CSCF v2027 Controls Evolution


As announced by Swift, this year the first phase of control 2.4 has become mandatory. The control objective is to ensure the confidentiality, integrity, and authenticity of data exchanged between the user's Swift infrastructure and the first back-office systems ("first hops"). In practice, this boils down to strong encryption, either end-to-end between the back-office and Swift systems, or by encrypting each leg of the data transfer related to payment messages. More details of implementation can be found in the CSCF (here) on page 52 and page 132.
Phase 1 (starting with CSCF v2026):
New data connections and the systems enabling them must be protected right away, using strong security measures. This ensures that any new data flows your systems use to exchange data are appropriately secured against cyber threats.
Phase 2 (expected in CSCF v2028):
Older, existing data (legacy) connections will also need to be secured according to modern encryption standards. Organisations should start planning and prioritising which older connections to protect first, based on risk.

Organisations using any kind of application-to-application communication in the Swift payment process will typically fall under Type A4. Only organisations still fully manually inputting payments in a GUI can attest as Type B. The system enabling these (semi-) automated payments is called a “customer client connector,” and must be protected by several key security controls.
Last year, protecting these connectors was only recommended, but now it is mandatory. This means every customer connector, regardless of whether it’s a server-based or a client connector, must meet basic cyber security standards. Examples of these client connectors are IBM MQ clients, sFTP clients and API clients.
These changes matter because the connections between Swift infrastructure, customer connectors and back-oce systems are often where payment data leaves the most tightly controlled environment. If these flows are not properly identified, encrypted and monitored, attackers may be able to intercept, manipulate or misuse sensitive transaction data before traditional security controls detect the issue.
Frontier AI, referring to the most advanced artificial intelligence systems, is becoming an important development in the cyber security landscape. These systems can accelerate activities such as vulnerability discovery, exploit development and threat automation. Think about recent examples such as Anthropic’s Mythos AI, or the incident in which AI agents escaped a sandboxed OpenAI test environment and breached a real company’s system. These recent developments have an impact on all organisations, given how the speed and scale at which cyber threats materialise may increase significantly. Swift is proactively responding to AI-driven threats and has developed a clear security plan that includes assessing emerging risks, adopting an assumed breach of mentality, strengthening remediation, and exploring defensive use of AI.
Quantum technology applies the principles of quantum physics to process information in fundamentally new ways, using quantum bits to unlock potential speed advantages for specific problems. While this creates promising opportunities across several domains, it also introduces significant risks for cryptography, making post-quantum readiness an important area of attention for organisations. A key risk is “harvest now, decrypt later”, where attackers capture encrypted data today and store it until future quantum computers may be able to break the cryptography protecting it. Post-Quantum Cryptography (PQC) consists of new cryptographic algorithms designed to remain secure against future quantum-enabled attacks. Swift’s objective is to support the migration of its community to new post-quantum cryptography standards by 2030.
.png)
Meet our global Center of Excellence (CoE), aimed at enhancing the effectiveness of our assessments and global standardisation.
Our BDO network of Swift CSP Certified Assessors means your assessments are performed by experienced, certified assessors. You can feel confident about your compliance status and will receive the most relevant and actionable recommendations to further enhance your cyber security.
The Center of Excellence (CoE) performs over 100 assessments every year. Its success can be attributed to two significant advantages:
Number of Swift CSP Assessments

As your trusted partner, BDO will help you achieve your objectives in a pragmatic yet qualitative way.
We get many questions from our clients and prospects regarding the scope and depth of the assessment, timelines and compliance. In the dropdowns below, we answer the most common questions.