Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

SWIFT Customer Security Controls Framework:

Cryptography for Correspondent Banking

Updated: August 24, 2026
RegionInternational mandatory for all SWIFT-connected institutions worldwide
ApplicabilitySWIFT Users: banks and financial institutions connected to the SWIFT network, Service Bureaus and Outsourcing Agents: third parties hosting or operating SWIFT infrastructure on behalf of users Group Entities: parent and subsidiary organizations sharing infrastructure, each with attestation obligations
Relevant sectionsControl 2.4A: Back Office Data Flow Security — advisory, becoming mandatory under CSCF v2026 Objective 4: Prevent Compromise of Credentials, including hardware-backed key storage Independent Assessment Framework: underpins the annual Know Your Customer Security Attestation (KYC-SA)

Overview

SWIFT publishes an updated Customer Security Controls Framework (CSCF) annually, roughly a year ahead of the enforcement window, giving users time to prepare before the following year’s attestation cycle. The framework currently comprises 32 controls, 25 mandatory and 7 advisory, mapped to recognized standards including ISO 27002, PCI DSS, SOC 2, and NIST CSF, and every SWIFT user must attest annually against at least the current mandatory set, verified through an independent assessment.

CSCF v2026 makes its most significant change in several cycles: Control 2.4A, Back Office Data Flow Security, moves from advisory to mandatory. This extends the framework’s reach beyond the SWIFT Secure Zone into bridging servers, middleware, file transfer systems, and other back-office components that handle SWIFT-related data after it leaves the core secure infrastructure.

Why it matters 

Every SWIFT user must complete the annual KYC-SA attestation, and counterparties and regulators can see attestation status, making non-attestation or material non-compliance a direct factor in correspondent-banking relationships, not just an internal audit finding.

Control 2.4A’s shift to mandatory status means cryptographic protection can no longer stop at SWIFT-branded messaging components. Institutions must now inventory the data flows between the Secure Zone and back-office systems and demonstrate that financial messages, reconciliation files, and reference data are protected wherever they travel.

How this maps to cryptography 

SWIFT Customer Security Controls Framework addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:

SectionFunctionWhat it saysSupporting Products
Objective 4 (Prevent Compromise of Credentials)HSM-Backed Key Storage and Credential ProtectionHardware-backed generation and storage of SWIFT-related keys and certificates, preventing the credential compromise the control set is built to stop.EJBCA
Control 2.4ABack Office Data Flow EncryptionEncryption of financial messages, reconciliation files, and reference data flowing between the Secure Zone and back-office or bridging systems.EJBCA / Keyfactor Command
Objective 2 (Reduce Attack Surface and Vulnerabilities)System Hardening and Certificate-Based AccessCertificate-based authentication reducing reliance on static or shared credentials across in-scope SWIFT-related components.EJBCA
Control 2.4A implementation guidanceData Flow and Cryptographic Asset InventoryAn inventory of data flows and the cryptographic mechanisms protecting each, supporting the evidence an independent assessor will expect to see.AgileSec
Objective 2Software and Configuration IntegritySigned software and configuration files for SWIFT-related components and middleware, verified before deployment.SignServer
Independent Assessment Framework / KYC-SAIndependent Assessment EvidenceCentralized reporting that maps cryptographic controls directly to specific CSCF control numbers for the independent assessor.Keyfactor Command

Audit readiness

Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:

  • Control 2.4A Data Flow Inventory:  Has the organization inventoried direct and indirect data flows between the Secure Zone and back-office systems, and assessed each for confidentiality, integrity, and authenticity?
  • HSM and Key Custody Evidence:  Is there evidence that SWIFT-related keys are generated and stored using hardware-backed mechanisms?
  • KYC-SA Attestation Accuracy:  Does the organization’s attestation accurately reflect its status against the current mandatory control set?
  • Independent Assessment Documentation:  Is documentation, such as architecture diagrams and data flow inventories, available to support an independent assessor’s review?
  • Bridging Server and Middleware Scope Mapping:  Have all bridging servers, middleware, and file transfer systems in scope of Control 2.4A been identified?
  • Software and Configuration Signing Verification:  Can the organization demonstrate that software and configuration changes to SWIFT-related components are signed and verified before deployment?