SWIFT Customer Security Programme (CSCF v2026): cited answers and gap reviews
The SWIFT Customer Security Controls Framework sets the controls every SWIFT user attests to each year. Compliance Colleague covers CSCF v2026, the architecture types and the attestation cycle, control by control.
What it covers
- CSCF v2026: 32 controls (26 mandatory, 6 advisory) across three objectives
- Architecture types A1, A2, A3, A4 and B
- Control 2.4 (back-office data flow security), mandatory in v2026
- Independent assessment and the KYC-SA attestation
- The v2026 attestation window, 1 July to 31 December 2026
Questions you can ask
- “Which architecture type are we if we use a service bureau?”
- “What does control 2.4 now require of our back-office data flows?”
- “What has to be independently assessed before we attest?”
Every answer cites the SWIFT CSP requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- A diagram of your SWIFT secure zone checked against the architecture type
- Your SWIFT operator access policy checked against the MFA controls
- A CSCF control tracker (Excel) checked for gaps in mandatory controls
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk SWIFT CSP to other standards
With SWIFT CSP in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
What it’s built from
Compliance Colleague works from our own clause-referenced material, checked against: Swift Customer Security Controls Framework (CSCF) v2027, Detailed Description (Swift). It cites the clause so you can check it against your own copy.
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More Global standards
PCI DSS · ISO 27001 · ISO 27701 · ISO 42001 · SOC 2 · WCAG
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.