Kilde › Guides › SWIFT CSP › SWIFT CSP architecture types: A1 to B,…
Current to 26 August 2026 · updates land in the changelog.
Everything in your attestation hangs off one early answer: your architecture type. Get it wrong and you attest against the wrong control set — the misclassification assessors describe as the most common structural error, and the one v2026 made easier to commit by redefining what counts as a connector.
| Type | Your footprint |
|---|---|
| A1 | You own the communication interface |
| A2 | You own the messaging interface; a provider owns comms |
| A3 | A SWIFT-footprint connector on your premises (Alliance Cloud SIL, Direct Link, Lite2 AutoClient, Microgateway) |
| A4 | A customer connector — file-transfer client or server, middleware, in-house app on SWIFT or provider APIs — talking application-to-application (WebAccess front-end webservers included) |
| B | No local footprint: humans in a browser GUI — with operator PCs still in scope as general-purpose machines |
The line that reclassifies institutions: any locally owned component making the connection application-to-application makes you A4 — and it is the component's technical function and connectivity method that decides, not how incidental it feels. The classic case: a “browser-only” institution with a forgotten SFTP script or middleware feed uploading payment files. That script is a customer connector; the institution is A4; and roughly an extra control-set's worth of expectations (including A4-only 1.5 Customer Environment Protection) applies. Ownership follows the BIC — hosting location is irrelevant, so “it runs in the cloud” changes nothing.
The v2026 framework makes customer connectors mandatory in-scope components across a broad set of controls, and SWIFT's own change material acknowledges the consequence: some prior Architecture-B users must now attest as A4. The v2026 changes guide covers the full delta. Control counts per type are approximations in public material — the per-type applicability lives in the grid in your own CSCF download, which is the thing to walk, row by row, before July.
Assessor-documented traps: carrying forward last year's type without revalidation; operator PCs assumed out of scope; hosted components assumed to be the provider's problem (accountability doesn't transfer); test systems touching production credentials quietly entering scope. The classification worksheet in a good scoping exercise produces the artifact that matters: a components register with the technical function of each item and the resulting type, dated this cycle.
The SWIFT CSP Evidence Pack: the v2026 delta map, the architecture & scoping worksheet, the control 2.4 evidence workbook, the full 26-control evidence checklist, the independent-assessment and attestation runbooks, the service-bureau file and the update tracker — independent, built from public assessor consensus. Most controls fail on evidence, not implementation; this pack is the evidence layer.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
Independent publication by Kilde — not affiliated with, endorsed by, or approved by S.W.I.F.T. SC. SWIFT is a registered trademark of S.W.I.F.T. SC. Controls are identified by number and short official title only; nothing on this page restates SWIFT's controls text, and all descriptions are our own orientation built from public assessor material — not legal advice, not security consulting, not an independent assessment. Download the CSCF v2026 yourself from SWIFT's Knowledge Centre (publication page cscf_dd/70.0 — free, no login) and verify everything against it. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com