{"id":61419,"date":"2025-10-09T14:16:21","date_gmt":"2025-10-09T12:16:21","guid":{"rendered":"https:\/\/www.usd.de\/?p=61419"},"modified":"2025-10-09T14:16:23","modified_gmt":"2025-10-09T12:16:23","slug":"swift-cscfv2026-assessment-changes","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/swift-cscfv2026-assessment-changes\/","title":{"rendered":"Update to the SWIFT Customer Security Controls Framework: What Changes Does CSCFv2026 Introduce?"},"content":{"rendered":"\n<p>Since 2017, the Customer Security Controls Framework (<a href=\"https:\/\/www.swift.com\/de\/node\/300801\" target=\"_blank\" rel=\"noopener\">CSCF<\/a>) has been helping organizations to effectively secure their SWIFT infrastructure. The aim is to reduce cyber risks and to detect and stop fraudulent transactions at an early stage.<\/p>\n\n\n\n<p>SWIFT users must demonstrate annually that they meet the CSCF requirements. The basis for this is an independent <a href=\"https:\/\/www.usd.de\/en\/pci-payment-security\/swift-assessment\/\">SWIFT assessment<\/a>. This confirms that the organization's SWIFT infrastructure and connected systems are effectively and reliably protected against potential threats and vulnerabilities.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66%\">\n<p>With the <strong>latest update to the framework, <a href=\"https:\/\/www2.swift.com\/knowledgecentre\/publications\/cscf_dd\" target=\"_blank\" rel=\"noopener\">CSCFv2026<\/a><\/strong>, SWIFT has introduced key changes and significant improvements. Together with our colleague Najim Quraishi, Managing Security Consultant at usd AG and auditor for international security standards, we provide you with an overview of the most important new features. Knowing these now gives you an advantage \u2013 both in the upcoming SWIFT assessment according to CSCFv2025 and in the subsequent transition phase until your next SWIFT assessment in 2026.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33%\">\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/Ahmad-Najim-Quraishi-usd.jpg\" alt=\"Portrait of Najim Quraishi, Managing Security Consultant at usd AG, wearing a suit and white shirt, taken in a modern office building.\" class=\"wp-image-42893\" style=\"width:160px;height:auto\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What changes does CSCFv2026 introduce?<\/h2>\n\n\n\n<p>CSCFv2026 builds incrementally on the previous version. As announced in CSCFv2025, control 2.4 \u201cBack Office Data Flow Security\u201d is now mandatory in CSCFv2026.<\/p>\n\n\n\n<p>This means that the customer client connector (e.g., API users, middleware, or file transfer clients) is classified as a mandatory component for several controls. Every endpoint that is indirectly connected to SWIFT via shared resources from service providers is now considered a customer connector, regardless of whether it is server- or client-based.<\/p>\n\n\n\n<p>This may cause institutions that were previously certified according to architecture type B to be reclassified as type A4 if customer connectors are used. Details on the implications and reclassification can be found in our previous article \u201c<a href=\"https:\/\/www.usd.de\/en\/swift-cscfv2025-architecture-type-b\/\">SWIFT CSCFv2025: Current Version of the Framework Brings Changes for Architecture Type B<\/a>\u201d.<\/p>\n\n\n\n<p>The following controls list the Customer Connector as an in-scope component and are classified as mandatory with the introduction of CSCFv2026:<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-center\" data-align=\"center\"><strong><strong>Control Number<\/strong><\/strong><\/th><th class=\"has-text-align-center\" data-align=\"center\"><strong>Security Control<\/strong><\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-center\" data-align=\"center\">1.2<\/td><td class=\"has-text-align-center\" data-align=\"center\">Operating System Privileged Account Control<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">1.3<\/td><td class=\"has-text-align-center\" data-align=\"center\">Virtualisation or Cloud Platform Protection<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">1.4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Restriction of Internet Access<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">2.2<\/td><td class=\"has-text-align-center\" data-align=\"center\">Security Updates<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">2.3<\/td><td class=\"has-text-align-center\" data-align=\"center\">System Hardening<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">2.6<\/td><td class=\"has-text-align-center\" data-align=\"center\">Operator Session Confidentiality and Integrity<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">2.7<\/td><td class=\"has-text-align-center\" data-align=\"center\">Vulnerability Scanning<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">3.1<\/td><td class=\"has-text-align-center\" data-align=\"center\">Physical Security<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">4.1<\/td><td class=\"has-text-align-center\" data-align=\"center\">Password Policy<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">4.2<\/td><td class=\"has-text-align-center\" data-align=\"center\">Multi-Factor Authentication<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">5.1<\/td><td class=\"has-text-align-center\" data-align=\"center\">Logical Access Control<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">5.4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Password Repository Protection<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">6.1<\/td><td class=\"has-text-align-center\" data-align=\"center\">Malware Protection<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">6.4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Logging and Monitoring<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The Alliance Connect instances are also included as part of the components that fall within the scope of the framework.<\/p>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Why should you start thinking about CSCFv2026 now?<\/h2>\n\n\n\n<p>Your current SWIFT assessment is carried out in accordance with CSCFv2025. Nevertheless, we recommend that you familiarize yourself with the changes in the new CSCFv2026 and take them into account. Why? By making use of the transition phase, you can plan with certainty and avoid any last-minute surprises.<\/p>\n\n\n\n<p><strong>Our tip:<\/strong> Conduct a gap analysis according to CSCFv2026 in parallel to your current assessment. This will allow you to identify whether your architecture is affected and whether a reclassification to architecture type A4 is necessary at an early stage. This gives you the opportunity to implement major adjustments strategically and without time pressure.<\/p>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<div style=\"height:23px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Do you have any questions or need support with your upcoming SWIFT assessment?&nbsp;<a href=\"https:\/\/www.usd.de\/en\/contact-form-security-audits\/\">Contact us<\/a>, we will be happy to help.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since 2017, the Customer Security Controls Framework (CSCF) has been helping organizations to effectively secure their SWIFT infrastructure. The aim is to reduce cyber risks and to detect and stop fraudulent transactions at an early stage. SWIFT users must demonstrate annually that they meet the CSCF requirements. The basis for this is an independent SWIFT [&hellip;]<\/p>\n","protected":false},"author":120,"featured_media":52364,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[410,373,389],"tags":[4218,5077,4219,14770,4800,7440],"class_list":["post-61419","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-financial-sector-compliance-en","category-news-en","category-security-audits-en","tag-swift-en","tag-swift-assessment-en","tag-swift-cscf-en","tag-swift-cscfv2026","tag-swift-csp-en","tag-swift-customer-security-controls-framework-2-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/61419","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/120"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=61419"}],"version-history":[{"count":5,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/61419\/revisions"}],"predecessor-version":[{"id":61427,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/61419\/revisions\/61427"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/52364"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=61419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=61419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=61419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}