Swift Customer Security Programme v2026

Enhancing global financial security 

Colleagues of Cyber Security
The main goal of the Swift Customer Security Programme (CSP) initiative is to strengthen the security of the global financial community. For financial institutions, the CSP is becoming increasingly important in risk and compliance programmes because it creates value beyond mere compliance by helping improve security hygiene. 

So what changes with CSCF v2026? In this article, we take you through the new requirements, show how Swift is responding to emerging technologies such as Frontier AI and explain how we, as one of the top firms in the Certified Assessors Directory, can help you.

What’s changing in CSCF v2026?

Evolution of Swift

© Swift

Control 2.4 - Back Office Data Flow Security becomes mandatory in v2026

As announced by Swift, this year the first phase of control 2.4 has become mandatory. The control objective is to ensure the confidentiality, integrity, and authenticity of data exchanged between the user’s Swift infrastructure and the first back-office systems (“first hops”). In practice, this boils down to strong encryption, either end-to-end between the back-office and Swift systems, or by encrypting each leg of the data transfer related to payment messages. More details of implementation can be found in the CSCF (here) on page 52 and page 132. 

Phase 1 (starting with CSCF v2026):

New data connections and the systems enabling them must be protected right away, using strong security measures. This ensures that any new data flows your systems use to exchange data are appropriately secured against cyber threats. 

Phase 2 (expected in CSCF v2028):

Older, existing data (legacy) connections will also need to be secured according to modern encryption standards. Organisations should start planning and prioritising which older connections to protect first, based on risk. 

  Diagram showing the implementation phases of control 2.4. 

  © Swift

Moving from Type B to A4: Customer Client Connector is now a mandatory component

Organisations using any kind of application-to-application communication in the Swift payment process will typically fall under Type A4. Only organisations still fully manually inputting payments in a GUI can attest as Type B. The system enabling these (semi-) automated payments is called a “customer client connector,” and must be protected by several key security controls. 

Last year, protecting these connectors was only recommended, but now it is mandatory. This means every customer connector, regardless of whether it’s a server-based or a client connector, must meet basic cyber security standards. Examples of these client connectors are IBM MQ clients, sFTP clients and API clients.

These changes matter because the connections between Swift infrastructure, customer connectors and back-office systems are often where payment data leaves the most tightly controlled environment. If these flows are not properly identified, encrypted and monitored, attackers may be able to intercept, manipulate or misuse sensitive transaction data before traditional security controls detect the issue. 

© Swift

Emerging technologies – how does Swift respond?

1. Frontier AI systems 

Frontier AI, referring to the most advanced artificial intelligence systems, is becoming an important development in the cyber security landscape. These systems can accelerate activities such as vulnerability discovery, exploit development and threat automation. Think about recent examples such as Anthropic’s Mythos AI, or the incident in which AI agents escaped a sandboxed OpenAI test environment and breached a real company’s system. These recent developments have an impact on all organisations, given how the speed and scale at which cyber threats materialise may increase significantly. 

Swift is proactively responding to AI-driven threats and has developed a clear security plan that includes assessing emerging risks, adopting an assumed breach of mentality, strengthening remediation, and exploring defensive use of AI. 

What does Swift expect of you? Swift’s response to Frontier AI does not introduce separate AI-specific CSCF controls but reinforces the need to implement existing controls with greater urgency, consistency and operational discipline as the time to detect, contain and remediate cyber threats continues to shrink. 

2. Post-Quantum Cryptography (PQC) 

Quantum technology applies the principles of quantum physics to process information in fundamentally new ways, using quantum bits to unlock potential speed advantages for specific problems. While this creates promising opportunities across several domains, it also introduces significant risks for cryptography, making post-quantum readiness an important area of attention for organisations. 

A key risk is “harvest now, decrypt later”, where attackers capture encrypted data today and store it until future quantum computers may be able to break the cryptography protecting it. 

Post-Quantum Cryptography (PQC) consists of new cryptographic algorithms designed to remain secure against future quantum-enabled attacks. Swift’s objective is to support the migration of its community to new post-quantum cryptography standards by 2030. 

© Swift

BDO’s Swift CSP Center of Excellence

Meet our global Center of Excellence (CoE), aimed at enhancing the effectiveness of our assessments and global standardisation. Our BDO network of Swift CSP Certified Assessors means your assessments are performed by experienced, certified assessors. You can feel confident about your compliance status and will receive the most relevant and actionable recommendations to further enhance your cyber security. 

The Center of Excellence (CoE) performs over 100 assessments every year. Its success can be attributed to two significant advantages: 

Our Certified Assessors can perform a review of all assessments worldwide, ensuring high-quality globally. This allows our clients to demonstrate to their counterparties and Swift that their audit was conducted by a Certified Assessor, thereby increasing the value of their attestation.  

BDO is active in over 160 countries across the world, so you get the same quality of service wherever you operate. Our dedicated CoE works alongside local BDO teams to keep quality standards equally high across the entire network.

Why BDO?

As your trusted partner, BDO will help you achieve your objectives in a pragmatic yet qualitative way. 

  • As Swift Certified Assessor, our assessments are of the highest quality and strive to add value to your organisation instead of just tick-the-box compliance. Our detailed yet straightforward reporting pinpoints what areas you should focus on. 
  • As implementation partners, we focus on the high-risk areas first, making sure your main security gaps are covered. Then, we focus on compliance areas, to ensure an assessment will pass the test. 

Thanks to BDO’s broad expertise, experience and proven record of assisting organisations in both the implementation and the assessment of Swift security controls, you can rely on both enhanced security and compliance with the CSP framework. 

BDO tailors its work to each individual client’s needs, to ensure our solutions add value where you most need it. Ranging from implementing an ISO27K-compliant GRC security program or a third party security management system to providing DORA and NIS2 assessments and implementations – always in a pragmatic way, tailored to your needs.  

Our experts are well-versed in the Swift CSP controls and implementation guidelines, on top of their strong financial sector focus. This enables them to understand the complex regulatory landscape and the evolving cyber security threats. 

All our Lead Auditors have proven experience in Swift CSP assessments, IT audits and ISO27K implementations and assessments, and have relevant certifications including the Swift Certified Assessors certification and a combination of CISA, CISM, CISSP, ISO27K Lead Auditor, etc. Furthermore, our low partner-to-staff ratio means high involvement and guidance from partners and experienced staff, and a solid and stable team to perform the assessments. 

Frequently asked questions

We get many questions from our clients and prospects regarding the scope and depth of the assessment, timelines and compliance. In the dropdowns below, we answer the most common questions.

cyber security audit is a review of an organisations cyber security policies, procedures and technology, following auditing standards as imposed by the Institute of Internal Auditors, for example. The goal is to ensure compliance with specific regulations and/or internal policies by looking back at a certain period of time and verifying the operating effectiveness of the controls  

In contrast, cyber security assessment is more high-level review of an organisations cybersecurity posture to identify potential risks and areas for improvement. As an assessment does not need to follow strict testing and reporting requirements, unlike an audit, the cost is often lower 

Swift recommends conducting an assessment instead of an audit to reduce the cost and workload for internal staff. All the while ensuring quality of the assessment is maintained and focused on the evaluation and review of security controls, and putting less emphasis on scoping, risk assessments and reporting. 

The assessment in 2026 can potentially rely on an assessment performed in 2025, if four conditions are fulfilled for each control: 

  • Last year’s assessment was performed against last year’s version of the CSCF (or more recent) 
  • Last year’s assessment was not itself reliant on the year before or on an external assurance report* 
  • The new CSCF version does not materially affect the implementation 
  • The control design and implementation and Swift user environment have not materially changed 

*Note that you can rely on Third Party Assurance reports such as SOC2, ISAE3000, PCI-DSS 4.0 or ISO27K, as long as the scope of the report covers the Swift CSP controls, and the timing of the report is recent enough the period covered by the report must be no more than 18 months before the attestation is submitted (e.g. an attestation submitted on 24/12/2026 can still rely on a SOC2 Type II report for the period ending 30/06/2025. 

Users are required to confirm their compliance with the mandatory security controls between 1 July and 31 December of each year (whether fully compliant or not!). New joiners or BICs must complete their attestation before accessing the Swift network.  

The KYC Security Attestation application (KYC-SA) is used to submit security attestations. Swift releases the new version of the controls each year in early July, and these controls are then attested against between July and December the next year. 

We strongly urge all Swift users to implement and ensure compliance with the CSP controls as soon as possible. The CSP controls establish a baseline for security hygiene and should be within the capability of each organisation that processes financial transactions. Failing to implement CSP controls puts the organisation at an increased risk of cyber attacks, which can result in severe financial and operational losses and reputational impacts.   

Nevertheless, if you submit a non-compliant attestation, you will not be kicked out of the Swift network. Your non-compliance status will, however, be listed in the KYC-SA directory for your counterparties to see, and Swift will communicate your non-compliance to your financial supervisory authority.  

Swift does ask each user to submit an attestation, even if it is non-compliant. Failure to do so is in breach of your contractual obligations according to the Customer Security Programme (CSP) and Swift Terms and Conditions. 

The typical scope of CSP is the secure zone, the underlying infrastructure (network security such as firewalls, IPS etc) and the middleware and file transfer serversThe back office and the connection to the Swift network are typically not within the scope of the CSP.

Each control has its specific in-scope components that are well-defined in the controls framework. Review this together with your assessor to ensure mutual agreement on the scope of the assessment and to better prepare your staff.

in scope

© Swift

In this case, you will most likely be an architecture type A4 or BDepending on the depth of outsourcing, the responsibilities will be split between you and the third party providing your services (the outsourcing agent) 

The visual below illustrates typical differences in architecture ranging from managed fully in-house to fully outsourced. In the end, your architecture type determines the CSP control in scope, but all responsibility for the assessment remains with you: you must obtain assurance on the compliance of your third parties. 

data managementyou manage

© Swift

Swift has a Knowledge Centre that you can use to find relevant articles, frequently asked questions and general information on Swift product and services. Furthermore, via SwiftSmart, Swift also offers e-learning courses specifically on the Swift CSP. Some useful links: 

Questions about Swift CSP? Don't hesitate to contact our expert Thomas Cornelis

Thomas Cornelis

Thomas Cornelis

Senior Manager Risk Advisory
View bio