Skip to Content

Swift CSP


Meet your CSP attestation with evidence, not guesswork

Every Swift user must attest against the Customer Security Controls Framework each year, and self-attestation without independent verification is no longer accepted. A missed or weak attestation is visible to your counterparties and supervisors.


Talk to Swift Expert!
What it is.

SWIFT’s Cybersecurity Compliance Framework

The Customer Security Programme (CSP) is Swift's framework for protecting member environments against cyber fraud. Its core is the Customer Security Controls Framework (CSCF), updated every year.

Why it matters.

Protect Trust and Reduce Cyber-Fraud Exposure

Compliance is required, and your attestation status is shared with counterparties. Weak controls raise your fraud exposure and can affect how others do business with you.

How it helps.

Build a Defensible and Audit-Ready Attestation

A clear scope, a correct architecture type, and an independent assessment turn the framework into a defensible attestation your assessor and supervisors accept.

Overview



The CSCF groups its controls under three objectives and seven principles. The 2026 framework contains 32 controls in total: 26 mandatory and 6 advisory. Mandatory controls apply to your architecture type; advisory controls often preview future mandates.
Secure your environmentKnow and limit accessDetect and respond
Restrict internet access, protect critical systems, reduce the attack surface, and physically secure the zone.Prevent credential compromise, manage identities, and segregate privileged access.Detect anomalous activity across systems and records, and plan for incident response and information sharing.
Self-attestation without verification is no longer permitted. Each member must complete an annual Independent Assessment Framework (IAF) review, carried out by an independent external assessor or an autonomous internal audit function.

What changed in CSCF 2026

Control 2.4 on back-office data flow security is now mandatory. It requires encryption, integrity checks, and message validation between your general corporate IT and the Swift secure zone. Swift has signalled that remaining legacy first-hop connections become mandatory to secure by 2028.
The definition of customer client connectors has widened to include API consumers, middleware clients, and external service provider components. Fourteen controls now apply to these connectors, so many institutions previously scoped as Architecture Type B must reclassify and be assessed as Type A4.
Further changes include mandatory anti-malware on non-Windows machines in the secure zone, tighter Windows hardening under Control 2.3, and mandatory multi-factor authentication for Left and Right Security Officer accounts and firewall administrator interfaces. Security awareness training must now cover deepfake text, voice, and video, and penetration testing follows a defined three-year cycle.




Benefits



 A defensible attestation

Controls mapped to evidence that an independent assessor can review without rework.


 Correct architecture scoping

Confirm whether you fall under Type A4 or Type B before the assessment, avoiding a late reclassification.


 Lower fraud exposure

Controls that address credential compromise, back-office data flows, and anomalous activity where attacks occur.


 Readiness for future mandates

Advisory controls and the 2028 first-hop change planned for, not discovered at the next deadline.

FAQs


You still submit an attestation, but it must be backed by an independent assessment under the IAF, carried out by an external assessor or an independent internal audit function. Unverified self-attestation is not accepted.
The 2026 framework has 32 controls: 26 mandatory and 6 advisory. Which mandatory controls apply depends on your architecture type.
Customer client connectors now include API consumers and middleware clients. Fourteen controls apply to them, so institutions previously scoped as Type B may need to reclassify as Type A4.
It moved from advisory to mandatory in 2026. It requires securing the data flow between your corporate IT back office and the Swift secure zone, using encryption, integrity checks, and message validation.

Every year. Advisory controls frequently become mandatory in later versions, so planning ahead reduces last-minute work.


Contact us

Have a question? We're here to help with your SWIFT journey.