On March 10, 2024, Brazil’s cybersecurity testing requirements will officially be enforced. According to ANATEL Act No. 2436, the following CPE products must undergo cybersecurity testing when applying for a new ANATEL application or renewal application:
a) Cable modem;
b) xDSL modem;
c) ONU, ONT (Optical Network Unit and Optical Network Terminal);
d) Router or modem intended for fixed wireless access (FWA – Fixed Wireless Access);
e) Router or modem for fixed broadband access via satellite;
f) Wireless router or access point.
Act No. 2436 includes password requirements, defense requirements against unauthorized access attempts, and mandates that vendors establish a Coordinated Vulnerability Disclosure Policy and release software/firmware updates to address security vulnerabilities. The referenced cybersecurity standards include ANATEL Resolution No. 740, Resolution No. 715, ANATEL Act No. 77, NST Special Publication 800-63B, Broadband Forum – TR-181 Issue-2, ISO/IEC 29147:2018, and ISO/IEC 30111:2019. The new Act 2436 will encompass password requirements, defense requirements against unauthorized access attempts, and requirements for vendors to have a Coordinated Vulnerability Disclosure Policy and policies for releasing software/firmware updates to fix security vulnerabilities. The referenced normative documents include ANATEL Resolution No. 740, Resolution No. 715, ANATEL Act No. 77, NST Special Publication 800-63B, Broadband Forum – TR-181 Issue-2, ISO/IEC 29147:2018, and ISO/IEC 30111:2019.
On March 9,2024, Brazil’s National Telecommunications Agency (ANATEL)issued Official Letter No. 83, stating that considering the time required for laboratories and OCDs to evaluate the corresponding testing procedures, ANATEL provided the following information regarding the submission timeline for cybersecurity test reports:
1. For new applications or renewal applications approved by OCD before March 9,2024, there is a temporary exemption from submitting the cybersecurity test report. Applicants can declare a commitment to submit the report to ANATEL by July 6, 2024; if not submitted by this deadline, the certificate will be suspended, and sold products will need to be recalled from the market.
2.From March 10,2024, all new applications and renewal applications for the aforementioned CPE-related devices must include a cybersecurity test application. Cybersecurity testing requires samples to be sent to ANATEL-designated laboratories in Brazil for testing, certification by OCD, and registration by ANATEL.
Our company can provide pre-testing services before samples are sent to Brazil. Please feel free to inquire!