SFC Circular 007: Cybersecurity Requirements for Colombia's Financial Sector

Cumplimiento y regulación
23 Sep 2026, 9:00 a.m. By Juan Carlos Hernandez 💬 0
SFC Circular 007: Cybersecurity Requirements for Colombia's Financial Sector

No Colombian bank signs a contract with a technology vendor without first asking about Circular 007. In the day-to-day reality of the financial sector, it's the exam any vendor has to pass before getting near sensitive data. If your business is an entity supervised by the Superintendencia Financiera (SFC) — a bank, fintech, financial cooperative, investment fund, or insurer — this circular isn't a suggestion. It's a regulatory instruction with concrete technical requirements and real consequences for non-compliance.

What It Actually Is

Circular Externa 007 is part of the set of instructions the SFC issues to entities under its supervision regarding cybersecurity risk management. Unlike Law 1581, which applies broadly to any business handling personal data, Circular 007 is sector-specific and considerably more demanding in technical detail. Having a written policy isn't enough; you need to demonstrate the controls actually work.

Who's Required to Comply

The list includes banks, financing companies, financial cooperatives, pension and severance funds, trust companies, brokerage firms, insurers, and fintechs that fall under the SFC's supervisory perimeter. If your business provides technology or cybersecurity services to any of these entities, sooner or later you'll be asked to prove you can support their compliance — it's not negotiable in the sales process.

What You Actually Have to Demonstrate

Beyond the regulatory text, here's what a supervised entity needs to have working:

Cyber risk governance at the board level, not just within the IT department — the circular doesn't accept cybersecurity as an IT-only concern.

A real inventory of information assets: what's handled, where it lives, how critical it is. Many entities underestimate this task until an auditor formally requests it and they discover nobody has the full map.

Verifiable technical controls: access management, encryption, network segmentation, continuous monitoring, real capability to detect an incident when it happens.

Tested continuity plans, not just documented ones — the entity must be able to show that, during an incident, it maintains or quickly restores critical operations.

Third-party management: if you outsource technology, the circular requires you to demand the same standards from your vendors. It's exactly why certifications get requested from the cybersecurity companies entities work with.

Reporting of significant incidents to the SFC within defined timeframes.

Periodic testing — vulnerability audits and pentesting — that validates controls actually work, not just look good on paper.

Why the Financial Sector Is in the Crosshairs

It's no accident this circular is so detailed. The sector absorbs a large share of the country's most sophisticated attacks: card fraud, social engineering aimed at employees with access to critical systems, phishing that impersonates banks to steal credentials. Colombia's Supreme Court has also ruled that financial entities carry strict liability for electronic fraud — they must compensate victims unless they can prove the user was solely at fault. With that legal exposure hanging over them, technically complying with Circular 007 stops being an image issue and becomes a matter of real financial exposure.

What This Looks Like in Practice

For a supervised entity, this is almost never a one-time project. It's a cycle:

1. An honest assessment of where the entity stands today.
2. A [cybersecurity audit](https://tirescue.com/en/auditoria-de-ciberseguridad/) that identifies concrete gaps, both technical and governance-related.
3. A remediation plan prioritized by actual risk, not by what's easiest to fix.
4. Implementing controls — from access management to 24/7 monitoring.
5. Periodic pentesting to validate that what's been implemented actually works.
6. Continuous review, since both threats and regulatory expectations change.

Frequently asked questions

Does a small fintech have to comply too?

If it falls under the SFC's supervisory perimeter, yes — though the level of rigor can be adjusted to its size and risk profile.

Does it replace the need for ISO 27001?

No, they're complementary. Many entities use ISO 27001 as a reference framework to structure their compliance with Circular 007.

What happens if an entity doesn't comply?

The SFC has powers ranging from formal remediation requirements to financial penalties, depending on severity and impact on financial consumers.

How often does pentesting need to happen?

There's no fixed number in the text, but the expected industry practice is at least once a year, more often on critical systems or after significant changes.

Let's talk

Complying with Circular 007 demands verifiable technical controls, not just documents. At T.I. RESCUE we work with financial entities on [cybersecurity audits](https://tirescue.com/en/auditoria-de-ciberseguridad/) designed for this framework, and on [cybersecurity consulting](https://tirescue.com/en/consultoria-de-ciberseguridad/) to structure compliance sustainably. If you also handle customer data, check out our guide to [Colombia's Habeas Data Law](https://tirescue.com/en/blog/colombia-habeas-data-law-businesses/), which applies in parallel. Need to know where your entity stands against this circular today? [Book a consultation](https://tirescue.com/en/contacto-ti-rescue/).

Contact us

You may also like

Comments (0)

Be the first to comment.