Compliance · · 11 min read · By Hackrowd Team
SWIFT CSCF Guide: Vulnerability Scanning, Pentesting and Evidence
Understand SWIFT CSCF v2026 vulnerability scanning, advisory penetration testing, independent assessment and KYC-SA evidence for SWIFT-connected institutions.
## What Is the SWIFT Customer Security Controls Framework?
The SWIFT Customer Security Controls Framework, or CSCF, is part of SWIFT's Customer Security Programme. It sets security controls for SWIFT users and maps applicability to architecture types such as A1, A2, A3, A4 and B.
The framework changes by version year. This guide addresses **CSCF v2026** and should be read alongside the authoritative material in SWIFT's Knowledge Centre. Do not reuse last year's control matrix without checking status and applicability for your architecture.
SWIFT describes v2026 as 32 controls: 25 mandatory and 7 advisory. The controls sit under three objectives—Secure and Protect, Know and Limit Access, and Detect and Respond.
## First Confirm Your Architecture Type
Architecture classification determines which components are in scope and which controls apply. Preserve:
- An approved SWIFT architecture diagram
- The selected architecture type and rationale
- SWIFT secure-zone boundaries
- Operator and administrator access paths
- Back-office and middleware data flows
- Service-provider responsibilities
- Any changes since the previous attestation
An incorrect architecture classification can invalidate otherwise polished evidence.
## Control 2.7: Vulnerability Scanning
Vulnerability Scanning, Control 2.7, is a mandatory control across the commonly listed architecture types in v2026. The programme should define scope, authenticated coverage where appropriate, review responsibility, remediation and exception handling.
Do not publish or adopt a scan cadence from an unauthorised summary. Confirm the current cadence and exact assessment criteria in the official CSCF v2026 text for your architecture. Evidence commonly includes scan schedules, asset coverage, reports, false-positive decisions, remediation tickets and rescans.
Scanning does not replace patch management, secure configuration or penetration testing. It provides repeatable discovery of known weaknesses; other controls address prevention and deeper validation.
## Control 7.3A: Penetration Testing Is Advisory
In CSCF v2026, Penetration Testing, Control 7.3A, is advisory rather than mandatory. Advisory does not mean irrelevant. It is a risk-reduction practice that can test attack paths across the secure zone, supporting systems and operator access.
Institutions should either perform risk-based testing or document the governance decision and residual risk. Never represent an advisory control as mandatory, and do not treat a penetration test as a substitute for mandatory vulnerability scanning or the annual independent assessment.
A suitable scope may include:
- SWIFT secure-zone network boundaries
- Operator workstations and privileged access paths
- Supporting identity and directory services
- Middleware and back-office connections
- Security monitoring and containment controls
- Segmentation from general corporate networks
Testing must operate under written authorization and protect the availability of payment operations.
## Annual Independent Assessment
SWIFT requires users to obtain an independent assessment supporting their security attestation. The assessment can follow an eligible internal or external route under SWIFT's Independent Assessment Framework. SWIFT also maintains a directory of CSP Certified Assessors.
The assessment validates applicable mandatory controls. Its evidence should be collected throughout the year rather than assembled hurriedly at the attestation deadline.
Read SWIFT's current [Independent Assessment guidance](https://www.swift.com/myswift/customer-security-programme-csp/independent-assessment) before selecting the assessor and approach.
## KYC-Security Attestation
Users submit their annual security attestation through the KYC-Security Attestation application. SWIFT's published process describes an annual submission window and requires users to attest before the applicable version expires; new users must attest before going live.
Confirm current dates and procedural details on SWIFT's [KYC-Security Attestation page](https://www.swift.com/myswift/customer-security-programme/submit-kyc-security-attestation). Internal project deadlines should leave time for remediation and assessor review before submission.
## Evidence Checklist for CSCF v2026
Prepare evidence mapped to each applicable control:
- Architecture type, diagrams and scope rationale
- Current control applicability matrix
- Policies and technical standards
- Secure configuration and hardening evidence
- Privileged-access reviews and authentication settings
- Vulnerability scan schedule, reports and rescans
- Finding register, remediation tickets and exceptions
- Penetration-test report or documented advisory-control decision
- Change records for the SWIFT environment
- Logging, monitoring and incident-response evidence
- Previous attestation and independent assessment outputs
- Management approval of residual gaps
The assessor needs operating evidence, not only policy documents. Use samples covering the assessment period.
## A Practical Annual Cycle
### January to March
Confirm the new framework version, architecture type, control changes and owners. Convert gaps into funded remediation plans.
### April to June
Collect operating evidence, complete technical reviews and resolve high-risk weaknesses. Schedule the independent assessment.
### July to September
Complete the assessment, address findings and obtain rescans or retests where needed.
### October to December
Finalize management approval, submit the attestation and archive the evidence package according to your retention requirements.
## Common SWIFT CSCF Gaps
- Using the prior year's control matrix
- Scanning assets outside the secure zone while missing in-scope supporting systems
- Reports with no remediation or rescan evidence
- Treating advisory penetration testing as mandatory—or ignoring it without a risk decision
- Architecture diagrams that do not match production
- Weak evidence for privileged access and operator workstations
- Starting the independent assessment too close to the attestation deadline
## Frequently Asked Questions
### Is penetration testing mandatory under SWIFT CSCF v2026?
Control 7.3A is advisory in v2026. Confirm status against the official version and your architecture every year because the framework evolves.
### Is vulnerability scanning mandatory?
Control 2.7 is mandatory in v2026 for the commonly listed architecture types. Confirm exact applicability and assessment criteria in the official control matrix.
### Does a penetration test replace the independent assessment?
No. They serve different purposes. The independent assessment supports the attestation; a penetration test provides deeper technical assurance for an advisory control and broader risk management.
### Must an external company perform the assessment?
SWIFT permits eligible internal or external independent assessment routes. Use the current Independent Assessment Framework to verify independence and assessor requirements.
## Strengthen Your SWIFT Evidence
Hackrowd can support [penetration testing](/penetration-testing), [vulnerability management](/vulnerability-management) and [Active Directory security](/active-directory-security) for SWIFT-connected environments. The institution and its independent assessor remain responsible for architecture classification, control applicability and attestation.