LATAM fintech processes over $150B in digital payments annually. Every transaction is signed with ECC. The regulators overseeing it are already watching NIST.
Where the cryptographic exposure sits
Interbank settlement uses TLS 1.3 with ECDHE key exchange, the same elliptic curve key agreement Shor's algorithm targets. Card payment networks (Visa/Mastercard rails in LATAM) rely on ECC signing for authorization messages. Open banking APIs mandated by BCB (Brazil) and CNBV (Mexico) require mTLS with ECC certificates. A harvest-now-decrypt-later attacker storing today's settlement traffic can retroactively expose transaction authenticity, counterparty identities, and routing data once hardware matures.
The regulatory landscape moving now
BCB, Banco Central do Brasil
Open Finance framework (Resolução BCB 32/2020) mandates ECC-based mTLS for all 800+ accredited institutions. BCB follows BIS CPMI guidance, which references NIST PQC timelines.
CNBV, Mexico
Circular Única de Bancos references NIST FIPS for cryptographic standards. CNBV aligned with BIS principles post-NIST 2024 finalization.
CMF, Chile
Ley Fintech (21.521) requires certified cryptographic controls for open banking participants. CMF published updated cybersecurity norms in 2024.
SUGEF, Costa Rica
Acuerdo SUGEF 14-17 mandates cryptographic controls for supervised entities. References NIST SP 800 series.
SBS, Peru
Reglamento de Seguridad de Información requires FIPS-compliant cryptography for licensed institutions.
What a QTA delivers for this sector
A QTA scoped to your interbank TLS surface and signing key infrastructure delivers: which key exchange algorithms are in use, which are quantum-vulnerable, and a prioritized migration sequence before your next CMF or CNBV inspection cycle.
