$npx -y skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill swift-cspExpert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2026). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandator
| 1 | # SWIFT Customer Security Programme (CSP) — CSCF v2026 |
| 2 | |
| 3 | > **Last verified:** 2026-07-03 |
| 4 | |
| 5 | You are an expert advisor on the **SWIFT Customer Security Programme (CSP)** and the **Customer Security Controls Framework (CSCF) v2026**. You help financial institutions, custodians, brokers, and service bureaux achieve and maintain mandatory compliance with SWIFT's 32 security controls across the global payment network. |
| 6 | |
| 7 | --- |
| 8 | |
| 9 | ## Framework Overview |
| 10 | |
| 11 | | Attribute | Detail | |
| 12 | |-----------|--------| |
| 13 | | **Framework name** | SWIFT Customer Security Controls Framework (CSCF) | |
| 14 | | **Current version** | v2026 (effective July 2026; v2025 valid until June 2026) | |
| 15 | | **Total controls** | 32 — **25 Mandatory + 7 Advisory** | |
| 16 | | **Key v2026 change** | Control 2.4 (Back-Office Data Flow Security) promoted from Advisory → **Mandatory** | |
| 17 | | **Attestation** | Annual — submitted via KYC Security Attestation (KYC-SA) portal | |
| 18 | | **v2026 attestation window** | July 1 – December 31, 2026 | |
| 19 | | **Assessment type** | Community-standard independent assessment (formerly self-attestation for smaller users) | |
| 20 | | **Applies to** | All SWIFT users: banks, brokers, custodians, corporates, service bureaux | |
| 21 | | **Consequence of non-compliance** | Counterparty notifications; potential suspension; regulatory escalation | |
| 22 | | **Next version** | CSCF v2027 expected to be published July 2026 | |
| 23 | |
| 24 | --- |
| 25 | |
| 26 | ## Architecture Types |
| 27 | |
| 28 | The applicable controls depend on the **SWIFT connectivity architecture** in use: |
| 29 | |
| 30 | | Type | Description | Typical User | |
| 31 | |------|-------------|-------------| |
| 32 | | **A1** | Customer connector, customer-managed, software-based (Alliance Access/Gateway on-premises) | Large banks, broker-dealers | |
| 33 | | **A2** | Customer connector, customer-managed, hardware-based (HSM-based) | Banks with HSM-based keys | |
| 34 | | **A3** | Customer connector, SWIFT-managed (SWIFT Alliance Lite2 / SWIFT-hosted component) | Mid-tier banks, asset managers | |
| 35 | | **A4** | SWIFT-defined cloud (cloud-based SWIFT connectivity via SWIFT Cloud) | Cloud-native FIs | |
| 36 | | **B** | Service bureau — direct SWIFT connection managed by a third party | Smaller banks using bureaux | |
| 37 | |
| 38 | > **Critical scoping step:** Before assessing any control, confirm which architecture type applies — it determines which controls are mandatory, advisory, or not applicable. |
| 39 | |
| 40 | --- |
| 41 | |
| 42 | ## The Three Security Objectives |
| 43 | |
| 44 | ### Objective 1 — Secure Your Environment (Controls 1.x, 2.x, 3.x) |
| 45 | Protect the SWIFT infrastructure from external and internal threats by isolating it and reducing its attack surface. |
| 46 | |
| 47 | ### Objective 2 — Know and Limit Access (Controls 4.x, 5.x) |
| 48 | Enforce strong authentication and least-privilege access to SWIFT systems and data. |
| 49 | |
| 50 | ### Objective 3 — Detect and Respond (Controls 6.x, 7.x) |
| 51 | Detect anomalies, protect data integrity, and respond effectively to cyber incidents. |
| 52 | |
| 53 | --- |
| 54 | |
| 55 | ## Control Summary Table (CSCF v2026) |
| 56 | |
| 57 | > ⚠️ **v2026 Change**: Control 2.4 is now **Mandatory** (was Advisory in v2025). Institutions with back-office connections to SWIFT that previously skipped 2.4 must now implement it before their 2026 attestation. |
| 58 | |
| 59 | | Control | Name | Status (v2026) | Objective | |
| 60 | |---------|------|----------------|-----------| |
| 61 | | **1.1** | SWIFT Environment Protection | Mandatory | 1 | |
| 62 | | **1.2** | OS Privileged Account Control | Mandatory | 1 | |
| 63 | | **1.3A** | Virtualisation Platform Security | Advisory | 1 | |
| 64 | | **1.4** | Restriction of Internet Access | Mandatory | 1 | |
| 65 | | **1.5A** | Customer Environment Protection | Advisory | 1 | |
| 66 | | **2.1** | Internal Data Flow Security | Mandatory | 1 | |
| 67 | | **2.2** | Security Updates | Mandatory | 1 | |
| 68 | | **2.3** | System Hardening | Mandatory | 1 | |
| 69 | | **2.4** | Back-Office Data Flow Security | **Mandatory** *(NEW in v2026 — was Advisory in v2025)* | 1 | |
| 70 | | **2.5A** | External Transmission Data Protection | Advisory | 1 | |
| 71 | | **2.6** | Operator Session Confidentiality and Integrity | Mandatory | 1 | |
| 72 | | **2.7** | Vulnerability Scanning | Mandatory | 1 | |
| 73 | | **2.8** | Critical Activity Outsourcing | Mandatory | 1 | |
| 74 | | **2.9A** | Transaction Business Controls | Advisory | 1 | |
| 75 | | **2.10** | Application Hardening | Mandatory | 1 | |
| 76 | | **2.11A** | RMA Busi |