Onwyn › Standards › SWIFT Customer Security Programme (CSCF v2026)
Scheme / framework · CSCF v2026SWIFT Customer Security Programme (CSCF v2026)
The Customer Security Programme is SWIFT's mandatory security regime for every institution connected to the SWIFT network. It sets out the Customer Security Controls Framework — 32 controls across three objectives and seven principles — and requires each user to attest annually against it, supported by an independent assessment. Which controls apply depends on your architecture type (A1, A2, A3, A4 or B), and controls move between advisory and mandatory as the framework is revised: 2.4 Back-Office Data Flow Security became mandatory in v2026. Attestation for v2026 runs July to December 2026. This pack carries every control for completeness; scope it to your architecture before working it, and confirm mandatory status against the CSCF publication for your attestation year, because published summaries of the mandatory/advisory split disagree with each other and only SWIFT's own document governs.
What this standard asks for
Every requirement in SWIFT Customer Security Programme (CSCF v2026), grouped the way the standard groups them. In the Semantic Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
P1 · Restrict internet access & protect critical systems
5 requirements
- 1.1SWIFT Environment Protection
- 1.2Operating System Privileged Account Control
- 1.3Virtualisation or Cloud Platform Protection
- 1.4ARestriction of Internet Access
- 1.5ACustomer Environment Protection
P2 · Reduce attack surface and vulnerabilities
11 requirements
- 2.1Internal Data Flow Security
- 2.2Security Updates
- 2.3System Hardening
- 2.4Back-Office Data Flow Security
- 2.5AExternal Transmission Data Protection
- 2.6Operator Session Confidentiality and Integrity
- 2.7Vulnerability Scanning
- 2.8AOutsourced Critical Activity Protection
- 2.9ATransaction Business Controls
- 2.10Application Hardening
- 2.11ARMA Business Controls
P3 · Physically secure the environment
1 requirement
- 3.1Physical Security
P4 · Prevent compromise of credentials
2 requirements
- 4.1Password Policy
- 4.2Multi-Factor Authentication
P5 · Manage identities and segregate privileges
4 requirements
- 5.1Logical Access Control
- 5.2Token Management
- 5.3APersonnel Vetting Process
- 5.4Physical and Logical Password Storage
P6 · Detect anomalous activity
5 requirements
- 6.1Malware Protection
- 6.2Software Integrity
- 6.3Database Integrity
- 6.4Logging and Monitoring
- 6.5AIntrusion Detection
P7 · Plan for incident response and information sharing
4 requirements
- 7.1Cyber Incident Response Planning
- 7.2Security Training and Awareness
- 7.3APenetration Testing
- 7.4AScenario-Based Risk Assessment
Attestation & independent assessment
2 requirements
- ATT.1Determine architecture type and control scope
- ATT.2Independent assessment and annual attestation
The documents you will end up with
The recommended document set for SWIFT Customer Security Programme (CSCF v2026) — 12 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
The top-level statement of how the secure zone is defined, bounded and governed, and who owns it.
Least privilege, segregation of duties and the review cycle for every account reaching the SWIFT environment.
Issue, assignment, storage, revocation and destruction of authentication tokens and HSM backup devices.
The baseline each in-scope platform and SWIFT application is built to, and how deviations are recorded.
Scanning cadence, patch SLAs by severity, and how exceptions are justified and time-bound.
Cipher suites, key sizes and the protection applied to internal, back-office and external flows.
Which events are logged, how logs are protected from the administrators they record, retention, and who reviews them.
SWIFT-specific response steps, the notification path to SWIFT, and the exercise programme.
Role-differentiated training for SWIFT operators and staff, including social-engineering and synthetic-media techniques.
Contractual security obligations on providers operating SWIFT components, and how their assurance is obtained and reviewed.
Value, currency, counterparty and timing limits, and the review of RMA authorisations against actual traffic.
How the architecture type is determined each year, how the independent assessment is scoped and commissioned, and how attestation is submitted.
Start SWIFT Customer Security Programme today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.