SWIFT CSP

The controls behind your SWIFT connection: attested annually, assessed independently, seen by counterparties.

Conditional standard · SWIFT Customer Security Programme (Customer Security Controls Framework)

Issued by

SWIFT

Region

International

Effective

CSP since 2016; the CSCF revises annually

Oversight

Annual attestation via KYC-SA, independently assessed

Applies when

You connect to SWIFT, directly or through a service bureau

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

The Customer Security Programme binds every SWIFT participant to the Customer Security Controls Framework: mandatory controls over the secure zone, access, hardening, detection and response around the SWIFT footprint, attested every year in KYC-SA and, since 2021, supported by an independent assessment.

It is often the most overlooked framework in a bank's stack because it is contractual rather than governmental, yet counterparties and supervisors both read the attestation. The mandatory controls map cleanly onto the technical family an institution already runs.

Where programmes are tested.

01

The secure zone

The SWIFT environment segregated, hardened and access-controlled to the CSCF's architecture types.

02

Mandatory controls

The framework's mandatory set, revised annually, implemented and evidenced against the current year.

03

Attestation and assessment

Annual KYC-SA attestation, backed by an independent assessment, visible to counterparties.

Curated once, evidenced continuously.

  • The CSCF's mandatory controls are curated at requirement level and cross-mapped to the technical control family, so the SWIFT attestation draws on the same evidence as ISO 27001 and the supervisory cyber regimes. Attestation is always against the current-year CSCF; the catalog versions with it.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

SWIFT CSP, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who has to attest under the CSP?

Every SWIFT user organisation, banks and non-banks alike, attests annually in KYC-SA against the current CSCF, including those connecting through service bureaus, whose architecture type determines which controls apply. Counterparties can request your attestation, which is why it behaves like a market-facing certification.

What changed with independent assessment?

Since 2021 attestations must be supported by an independent assessment, internal audit or an external assessor, ending pure self-attestation. The practical effect: the evidence behind each control has to stand inspection, not just assertion.

The CSCF changes every year — how do we keep up?

That is precisely the curation problem this platform exists for: the CSCF revision is mapped once, centrally, and adopters see the new version through their overlay with the delta explicit. Your controls mostly persist; what changes is which are mandatory and what the attestation asks.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.