home / frameworks / swift-csp

// Industry frameworks and attestations

Swift Customer Security Programme (CSP) and Customer Security Controls Framework (CSCF)

The Swift Customer Security Programme requires every Swift user to attest each year against the Customer Security Controls Framework. CSCF v2026 has 32 controls, 26 of them mandatory, and each attestation must be backed by an independent assessment.

International

Overview

Swift, the cooperative that runs the global financial messaging network, set up the Customer Security Programme (CSP) after attackers compromised member banks' local systems to send fraudulent payment messages. At the centre of the program is the Customer Security Controls Framework (CSCF), a set of security controls for the parts of a customer's environment that connect to Swift. Swift updates the framework every year. CSCF v2026, the version customers attest against in 2026, has 32 controls under 3 objectives and 7 principles, of which 26 are mandatory and 6 advisory.

Every Swift user must attest each year, through Swift's KYC Security Attestation (KYC-SA) application, to its compliance with the mandatory controls that apply to its architecture type. Attestations are submitted between July 1 and December 31, and each must be supported by an independent assessment, carried out either by an internal function independent from the first line of defence or by an external assessor. Counterparties can view each other's attestation status. Swift can report users that don't attest, or that don't meet the mandatory controls, to their supervisors.

In Canada, the CSP applies to banks, payment firms, securities firms, and large corporates that connect to Swift directly or through a service provider. Federally regulated institutions also follow OSFI Guideline B-13 on technology and cyber risk, and the CSP work can feed into that program. Scope keeps growing. CSCF v2026 made Control 2.4A, back office data flow security, mandatory, and brought customer client connectors such as APIs, middleware, and file transfer clients into scope for many controls, which moved some users from architecture type B to type A4.

Who it applies to in Canada

Banks, payment firms, securities firms, market infrastructures, and corporates that connect to the Swift network, directly or through a service bureau.

Canadian banks and payment firms that send or receive Swift messages must attest to the CSCF each year. Federally regulated institutions also answer to OSFI Guideline B-13 on technology and cyber risk, which covers much of the same ground.

Controls at a glance

The CSCF groups its controls under 3 objectives (secure your environment, know and limit access, detect and respond) and 7 principles.

Principle 1: restrict internet access and protect critical systems from the general IT environment

  • Separate the Swift secure zone from the wider network
  • Control operating system privileged accounts
  • Protect virtualization and cloud platforms that host Swift components
  • Restrict internet access from Swift systems
  • Protect the customer's connected environment

Principle 2: reduce attack surface and vulnerabilities

  • Secure back office data flows (2.4A, mandatory since v2026)
  • Apply security updates and harden systems
  • Protect operator sessions and external data transmission
  • Scan for vulnerabilities
  • Protect outsourced Swift-related activities
  • Business controls on transactions and relationship management

Principle 3: physically secure the environment

  • Physical access controls for Swift-related systems
  • Protect devices and workspaces used for Swift operations
  • Secure handling of hardware and removable media

Principle 4: prevent compromise of credentials

  • Enforce a strong password policy
  • Multi-factor authentication for access to Swift systems
  • Protect authentication secrets in use

Principle 5: manage identities and separate privileges

  • Logical access control based on need to know and least privilege
  • Manage hardware tokens and connected devices
  • Screen staff with access to Swift systems
  • Protect password repositories

Principle 6: detect anomalous activity to systems or transaction records

  • Malware protection
  • Software and database integrity checks
  • Logging and monitoring of security events
  • Intrusion detection

Principle 7: plan for incident response and information sharing

  • Cyber incident response plan
  • Security training and awareness
  • Penetration testing
  • Scenario-based risk assessment

Certification and assessment

The user identifies its architecture type, has the applicable controls independently assessed, and submits its attestation through the KYC-SA application. Counterparties can request to view the attestation. Users that fail to attest or comply can be reported to their supervisors.

Dates to know

2026-07-01
Attestation window opens for CSCF v2026, with Control 2.4A now mandatory
2026-12-31
Deadline to attest against CSCF v2026

Resources

Official texts and free tools for Swift CSP. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Customer Security Programme (CSP), Swift
  2. Swift Customer Security Programme v2026, BDO Belgium
  3. Guideline B-13: Technology and Cyber Risk Management, Office of the Superintendent of Financial Institutions