Attestation · Last verified

Customer Security Programme

Swift's Customer Security Programme (CSP) is a mandatory yearly attestation against baseline security controls for all Swift network users. Attestation runs each year from 1 July to 31 December against the latest published Customer Security Controls Framework, validated through an independent assessment that can be performed internally or by an external assessor.

Class
Attestation
Owner
Swift
Last verified

What it is

Swift itself describes the programme as compulsory: "Swift's Customer Security Programme (CSP) is a mandatory initiative that helps financial institutions protect their Swift footprint against cyber threats."

Compliance is demonstrated through a recurring yearly attestation, not a one-off event: "Submitting your annual Security Attestation is a key milestone in your CSP compliance journey," and "The CSP is a yearly process." Each cycle has a fixed window: "you have from 01 July until 31 December to submit your attestation reflecting your level of compliance against the latest mandatory controls (at least)."

The control baseline behind the attestation is republished on a fixed annual schedule: "Swift publishes an updated version of the CSCF annually in July, a year before it comes into effect." Its reach is broad but not uniform: "The Customer Security Controls Framework (CSCF) defines the security baseline applicable to all Swift users" — with the qualification that "Controls in scope depend on the user connectivity to Swift."

The attestation itself is not simply self-declared: users must "Validate the effectiveness [of controls] ... through an independent assessment. This can be performed internally by a second or third line of defence (e.g. risk, compliance, internal audit) or externally by an independent assessor" — so an independent assessment does not necessarily mean an external auditor.

Who owns it

The programme is Swift's own — its official pages present it in the first person as "Swift's Customer Security Programme (CSP)," run for the users of the Swift network.

Who assesses it

Validation is flexible on who performs it: it can be done "internally by a second or third line of defence (e.g. risk, compliance, internal audit) or externally by an independent assessor," rather than requiring an outside auditor in every case.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Customer Security Programme." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/swift-csp

All frameworks & audits →