Brazil has established itself as Latin America’s most significant regulated market for virtual assets, and obtaining VASP authorisation in Brazil is now a concrete, operationalised process. This page is designed for founders, compliance officers, in-house counsel and foreign crypto platforms that need to understand step by step how to secure authorisation from the Banco Central do Brasil (BCB) to operate as a prestadora de serviços de ativos virtuais (virtual asset service provider). The statutory foundation is Law No. 14,478 of 21 December 2022, which assigned the Central Bank primary rule-making and supervisory authority over VASPs. The BCB translated that mandate into actionable guidance through a suite of normative instructions most critically Instrução Normativa BCB No. 704, published on 29 January 2026, with follow-up amendments through May 2026. The market now has a defined pathway: specific documents, phases, transitional deadlines and reporting obligations. This guide walks you through every stage, from preliminary corporate decisions to post-authorisation compliance, with precise regulatory citations and realistic timelines.
Law No. 14,478/2022 created Brazil’s virtual asset framework (marco legal dos criptoativos). The statute defines a virtual asset as a digital representation of value that can be traded or transferred electronically, expressly excluding assets already regulated under capital-markets or payments legislation. It captures a broad set of services: intermediation or exchange of virtual assets, custody and administration, transfer services, and any other activities defined by future regulation. The law also updated Brazil’s Penal Code to criminalise fraud involving virtual assets and established a duty for VASPs to comply with anti-money-laundering and counter-terrorism-financing norms (PLD/FT). Importantly, Law 14,478 delegated to the executive branch the power to designate a supervisory authority a designation that fell to the BCB via presidential decree.
The BCB supervises VASPs through the same institutional architecture it uses for banks and payment institutions, adapted for the crypto sector. The principal corporate form for a pure-play crypto platform is the sociedade prestadora de serviços de ativos virtuais (SPSAV), a category created by Resolução BCB No. 520. Other BCB-authorised institutions such as banks, fintechs and payment institutions may also provide virtual-asset services, but they do so under their existing licences with additional conditions. For new market entrants or crypto-native platforms, the SPSAV authorisation is the relevant pathway. IN BCB No. 704 operationalises this by prescribing the exact documents, filing channels and review phases for an SPSAV application. The BCB has continued to refine these rules, most recently through IN BCB No. 739 (29 May 2026), signalling an evolving but increasingly settled regulatory environment.
The BCB application process can be understood in sequential phases: preliminary readiness, documentation assembly, filing and protocol submission, technical review, possible phased authorisation, and post-authorisation set-up. Below are the eight steps a platform should follow, mapped to the requirements of IN BCB No. 704 and related normative instruments. Items marked with an asterisk (*) are typical supporting materials frequently requested during review; all other items are expressly required by the BCB.
Before engaging with the BCB, applicants must make foundational decisions. The entity type must be an SPSAV (or an already-authorised institution seeking to add virtual-asset services). Applicants should pass a board resolution authorising the application, define a corporate purpose that explicitly references virtual-asset service provision in accordance with Law 14,478, and establish a local presence in Brazil including a physical registered office and at least one locally resident statutory representative. Foreign groups must determine whether to incorporate a Brazilian subsidiary (sociedade limitada or S.A.) or register a branch, keeping in mind that the BCB typically expects a fully capitalised local entity with segregated governance.
The BCB expects applicants to present a mature governance and compliance framework at the time of filing. This includes a comprehensive AML/PLD programme aligned with Law 14,478’s requirements and the BCB’s broader PLD/FT norms covering customer due diligence, enhanced due diligence for high-risk clients, suspicious-transaction identification and reporting to COAF (Brazil’s financial-intelligence unit). Applicants must appoint a dedicated compliance officer (diretor responsável pela PLD/FT), establish an internal-controls function, and document audit arrangements (internal and external). The governance section should also describe the board composition, committee structures, risk-management policies, and the escalation process for regulatory notifications. Anti-money-laundering compliance is a central pillar of the BCB’s assessment; platforms without a robust PLD programme at filing are almost certain to face objections.
Applicants must submit detailed technical documentation describing their system architecture, custody model, wallet infrastructure (cold/hot wallet controls, key-management protocols), and cybersecurity framework. The BCB expects third-party risk assessments for any outsourced technology component, penetration-test reports conducted by an independent firm, business-continuity and disaster-recovery plans, and an incident-response procedure. The custody model must demonstrate clear segregation between client assets and proprietary assets, with documented reconciliation processes. Platforms using multi-signature wallets, hardware security modules (HSMs) or institutional custody providers should describe these arrangements in detail, including contractual and operational safeguards.
The application must include audited financial statements prepared in accordance with Brazilian accounting standards (NBC TG), proof of initial capital or funding adequate for the proposed scale of operations, a detailed ownership structure (including ultimate beneficial owners), and consolidated group information where the applicant belongs to a conglomerate. The BCB’s accounting and reporting layouts CADOC documents 5710 and 5711 define the chart of accounts and data format that authorised VASPs must adopt. Applicants should begin mapping their financial data to these layouts early, as misalignment is a common source of delay. While the BCB has not published a single fixed minimum-capital figure applicable to all SPSAVs, Resolução BCB No. 520 provides the framework for capital adequacy and prudential requirements.
Filing is conducted through the BCB’s established channels. IN BCB No. 704 (29 January 2026) specifies the protocol rules: applications are submitted via the Deorf/Unicad system, with supporting documentation digitally signed using ICP-Brasil certificates. The application package must be assembled in the sequence prescribed by the normative instruction, accompanied by a cover letter identifying the applicant, the requested authorisation type (SPSAV), and a summary of the services to be provided. Certain declarations including fitness-and-propriety attestations for directors and controlling shareholders must follow specific BCB templates. Applicants should confirm that all digital signatures are current and that the complete package has been uploaded before requesting protocol; incomplete submissions will be returned without review.
The BCB requires independent technical certification of certain operational elements. IN BCB No. 701 and related instructions set the expectations for technical attestation: an independent certifier must validate the platform’s information-security controls, custody architecture and operational resilience. The certifier’s report should address compliance with the BCB’s cybersecurity requirements (aligned with Resolução BCB No. 520 and supplementary guidance), confirm that penetration tests have been performed, and attest that the platform’s infrastructure meets minimum operational standards. Engaging a qualified certifier early ideally during the readiness phase can materially accelerate the review timeline.
The BCB may grant authorisation on a phased or probationary basis, particularly where the platform has not yet completed production-environment testing at the time of the decision. IN BCB No. 713 addresses conditions that may attach to an authorisation, including volume limits, restricted product offerings, or enhanced reporting requirements during an initial operating period. The platform must demonstrate readiness to meet all post-authorisation obligations before proceeding to full go-live. During the phased period, the BCB may conduct remote or on-site inspections to verify compliance with the authorisation conditions.
Upon authorisation, the VASP must register its systems in Sisbacen (the BCB’s information system) and begin data remittance according to the cadence prescribed by IN BCB No. 693 (effective 2 February 2026). This includes periodic submission of CADOC 5710/5711 reports, transaction-monitoring data, and foreign-exchange operations reports where applicable. The platform must also implement ongoing AML/KYC transaction monitoring, maintain a change-notification register (informing the BCB of material changes to directors, ownership, technology or corporate purpose), and prepare for the annual submission of audited financial statements. Establishing these workflows before go-live is critical to avoiding enforcement action in the first reporting cycle.
Download the VASP Application Checklist (PDF) a comprehensive, itemised document list mapped to IN BCB No. 704 and all supporting normative instructions.
For platforms evaluating where to establish their regional hub, the following high-level comparison provides a starting point. The table focuses on structural features; detailed procedural analysis for Mexico and Argentina is beyond the scope of this page.
| Feature | Brazil (BCB) | Mexico | Argentina |
|---|---|---|---|
| Primary legislation | Law No. 14,478/2022 | Ley Fintech (2018) | No dedicated crypto licensing statute (CNV resolutions apply to certain tokens) |
| Regulator | Banco Central do Brasil (BCB) | CNBV / Banxico | CNV (securities tokens); BCRA (payment-related) |
| Required local entity | SPSAV or existing BCB-authorised institution | Mexican-incorporated ITF | Argentine-registered entity (for registered providers) |
| Indicative authorisation timeline | GLE estimate: 6–12 months from filing (subject to completeness) | 12–18 months (industry estimate) | No formal licensing pathway for most crypto activities |
| Transitional rules / counterparty restrictions | Banks prohibited from transacting with unauthorised VASPs from 30 Oct 2026 (Res. BCB 520) | Grandfathering provisions applied to existing fintechs | No formal transition mechanism |
Applicants must operate through a Brazilian legal entity typically a sociedade limitada (Ltda.) or sociedade anônima (S.A.) with a corporate purpose explicitly covering virtual-asset services as defined by Law 14,478. The beneficial-ownership structure must be transparent to the BCB, including identification of all individuals holding direct or indirect control or significant influence. Foreign controlling shareholders must provide equivalent corporate documentation authenticated and apostilled. The entity must maintain a physical registered office in Brazil with adequate operational infrastructure.
Directors, officers and controlling shareholders are subject to fit-and-proper assessments conducted by the BCB. Applicants must submit detailed CVs, criminal and civil background checks (including international clearance for foreign nationals), financial-integrity declarations, and evidence of relevant professional experience. The BCB may interview proposed directors as part of its review. Governance arrangements must include clearly defined roles, documented decision-making processes, and an effective internal-audit function.
Audited financial statements prepared and signed by an independent auditor registered with the CVM are mandatory. The BCB assesses whether the applicant’s capital is adequate for its proposed operations, taking into account the nature, volume and complexity of the virtual-asset services offered. Resolução BCB No. 520 establishes the prudential framework, and applicants should be prepared to demonstrate ongoing capital adequacy, not merely point-in-time funding at application.
Law 14,478 subjects VASPs to Brazil’s AML architecture, requiring implementation of customer identification and verification (KYC), ongoing monitoring, record-keeping for a minimum of five years, and reporting of suspicious transactions to COAF. The BCB’s PLD/FT norms apply in full, including enhanced due diligence for politically exposed persons (PEPs), cross-border transactions, and correspondent relationships. Failure to present a compliant PLD programme at the time of filing is one of the most common grounds for application objection.
Foreign crypto platforms that serve Brazilian customers or interact with Brazilian financial institutions face a clear regulatory deadline. Resolução BCB No. 520 establishes that, from 30 October 2026, banks, payment institutions and other BCB-supervised entities are prohibited from maintaining transactional relationships with VASPs that have not been authorised or are not in the process of being authorised by the BCB. In practice, this means that foreign platforms must either obtain SPSAV authorisation, partner with an authorised Brazilian entity, or file a notice of interest and demonstrate progress toward authorisation before the cut-off date. Practical steps for foreign platforms include appointing a local legal representative, initiating corporate formation in Brazil, conducting a gap analysis against BCB requirements, and filing a preliminary engagement with the Deorf to document the platform’s intent to apply. Industry observers expect the BCB to treat platforms that have filed a complete application before the deadline more favourably than those that have not engaged at all.
The BCB has not published a single fixed statutory clock for the complete VASP authorisation process under IN BCB No. 704. However, the normative instructions do prescribe specific phases completeness review, substantive analysis and decision and set deadlines for applicants to respond to information requests (typically 30 to 60 days, after which an incomplete file may be archived). Based on the structure of these phases and market experience with analogous BCB authorisation processes (e.g., payment institutions), GLE estimates the following indicative timelines:
The most common factors that delay applications include incomplete AML/PLD programmes, missing or outdated audited financial statements, insufficiently detailed custody-model documentation, absence of third-party technical certification reports, and slow responses to BCB information requests. Applicants can materially shorten the process by conducting a pre-filing readiness audit, engaging technical certifiers before submission, and assembling all documentation in the format and sequence prescribed by IN BCB No. 704.
Authorisation is not the end of the regulatory journey it is the beginning of ongoing supervisory engagement with the BCB. Authorised VASPs must comply with a structured reporting cadence, submitting CADOC 5710 and 5711 reports (accounting and operational data) at intervals prescribed by IN BCB No. 693. Registration in the Sisbacen system is mandatory, and the VASP must maintain current data in Unicad regarding its directors, shareholders, corporate structure and authorised services. The BCB conducts both remote monitoring (based on submitted data) and on-site inspections. Material changes to ownership, directors, technology infrastructure, custody arrangements or corporate purpose must be notified to the BCB in advance or within prescribed deadlines. Annual audited financial statements must be filed. VASPs engaging in foreign-exchange-related operations face additional reporting requirements. Incident-reporting obligations require the platform to notify the BCB promptly of cybersecurity events, data breaches or significant operational disruptions. Custody and asset-segregation rules mandate that client virtual assets be held separately from proprietary assets at all times, with documented reconciliation procedures.
BCB reviews are thorough, and applications are frequently returned or objected to on specific grounds. The most common reasons for rejection or delay include:
The window for securing VASP authorisation in Brazil before the critical 30 October 2026 counterparty deadline is narrowing. Platforms should take immediate action:
Obtaining VASP authorisation in Brazil requires careful planning, rigorous documentation and expert guidance on the BCB’s evolving normative framework. Platforms that begin early and file complete, well-structured applications will be best positioned to operate in Latin America’s largest digital-asset market.
posted 16 minutes ago
posted 40 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message