Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CSCF v2026 explained

CSCF v2026: What Changed in the 32 SWIFT Controls (Complete Guide)

CSCF v2026 is the version of the Swift Customer Security Controls Framework every Swift user must attest against by 31 December 2026, and it carries the change Swift announced a year in advance: control 2.4, Back Office Data Flow Security, is now mandatory. It also pulls customer client connectors into the mandatory scope of fourteen controls, which moves some users from architecture type B to A4 and changes which controls apply to them.

Swift publishes a new CSCF every July for the following year’s attestation, so two versions are always live — v2026 for the current window, v2027 (published 10 July 2026) for planning — and a user attesting against last year’s control set is attesting against the wrong one. This guide lists what changed in CSCF v2026, the 32 controls with their mandatory or advisory status, the architecture types and the connector reclassification, and what the attestation window requires.

CSCF v2026: 32 controls, 26 mandatory, the 2.4 change and the connector scope
Three objectives, seven principles, 32 controls; 2.4 Back Office Data Flow Security becomes mandatory and customer client connectors enter the scope of fourteen controls.

What changed in CSCF v2026

Swift’s own Overview of Changes in the v2026 detailed description sets out the delta from v2025.

Change Detail Who it affects
2.4 Back Office Data Flow Security becomes mandatory “As announced last year, the control 2.4 Back Office Data Flow Security has become mandatory.” Phased under Appendix H: bridging servers and the flows between them are mandatory now; legacy direct back-office flows remain advisory, tentatively becoming mandatory in 2028 Every architecture with a back-office connection — A1 to A4
Customer client connectors become mandatory in-scope components Of controls 1.2, 1.3, 1.4, 2.2, 2.3, 2.6, 2.7, 3.1, 4.1, 4.2, 5.1, 5.4, 6.1 and 6.4 Users of customer client connectors
Architecture reclassification “Such change requires some users who previously attested as Architecture type B, to attest as A4 when using a customer client connector” Former type B users with a connector
Clarifications WMI and PowerShell named in 2.3 System Hardening; Swift Universal Confirmation in 2.9 Transaction Business Controls; Luna Backup device in 3.1 and 5.4; LSO and RSO named as privileged accounts for 4.2; the Alliance Connect SDWAN/SSR VPN migration running 2026–2028 Users of the named components

The first two changes are the ones that move attestations. A user who attested type B in 2025 with a customer client connector in place attests A4 in 2026, and A4 carries controls B never did. Our guide to SWIFT architecture types covers the five types and how the connector scope decides between them.

The CSCF v2026 structure

The framework has three objectives, seven principles and 32 controls: 26 mandatory and 6 advisory. In CSCF notation the “A” suffix on a control number is the advisory marker, so the identifier itself states the status.

Objective / principle Controls (CSCF v2026) Status
1. Secure your environment — Restrict internet access and protect critical systems from the general IT environment 1.1 Swift Environment Protection · 1.2 Operating System Privileged Account Control · 1.3 Virtualisation or Cloud Platform Protection · 1.4 Restriction of Internet Access · 1.5 Customer Environment Protection All mandatory
Reduce attack surface and vulnerabilities 2.1 Internal Data Flow Security · 2.2 Security Updates · 2.3 System Hardening · 2.4 Back Office Data Flow Security · 2.5A External Transmission Data Protection · 2.6 Operator Session Confidentiality and Integrity · 2.7 Vulnerability Scanning · 2.8 Outsourced Critical Activity Protection · 2.9 Transaction Business Controls · 2.10 Application Hardening · 2.11A RMA Business Controls 2.5A and 2.11A advisory; the rest mandatory
Physically secure the environment 3.1 Physical Security Mandatory
2. Know and limit access — Prevent compromise of credentials 4.1 Password Policy · 4.2 Multi-Factor Authentication Mandatory
Manage identities and segregate privileges 5.1 Logical Access Control · 5.2 Token Management · 5.3A Staff Screening Process · 5.4 Password Repository Protection 5.3A advisory; the rest mandatory
3. Detect and respond — Detect anomalous activity to systems or transaction records 6.1 Malware Protection · 6.2 Software Integrity · 6.3 Database Integrity · 6.4 Logging and Monitoring · 6.5A Intrusion Detection 6.5A advisory; the rest mandatory
Plan for incident response and information sharing 7.1 Cyber Incident Response Planning · 7.2 Security Training and Awareness · 7.3A Penetration Testing · 7.4A Scenario-based Risk Assessment 7.3A and 7.4A advisory; the rest mandatory

Applicability is by architecture type, and it cannot be read from a control’s number: 1.5 applies to A4 only; 1.1, 2.1 and 2.10 apply to A1–A3; 6.3 applies to A1, A2 and A4; controls 1.2, 1.3, 2.3, 2.7, 2.9 and 7.3A apply to all five types including B. Read the applicability matrix in the v2026 document positionally, column by column, and record the result per control — the mistakes most attestation workbooks carry are in this table. Our guide to SWIFT mandatory vs advisory controls covers the status question in depth.

The attestation window

The CSCF v2026 attestation window runs from 1 July to 31 December 2026, submitted through the KYC-SA application. Since 2021 every attestation must be supported by an independent assessment — by an independent internal function or an external assessment provider — covering at least all mandatory controls applicable to the user’s architecture.

Deloitte Canada, reporting on more than 200 assessments in 2025, found that 80% of major financial institutions were non-compliant on at least one mandatory control at their initial assessment, falling to 10% after remediation and reassessment — which is the argument for starting the assessment early in the window rather than in November. Our guide to the KYC-SA application covers the submission; the SWIFT CSP assessment cost post covers what the independent assessment costs.

Preparing for CSCF v2026

  1. Confirm the architecture type first. If a customer client connector is in use, the type is A4, not B, and fourteen controls now include it in scope.
  2. Re-run the applicability matrix. Per control, per architecture, from the v2026 document — not from last year’s workbook.
  3. Treat 2.4 as mandatory and read Appendix H. Bridging servers and the flows between them are in scope now; identify every back-office flow and classify it.
  4. Check the clarifications against your components. WMI and PowerShell hardening, Universal Confirmation in transaction controls, the Luna Backup device, LSO and RSO accounts under MFA.
  5. Book the independent assessment for the first half of the window. Findings need remediation and reassessment before 31 December.
  6. Read v2027 now. Published 10 July 2026, it is the control set for the second half of 2027; what it makes mandatory is what to build this year.

Frequently asked questions

What is CSCF v2026?
The 2026 version of Swift’s Customer Security Controls Framework: 32 controls (26 mandatory, 6 advisory) under three objectives and seven principles, against which Swift users must attest, with an independent assessment, by 31 December 2026.

What changed in v2026?
Control 2.4 Back Office Data Flow Security became mandatory (phased under Appendix H); customer client connectors became mandatory in-scope components of fourteen controls, moving some type B users to A4; and clarifications were added to 2.3, 2.9, 3.1, 4.2 and 5.4.

Which controls are advisory in v2026?
2.5A External Transmission Data Protection, 2.11A RMA Business Controls, 5.3A Staff Screening Process, 6.5A Intrusion Detection, 7.3A Penetration Testing and 7.4A Scenario-based Risk Assessment. Everything else is mandatory.

When is the attestation due?
The window runs 1 July to 31 December 2026, submitted through KYC-SA and supported by an independent assessment of at least all applicable mandatory controls.

Is v2027 already published?
Yes, on 10 July 2026, for attestation in the second half of 2027. Swift publishes each version a year ahead so users can plan.

Where this leaves you

Attest against CSCF v2026, not against the workbook you used last year: confirm the architecture type with the connector rule, re-derive the applicability matrix, treat 2.4 as mandatory, check the named components, and get the independent assessment done early enough to remediate. Then open v2027, because the July publication cycle means next year’s mandatory controls are already known.

References

More on SWIFT CSP

The CSCF Control Implementation Summary, the KYC-SA Self-Attestation Workbook, the Independent Assessment Evidence Pack and the policies and procedures behind all 32 v2026 controls — plus a v2027 transition guide — are in the SWIFT CSP Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.