Mexico SMEs Face 80% Non-Compliance After PUI Rollout
By Duncan Randall | Journalist & Industry Analyst -
Wed, 05/06/2026 - 15:37
The implementation of the Single Identity Platform (PUI) has created a significant compliance gap for Mexican small and medium-sized enterprises (SMEs) following the expiration of the official integration deadline on March 31, 2026, according to an analysis by digital solutions provider Konfront. Following the publication of technical guidelines on Jan. 23, 2026, private entities were granted a period of 45 business days to develop and implement the necessary technical capabilities to interconnect with the federal system.
The impact of the new regulation is concentrated in the SME segment, which represents 99.8% of economic units in Mexico, according to the 2024 INEGI Economic Census. Analysts from Konfront estimate that up to 80% of these companies are currently in a state of non-compliance. Under the current legal framework, organizations that failed to integrate by the deadline face administrative sanctions and fines ranging from MX$1.1 million (US$63,727) to MX$2.3 million (US$133,249).
Analysts indicate that the pressure to meet these requirements within a short timeframe is generating elevated operational and compliance risks. Santiago Zabalgoitia, Director of Operations, Konfront, stated that many companies are attempting to understand the requirements while simultaneously deploying solutions without adequate technical or regulatory guidance.
“The deadline to integrate the PUI has passed, and many companies are still trying to understand in real time what compliance entails,” Zabalgoitia said. “With fines of this magnitude, doing it wrong is more expensive than not doing it; SMEs need options that reduce risks, not multiply them.”
Industry experts also warn that rushed implementations could significantly weaken cybersecurity postures. Ariel Szpecht, CEO, Fortem Cybersecurity, noted that the urgency is forcing companies to expose critical systems without standardized security validation protocols. According to Szpecht, this can lead to misconfigured access points, data exposure, and operational disruptions.
“The main risk is not the obligation itself, but its execution without proper preparation,” Szpecht said. “The timeline is forcing many companies to expose critical systems under pressure, without going through established security validation processes.”
Technical Manual Details
The legal framework is defined by the Technical Manual for the Technological Solution for Diverse Institutions. This document establishes mandatory requirements for interconnection, system operation, internal searches, and cybersecurity. The regulation applies to “Diverse Institutions,” a category that encompasses financial services, health, telecommunications, insurance, and transportation sectors, as well as any entity that manages databases used for individual identification.
The PUI law entails a specific model of interoperability through web services, requiring standardized data exchange protocols between private entities and federal systems. It mandates that companies conduct internal searches across three distinct phases: basic data, historical data covering up to 12 years, and continuous data.
To maintain security, the mandate imposes a compliance regime aligned with Open Worldwide Application Security Project (OWASP) and National Institute of Standards and Technology (NIST) standards, reflecting internationally recognized cybersecurity best practices. Before beginning operations, entities must provide Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) reports demonstrating the absence of critical vulnerabilities.
The Technical Manual establishes that non-compliance involves more than financial penalties. Entities that fail to meet the technical and cybersecurity obligations are subject to civil, administrative, and potential operational liabilities, which could include service restrictions or increased regulatory scrutiny.








