Kilde › Guides › SWIFT CSP › CSCF v2026, as a delta: one promotion,…

CSCF v2026, as a delta: one promotion, one redefinition, and a dozen tightenings

Current to 26 August 2026 · updates land in the changelog.

Two changes carry the year, and neither is subtle. First: 2.4 Back Office Data Flow Security is promoted from advisory to mandatory — the framework's only promotion this cycle, and the one that lands as a project rather than a policy edit. Second: customer connectors became mandatory in-scope components of 14 controls — the redefinition that quietly reclassifies architectures.

The headline numbers

v2026 totals 32 controls: 26 mandatory + 6 advisory (v2025 ran 25M+7A). The advisory set is 2.5A, 2.11A, 5.3A, 6.5A, 7.3A, 7.4A. “Connector” now covers server or client endpoints connecting to a service provider or SWIFT — file-transfer clients, middleware, API integrations — with SWIFT's own material acknowledging that some prior Architecture-B users must now attest as A4 (the reclassification trap).

Why 2.4 is the project

The newly mandatory 2.4 protects the corridor between back office and SWIFT infrastructure, and its evidence burden is inventory-shaped: flow inventories, diagrams, bridging-server registers, per-flow pattern claims, written risk acceptances. In force for 2026: new direct flows and bridging-server legs; legacy direct flows stay advisory until tentatively v2028 — tentative and announced, not in force. Institutions that never inventoried the corridor are doing discovery work, not documentation work.

The smaller tightenings, so nothing surprises you

One announced-not-in-force item to track, not act on: the Alliance Connect SD-WAN evolution (2026–2028) naming a new on-premises VPN component in scope.

Sequencing the cycle

The assessor-consensus order: revalidate architecture type first (the redefinition may have moved you), walk the applicability grid in your own CSCF download, run the 2.4 flow inventory early (it has the longest tail), then close evidence gaps control by control before the window closes 31 December.

Related guides

Quick answers

What changed in CSCF v2026?
One promotion — 2.4 Back Office Data Flow Security became mandatory — plus customer connectors becoming in-scope components of 14 controls, for a total of 26 mandatory + 6 advisory. Smaller tightenings touch MFA for privileged remote access, WMI/PowerShell hardening, non-Windows malware coverage and privileged-account scope.
Does CSCF v2026 change architecture classifications?
Effectively yes for some: the connector redefinition means institutions with locally owned application-to-application components — file-transfer clients, middleware, API integrations — attest as A4 even if they previously ran as Type B.
Walk into your assessment with the evidence pre-indexed.

The SWIFT CSP Evidence Pack: the v2026 delta map, the architecture & scoping worksheet, the control 2.4 evidence workbook, the full 26-control evidence checklist, the independent-assessment and attestation runbooks, the service-bureau file and the update tracker — independent, built from public assessor consensus. Most controls fail on evidence, not implementation; this pack is the evidence layer.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

Independent publication by Kilde — not affiliated with, endorsed by, or approved by S.W.I.F.T. SC. SWIFT is a registered trademark of S.W.I.F.T. SC. Controls are identified by number and short official title only; nothing on this page restates SWIFT's controls text, and all descriptions are our own orientation built from public assessor material — not legal advice, not security consulting, not an independent assessment. Download the CSCF v2026 yourself from SWIFT's Knowledge Centre (publication page cscf_dd/70.0 — free, no login) and verify everything against it. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com