Authorisation is the beginning: Resolutions 552 and 553 and life after the BCB says yes
The Brazilian virtual asset framework has one date everyone repeats and a structure almost nobody plans past. The date is 30 October 2026. The structure is what happens after it: authorisation by the Banco Central do Brasil is not a certificate you file away, it is entry into a standing supervisory relationship governed by rulebooks written for banks and payment institutions.
Where the deadline actually sits
- The framework came into force on 2 February 2026 — Resolução BCB 519, art. 28. (Instrument text.)
- Providers already operating on that date file Phase 1 by 30 October 2026 — Instrução Normativa BCB 704, art. 9 caput. (Instrument text.) No prorogation has been issued.
- Phase 2 follows within 60 days of a favourable Phase 1 decision, extendable by up to 60 further days at BCB discretion on a justified request — IN BCB 704, art. 10.
- New entrants, and institutions the BCB already supervises, use the single procedure at art. 5 instead of the two-phase route.
Phase 1 ends at item VIII: three financial years of statements audited by an independent auditor registered with the Comissão de Valores Mobiliários. That is a backward-looking document about a company that already exists. Everything below is forward-looking, and it is the part that decides whether an authorised provider stays authorised.
Two resolutions that wire PSAVs into the rest of the rulebook
Resolução BCB 552 and Resolução BCB 553 are the instruments that stop the virtual asset regime being a self-contained annexe. A caution on sourcing: the descriptions in this section are taken from legislative databases and Brazilian law-firm commentary, not from the BCB consolidated text, which I was not able to open at the time of writing. Both are reported as dated 3 March 2026. Treat the resolution numbers below as reporting, and confirm each against the BCB normative database before you build a plan on it.
On that reporting, Resolution 552 brings PSAVs inside a set of existing governance norms, including the ombudsman rules (Res. BCB 28/2020), the compliance policy rules (65/2021), cybersecurity and cloud contracting (85/2021), internal audit (93/2021), customer relationship principles (155/2021), the internal control system rules (260/2022), fraud indicator sharing (343/2023) and administrator remuneration policy (432/2024).
Resolution 553 does the accounting half: it extends COSIF, the BCB accounting plan, to PSAVs, together with the associated rules on recognition and measurement, financial instruments, provisions and contingencies, consolidation and the application of IFRS. Commentary consistently describes it as amending around nineteen resolutions. I have not verified an individual article number inside either instrument and so do not quote one here.
Why this changes the shape of the project
An application file is a document. An ombudsman is a function with a person in it, a phone line and a reporting route. Internal audit is independent by definition, which means it cannot be the same people who wrote the controls. A compliance policy under a BCB norm has a governance structure and a reporting cadence attached to it, not just a PDF.
The accounting side is heavier still. Moving to COSIF is a migration: a regulatory chart of accounts, regulatory reporting submissions, and consolidated statements prepared to a standard your existing bookkeeping probably does not produce. If your finance function currently closes on a commercial accounting package with an annual audit bolted on, the gap between that and a COSIF-based regulatory reporting cycle is measured in quarters, not weeks — and it does not begin on the day the authorisation letter arrives. It begins when you decide to apply.
Two things worth marking as open
- One Brazilian source states an implementation deadline of 30 October 2026 for the fraud indicator sharing obligation. I found that in a single place and could not corroborate it. If fraud data sharing matters to your build, check it against the norm itself rather than against this article.
- The relationship between the phase-in of these prudential and accounting norms and an individual firm’s authorisation date is not something I can state generally. Ask the question specifically for your entity.
The consequence of getting it wrong is not a fine
If authorisation is refused, withdrawn or the file is archived, the institution must evidence within 15 days either corporate dissolution or a change of corporate object to a non-regulated activity with a matching change of name. An institution still operating at that point must cease within 30 days, notify its clients, and transfer their virtual assets and funds to other authorised institutions. Separately, from the cut-off, BCB-supervised institutions are prohibited from facilitating virtual asset operations with unauthorised providers — which is to say the banking rails close before any enforcement action is needed.
That is the reason to read 552 and 553 now rather than after Phase 2. The authorisation is not the deliverable. The operating company that can survive supervision is the deliverable.
The checklist behind this article
The Brazil PSAV Authorisation Readiness Checklist walks the IN BCB 704 route item by item, with every requirement cited to its article and every figure marked as instrument text or as reporting of it — including the ones, like the 552 and 553 detail above, that are still marked open. USD 79, and you get the updated edition free as the position develops.
If your Phase 1 route is clear — you know which category you fall into, you have three years of CVM-audited statements and your capital is paid in cash — the checklist is all you need and you should stop there. If instead you are unsure whether you are an existing provider at all, or whether a group restructuring resets your route, the 48-hour gap check exists for exactly that kind of question.