What is SUSEP Circular 638/2021 compliance?

If you're an insurer, open private pension entity, capitalization company, or local reinsurer operating in Brazil, SUSEP 638 compliance is what you must meet under Circular SUSEP 638/2021—the cybersecurity rule covering the data and systems behind your operations.

On this page  
  • Introduction
  • Applicability and scope
  • Compliance levels and requirements
  • Chapter III: General provisions
  • Chapter IV: Cybersecurity policy
  • Chapter V: Prevention, detection, and response to incidents
  • Chapter VI: Outsourcing of data processing and storage
  • Challenges of implementing SUSEP 638
  • Benefits of implementing SUSEP 638
  • Best practices
  • Conclusion
 

Introduction

If your company sells insurance, runs an open private pension plan, issues capitalization bonds, or operates as a local reinsurer in Brazil, SUSEP 638 compliance is already on your roadmap. Circular SUSEP 638, published by the Superintendência de Seguros Privados (SUSEP) in 2021, sets out how you protect the confidentiality, integrity, and availability of the data your business depends on. The rule treats cybersecurity as a risk to be managed over time rather than a project to close out once.

The circular landed as the Brazilian insurance market moved hard into digital channels and shared infrastructure, from Open Insurance to the System for Registry of Operations. It aligns the sector with the General Data Protection Law (LGPD) and folds cyber risk into your organization's existing Internal Controls System (SCI) and Risk Management Framework (EGR). It does not replace the earlier prudential rules; it builds on them, with requirements that echo the principles the Central Bank had already set for banks and payment institutions.

Applicability and scope

SUSEP 638 reaches across the supervised insurance market rather than a single line of business, and how much you have to do scales with its prudential segment under Resolução CNSP 388/2020. If your firm sits in the S1 or S2 segment, among the larger and more complex operators, you carry the full set of obligations and an earlier adaptation deadline than the smaller S3 and S4 entities.

The circular applies to supervised entities operating in Brazil's insurance market, including:

  • Insurance companies (seguradoras)
  • Open private pension entities (EAPCs)
  • Capitalization companies (sociedades de capitalização)
  • Local reinsurers (resseguradores locais)

Compliance levels and requirements

SUSEP 638 runs to seven chapters and eighteen articles, but the substance falls into four areas that move from governance down to daily controls. After the opening scope and definitions, the rule covers how cyber risk fits the wider risk framework, the cybersecurity policy your organization has to hold, the processes for preventing and handling incidents, and the requirements for outsourcing and cloud services. Taken in order, they carry you from board-level accountability to the operational controls that satisfy the SUSEP cybersecurity requirements.

The circular's substantive chapters cover:

  • Chapter III: General provisions: How cyber risk fits within the internal controls and risk management frameworks.
  • Chapter IV: Cybersecurity policy: The documented policy your organization must hold, scaled to its size and risk.
  • Chapter V: Prevention, detection, and response to incidents: The processes that identify vulnerabilities and handle incidents.
  • Chapter VI: Outsourcing of data processing and storage: The controls and oversight for third-party and cloud services.

Chapter III: General provisions

Chapter III sets the governance frame for everything after it. Cybersecurity has to sit inside the general context of the SCI and the EGR, which means cyber risk gets treated as a category of operational risk rather than a separate technical worry. When your organization decides how to treat those risks, you must also draw on recognized national and international cybersecurity practices.

Chapter IV: Cybersecurity policy

This is where you put the rulebook in writing. Chapter IV calls for a documented cybersecurity policy that states your objectives, records your board's commitment to improving cyber controls, and sets the parameters for ranking data, incidents, and services by relevance. The policy has to stay proportional to your size, how complex your operations are, and how exposed you are to cyber risk, so a large insurer and a small capitalization company will not end up carrying the same policy.

Chapter V: Prevention, detection, and response to incidents

Chapter V turns the policy into working capability. You have to keep current processes that identify and reduce vulnerabilities and that detect, respond to, and recover from incidents, with those processes written into the business continuity plan for the relevant scenarios. Two reporting duties sit here as well: telling SUSEP about a relevant incident within five business days and producing an annual report on how incidents were prevented and handled.

Chapter VI: Outsourcing of data processing and storage

If you lean on third parties or cloud providers, and most insurers do, Chapter VI is where a lot of the work lands. You need the resources and governance to monitor contracted services, you have to require providers to keep controls no weaker than your own, and you have to make sure your data stays segregated from the data of other clients. For relevant services, add two more steps: notify SUSEP within 30 days of signing, and either obtain independent certification or run prior due diligence.

Challenges of implementing SUSEP 638

Reaching SUSEP 638 compliance can be demanding, especially if your organization's digital operations outgrew its security controls.

Folding cyber risk into the existing risk framework

Plenty of entities have run security as an IT function, off to the side of enterprise risk. The circular wants it inside the SCI and the EGR, counted as operational risk. In practice that means new reporting lines and a board that reviews cyber risk rather than nodding at it once a year.

Writing a policy that is proportional, not generic

A policy borrowed from another market rarely survives contact with SUSEP 638. It has to fit your operations and your risk exposure, and every section needs a control behind it that you actually run. Even the classification step pulls in security, legal, and the business lines before an organization can call it finished.

Building real detection and response

A written incident plan is not the same as being able to act on one. Detecting, responding to, and recovering from incidents takes tooling and rehearsed playbooks. When logs are scattered or monitoring is thin, a relevant incident can run for days before anyone notices, and the recovery steps meant for the continuity plan stay theoretical.

Meeting the five-day reporting clock

Five business days feels comfortable until you are inside an incident. In that window, you must confirm the incident is relevant, size up the damage, and get the report to SUSEP with remediation already under way. Teams without a rehearsed process usually burn most of that time just assembling the facts.

Governing outsourced and cloud providers

Most of your sensitive processing probably runs on someone else's platform. SUSEP 638 still puts the responsibility on you, so you need the contractual right to monitor, evidence that a provider's controls are at least as strong as yours, and proof your data is kept apart from other tenants' data. Across a handful of vendors, that is never a one-time check.

Benefits of implementing SUSEP 638

Done properly, SUSEP 638 leaves your organization with more than a compliance certificate.

Stronger protection for policyholder data

The controls the circular asks for are the ones that keep policyholder and beneficiary data out of the wrong hands. Put them in place and a serious breach gets less likely, which protects both the people who trusted you and the reputation you sell on.

A defensible position with the regulator

If your organization shows a proportional policy, controls that work, and has a clean history of handling incidents, you'll walk into supervision on solid ground. When the documentation lines up with the circular's chapters, a tense review becomes a routine one.

Faster, calmer audits

Evidence organized around the circular means much less scrambling before each review. Maintained policies and reusable reports turn an audit into a confirmation of what already happens, instead of a year-end fire drill.

Better resilience and continuity

Writing incident processes into the business continuity plan pushes your organization toward resilience it can actually use. When something real goes wrong, the firms that prepared recover faster and lose less.

Alignment with the LGPD and market peers

SUSEP 638 was written to sit next to the LGPD, and it echoes the cyber rules the Central Bank already set for banks. So the effort travels: much of your SUSEP cybersecurity requirements work doubles as progress on data protection and your wider regulatory posture.

Best practices

For anything past minimum compliance, a few habits earn their keep over time.

Governance and policy

  • Treat the cybersecurity policy as a living document, and revisit it when your operations or risk exposure shift rather than once a year.
  • Make the relevance classification drive real decisions, so a "relevant" rating changes how something is protected instead of sitting in a spreadsheet.
  • Give the board a genuine view of cyber risk as operational risk, reported on the rhythm the risk committee already keeps.

Detection, response, and reporting

  • Centralize and retain logs so a relevant incident can be caught, traced, and pieced back together quickly.
  • Run tabletop exercises against the five-business-day notification before a live incident sets the clock for you.
  • Assemble the annual incident report from data you gather all year, not in a December rush.

Vendor and cloud oversight

  • Write monitoring and audit rights into provider contracts from the start, especially for relevant processing and storage.
  • Recheck that provider controls stay at least as strong as yours on a schedule, not only at onboarding.
  • Keep track of where your data lives across providers and regions, so segregation and access claims are something you can actually evidence.

Conclusion

SUSEP 638 matters because insurers hold some of the most sensitive financial and personal data in Brazil, and one serious incident can spread fast across policyholders, partners, and the market around them. If you treat the circular as a one-time project, you'll watch the same gaps reopen after every supervision cycle, because the rule is built around a capability you keep rather than a checklist you file.

The better move is to run SUSEP 638 as a standing program: a policy you keep current, controls you operate for real, and incident and vendor processes you actually rehearse. Handled that way, the SUSEP cybersecurity requirements become part of how your business runs day to day, and protecting your customers and your standing with the regulator stops being a separate job.