Law / Brazil

Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Ato nº 2.436 de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 10 March 2024.

A product security requirements rule binding private bodies.

As of 14 September 2026.

What it requires

  • This binds a manufacturer or supplier of a cable modem, xDSL modem, ONU or ONT, fixed-wireless-access (FWA) router or modem, satellite-broadband router or modem, or wireless router or access point marketed to the general public in Brazil to connect a subscriber to an internet service provider's network; it does not reach a mobile app, a SaaS product, or any product that does not perform this connectivity function.
  • Do not ship the device with weak, blank, or identical-across-all-units default credentials, and do not derive an initial password from information easy to obtain by scanning network traffic, such as a MAC address; alternatively, force the user to set a new password meeting the strength rules the first time the device is used or after a factory reset.
  • Print any factory-set password on a label on the device and restore it whenever the device is reset to factory settings; require any user-set password to be at least 8 characters with an uppercase letter, a lowercase letter, a number, and a special character, and check new passwords against a password dictionary or an equivalent method to block weak or commonly used ones.
  • Do not hard-code credentials or cryptographic keys in the device's software or firmware source code, encrypt or hash any password, key, or credential you store or transmit, implement inactive-session timeouts, ship with unused communication ports and services disabled, and let the user disable non-essential communication features.
  • Publish a clear support policy stating how long and in what circumstances you will provide security updates, and provide security updates free of charge for at least 2 years after the product's launch or for as long as you keep distributing it to consumers, whichever period is longer.
  • Provide a dedicated, securely reachable channel, such as an HTTPS web form or a PGP-encrypted email address, for a customer, end user, or third party to report a security vulnerability, and publish a coordinated vulnerability-disclosure policy on your website covering how you want to be notified, what a reporter should expect, and your process's scope and limits.
  • Maintain a public, Portuguese-language support page listing known vulnerabilities in your products together with their mitigations, and keep making corrected software or firmware available.
  • Demonstrate this compliance to Anatel's conformity-assessment agent when you seek homologação for the device, or by presenting your own Cybersecurity Policy showing you meet the full set of supplier requirements; Anatel can suspend a homologação it already granted if it later finds a security flaw or vulnerability, and a suspended homologação bars the product from being distributed in the Brazilian market until the problem is fixed.
  • This duty took effect 1 July 2023 and its Annex, which carries the substantive requirements above, has been mandatory since 10 March 2024.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

This Ato creates an administrative product-conformity requirement enforced through homologação, not a criminal offense; no provision of the Ato or its Annex attaches imprisonment or a criminal fine to non-compliance.

Who enforces it

Enforcement body

The Superintendência de Outorga e Recursos à Prestação sets these requirements and Anatel oversees them through the device's conformity assessment and homologação; Resolução nº 740/2020's Regulamento de Segurança Cibernética directs that cybersecurity aspects be considered in that homologação procedure (art. 22), and Anatel's own published guidance states it monitors homologated products in the market on an ongoing basis and can suspend a product's homologação, barring its distribution in Brazil, if it finds a security flaw. No published record of a specific enforcement action under this Ato is confirmed in the primary text.

What it reaches

Obligation class

Security, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A manufacturer or supplier of specified consumer customer-premises equipment, meaning a cable modem, xDSL modem, ONU or ONT, fixed-wireless-access or satellite-broadband router or modem, or wireless router or access point sold in Brazil to connect a subscriber to an internet service provider's network, must meet mandatory minimum cybersecurity requirements before Anatel will certify the device.

The device may carry no default, blank, or weak passwords and no password shared across all units as manufactured. It may also carry no credentials or cryptographic keys hard-coded in the device's software or firmware. The manufacturer must provide at least two years of free security updates after launch or for as long as the product stays on the market, whichever is longer.

It must also maintain a published, securely reachable channel plus a coordinated vulnerability-disclosure policy for reporting a security flaw. Anatel enforces the requirement through the device's conformity assessment (homologação) and can suspend a product's homologação, which bars its distribution in Brazil, if it later finds a security flaw.

When LexLint raises it

  • distributes_software_product

Read the law

Official act text, Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações (Anatel)

Back to the example  ·  Lint your app