightly supervised crypto environment. Separating customer assets from a firm’s own balance sheet can reduce the chance that client holdings are caught up in proprietary losses or a bankruptcy process. Independent audits and reserve reporting also add periodic outside verification.
At the same time, the rules do not eliminate crypto risk. Proof of reserves and audits are still point-in-time exercises, not continuous guarantees. The source article notes that cyberattacks, zero-day exploits, insider threats and supply-chain compromises may still succeed despite stricter controls.
Other risks also remain, including operational breakdowns, third-party failures, smart-contract issues, and market, liquidity and counterparty exposure. Authorization under the Brazilian system does not amount to a government guarantee of solvency or performance.
What changes after February 2026
From February 2, 2026, Brazil’s regime is set to raise the compliance baseline for exchanges and custodians serving the market. In addition to reserve disclosures, firms will be expected to maintain governance, monitoring and technical safeguards that can be independently checked.
The next confirmed step for existing operators is the October 30, 2026 filing deadline. By then, they must be able to document working controls for AML and sanctions compliance, custody segregation and cybersecurity, supported by an auditor’s reasonable assurance report. The overall shift, as described in the source article, is from promises about safety toward documented evidence.
Source: Coin Edition