SWIFT CSCF
SWIFT Customer Security Controls Framework
SWIFT CSCF is a compliance framework from International with 15 domains and 34 controls that map to 112 other frameworks. The largest domains are Objective 2: Reduce Attack Surface and Vulnerabilities (10 controls), Objective 1: Restrict Internet Access and Protect Critical Systems (4 controls), Objective 5: Manage Identities and Segregate Privileges (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Attack Surface
| Code | Title |
|---|---|
| SWIFTCSCF-2 | Reduce Attack Surface and Vulnerabilities (Objective 2) |
Attestation
| Code | Title |
|---|---|
| SWIFTCSCF-8 | Annual Attestation and Independent Assessment |
Credentials
| Code | Title |
|---|---|
| SWIFTCSCF-4 | Prevent Compromise of Credentials (Objective 4) |
Detection
| Code | Title |
|---|---|
| SWIFTCSCF-6 | Detect Anomalous Activity (Objective 6) |
IR
| Code | Title |
|---|---|
| SWIFTCSCF-7 | Plan Incident Response (Objective 7) |
Identity
| Code | Title |
|---|---|
| SWIFTCSCF-5 | Manage Identities and Segregate Privileges (Objective 5) |
Objective 1: Restrict Internet Access and Protect Critical Systems
Objective 1: Restrict Internet Access and Protect Critical Systems
Objective 2: Reduce Attack Surface and Vulnerabilities
Objective 2: Reduce Attack Surface and Vulnerabilities
| Code | Title |
|---|---|
| CSCF-2.1 | Internal Data Flow Security |
| CSCF-2.11A | RMA Business Controls |
| CSCF-2.2 | Security Updates |
| CSCF-2.3 | System Hardening |
| CSCF-2.4A | Back Office Data Flow Security |
| CSCF-2.5A | External Transmission Data Protection |
| CSCF-2.6 | Operator Session Confidentiality and Integrity |
| CSCF-2.7 | Vulnerability Scanning |
| CSCF-2.8A | Outsourced Critical Activity Protection |
| CSCF-2.9 | Transaction Business Controls |
Objective 3: Physically Secure the Environment
Objective 3: Physically Secure the Environment
| Code | Title |
|---|---|
| CSCF-3.1 | Physical Security |
Objective 4: Prevent Compromise of Credentials
Objective 4: Prevent Compromise of Credentials
Objective 5: Manage Identities and Segregate Privileges
Objective 5: Manage Identities and Segregate Privileges
Objective 6: Detect Anomalous Activity to Systems or Transaction Records
Objective 6: Detect Anomalous Activity to Systems or Transaction Records
Objective 7: Plan for Incident Response and Information Sharing
Objective 7: Plan for Incident Response and Information Sharing
Physical Security
| Code | Title |
|---|---|
| SWIFTCSCF-3 | Physically Secure the Environment (Objective 3) |
Restrict Internet
| Code | Title |
|---|---|
| SWIFTCSCF-1 | Restrict Internet Access and Protect Critical Systems (Objective 1) |
Your Compliance Coverage
If you comply with SWIFT CSCF, you already cover:
FDA Quality Management System Regulation (QMSR)
12%
4 controls mapped
Compare →GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
12%
4 controls mapped
Compare →ICH E6(R3) - Good Clinical Practice
12%
4 controls mapped
Compare →+ 109 more: PIC/S Guide to Good Manufacturing Practice for Medicinal Products (12%), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (9%)
See all 112 mapped frameworks ↓Maps to 112 other frameworks
What is SWIFT CSCF and who does it apply to?
SWIFT CSCF is a compliance framework from International with 15 domains and 34 controls. SWIFT Customer Security Controls Framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does SWIFT CSCF actually require?
SWIFT CSCF has 34 controls organised across 15 domains. The largest domains are Objective 2: Reduce Attack Surface and Vulnerabilities (10 controls), Objective 1: Restrict Internet Access and Protect Critical Systems (4 controls), Objective 5: Manage Identities and Segregate Privileges (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of SWIFT CSCF do I already cover?
SWIFT CSCF maps to 112 other compliance frameworks. The top mapping partners are FDA Quality Management System Regulation (QMSR) (12% coverage), GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 (12% coverage), ICH E6(R3) - Good Clinical Practice (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement SWIFT CSCF?
Start your SWIFT CSCF compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about SWIFT CSCF requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required