Kilde › Guides › SWIFT CSP › SWIFT CSP architecture types: A1 to B,…

SWIFT CSP architecture types: A1 to B, and the reclassification trap in v2026

Current to 26 August 2026 · updates land in the changelog.

Everything in your attestation hangs off one early answer: your architecture type. Get it wrong and you attest against the wrong control set — the misclassification assessors describe as the most common structural error, and the one v2026 made easier to commit by redefining what counts as a connector.

The five types, in one breath each

TypeYour footprint
A1You own the communication interface
A2You own the messaging interface; a provider owns comms
A3A SWIFT-footprint connector on your premises (Alliance Cloud SIL, Direct Link, Lite2 AutoClient, Microgateway)
A4A customer connector — file-transfer client or server, middleware, in-house app on SWIFT or provider APIs — talking application-to-application (WebAccess front-end webservers included)
BNo local footprint: humans in a browser GUI — with operator PCs still in scope as general-purpose machines

The B→A4 trap

The line that reclassifies institutions: any locally owned component making the connection application-to-application makes you A4 — and it is the component's technical function and connectivity method that decides, not how incidental it feels. The classic case: a “browser-only” institution with a forgotten SFTP script or middleware feed uploading payment files. That script is a customer connector; the institution is A4; and roughly an extra control-set's worth of expectations (including A4-only 1.5 Customer Environment Protection) applies. Ownership follows the BIC — hosting location is irrelevant, so “it runs in the cloud” changes nothing.

v2026 sharpened exactly this edge

The v2026 framework makes customer connectors mandatory in-scope components across a broad set of controls, and SWIFT's own change material acknowledges the consequence: some prior Architecture-B users must now attest as A4. The v2026 changes guide covers the full delta. Control counts per type are approximations in public material — the per-type applicability lives in the grid in your own CSCF download, which is the thing to walk, row by row, before July.

Classify with evidence, not memory

Assessor-documented traps: carrying forward last year's type without revalidation; operator PCs assumed out of scope; hosted components assumed to be the provider's problem (accountability doesn't transfer); test systems touching production credentials quietly entering scope. The classification worksheet in a good scoping exercise produces the artifact that matters: a components register with the technical function of each item and the resulting type, dated this cycle.

Related guides

Quick answers

What decides a SWIFT CSP architecture type?
The technical function and connectivity method of locally owned components: any local component connecting application-to-application makes the institution A4, regardless of hosting location — ownership follows the BIC.
Can a browser-only institution really be A4?
Yes — that is the classic v2026 trap: an unnoticed file-transfer script or middleware feed is a customer connector, reclassifying a 'Type B' institution to A4 with a larger control set including 1.5 Customer Environment Protection.
Where do I find which controls apply to my type?
In the applicability grid of your own CSCF v2026 download from SWIFT's Knowledge Centre — public control-count figures are approximations; the grid is authoritative.
Walk into your assessment with the evidence pre-indexed.

The SWIFT CSP Evidence Pack: the v2026 delta map, the architecture & scoping worksheet, the control 2.4 evidence workbook, the full 26-control evidence checklist, the independent-assessment and attestation runbooks, the service-bureau file and the update tracker — independent, built from public assessor consensus. Most controls fail on evidence, not implementation; this pack is the evidence layer.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

Independent publication by Kilde — not affiliated with, endorsed by, or approved by S.W.I.F.T. SC. SWIFT is a registered trademark of S.W.I.F.T. SC. Controls are identified by number and short official title only; nothing on this page restates SWIFT's controls text, and all descriptions are our own orientation built from public assessor material — not legal advice, not security consulting, not an independent assessment. Download the CSCF v2026 yourself from SWIFT's Knowledge Centre (publication page cscf_dd/70.0 — free, no login) and verify everything against it. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com