Glossary Term

SWIFT CSP

The SWIFT Customer Security Programme - a set of mandatory security controls for all institutions connected to the SWIFT financial messaging network.

What is SWIFT CSP?

The SWIFT Customer Security Programme (CSP) was established in response to sophisticated cyber attacks targeting SWIFT-connected financial institutions. It defines mandatory security controls through the Customer Security Control Framework (CSCF) that all SWIFT users must implement and attest to annually.

Control Framework

The CSCF organizes controls into three objectives:

  • Secure Your Environment: Restrict internet access, protect critical systems, reduce attack surface
  • Know and Limit Access: Manage identities, enforce least privilege, control physical access
  • Detect and Respond: Monitor for anomalies, plan incident response, share threat intelligence

Mandatory vs. Advisory Controls

The framework includes 32 mandatory controls that all SWIFT users must implement, plus advisory controls that represent best practices. SWIFT regularly elevates advisory controls to mandatory status.

Annual Attestation

All SWIFT users must submit an annual self-attestation confirming their compliance status. Independent assessment by qualified assessors is now mandatory for most institution types.

Back to Glossary

Need Expert Guidance?

Our consultants can help you understand and implement the requirements of this standard or framework.