Cybersecurity 2026

MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel

Mexico does not have a standalone operational resil - ience regulation. Nevertheless, financial institutions such as banks, fintechs, insurance companies and other market participants are required to comply with a combination of laws, regulations and supervisory guidelines aimed at ensuring business continuity, cybersecurity and risk management. These regulatory norms and provisions include: • the General Provisions Applicable to Credit Institu - tions ( Disposiciones de Carácter General Aplicables a las Instituciones de Crédito ) issued by CNBV; • CNBV Guidelines on Cybersecurity and Information Security; • the Fintech Law ( Ley para Regular las Instituciones de Tecnología Financiera ); • the Payment Systems Law ( Ley de Sistemas de Pagos ); • Circular 8/2019 directed to participants of the Interbank Electronic Payments System issued by Banxico; • Principles to reinforce information security within the financial system ( Principios para reforzar la seguridad de la información en el sistema financi - ero ) issued by Banxico; • Coordinating Bases for Information Security ( Bases de Coordinación en Materia de Seguridad de la Información ) established by the Ministry of Finance (SHCP), Banxico, CNBV, CONDUSEF and other governmental agencies and market participants; and • the 2024–2027 Cybersecurity Strategy of Banx - ico ( Estrategia de Ciberseguridad del Banco de México 2024-2027). Additionally, Mexico is an active participant in several international treaties, agreements, and frameworks that focus on cybersecurity, financial sector resilience and digital crime prevention. Mexico has not formally ratified the Budapest Convention on Cybercrime, but it has aligned its financial cybersecurity regulations with international standards through frameworks such as the Financial Action Task Force (FATF or GAFI in Spanish) (of which it is a member), Basel III guidelines on operational risk and cyber resilience and G20 initia - tives. Furthermore, regional and bilateral cooperation, particularly with the United States, the Organisation of

American States and the Pacific Alliance, enhances its financial sector’s operational and cyber-resilience. 3.2 ICT Service Provider Contractual Requirements ICT service providers in Mexico are obligated to meet specific contractual and regulatory requirements when working with financial institutions. Such requirements focus on cybersecurity, data protection, operational resilience, third-party risk management and the ability to afford regulatory supervision. Please note that the authority and functions of these two last agencies are in the process of being transferred to other agencies within the Federal Government as a result of recent constitutional reforms. ICT service providers working with financial institu - tions must adhere to outsourcing and cybersecuri - ty regulations issued by CNBV and Banxico, which include cybersecurity requirements for ICT providers handling: • banking systems; • data encryption; • access controls and authentication measures; • service level agreements; • audit rights; and • incident response obligations. • Such providers must also comply with Banxico’s cybersecurity and operational resilience standards and grant Banxico regulatory oversight and audit access. Under Mexico’s Data Protection Law, ICT contracts must establish data protection obligations, and pro - viders must implement technical and organisational security measures. If an ICT provider processes per - sonal data on behalf of a financial institution, the con - tract must specify processing purposes and permitted activities, data retention policies and obligations to notify data breaches. Mexico is expected to introduce enhanced outsourc - ing regulations for ICT providers, similar to those set forth in the EU’s Digital Operational Resilience Act (DORA).

251 CHAMBERS.COM

Powered by