CNBV Allows SMS for Fintech Authentication
Mexico’s CNBV now permits SMS, email and encrypted messaging for authentication codes in fintech operations.
Mexico’s CNBV changed bank rules to allow authentication codes by SMS, email or encrypted messaging in operations with technology-based commission agents. The measure took effect on Sept. 2, 2026, and also loosens rules for balance and transaction queries, while requiring credential changes through the bank’s infrastructure.
Mexico’s CNBV has changed the rules for credit institutions to allow security codes to be sent by SMS, email and encrypted instant messaging in transactions carried out through technology-based commission agents. The resolution was published in the Official Gazette on Sept. 1, 2026, and took effect on Sept. 2, 2026, according to regulatory compilations.
What changes in authentication?
The new wording keeps the password defined by the customer and adds SMS as a valid channel for receiving category 3 authentication factors. The CNBV also allows customers to choose email, encrypted instant messaging or a mobile phone number to receive the code, while some balance and transaction queries now require only a category 2 authentication factor.
That adjustment lowers the number of required factors in certain operations compared with the previous scheme. According to coverage based on the CNBV, the change applies to specific queries made through technology-based commission agents.
What operations does it cover?
The new rules apply, among other cases, to opening level 2 accounts, transfers linked to those accounts, loans of up to 3,000 UDIs and payments for goods and services made through technology-based commission agents. They also cover operations in which category 3 authentication factors are sent.
The amended resolution also adds an operational requirement for credit institutions. They must let customers change both their category 2 authentication factor and the contact method used to receive the category 3 factor, including SMS, through an explicit option on the commission agent’s website or app that redirects to the bank’s technology infrastructure.
What role does the bank still keep?
The bank’s technology infrastructure remains the central control point for new registrations and credential changes. Private analyses of the resolution text say commission agent interfaces must redirect to that infrastructure whenever a customer updates personal data or the channel used to receive the code.
In practice, the CNBV loosened the delivery channel for the second or third factor, but kept operational control at the bank. Sector summaries also describe the reform as a way to allow SMS without losing traceability over the authentication process.
How does this connect to the rest of financial regulation?
The decision comes alongside another regulatory effort opened for public consultation by Banxico and the CNBV, a draft set of rules for payment card networks aimed at payment transactions and at giving greater legal certainty to financial intermediaries, acquirers and clearing houses.
That draft includes limits on interchange fees. For credit cards, it proposes a cap of 1.30% per transaction and an additional restriction so that the total charged over 12 months does not exceed 1% of the volume processed with each issuer’s credit cards. For debit cards, it keeps a 0.30% fee per transaction and introduces a cap of 10.80 pesos per transaction.
The public consultation will remain open until Sept. 24, 2026, and the percentages and caps can still be adjusted based on market comments. Fintech Mexico acknowledged progress in the publication of the draft, although it said it would assess the impact on competition and its business model before taking a final position.
What recent precedent did Superdigital set?
At the same time, the CNBV ruled that the revocation of Superdigital’s authorization to operate was valid. Superdigital is the fintech linked to Santander through PagoNxt. The official notice published in the Official Gazette and business coverage agree that the decision affected its operation as an e-money institution, without directly affecting other banking businesses of the group in Mexico.
The authority assessed operational and technology risk, information security and compliance with anti-money laundering and counterterrorism financing rules. According to the revocation order, the action was issued at the institution’s own request.
Sources
- Fintech Brief | Banxico aprieta, pero despaciofintechexpert.mx· Fintech Expert MX
- CNBV revoca autorización a Superdigital, vinculada a Santander, para operar en Méxicoelceo.com· El CEO
- Fintech México reconoce avances en regulación de pagos; evaluará impacto en competenciaeleconomista.com.mx· El Economista
- CNBV Allows SMS Authentication for Digital Banking Agentsstartupresearcher.com· Startup ResearcherUnverified URL
- Mexico Import Evidence Change Radar – Revocación SDMX Superdigitaltyllus.com· Tyllus
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de crédito.vlex.com.mx· vLex México
- CNBV revoca licencia de Superdigital, fintech de Santandermilenio.com· Milenio
- Oficio de revocación de autorización a SDMX Superdigital, S.A. de C.V., Institución de Fondos de Pago Electrónicovlex.com.mx· vLex México
- Nu México perdería hasta 13% de sus utilidades por cambios de Banxico y CNBV a pagos con tarjetaelceo.com· El CEO
- Resolución que modifica las Disposiciones de carácter general aplicables a las instituciones de crédito (comisionistas de base tecnológica)sdv.com.mx· SDV
- Certeza jurídica, eje de la consulta del Banxico para modernizar los pagos con tarjetaeleconomista.com.mx· El Economista
- CNBV flexibiliza autenticación para comisionistas fintech y permite SMSmsn.com· MSN / Información basada en CNBV
- A partir de este miércoles, recibirás estos mensajes de SMS que no debes ignorarxeu.mx· XEU
- Monitoreo de medios y redes sociales – 1 de septiembre de 2026unifimex.org.mx· UNIFIMEX



