GDPR’s 72 Hour Rule Explained: Why...
The GDPR requirement to report certain personal data breaches within 72 hours is one of the most widely cited obligations...
Read MoreThe financial sector remains a prime target for cybercriminals, leading to continuous updates in compliance standards. Each year, SWIFT revises its CSCF, which can impact payment operations and associated technologies. These updates apply to all organisations using SWIFT. To meet the 2026 requirements, businesses must undergo an independent review to verify that at least all mandatory controls are in place before completing their attestation. Advisory controls are recommended as part of best practice, and to ensure compliance ahead of these becoming mandatory.
The framework consists of 32 security controls – 25 mandatory and 7 advisory – structured around key objectives to strengthen the security of SWIFT users’ infrastructure. These controls serve as the basis for independent security assessments and the required Know Your Customer-Security Attestation (KYC-SA), which all SWIFT users must complete.
The latest update to SWIFT’s Customer Security Controls Framework (CSCF) for 2025 introduces no major changes, with a focus instead on minor adjustments and clarifications to improve understanding and consistency. Unlike previous years, no advisory controls have been elevated to mandatory status, and SWIFT has indicated that the overall requirement level will remain stable after successive increases in recent updates. Uncharacteristically, they have already announced Control 2.4 becomes mandatory in 2026.
The latest update to SWIFT’s Customer Security Controls Framework (CSCF) for 2026 introduces one major change alongside a series of more minor changes. One advisory control has been elevated to mandatory status, the details of which can be found below.
Are you Ready for Compliance v2026?
It is essential for SWIFT users to align their security controls with CSCF requirements and undergo annual compliance verification. SWIFT requires an independent review of at least all mandatory controls within the attestation process to ensure reliability, consistency, and accuracy in security assessments.
Ensure timely resolution of any non-compliance issues prior to the end of 2025 with our SWIFT Compliance Assessment. AJC offers comprehensive cybersecurity services encompassing assistance in evaluating the SWIFT customer security programmes. Our comprehensive SWIFT assessment reviews your current security posture and offers clear, actionable recommendations to help you meet the 2025 requirements.
Please contact us on 020 7101 4861 email us info@ajollyconsulting.co.uk if you think we can help.
Image accreditation: Philipp Katzenberger (January 2019) from Unsplash.com. Last accessed on 12th March 2024. Available at: https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ
The GDPR requirement to report certain personal data breaches within 72 hours is one of the most widely cited obligations...
Read MoreThe Data (Use and Access) Act 2025 is being introduced in stages, with ICO guidance continuing to evolve alongside it....
Read MoreAs fraud tactics continue to evolve, organisations are being forced to rethink security measures that were once seen as standard....
Read More