Kilde › Guides › SWIFT CSP guides for the v2026 cycle: …

SWIFT CSP guides for the v2026 cycle: every control's evidence question, independently explained

Current to 26 August 2026 · updates land in the changelog.

The 2026 SWIFT CSP attestation window runs 1 July – 31 December 2026, against CSCF v2026: 26 mandatory + 6 advisory controls, one headline promotion (2.4 Back Office Data Flow Security), and a connector redefinition that quietly reclassifies architectures. These independent guides orient you control by control — in our own words, at public-assessor-consensus level, always pointing back to your own CSCF download as the source.

Start here

The cycle, end to end

All 32 controls, by objective

Mandatory and advisory (marked “A”), each with the evidence question, what typically satisfies, and the common gap:

Objective 1 — Secure Your Environment1.1 Swift Environment Protection, 1.2 Operating System Privileged Account Control, 1.3 Virtualisation or Cloud Platform Protection, 1.4 Restriction of Internet Access, 1.5 Customer Environment Protection, 2.1 Internal Data Flow Security, 2.2 Security Updates, 2.3 System Hardening, 2.4 Back Office Data Flow Security, 2.5A External Transmission Data Protection, 2.6 Operator Session Confidentiality and Integrity, 2.7 Vulnerability Scanning, 2.8 Outsourced Critical Activity Protection, 2.9 Transaction Business Controls, 2.10 Application Hardening, 2.11A RMA Business Controls, 3.1 Physical Security
Objective 2 — Know and Limit Access4.1 Password Policy, 4.2 Multi-Factor Authentication, 5.1 Logical Access Control, 5.2 Token Management, 5.3A Staff Screening Process, 5.4 Password Repository Protection
Objective 3 — Detect and Respond6.1 Malware Protection, 6.2 Software Integrity, 6.3 Database Integrity, 6.4 Logging and Monitoring, 6.5A Intrusion Detection, 7.1 Cyber Incident Response Planning, 7.2 Security Training and Awareness, 7.3A Penetration Testing, 7.4A Scenario-based Risk Assessment

What's free here — and what the pack adds

These guides (free)Per-control orientation: the question each control answers, the headline evidence artifact, the common gap, what v2026 changed — plus architecture, attestation and assessment mechanics.
The SWIFT CSP Evidence Pack (US$390)The execution layer: the full 26-control evidence checklist with per-control artifact lists, the control 2.4 flow-inventory workbook, the architecture & scoping worksheet, assessment and attestation runbooks, the service-bureau file, assessor handover index, update tracker.

The guides carry the rules, dates and definitions — kept current, no signup. The pack carries the documents you would otherwise build from scratch. See the shape first: free 4-page sample (PDF) · full contents.

Quick answers

When must SWIFT users attest against CSCF v2026?
In the annual window 1 July – 31 December 2026, in KYC-SA — with re-attestation within 3 months after material infrastructure changes, and before go-live for new joiners.
How many controls does CSCF v2026 have?
32: 26 mandatory and 6 advisory. The one promotion this cycle is 2.4 Back Office Data Flow Security, advisory to mandatory; customer connectors also became in-scope components of 14 controls.
Are these guides affiliated with SWIFT?
No — independent publication by Kilde, not affiliated with or endorsed by S.W.I.F.T. SC. Controls are identified by number and short title only; the authoritative text is your own CSCF v2026 download from SWIFT's Knowledge Centre.
Walk into your assessment with the evidence pre-indexed.

The SWIFT CSP Evidence Pack: the v2026 delta map, the architecture & scoping worksheet, the control 2.4 evidence workbook, the full 26-control evidence checklist, the independent-assessment and attestation runbooks, the service-bureau file and the update tracker — independent, built from public assessor consensus. Most controls fail on evidence, not implementation; this pack is the evidence layer.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

Independent publication by Kilde — not affiliated with, endorsed by, or approved by S.W.I.F.T. SC. SWIFT is a registered trademark of S.W.I.F.T. SC. Controls are identified by number and short official title only; nothing on this page restates SWIFT's controls text, and all descriptions are our own orientation built from public assessor material — not legal advice, not security consulting, not an independent assessment. Download the CSCF v2026 yourself from SWIFT's Knowledge Centre (publication page cscf_dd/70.0 — free, no login) and verify everything against it. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com