SWIFT CSP assessment

SWIFT CSP independent assessment, from a UK team

CSCF v2026 makes the independent assessment mandatory: self-attestation alone is no longer accepted. We assess your mandatory controls, review the evidence and hand you an attestation-ready report, at a fixed fee published by architecture type, from a team working in the UK.

The essentials

What the CSP and the CSCF are

The SWIFT Customer Security Programme (CSP) is SWIFT's framework for securing the environments its users connect from. Its core is the Customer Security Controls Framework (CSCF), a published set of security controls every SWIFT user attests against each year. The current version, CSCF v2026, was published in July 2025 and defines 32 controls, of which 26 are mandatory.

Does SWIFT CSP require an independent assessment?

Yes. Under CSCF v2026 the independent assessment is mandatory for every attesting SWIFT user: self-attestation alone is no longer accepted. Your attestation, submitted in KYC-SA between July and 31 December 2026, must be backed by an assessment of your mandatory controls.

Reviewed July 2026, against CSCF v2026.

Scope of the service

Who needs assessing, and what the assessment covers

If your organisation attests in KYC-SA, this applies to you. That is every SWIFT user: banks, but also corporates, market infrastructures and service bureaus with a BIC. The assessment itself has three jobs.

Every mandatory control in your scope

CSCF v2026 defines 32 controls, 26 of them mandatory. Which ones apply to you depends on your architecture type; the assessment works through each in-scope control against the framework's stated objective.

Evidence review, not a questionnaire

An independent assessment tests what you can show, not what you can say. We examine configurations, policies, logs and screenshots against each control, and tell you where the evidence is thin before it becomes a finding.

An attestation-ready report

The deliverable is written for KYC-SA: a control-by-control conclusion your CISO can attest against, plus a plain-English summary for the board and a remediation list ordered by what blocks attestation.

A1 to A4, or B

Your architecture type decides scope and fee

SWIFT classifies every user by how much SWIFT-related infrastructure sits on their side of the connection. The classification is not paperwork: it determines which controls are in scope, how much evidence exists to review, and therefore what the assessment costs.

Type What it means in practice What it does to your assessment
A1 The full stack is yours. You run both a messaging interface and a communication interface, on premises or hosted on your behalf. The widest control scope and the most evidence to review, because every layer of the connection belongs to you.
A2 You own a messaging interface, but the communication interface is operated by a service provider. A broad scope centred on the interface you own and the join to your provider.
A3 You run a SWIFT connector locally that links your applications to a service provider or to SWIFT. Scope concentrates on the connector, the machines it runs on and the flows through it.
A4 You run a customer connector: server-to-server software passing business data to a provider's interface. Similar shape to A3, scoped around the server-to-server link and its supporting systems.
B No SWIFT-specific infrastructure on your side at all. Users reach SWIFT services through a provider's application or APIs. The narrowest scope and the lowest fee, because the smallest part of the chain is yours to secure.

Unsure which row is yours? Most firms can self-place from the middle column, and we confirm it on the scoping call before quoting a penny more than the published fee.

Published fees

A fixed fee, published by architecture type

Assessors in this market quote after a call and publish nothing. We publish the number first, banded by the one thing that genuinely drives effort.

Architecture B

from £4,950

No local SWIFT footprint: the narrower control set, assessed against your provider arrangements and user environment.

Architectures A1 to A4

£8,950 per architecture

Local interfaces or connectors: the fuller control set, with the exact band confirmed in writing once your type is agreed.

Both fees sit alongside the rest of our published services on the pricing page.

How it runs

From scoping call to submitted attestation

Five stages, each with a defined output, ending with your attestation entered in KYC-SA inside the window.

1

Scoping

A call confirms your architecture type, which fixes both the control set and the fee. You get the scope and the number in writing before anything starts.

2

Evidence gathering

We issue a control-by-control evidence request matched to your architecture, so your team collects once rather than drip-feeding documents for weeks.

3

Assessment

Each in-scope mandatory control is assessed against its CSCF objective: interviews where needed, but evidence does the talking.

4

Report

You receive the independent assessment report KYC-SA expects, with any gaps described precisely enough for your engineers to close them.

5

Attestation support

We stay available while you submit, so the attestation entered in KYC-SA matches what the assessment found. The submission process itself is walked through in our attestation guide.

For the full 2026 cycle, from confirming your architecture type to the KYC-SA submission itself, read your 2026 SWIFT attestation, step by step.

The UK gap

Why a UK assessment team matters

Search for a SWIFT CSP assessor today and the visible market answers from the US, the Gulf and South Asia. That works, until you need a workshop in your office, an assessor who overlaps your working day, or findings written with your other UK obligations in mind.

We assess from the UK, in your hours, and we already speak the language of the FCA and PRA operational resilience regime your firm is measured against. A CSCF finding about payment-system access rarely lives alone: it usually touches an important business service you have mapped elsewhere, and the report joins those dots rather than leaving them for you.

If you want to talk it through before the window tightens, book a call. If you first want to understand the cycle you are attesting into, start with the 2026 attestation guide.

Quick answers

SWIFT CSP assessment questions, answered

Is an independent assessment mandatory for SWIFT CSP?

Yes. Under CSCF v2026, every SWIFT user's attestation must be supported by an independent assessment. Self-attestation alone is no longer accepted. The assessment can be performed by a qualified external firm, which is the service on this page.

What architecture type are we?

It depends on what SWIFT-related infrastructure sits on your side of the connection. If you run your own interfaces you are in the A1 to A4 family; if your users simply reach SWIFT through a provider's application or APIs, you are type B. Most firms can place themselves from the descriptions above, and we confirm the classification on the scoping call because it decides both scope and fee.

When must we attest?

The CSCF v2026 attestation window runs from July to 31 December 2026, with the attestation submitted in KYC-SA. Commissioning the assessment early in the window leaves room to remediate anything it finds; the step-by-step timeline is in our attestation guide.

The 2026 attestation, step by step

Rocket above the Operational Resilience UK call to action

Fixed fee, confirmed on one call

Book your CSCF v2026 assessment

A scoping call confirms your architecture type and your fee, both in writing, before anything is committed. The earlier in the window you assess, the more room you have to remediate.