Readiness assessment
A detailed assessment of your Swift CSP controls ahead of the formal work, so you know where you stand before you attest.
Independent Swift CSP assessments that support your yearly attestation, with clear results for each control that applies to you.
Every Swift user must attest each year to how well it meets the mandatory controls in the Customer Security Controls Framework (CSCF). Since 2021, that attestation must be backed by an independent assessment. Vectra performs that assessment, confirming your scope and architecture type, testing each control that applies and documenting the evidence you need to attest. Our team holds the specialist certifications this work needs, and we have run Swift CSP engagements in Australia and overseas.
Swift calls this a Community Standard Assessment. It is an assessment, not an audit, and it must be done before you attest.
The work checks that the controls you attest to are in place, for the architecture you run.
Confirm which components and data flows are in scope. Your architecture type decides which controls apply.
Assess against the CSCF version that applies on your attestation date.
Test every mandatory control that applies, and review the advisory ones so you can plan ahead.
Base each result on settings, records and interviews, not on controls that are only planned.
When you need more than an assessment.
Some users need a higher level of assurance for a regulator, a parent company or their own board. For them we run a Swift CSP audit, with a controls report under a recognised standard such as ISAE 3000.
We plan the work around your attestation window, so there is time to fix gaps before you attest.
Agree the timing, the CSCF version that applies on your attestation date and who will sign off.
Map your Swift components, operator PCs, connectors and back-office data flows, and confirm your architecture type.
Review settings, policies, records and logs, and interview the people who run your Swift environment.
Check each control that applies against the CSCF, and record whether it is in place and working.
Give you the results you need to complete your Security Attestation in the KYC-SA application.
Help you close gaps before you attest, and plan for changes in the next version of the controls.
A detailed assessment of your Swift CSP controls ahead of the formal work, so you know where you stand before you attest.
The independent assessment Swift requires to support your attestation, performed by assessors outside your organisation.
We confirm your controls line up with the Swift CSP guidelines, with a controls report under a recognised standard such as ISAE 3000.
A check of your Swift footprint and data flows, so you attest against the right architecture type and controls.
Penetration tests and vulnerability scans of the systems in your Swift environment.
Help to fix the gaps we find and to prepare for controls that change from year to year.
An independent assessment that supports your yearly attestation.
A clear result for each control that applies to your architecture type.
A ranked list of gaps, with the fixes needed.
Evidence you can show regulators, auditors and your board.
An early view of changes in the next version of the controls.
Every Swift user must submit a Security Attestation in the KYC-SA application, confirming its compliance with the mandatory controls. Users must re-attest at least once a year, and new users attest before they go live on the Swift network.
Swift allows the assessment to be internal or external. An internal team, such as internal audit, must be independent of the people who run the Swift controls. An external assessor can help where your team lacks the time, the independence or the specialist skills.
External assessors need experience assessing against an industry standard, such as PCI DSS, ISO 27002 or the NIST Cybersecurity Framework. The lead assessor must hold at least one relevant professional certification.
No. Swift requires an assessment, which involves less time and cost than an audit. An audit gives a higher level of assurance and a formal controls report. We offer both.
The version that applies on your attestation date. Swift publishes a new version each year. A new version can add controls or make an advisory control mandatory, so we check what has changed before we start.
Speak to us about your cyber governance and compliance requirements.