Kilde › Guides › SWIFT CSP › The 2026 SWIFT CSP attestation: window…

The 2026 SWIFT CSP attestation: window, roles, and what happens if you don't

Current to 26 August 2026 · updates land in the changelog.

The annual attestation window runs 1 July to 31 December 2026, against CSCF v2026, inside the KYC Security Attestation (KYC-SA) application — each year's control set goes live there in early July. If your institution connects to SWIFT, this is not optional paperwork: counterparties and supervisors can see how you stand.

The two roles, and who may hold them

KYC-SA splits the act in two: a Submitter completes the attestation; an Approver signs it off. The Approver must be the CISO — or an officer of similar seniority (CIO, CRO, chief auditor), with the CEO as last resort — and the approver's name and function are visible to counterparties. That visibility is deliberate: a senior officer personally signs the security claim, and the network can see who.

Independent assessment is not optional

Since the 2021 cycle, attestations require an independent assessment — internal second/third line or external assessor, with a certified lead. Attesting without one is itself a reportable state.

The triggers people miss

Consequences: the visibility machine

SWIFT reserves the right to report to your supervisors — for late or absent attestation, attested non-compliance, missing independent assessment, or reliance on non-compliant providers — and supervisors hold real-time KYC-SA access of their own. Counterparties see your status colour-coded: green valid, amber expired, grey none. In correspondent banking, grey is a due-diligence question you've forced your counterparties to ask.

Related guides

Quick answers

When is the SWIFT CSP attestation deadline for 2026?
The annual window runs 1 July to 31 December 2026 in KYC-SA, against CSCF v2026. Material infrastructure changes additionally trigger re-attestation within 3 months, any time of year.
Who must approve a SWIFT CSP attestation?
The CISO — or an officer of similar seniority (CIO, CRO, chief auditor; CEO as last resort). The approver's name and function are visible to counterparties in KYC-SA.
What happens if an institution doesn't attest?
Counterparties see the status (green/amber/grey), and SWIFT reserves the right to report late or absent attestation, attested non-compliance, or missing independent assessment to the institution's supervisors, who have their own KYC-SA access.
Walk into your assessment with the evidence pre-indexed.

The SWIFT CSP Evidence Pack: the v2026 delta map, the architecture & scoping worksheet, the control 2.4 evidence workbook, the full 26-control evidence checklist, the independent-assessment and attestation runbooks, the service-bureau file and the update tracker — independent, built from public assessor consensus. Most controls fail on evidence, not implementation; this pack is the evidence layer.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

Independent publication by Kilde — not affiliated with, endorsed by, or approved by S.W.I.F.T. SC. SWIFT is a registered trademark of S.W.I.F.T. SC. Controls are identified by number and short official title only; nothing on this page restates SWIFT's controls text, and all descriptions are our own orientation built from public assessor material — not legal advice, not security consulting, not an independent assessment. Download the CSCF v2026 yourself from SWIFT's Knowledge Centre (publication page cscf_dd/70.0 — free, no login) and verify everything against it. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com