Framework Financial Services
SWIFT CSP
The Swift Customer Security Programme is the security regime Swift imposes on every organization connected to its messaging network. Its core document, the Customer Security Controls Framework (CSCF), lists mandatory and advisory controls grouped under three objectives: secure your environment, know and limit access, and detect and respond.
Each year users attest to their compliance with the current CSCF in the KYC-Security Attestation application, and since 2021 every attestation must be supported by an independent assessment rather than self-assessment alone.
In writing, a Swift user needs a documented architecture type decision, a control-by-control assessment with evidence for each mandatory control, the independent assessor's report, and the policies that sit behind the controls: privileged access, password and multi-factor authentication, change and patch management, logging and monitoring, and incident response.
Counterparties can request to see the attestation, and Swift may report non-compliant users to their supervisors.
help
Who has to comply
Every Swift user with a BIC connected to the network: banks, market infrastructures, corporates, and service bureaus. The applicable mandatory controls depend on the user's architecture type (A1 through A4, or B).
What the assessor asks to see
The assessor asks for the architecture type and scope definition, the secure zone and network segmentation design, operator PC and privileged account controls, multi-factor authentication configuration, patching and vulnerability scanning records, logging and monitoring evidence, back-office data flow security, the incident response plan and exercise records, staff security training, and the previous year's attestation and assessment report.
Named assessors
Swift publishes the directory of CSP assessment providers on swift.com. The directory page could not be retrieved while this profile was written, so no firms are named here; use the registry link to filter by region and number of certified assessors.
Assessors
Who assesses SWIFT CSP
An independent assessment by either an internal second or third line of defense function (risk, compliance, internal audit) that is independent of the first line, or an external assessment provider. Swift maintains a directory of CSP assessment providers that employ certified assessors.
Accredited by Swift sets eligibility for the assessment provider directory; listed companies employ at least two assessors who passed the Swift CSP assessor certification exam. There is no separate accreditation body.
Public register of assessors: https://www.swift.com/myswift/customer-security-programme/csp-certified-assessors-directory
No firm has claimed a SWIFT CSP assessor listing yet. Claim yours →
Consultants
Who helps with SWIFT CSP
Cyber consultancies and audit firms with Swift-certified assessors, plus service bureaus that support smaller users. Engagements are typically an annual readiness review followed by the independent assessment and help completing the KYC-SA submission.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a SWIFT CSP consultant listing yet. Claim yours →
Software
Tools for SWIFT CSP
Tools that name this framework in their own material.
No firm has claimed a SWIFT CSP tool listing yet. Claim yours →
Related reading
- Swift Customer Security Programme v2025Covers the CSCF v2025 changes, the Type B to A4 architecture shift, and what a certified assessor is expected to do.BDO
- SWIFT CSCF v2025: Changes for Architecture Type BAn auditor explains exactly who the customer client connector change catches and which extra controls come into scope.usd AG
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SWIFT CSP
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SWIFT CSP
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.