Skip to main content
← All frameworks
SWIFT CSP / CSCF Automation

SWIFT CSCF controls, hardened and continuously verified.

Every SWIFT user must attest annually against the Customer Security Controls Framework. CISGuard continuously hardens and verifies the secure zone systems those controls target, producing the technical evidence your assessment needs.

GlobalBanking, Financial Market Infrastructure, Corporates on SWIFT
Quick Facts

SWIFT CSP at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Obligation
Annual attestation via SWIFT's KYC Security Attestation application
Framework
CSCF with mandatory + advisory controls, updated annually
Assessment
Independent assessment required to support the attestation
Scope center
The SWIFT secure zone and related infrastructure
Consequences
Non-compliance can be reported to counterparties and regulators
CISGuard role
Continuous hardening verification of secure zone systems; attestation stays with you and your assessor
Overview

What is SWIFT CSP?

The SWIFT Customer Security Programme (CSP) obliges every organization connected to the SWIFT network to implement the Customer Security Controls Framework (CSCF) and attest to compliance annually via SWIFT's KYC Security Attestation application. The CSCF divides controls into mandatory controls, which every user must meet for their architecture type, and advisory controls, which are recommended and have migrated into the mandatory set over successive annual versions. Attestations must be supported by an independent assessment, and SWIFT can report non-compliance to counterparties and regulators. The framework's center of gravity is the secure zone: the segregated environment containing SWIFT-related infrastructure, which must be hardened, access-restricted, patched, and monitored. Controls covering system hardening, security updates, password policy, multi-factor authentication, logical access, malware protection, and logging are exactly the territory of CIS Benchmarks, which is where CISGuard turns an annual attestation scramble into a continuously verified state.

Control Mapping

CSCF control areas CISGuard automates.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Secure zone protection
    Controls
    CSCF 1.1 SWIFT Environment Protection
    Mapped by
    CIS OS + network hardening benchmarks applied to secure zone systems
  • System hardening
    Controls
    CSCF 2.3 System Hardening
    Mapped by
    Continuous scanning against 22 CIS Benchmarks (3,928 controls)
  • Security updates
    Controls
    CSCF 2.2 Security Updates
    Mapped by
    CIS update and patch state benchmarks
  • Authentication
    Controls
    CSCF 4.1 Password Policy, 4.2 Multi-Factor Authentication
    Mapped by
    CIS Password Policy + authentication configuration benchmarks
  • Logical access
    Controls
    CSCF 5.1 Logical Access Control
    Mapped by
    CIS Account + Privilege Management benchmarks
  • Detection
    Controls
    CSCF 6.1 Malware Protection, 6.4 Logging and Monitoring
    Mapped by
    CIS Anti-malware + Audit Policy benchmarks
How It Works

How CISGuard automates SWIFT CSP evidence.

CSCF control 2.3 requires SWIFT-related systems to be hardened to an industry-standard baseline, and CIS Benchmarks are the canonical example of such a baseline. CISGuard applies them continuously: every secure zone server, operator PC, and supporting system is scanned on schedule against its CIS Benchmark, with per-control pass/fail results and drift detection between scans. That directly evidences hardening (2.3), and the same scans cover password policy (4.1), account and privilege state (5.1), patch posture (2.2), anti-malware configuration (6.1), and audit logging (6.4). When your independent assessor arrives, the Framework Coverage Report shows each mapped CSCF control area, its status, and the scan history behind it, replacing screenshots gathered system by system. Because SWIFT secure zones are segregated by design, CISGuard's on-premises and air-gapped deployment model fits naturally: scanning runs entirely inside the zone with no outbound data path. CISGuard does not submit attestations or perform assessments; it supplies the technical evidence both depend on.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • Per-system CIS benchmark hardening reports for every secure zone component
  • Framework Coverage Report mapping CIS controls to CSCF control areas
  • Drift detection alerts when a secure zone configuration diverges from baseline
  • Password policy, privilege, and account configuration state with timestamps
  • Patch and update posture reports supporting CSCF 2.2 evidence
  • Audit logging configuration evidence supporting CSCF 6.4
Frequently Asked

SWIFT CSP questions, answered directly.

What is the SWIFT Customer Security Programme?

The CSP is SWIFT's mandatory security program for every organization connected to its network, introduced after attackers abused compromised member environments to send fraudulent payment messages. It requires implementing the Customer Security Controls Framework (CSCF) and attesting to compliance annually through SWIFT's KYC Security Attestation application, with an independent assessment supporting the attestation. Counterparties and regulators can be informed of non-compliance.

What is the difference between mandatory and advisory CSCF controls?

Mandatory controls must be met by every SWIFT user for their architecture type and are the basis of the annual attestation. Advisory controls are recommended practices; SWIFT has historically promoted advisory controls into the mandatory set in successive annual CSCF versions, so treating them as a roadmap is prudent. CISGuard's continuous scanning covers the system hardening, access, update, and logging territory on both lists.

How does CISGuard help with CSCF system hardening (control 2.3)?

Control 2.3 expects SWIFT-related infrastructure to be hardened against an industry-recognized baseline, and CIS Benchmarks are the reference example. CISGuard scans every secure zone system against the applicable CIS Benchmark on a continuous schedule, reports per-control pass/fail with timestamps, and raises drift alerts when configurations change between scans, so hardening is a maintained state, not an annual project.

Can CISGuard run inside a segregated SWIFT secure zone?

Yes. CISGuard deploys fully on-premises and supports air-gapped operation, so scanning, evidence storage, and reporting all run inside the secure zone with no outbound connectivity required. That matches the CSCF's segregation intent: the hardening evidence for the zone never has to leave the zone. Reports are exported on your terms for the assessor.

Does CISGuard submit my SWIFT attestation?

No. The attestation is submitted by your organization through SWIFT's KYC Security Attestation application, supported by an independent assessment. CISGuard's role is the technical evidence layer underneath: continuous CIS benchmark results, drift history, and configuration state for the secure zone systems the CSCF controls target. Assessors receive auditor-grade reports instead of ad hoc screenshots.

Ready for SWIFT CSP readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.