swift-csp

Assess and remediate compliance gaps against SWIFT CSCF v2026 security controls.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill swift-csp-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: swift-csp
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/swift-csp
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill swift-csp-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Financial institutions connected to SWIFT must attest annually to the Customer Security Controls Framework (CSCF), and keeping up with version changes, architecture-specific applicability, and evidence requirements is complex and error-prone. This Skill provides expert guidance on all 32 CSCF v2026 controls so compliance teams can scope, assess, and remediate gaps before the attestation deadline. ## Core Features & Use Cases - Gap Assessment: Produces structured control-by-control status tables with evidence requirements and remediation steps for all 25 mandatory and 7 advisory controls. - Architecture Scoping: Maps controls to SWIFT architecture types (A1/A2/A3/A4/B) so you only assess what applies to your connectivity model. - v2026 Change Guidance: Details the promotion of Control 2.4 (Back-Office Data Flow Security) from advisory to mandatory, with concrete remediation steps. - Cross-Framework Mapping: Aligns CSCF controls to ISO 27001:2022, PCI DSS v4.0.1, and NIST CSF 2.0 to reuse existing compliance evidence. - Use Case: A bank's security team asks for a gap analysis of their A1 architecture against CSCF v2026 and receives a prioritized table of non-compliant controls, evidence artifacts, and remediation actions ahead of the KYC-SA attestation window. ## Quick Start Ask for a CSCF v2026 gap assessment for your SWIFT architecture type, including the status and remediation plan for each mandatory control.

Frequently Asked Questions about swift-csp

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for SWIFT CSCF v2026 attestation?

Identify your architecture type (A1/A2/A3/A4/B), assess all applicable mandatory controls, gather evidence artifacts, and engage an independent assessor. Submit the KYC-SA attestation through the SWIFT portal within the July 1 to December 31, 2026 window.

What changed in SWIFT CSCF v2026 compared to v2025?

The key change is Control 2.4 (Back-Office Data Flow Security) being promoted from advisory to mandatory, requiring encryption and authentication of data flows between the SWIFT secure zone and back-office systems. The framework now has 25 mandatory and 7 advisory controls.

Which SWIFT CSCF controls apply to my architecture type?

Applicability depends on whether you use A1, A2, A3, A4, or B architecture. Most controls are mandatory across all types, but Control 1.2 (OS Privileged Account Control) does not apply to A3 and A4. The skill provides a full applicability matrix per control.

Does SWIFT CSP require hardware tokens for MFA?

Yes, Control 4.2 requires MFA for all interactive operator access, and software-based OTP apps generally do not satisfy the requirement. Acceptable methods include hardware OTP tokens, smart cards with PIN, and FIDO2 hardware keys.

How does SWIFT CSCF map to ISO 27001 or PCI DSS?

Most CSCF controls map to ISO 27001:2022 Annex A and PCI DSS v4.0.1 requirements, so existing certifications cover much of the groundwork. However, SWIFT-specific obligations like hardware MFA, KYC-SA submission, and SWIFT log retention require additional controls.

What are the SWIFT incident notification deadlines?

You must notify SWIFT within 24 hours of confirming a cyber incident affecting SWIFT infrastructure or transactions, and submit a full incident report within 30 days. Notifiable events include credential compromise, fraudulent transactions, and malware on SWIFT-connected systems.