AuditXYZ

Compliance Framework

SWIFT Customer Security Programme (SWIFT CSP)

The SWIFT Customer Security Programme requires all SWIFT users to meet mandatory security controls. This guide covers the CSCF, architecture types, assessment requirements, and implementation strategies.

$30,000–$300,0003–9 monthsAudit Required2024 (CSCF v2024)
Issuing BodySociety for Worldwide Interbank Financial Telecommunication (SWIFT)
First Published2017-01-01
Latest Version2024 (CSCF v2024)
Typical Cost$30,000–$300,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual independent assessment against the Customer Security Controls Framework (CSCF). Results submitted via the KYC Security Attestation.
Geographyglobal

SWIFT CSP: Customer Security Programme Guide

The SWIFT Customer Security Programme (CSP) was launched in 2017 following a series of high-profile cyberattacks targeting SWIFT-connected institutions, most notably the $81 million Bangladesh Bank heist in 2016. The programme requires all SWIFT users worldwide to meet mandatory security controls defined in the Customer Security Controls Framework (CSCF) and to attest to their compliance annually. In a network connecting over 11,000 financial institutions across 200 countries, the security of each participant affects the security of all — making CSP a systemic resilience initiative as much as an individual compliance requirement.

What SWIFT CSP Is and Who Issues It

SWIFT (Society for Worldwide Interbank Financial Telecommunication) is a member-owned cooperative providing messaging network, products, and services for financial institutions worldwide. SWIFT itself is not a government regulator, but its position as the global interbank messaging infrastructure gives it de facto regulatory authority — non-compliance with CSCF requirements can result in loss of access to the SWIFT network, an existential consequence for most financial market participants.

SWIFT publishes the Customer Security Controls Framework (CSCF) annually, updating mandatory and advisory control requirements to reflect the evolving threat landscape. The v2024 CSCF was released in 2023 and applies to attestations submitted from January 2024. Each annual version may add, remove, or reclassify controls between mandatory and advisory status.

The CSP is mandatory for all SWIFT users. SWIFT publishes aggregated compliance statistics and has increasingly flagged non-attesting institutions to counterparty banks, creating strong commercial incentives for compliance beyond SWIFT's own enforcement mechanisms. SWIFT can suspend or restrict network access for institutions that persistently fail to attest or demonstrate significant compliance gaps.

Who Must Comply

Every organization connected to the SWIFT network must participate in the CSP. This includes:

  • Commercial and central banks
  • Broker-dealers and investment banks
  • Clearing houses and central counterparties
  • Custodian banks and fund administrators
  • Insurance companies
  • Corporates with direct SWIFT connectivity for treasury operations
  • Service bureaus operating SWIFT infrastructure on behalf of other institutions

Service bureaus face additional requirements because they provide SWIFT connectivity to multiple client institutions, making their security posture systemically important within the CSP framework.

The specific controls applicable to each institution depend on their architecture type — a critical determinant of CSP scope.

SWIFT Architecture Types

SWIFT classifies users into architecture types based on how SWIFT infrastructure is deployed:

Type A1 — SWIFT infrastructure within the user's local environment: The user operates SWIFT messaging software, interfaces, and connectivity on their own premises. Full CSCF scope applies.

Type A2 — User's SWIFT infrastructure partially outsourced: SWIFT software runs in a data center or cloud environment managed by the user or a shared-service entity under the user's control. Full CSCF scope applies.

Type A3 — User outsources SWIFT infrastructure to a service bureau or shared service: The user accesses SWIFT through a service bureau that manages the messaging infrastructure. Reduced mandatory control scope, as the service bureau carries responsibility for infrastructure-level controls.

Type A4 — User accesses SWIFT through a service bureau with no local SWIFT footprint: The lightest footprint — the user has no SWIFT software on their environment. The most limited mandatory control scope.

Type B — Users connecting via a SWIFT interface not under their direct control: Includes specific scenarios such as alliance lite2 lightweight connectivity.

Correctly classifying your architecture type is the first step in any CSP compliance program. The classification directly determines which mandatory controls apply, and misclassification can result in incorrect attestations and compliance gaps.

The Customer Security Controls Framework

Control Structure

The CSCF v2024 organizes controls into three security objectives, eight principles, and a set of mandatory and advisory controls:

Objective 1: Secure your environment

  • Restrict internet access and protect critical systems from the general IT environment
  • Reduce attack surface and vulnerabilities
  • Physically secure the environment

Objective 2: Know and limit access

  • Prevent unauthorized reading of sensitive credentials or data
  • Manage privileges and control access to SWIFT interfaces
  • Secure credentials for users accessing the SWIFT environment

Objective 3: Detect and respond

  • Detect anomalous activity in systems or transaction records
  • Plan for incident response and information sharing

Mandatory Controls (selected)

Every SWIFT user must implement all mandatory controls applicable to their architecture type. Key mandatory controls in v2024 include:

  • 1.1 SWIFT Environment Protection: Define and protect the secure zone containing SWIFT-related components, restricting general internet access to that zone
  • 1.2 Privileged Account Control: Restrict OS-level privileged accounts to the minimum necessary and audit their use
  • 1.3A Internal Data Flow Security: Protect the confidentiality and integrity of SWIFT-related data flows within the local environment
  • 1.4 Internet Access: Restrict internet access to within the secure zone, using proxies or equivalent controls
  • 2.1 Internal Data Flow Security for Operator PCs: Ensure operator workstations used for SWIFT access are appropriately secured
  • 2.2 Security Updates: Ensure SWIFT components and associated operator systems are maintained with security patches
  • 2.3 System Hardening: Remove unnecessary software, utilities, and features from SWIFT components and operator systems
  • 2.5A External Transmission Data Confidentiality and Integrity: Protect the confidentiality and integrity of SWIFT-related data transmitted between users and service providers
  • 2.7 Vulnerability Scanning: Conduct vulnerability scanning of SWIFT-related systems at least annually
  • 2.9 Transaction Business Controls: Implement controls to detect and prevent unauthorized transactions through monitoring of transaction activity and behavioural patterns
  • 4.1 Password Policy: Enforce a password policy meeting minimum standards for SWIFT user accounts
  • 5.1 Logical Access Controls: Authenticate and authorize all individual users accessing SWIFT-related components
  • 5.2 Token Management: Manage and protect hardware and software tokens used for SWIFT access, including multi-factor authentication
  • 6.1 Malware Protection: Ensure protection against malware on all components within the secure zone
  • 6.2 Software Integrity: Ensure software integrity of SWIFT-related components through file integrity monitoring or equivalent controls
  • 6.3 Database Integrity: Ensure integrity of the database recording SWIFT transactions
  • 7.1 Cyber Incident Response Planning: Define, test, and maintain a cyber incident response plan covering SWIFT-related components
  • 7.2 Security Training and Awareness: Ensure staff with access to SWIFT components receive appropriate security training

Advisory Controls

Advisory controls represent strongly recommended best practices that SWIFT encourages but does not mandate. Organizations demonstrating implementation of advisory controls signal a higher security maturity to counterparties. v2024 includes 7 advisory controls covering areas such as a networked anti-malware solution, penetration testing, and information sharing with SWIFT.

The Annual Assessment and Attestation Process

The CSP requires annual assessment and attestation through SWIFT's KYC Security Attestation (KYC-SA) portal:

PhaseTimingActivities
ScopingQ1Confirm architecture type; identify applicable mandatory and advisory controls
Gap assessmentQ1–Q2Assess current controls against CSCF; identify remediation needs
RemediationQ2–Q3Implement control improvements; document evidence
Independent assessmentQ3Engage a SWIFT-approved independent assessor
Attestation submissionBy annual deadlineSubmit completed KYC-SA attestation through SWIFT portal

Since 2021, SWIFT requires that attestations be validated by an independent external assessor — institutions can no longer self-attest without external validation. The assessor reviews evidence of control implementation and validates the attestation before submission.

SWIFT publishes annual compliance statistics, including the percentage of users that have attested and aggregate compliance rates by control. Non-attesting institutions are flagged in the KYC-SA database, which counterparties can access during due diligence processes.

Costs and Timeline

Institution TypeTypical TimelineEstimated Cost Range
Type A4 user (service bureau, no local footprint)3–4 months$30,000–$60,000
Type A3 user (limited local infrastructure)4–6 months$60,000–$120,000
Type A1/A2 user (full local SWIFT infrastructure)6–9 months$120,000–$300,000

Independent assessment costs typically add $20,000 to $50,000 to total compliance spend, regardless of architecture type.

  • ISO 27001: About 55% overlap. ISO 27001 provides a broad information security management foundation that covers many CSCF control domains. ISO 27001 certification reduces the evidence collection burden for the independent SWIFT assessment but does not cover SWIFT-specific controls such as SWIFT environment segregation and transaction monitoring.
  • PCI DSS: Approximately 45% overlap, particularly in network security, access control, and patch management. Financial institutions subject to both frameworks benefit from shared evidence where controls align, but SWIFT's SWIFT-specific architecture requirements have no PCI DSS equivalent. See /learn/pci-dss for the PCI DSS guide.
  • NIST CSF: About 50% overlap. NIST CSF's Identify, Protect, Detect, Respond, and Recover functions map to the CSCF's three security objectives and provide a useful governance overlay.
  • RBI Cybersecurity Framework: Indian banks connected to SWIFT must comply with both the RBI framework and SWIFT CSP. The overlap in network security and incident response is significant. See the RBI Cybersecurity guide.

How Automation Helps

SWIFT CSP compliance requires annual evidence collection, control testing, and assessor coordination. Compliance automation platforms contribute to:

  • Evidence collection and management: Centralizing control documentation, screenshots, configuration exports, and policy documents needed for independent assessment
  • Control gap tracking: Monitoring remediation status against the annual attestation deadline
  • Policy management: Maintaining current versions of SWIFT-related security policies aligned to CSCF requirements
  • Audit trail: Maintaining records of prior attestations and annual assessment documentation for auditor reference

LowerPlane supports SWIFT CSP compliance programs alongside ISO 27001, PCI DSS, and 50-plus additional frameworks. At $4,000 per year starting price (with a free tier available) and a 9.4/10 AuditXYZ rating, LowerPlane enables financial institutions to manage SWIFT CSP evidence collection and control tracking within a unified compliance platform. See /compare/best-compliance-automation-platforms for a full platform evaluation.

Frequently Asked Questions

What is the KYC Security Attestation and why does it matter?

The KYC Security Attestation (KYC-SA) is SWIFT's platform through which financial institutions submit their annual CSCF attestation. When a bank or financial institution conducts due diligence on a counterparty — as required by their own KYC and AML programs — they can query the counterparty's KYC-SA record to see whether the institution has attested to its CSP compliance and what its attestation status is. Non-attesting institutions or those with flagged compliance gaps may face increased due diligence requirements or, in extreme cases, reluctance from counterparties to transact. The KYC-SA therefore creates market-based enforcement of CSP compliance alongside SWIFT's own oversight mechanisms.

What does the mandatory transaction monitoring requirement (Control 2.9) involve?

Control 2.9 (Transaction Business Controls) requires SWIFT users to implement controls that detect and investigate unusual or unauthorized transaction activity within their SWIFT payment activity. This includes setting and maintaining payment activity profiles (expected transaction patterns for each counterparty), reviewing transactions that deviate from expected patterns, and investigating flagged transactions before processing. Many institutions implement this through SWIFT's Payment Controls service, which provides rule-based screening of outgoing SWIFT messages before they are transmitted. The Bangladesh Bank heist that triggered the CSP's creation involved fraudulent SWIFT messages that bypassed the absence of such controls.

Can small financial institutions comply with SWIFT CSP on a limited budget?

Yes, particularly for Type A3 and A4 architecture types where the service bureau carries primary responsibility for infrastructure security. Smaller institutions using a service bureau for their SWIFT connectivity typically face the most limited mandatory control scope — covering primarily their operator workstations, user access management, and transaction monitoring rather than SWIFT messaging infrastructure security. For these institutions, total compliance costs can be in the $30,000–$60,000 range including the independent assessment. SWIFT also provides implementation guidance, templates, and a community through the CSP to support smaller institutions.

How does SWIFT enforce CSP compliance?

SWIFT uses a combination of mechanisms. First, attestation status is visible to counterparties through the KYC-SA portal, creating peer pressure and due diligence incentives. Second, SWIFT can flag non-compliant institutions to their national central bank supervisors, who may take regulatory action under their own authority. Third, SWIFT can restrict or suspend network access for institutions with persistent compliance failures. SWIFT also conducts targeted SWIFT-initiated and customer-requested assessments for specific high-risk institutions. The overall enforcement framework relies heavily on market mechanisms — the reputational and commercial consequences of being flagged as non-compliant are substantial for institutions that depend on correspondent banking relationships.

What changed between CSCF v2023 and CSCF v2024?

Each CSCF version update adds, removes, or reclassifies controls. SWIFT publishes change summaries with each release. The trend across recent versions has been increasing the number of mandatory controls and tightening requirements around transaction monitoring, privileged access management, and cybersecurity detection capabilities. Institutions should review each new CSCF version against their current attestation to identify changes in applicability or control expectations, typically in Q4 before the new version's assessment cycle begins. SWIFT provides a self-assessment workbook and guidance documentation to support this review.

Request a SWIFT CSP consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001Medium55%
NIST CSFMedium50%
PCI DSSLow45%

Related frameworks

Get matched with a SWIFT CSP auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.