Brazil has no enacted, comprehensive cybersecurity law comparable to the EU's Cyber Resilience Act or NIS2. Its posture instead rests on a policy-setting decree, one enacted product-security regulation reaching a narrow class of consumer networking hardware, several sector-specific cybersecurity regimes that each bind a licensed or government-designated role this corpus's activity vocabulary cannot express, and a still-pending general cybersecurity bill.
Decreto nº 11.856, de 26 de dezembro de 2023 instituted the Política Nacional de Cibersegurança (PNCiber) and the Comitê Nacional de Cibersegurança (CNCiber), a public-private coordinating body chaired by the Gabinete de Segurança Institucional da Presidência da República with 19 government, business, civil-society, and scientific seats; its articles state principles and objectives for national cybersecurity activity and create a committee that recommends further policy, but the decree's own text imposes no requirement, duty, or penalty on a private business.
Decreto nº 12.573, de 4 de agosto de 2025 instituted the Estratégia Nacional de Cibersegurança (E-Ciber) that implements PNCiber's guidelines; its provisions are written throughout in the vocabulary of incentive (incentivo, estímulo) toward the private sector, including encouraging Brazilian companies to procure products and services that adopt minimum cybersecurity standards rather than requiring anyone to meet one, so it likewise creates no enforceable duty.
Brazil's one enacted, in-force product-security requirement is Ato nº 2.436, de 7 de março de 2023 of Anatel's Superintendência de Outorga e Recursos à Prestação, which sets mandatory minimum cybersecurity requirements for the conformity assessment (homologação) of consumer-facing customer-premises equipment: cable modems, xDSL modems, ONU/ONT units, fixed-wireless-access and satellite-broadband routers and modems, and wireless routers and access points. Its Annex became mandatory on 10 March 2024 and is researched as the instrument row below.
Three further sector regimes each bind a role this corpus's declared activities cannot identify, so each is named here and none is filed as an instrument, the treatment this profile gives DORA's financial entities and NY DFS Part 500's covered entities.
Anatel's own Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, requires a "prestadora" (a Brazilian telecommunications service provider) to adopt and maintain a board-approved Cybersecurity Policy, source equipment only from suppliers whose own cybersecurity policy is compatible with the Regulation and independently and periodically audited, run cybersecurity vulnerability-assessment cycles, report on its critical telecommunications infrastructure, and notify Anatel of relevant incidents; that duty binds the carrier, not an app or a SaaS product that merely rides the carrier's network, and it is the same Resolução that gives Anatel's product-conformity procedures their cybersecurity mandate, so the two regimes share one legal source without sharing a bound party.
The Banco Central do Brasil's Resolução Conjunta CMN/BCB nº 4.893, de 26 de fevereiro de 2021 requires every institution the Central Bank authorizes to operate, meaning banks and other regulated financial institutions, to implement and maintain a board-approved cybersecurity policy addressing incident response, vulnerability management, and the security of contracted cloud and data-processing services; the bound party is a licensed financial institution, not a declared LexLint activity.
Aneel's Resolução Normativa nº 964, de 28 de setembro de 2021 imposes an analogous cybersecurity policy duty on the electric-power sector; it does not reach a digital-service provider of the kind this corpus's activities identify and is named here for completeness only.
A general cybersecurity statute is pending, not enacted. Projeto de Lei nº 4.752, de 2025, authored by Senator Esperidião Amin and others, would institute a "Marco Legal da Cibersegurança" and a national digital security and resilience program.
As of its most recent Senate committee action the bill remains with a rapporteur in the Comissão de Ciência, Tecnologia, Inovação e Informática, having received further amendments in September 2026, and it has not been enacted, so nothing about its eventual content is asserted here.
Brazil's General Data Protection Law (LGPD, Lei nº 13.709/2018) carries its own security-of-processing duty (Arts. 46 to 49) and its own personal-data breach-notification duty (Art. 48); both are this jurisdiction's privacy-topic findings and are not restated here, the treatment this profile gives a comprehensive regime's own security article.
The Marco Civil da Internet (Lei nº 12.965/2014) likewise requires an internet connection or application provider to keep connection and application-access records under confidentiality in a controlled, secure environment; that duty attaches to the records themselves and is researched with this jurisdiction's other Marco Civil provisions rather than repeated here.
No published enforcement record specific to Anatel's CPE cybersecurity requirements is confirmed in the primary text; Anatel states only that it monitors homologated products in the market on an ongoing basis and can suspend a product's homologação, which bars its distribution in Brazil, if a security flaw is found.