SWIFT CSP / CSCF v2025/v2026: KYC-SA Assessment and Penetration Testing Guide
An authoritative guide to the SWIFT Customer Security Controls Framework (CSCF v2025/v2026), detailing all 32 controls, mandatory annual independent assessment expectations, and Control 1.1 scope segmentation testing methodologies.
SWIFT CSP and CSCF v2025/v2026 Architecture
The SWIFT Customer Security Programme (CSP) establishes mandatory cybersecurity baselines to safeguard the global financial messaging ecosystem.


- Structured around 3 overarching security principles: Secure your Environment, Know and Limit Access, and Detect and Respond.
- Comprises 7 security objectives and 32 controls: In CSCF v2025, 25 mandatory controls (must do) and 7 advisory controls (should do).
- Transition to CSCF v2026: Control 2.4 (Back Office Data Flow Security) transitions from Advisory 2.4A (should do) to Mandatory Control 2.4 (must do) for bridging servers (26 mandatory, 6 advisory), and customer client connectors are incorporated into mandatory control scope.
- Enforceable across all SWIFT-connected financial institutions globally, including commercial banks and specialized financial institutions in Thailand.
- Requires organizations to classify their deployment into Architecture Types (A1, A2, A3, A4, or B) to determine their applicable control baseline.
Mandatory Independent Assessment and KYC-SA Attestation
SWIFT mandates that every connected institution complete an annual independent assessment and submit their attestation via the KYC-SA portal.


- Mandatory requirement (must do): Assessments must be conducted as a Community Standard Independent Assessment by qualified external assessors or an independent internal audit function.
- Lead assessors must hold globally recognized professional credentials such as CISSP, CISA, CRISC, or offensive security certifications.
- Attestation window (must do): Annual attestations must be renewed and published in the SWIFT KYC Security Analytics (KYC-SA) directory between July 1 and December 31 annually.
- SWIFT reserves the right to report non-compliant institutions directly to international counterparties and national regulators including the Bank of Thailand.
Control 1.1 Scope Segmentation Testing and Back Office Security
Control 1.1 mandates strict physical or logical segregation of the SWIFT secure zone from general corporate enterprise networks.


- Mandatory requirement (must do): Independent scope segmentation testing must be performed at least annually and upon network changes to validate that perimeter firewalls enforce strict isolation.
- Assessments evaluate firewall rules, VLAN isolation, jump server / bastion host hardening, and multi-factor authentication enforcement.
- Control 2.4 enhancement: Back-office bridging servers interfacing directly with SWIFT messaging systems must enforce strict data flow protection to prevent unauthorized message tampering.
- Penetration testing evaluates host configuration hardening, session security timeouts, least-privilege administrative access, and anti-tampering.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| Control 1.1 | SWIFT Environment Protection (Network Segmentation) | Strictly isolate the SWIFT Secure Zone from general enterprise networks and perform independent segmentation penetration testing | At least annually and following significant network changes |
| Control 2.3 | System Hardening Baseline and Operating System Security | Disable unnecessary services, enforce baseline configurations, and restrict communication protocols into the Secure Zone | Continuous enforcement and annual independent review |
| Control 4.2 | Multi-Factor Authentication (MFA) | Mandate MFA for all interactive access into SWIFT components, jump hosts, and remote operator connections | Enforced continuously across all sessions |
| KYC-SA Assessment Policy | Community-Standard Independent Assessment Mandate | Independent validation of compliance across all mandatory CSCF controls by qualified external or independent assessors | Annually submitted to SWIFT KYC-SA by December 31 |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.