CNBV allows SMS authentication codes: what changes for embedded banking in Mexico

Since September 2, 2026, SMS has been enabled as a channel for delivering the category 3 authentication factor in operations that banks carry out through technology-based agents (comisionistas de base tecnológica). For teams building embedded banking flows, the change opens a door and, at the same time, raises the bar on how OTP is implemented.

Summary of the CNBV amendment that enables SMS for the category 3 authentication factor

What changed

Mexico’s National Banking and Securities Commission (Comisión Nacional Bancaria y de Valores, CNBV) amended the rules that apply to credit institutions to allow the category 3 authentication code to be delivered by SMS to the customer’s mobile phone, in addition to the channels already accepted, such as email and encrypted messaging. The resolution was published in the Diario Oficial de la Federación (Mexico’s official gazette) on September 1, 2026, and took effect the following day.

Read the full text in the Diario Oficial before making architecture decisions: press coverage summarizes the change, but the exact scope and conditions are in the resolution.

Who it applies to

The change is limited to operations that credit institutions carry out through technology-based agents, the model known in the market as embedded banking. It is not a general authorization for every channel of every bank. The operations covered include:

  • Opening level 2 accounts.
  • Transfers associated with those accounts.
  • Loans of up to 3,000 UDIS.
  • Payments for goods and services through the agent.
  • Balance and transaction inquiries, with lighter authentication requirements.

The rule also requires customers to stay in control of their factors: they must be able to choose and change the channel through which they receive the code, and those changes are managed on the bank’s infrastructure, not the agent’s.

Secure online payment from a smartphone with a digital security lock

Why implementation details matter more than before

Regulators in several other markets have been restricting SMS OTP because of its exposure to SIM swap and smishing. Mexico is moving in the opposite direction and enabling it for a specific use case, which shifts the responsibility to design: the channel is acceptable if the flow around it is solid. If your team already sends codes, this is a good time to review the whole flow, from generation to evidence. You can start with our guide to SMS OTP authentication.

Checklist for an OTP that holds up to review

  1. Short validity, two to five minutes, and single use per code.
  2. A limit on verification attempts and a temporary lock after failures.
  3. Request limits per number, per device and per IP, to prevent abuse and costs.
  4. No sensitive data in the message: no balances, accounts or cards.
  5. Clear text: what operation it authorizes, how long it lasts, and a warning not to share it.
  6. A consistent sender across all of the brand’s messages, so customers recognize the source.
  7. Verification rate monitored by country, prefix and number range, with alerts for drops or spikes.
  8. Traceability: date, channel, result and reason for non-delivery of each message, retained according to your evidence policy.
  9. A fallback plan when the SMS does not arrive: a voice retry or another channel, so the customer is never left without a way out.

The risks the rule does not remove

Enabling the channel does not solve the fraud associated with it. Three fronts remain open and are addressed with your own controls: SIM swap, mitigated by revalidating high-risk operations and watching for signals such as a recent device change; smishing, countered with a stable sender and messages that never ask for the code; and artificially inflated traffic, or SMS pumping, detected with rate limits and verification-rate monitoring. For higher-value operations, SMS works better as one factor within a layered scheme than as the only control.

What to check before you connect

  • That your contract with your messaging provider covers the traceability and delivery reports you need for audits.
  • That the test environment lets you validate retries, expiration and errors before production. See the developer documentation.
  • That authentication messages are separated from promotional ones, with their own configuration and priority.
  • That the fraud team receives the channel’s metrics, not just the operations team.

Sources

  • Official Gazette of the Federation (DOF), September 1, 2026 edition (CNBV resolution amending the general provisions for credit institutions; in Spanish). dof.gob.mx
  • “Te llegará un código del banco: desde mañana cambian estas reglas de autenticación”, UnoTV, September 1, 2026 (in Spanish). Read article
  • “CNBV permite SMS en autenticación de banca embebida”, FintechExpert, September 2026 (in Spanish). Read article
  • “CNBV abre la puerta a que bancos envíen códigos de seguridad por SMS y simplifica consultas de saldo”, El CEO, September 2026 (in Spanish). Read article

Frequently asked questions

Implementing SMS OTP in an embedded banking flow?

Grupo Tecnophone operates enterprise SMS messaging in Mexico with an API, a test environment, per-message delivery reports and real-time monitoring. You can request a 30-day pilot or explore our solutions for fintech and banking.

Scroll to Top