cyberx_
back to indexCompliance & Regulation4 min read

Virtual Asset Service Providers Have Until October 30 to Apply for Central Bank Authorization

The deadline cannot be extended and applies to firms already in operation. Those that fail to file have 30 days to wind down — and the clock is already running.

Robert F.
In this article

Virtual asset service providers already operating in Brazil have until October 30, 2026 to file an application for authorization with the Banco Central. The deadline runs 270 days from February 2, when the sector's new regulatory framework took effect, and it cannot be extended.

Any provider that fails to file in time is required to cease activities within 30 days of the end of the transition period. Those that file on time may continue operating until the regulator issues its preliminary decision.

What is actually in force

On November 10, 2025, the Banco Central published Resoluções BCB nº 519, 520 and 521, all in force since February 2, 2026. In broad terms:

  • 519 sets out who may provide virtual asset services and how these companies are incorporated and operate.
  • 520 governs the incorporation and operation of service providers, with supervision proportional to the risk of the activity.
  • 521 classifies part of these operations as foreign exchange market activity — including international payments and transfers involving virtual assets, transfers to and from non-custodial wallets, and stablecoin transactions. Since May 4, 2026, reporting these operations to the Banco Central has been mandatory.

The groundwork was laid earlier: Lei nº 14.478/2022 defined virtual assets and virtual asset service providers, and Decreto nº 11.563/2023 gave the Banco Central authority to regulate, authorize and supervise the sector. What was missing was the concrete authorization framework — and that now has a date attached.

What applicants must demonstrate

The compliance window is not simply a matter of filing a form. A provider must demonstrate prior operation, the fitness and propriety of its controlling shareholders, minimum capital, and compliance with rules on risk management, cybersecurity and anti-money laundering. While the application is under review, the regulator may require periodic submission of client registration data and custody information.

There is also a restriction that tends to go unnoticed: during the transition, the company may continue operating, but not expand its operation.

Why this matters if you are not an exchange

The obvious reading concerns those who need to be authorized. The less obvious one — and the more relevant for most of the market — concerns those who do business with a service provider.

As of October 30, there is a clear-cut question that did not exist before: did this counterparty file its application? This is not a matter of opinion or risk perception; it is a verifiable fact, with a date. And any institution that maintains a relationship with a provider that let the deadline lapse will struggle to explain why it never checked something that was public and binary.

It is the pattern that repeats with every new regulation: it does not create obligations only for the regulated entity. For everyone around it, it creates a duty to know.

What to do in the next 80 days

  • If you operate as a service provider: the deadline cannot be extended, and the application requires documentation that cannot be assembled in a week.
  • If you contract with or otherwise deal with service providers: identify them now, and document the check. After October 30, that same query becomes evidence of due diligence — or of its absence.
  • If you are an investor: a provider that fails to file will have to wind down and return assets held in custody. Knowing in advance who is in that position is the difference between redeeming calmly and racing the clock alongside everyone else.

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing and fraud prevention. This content is informational and does not constitute legal advice.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about ongoing cases, matters under judicial secrecy, clients, or operational detail that would compromise an investigation in progress.

Tags

[AML/CFT][Virtual assets][Central Bank][Due diligence]

Share