Assess, budget & plan
Confirm architecture type and in-scope components. Establish a structured gap assessment against current CSCF mandatory and advisory controls. Size the remediation effort and secure budget before the attestation window opens.
Talanos provides cyber security services related to the Swift Customer Security Programme. We help Swift-connected organisations assess control maturity, close gaps, prepare evidence and maintain stronger operational confidence — year-round, not just at attestation time.
Launched by Swift in 2016, the Customer Security Programme defines the controls that all Swift users must apply to the infrastructure supporting their Swift activity. Compliance is mandatory for every Swift user, and each user must publish an attestation against the current CSCF version between July and December every year — with a hard deadline of 31 December. The framework is structured across three security objectives, supported by seven principles that map directly onto the Identify, Protect and Detect & Respond capabilities Talanos delivers.
Swift defines four milestones in a complete CSP cycle. Most organisations have these steps covered on paper. What separates a defensible posture from a tactical one is how well each milestone connects to the next — and what happens in the months in between.
Confirm architecture type and in-scope components. Establish a structured gap assessment against current CSCF mandatory and advisory controls. Size the remediation effort and secure budget before the attestation window opens.
Remediate identified gaps and perform the independent assessment. As a listed cyber security service provider, Talanos performs community-standard independent assessments aligned to Swift's Independent Assessment Process Guidelines — with lead assessors holding recognised cyber security certifications.
Submit the attestation in KYC-SA between July and December, before the 31 December deadline. The Talanos independent assurance letter accompanies the attestation as evidence of community-standard assessment. Compliance status is then visible to counterparties.
Where gaps remain, mark controls as "I will comply by" in KYC-SA, remediate, and have the affected controls re-assessed by an independent assessor. Resubmit a new attestation once compliance is achieved.
The tangible output of a Talanos CSP engagement is the independent assurance letter — issued by Talanos, on our letterhead, confirming the outcome of the community-standard assessment against the applicable CSCF controls. Clients upload the letter to KYC-SA alongside their attestation, providing Swift and counterparties with the independent evidence required for a Compliant status.
Beyond the annual cycle, Swift requires a new attestation within three months of any of the following events. Mid-year change is a common gap: organisations often miss trigger events buried inside operational or vendor changes, leaving attestations technically out of date.
Any move between Swift architecture types — for example, from a self-hosted model to a service bureau, or between A and B variants.
Changing service bureau, L2BA provider, Group Hub or any other intermediary in your Swift connectivity path.
Where any part of the previously submitted attestation is no longer accurate, complete or up to date — including contact information or control compliance status.
Where Swift publishes an emergency release of the Control Framework that modifies an element against which you previously attested.
Any change to the traffic hierarchy of the entity. Swift Customer Support must be contacted before re-attesting.
Use of any new BIC that falls within the scope of the attestation obligation. New BIC activation requires an attestation before go-live.
Any material change to the design or implementation of a mandatory security control — for example, migration to a new operating system supporting an in-scope component, new supporting network devices, or a new patch management tool.
CSP scope is narrower than many institutions assume. The framework focuses on the infrastructure directly supporting Swift connectivity, not the wider enterprise IT environment. Defining scope accurately is the single biggest determinant of assessment cost and effort.
Out-of-scope for CSCF doesn't mean low-risk. The wider environment often presents the most attractive attack surface — and is where Talanos broader Identify, Protect and Detect & Respond services apply.
Our CSP work isn't a standalone offering — it draws on services from across our Identify, Protect and Detect & Respond capabilities. The same control environment that satisfies the CSCF is the one that has to withstand real-world attack, every day of the year.
Establish the baseline. Surface the gaps.
Close the gaps. Harden the environment.
Sustain resilience between assessments.
Talanos Cybersecurity Limited is included in Swift's Directory of cyber security service providers for selected regions, supporting Swift-connected organisations with services related to the Customer Security Programme.
As a managed SOC provider with capabilities spanning Identify, Protect and Detect & Respond, the same teams who run our 24/7 SOC also deliver the assessment and engineering work behind a defensible CSP posture. One team, one view of risk.
Cyber security is what we do. Consulting, engineering and managed services delivered by one specialist team, with a single view of risk across the engagement lifecycle.
Our work focuses on the security of the environment supporting Swift connectivity — not just the documentary evidence presented at attestation.
Coverage across Europe, Africa and Asia-Pacific, supporting institutions with Swift connectivity across multiple jurisdictions and regulators.
The questions we hear most often from Swift-connected organisations preparing for, working through, or maintaining CSP compliance.
The Customer Security Programme (CSP) was launched by Swift in 2016 to reinforce the security of the Swift community. It mandates that all Swift users implement and maintain a defined set of cyber security controls — the Customer Security Controls Framework (CSCF) — to protect their Swift-related infrastructure, reduce cyberattack risk, and minimise the impact of fraudulent transactions.
Every Swift user must publish at least one attestation against the current CSCF version between July and December each year. The hard deadline is 31 December of the year the CSCF version applies. A new attestation must also be submitted within three months of a number of trigger events, including changes to architecture type, service provider, traffic hierarchy, or any material change to a mandatory control implementation.
A self-assessment is conducted by the user's first line of defence, typically the CISO office. It is treated as "Not Compliant" in KYC-SA, and is usually only used as an interim measure — for example, when activating a new BIC where an attestation is a pre-requisite. A community-standard assessment is independently performed by an external or internal independent function, and is mandatory for a "Compliant" attestation. An independent assessment must cover, at a minimum, all applicable mandatory controls.
Independent assessors must have recent and relevant cyber security assessment experience. The lead assessor must hold at least one industry-recognised cyber security professional certification. They can be external (a third-party cyber security firm), internal (a function such as risk, compliance or internal audit — independent from the team that submits the attestation), or a mixed approach combining both. Talanos delivers external and mixed independent assessments aligned to Swift's Independent Assessment Process Guidelines.
In some cases, yes. Swift allows reliance on a third-party assurance or internal report provided three conditions are met: the report's control coverage matches the CSCF control definitions; the assessment period is no older than 18 months from attestation submission; and the issuing organisation is qualified and fully independent from the entity being assessed. Where these conditions are only partially met, complementary assessment work may be required.
A non-compliant attestation is visible to messaging counterparties through KYC-SA and to supervisory authorities through a real-time compliance dashboard. The practical consequences include higher cyber risk exposure, reputational impact, and potential commercial impact as counterparties consider compliance status in their own risk decisions. Swift also reserves the right to inform supervisors of users that fail to submit an attestation on time, or that fail to respond to a Swift-Mandated Assessment request.
The principal deliverable is an independent assurance letter, issued by Talanos Cybersecurity Limited on Talanos letterhead, confirming the outcome of the community-standard independent assessment performed against the applicable CSCF controls. Clients upload the letter to KYC-SA alongside their attestation submission, providing Swift and their counterparties with the independent evidence required for a Compliant attestation status. Engagements also typically produce a detailed assessment report covering each control, remediation guidance for any gaps, and supporting evidence appropriate to your internal governance.
No. Talanos Cybersecurity Limited is included in Swift's Directory of cyber security service providers for selected regions, but Swift does not certify, warrant, endorse or recommend any service provider listed in its directory, and Swift customers are not required to use providers listed in the directory. Our inclusion in the directory reflects our completion of Swift's CSP curriculum and our regional capability to support Swift-connected organisations.
Start a conversation about CSP readiness, control improvement, or ongoing resilience with one of our specialists.
Book a consultation →