Uruguay BCU proposes stronger authentication
The BCU opened a consultation on stronger authentication for wallet enrollment and transactions, plus a deadline for complaints.
Uruguay’s Central Bank Superintendency is consulting on new rules for electronic instrument issuers and complaint handling. The proposal strengthens transaction security and adds passkey and trusted-device requirements, with compliance set for Jan. 1, 2027 on that point.
Update September 25, 2026: The BCU added trusted-device requirements and passkey-based authentication to the discussion, with compliance due by Jan. 1, 2027 under Communication No. 2026-124. The rest of the proposal remains centered on stronger authentication, digital wallet enrollment, and complaints.
Uruguay’s Superintendency of Financial Services at the Central Bank opened a public consultation in September 2026 on a draft rule that would change obligations for issuers of electronic instruments and the complaint-handling process. According to El País (Uruguay), the proposal focuses on transaction security and fraud prevention.
What does the BCU’s new proposal require?
The draft would require stronger authentication to improve security for card-not-present transactions, given the fraud levels observed in those operations. That requirement would also apply when electronic instruments are linked to digital wallets.
The rule says issuers would have to apply strong customer authentication whenever clients are asked to authenticate for card-not-present transactions, in line with current standards. For digital wallet enrollment, they could treat a tokenized instrument, uniquely and securely linked to the customer’s device, as a possession factor.
What changes does it add for trusted devices and passkeys?
BCU Communication No. 2026-124 sets Jan. 1, 2027 as the compliance deadline for trusted-device requirements and passkey authentication, according to CCEA. That deadline adds to the broader set of controls the regulator is working on to strengthen user verification and cut fraud.
The new date does not replace the public consultation on electronic instrument issuers. Instead, it gives a concrete implementation target for those controls. In practice, the BCU has now set when those authentication-related requirements must be in place.
What exceptions does the text include?
The draft adds an exception to strong authentication for payer-initiated payments in recurring transactions. That covers service subscriptions and automatic debits, according to the text released by the BCU’s Superintendency of Financial Services.
That provision defines which transactions fall outside the stronger requirement, without changing the other obligations set for electronic instrument issuers. The proposal seeks to organize the treatment of repeat payments within the security framework now under consultation.
How does the complaint response deadline change?
The draft sets a maximum period of 60 calendar days from the filing of a complaint when the investigation requires the involvement of institutions abroad. That procedural standard would apply to financial entities that issue electronic instruments.
The rule is meant to put a time limit on cases in which a response depends on steps outside the country. In that scenario, the BCU says the final response cannot take longer than those 60 calendar days.
What is the scope of the public consultation?
The proposal is aimed at issuers of electronic instruments and their complaint-handling regime. It is still in public consultation, so the BCU’s published text describes proposed changes, not rules already in force.
Sources
- BCU: Comunicación N° 2026-124. Requisitos para dispositivos de confianza y autenticación mediante passkeys publicada 23-06-26ccea.com.uy· CCEA
- Decreto 66/025 Uruguay: obligaciones de ciberseguridadinfosecura.com.uy· InfoSecura
- De 2.000 a 30.000 denuncias: el ciberdelito crece, se profesionaliza y desafía a la justicialadiaria.com.uy· La Diaria
- Mayor protección ante fraudes: la nueva propuesta del BCU para realizar compras y definir reclamoselpais.com.uy· El País (Uruguay)
- ¿Hackearon tu empresa? Qué hacer en Uruguayinfosecura.com.uy· InfoSecura
- The BHU Cybersecurity Crisis. BANCO HIPOTECARIO ... (análisis de la crisis y referencia a Circular N° 2486 del BCU)x.com· Artículo y hilo divulgados vía X (Twitter)
- How to Report Cybercrime and Online Fraud in Uruguay (2026)ministryofcyberaffairs.com· Ministry of Cyber Affairs (Uruguay)



