The 2026 cycle, mapped
Your 2026 SWIFT attestation, step by step
This cycle is different: CSCF v2026 promotes Control 2.4 to mandatory and requires every attestation to be supported by an independent assessment. Here is the whole 2026 cycle in order, from confirming your architecture type to the KYC-SA submission, and what assessors will actually look for.
The essentials
What the annual attestation is
Every SWIFT user attests, once a year, that their environment meets the mandatory controls of the Customer Security Controls Framework. The attestation is submitted in KYC-SA, SWIFT's Know Your Customer Security Attestation application, where your counterparties can consult it when they weigh the risk of transacting with you.
For 2026 the framework is CSCF v2026, published in July 2025, and the attestation window runs from July to 31 December 2026. What follows is the cycle in the order it should happen, then the phase table, the v2026 changes and the places cycles most often go wrong.
Reviewed July 2026, against CSCF v2026.
The cycle, in order
Six steps from scoping to submission
Each step feeds the next, which is why sequencing matters more than effort: evidence gathered before the assessment is worth double the same evidence gathered during it.
Confirm your architecture type
Everything downstream hangs on whether you are A1, A2, A3, A4 or B, because the type fixes which controls you attest against. If your infrastructure changed in the last year, a provider migration or an interface decommission, re-check rather than roll the type forward.
Scope the mandatory controls
CSCF v2026 defines 32 controls, 26 of them mandatory. Map the mandatory set onto your architecture type, and pay particular attention to Control 2.4, which was advisory and is now mandatory: for many firms it is the one control with no prior-year evidence trail.
Gather the evidence
For each in-scope control, collect what proves it operates: configurations, policies, access reviews, logs. Doing this before the assessor arrives is the difference between a review and an archaeology project.
Commission the independent assessment
Under v2026 the assessment is not optional, so book it while the window is young. An assessor working from your prepared evidence can conclude on each control and leave you time for whatever they find.
Remediate the gaps
Findings before submission are a gift: close them, or document the remediation plan in full. What you attest in KYC-SA should match what the assessment concluded, not what you hoped it would.
Attest in KYC-SA by 31 December 2026
Submit the attestation in KYC-SA, supported by the independent assessment. Counterparties consult this data when they weigh their exposure to you, so it stands as your public security posture until the next cycle.
The window
The 2026 window, phase by phase
The window is generous if you use it in phases and unforgiving if you treat it as one date.
| Phase | Period | What happens |
|---|---|---|
| Window opens | July 2026 | KYC-SA accepts attestations against CSCF v2026. Architecture confirmation and control scoping should already be done or underway. |
| Evidence and assessment | Middle of the window | Evidence packs assembled, the independent assessment performed, conclusions issued control by control. |
| Remediation | After assessment findings | Gaps closed or remediation plans documented, so the attestation reflects the assessed reality. |
| Submission | By 31 December 2026 | Attestation entered in KYC-SA with the independent assessment behind it. |
| After the window | From January 2027 | The attestation stands as the record counterparties consult, until the next CSCF version opens the next cycle. |
What changed
CSCF v2026: the changes that bite
Three changes define this cycle, and two of them create work that did not exist last year.
32 controls, 26 mandatory
CSCF v2026, published in July 2025, sets the control count for this cycle. The mandatory set is the attestation baseline; advisory controls remain good practice but do not gate attestation.
Control 2.4 is now mandatory
The headline promotion this cycle: Control 2.4 moved from advisory to mandatory. Firms that skipped it as optional now need it operating, evidenced and assessed like every other mandatory control.
Independent assessment required
Self-attestation alone is no longer accepted. Every attestation submitted in this window must be supported by an independent assessment of the mandatory controls in your scope.
Inside the assessment
What assessors look for, and where cycles go wrong
The failure points repeat across firms of every size, and none of them is exotic. They are all sequencing and evidence.
Scope that matches reality
The first thing an assessor tests is the architecture type itself. A firm attesting as type B while quietly running a connector has mis-scoped the entire exercise, and it is a surprisingly common way for a cycle to go wrong.
Evidence, not assertion
A control described in a policy but invisible in configurations and logs will not conclude well. Assessors look for proof the control operates today, not that it was designed once.
The newly mandatory ground
Anything that changed status this cycle draws attention, Control 2.4 above all, because it is where prior-year attestations offer no comfort and evidence trails are shortest.
Time left to remediate
Assessments commissioned late compress remediation into the final weeks of the window. The most avoidable failure in the whole cycle is a fixable finding with no time left to fix it.
The assessment itself
When you are ready to commission
Steps four and five are where most firms want help, and they are the service we sell: a SWIFT CSP independent assessment from a UK team, at a fixed fee published by architecture type, ending in an attestation-ready report. Architecture B and A1 to A4 fees are both on the pricing page, so the budget conversation happens with numbers already public.
If you only take one thing from this page: the firms that find the window comfortable are the ones whose assessment happens in its middle, not its final weeks.
Quick answers
Attestation questions, answered
When is the SWIFT attestation deadline?
The CSCF v2026 attestation window runs from July to 31 December 2026. The attestation is submitted in KYC-SA and must be supported by an independent assessment, so the practical planning question is not the deadline itself but how much of the window you leave for assessment and remediation.
What is KYC-SA?
KYC-SA is SWIFT's Know Your Customer Security Attestation application: the platform where SWIFT users submit their annual attestation against the CSCF and where counterparties can consult attestation data when assessing who they transact with. If your organisation attests, it happens in KYC-SA.
Can we self-attest?
Not alone, under CSCF v2026. Self-attestation without support is no longer accepted: the attestation must be backed by an independent assessment of your mandatory controls. Ours is fixed fee, published by architecture type.
Use the window well
Get the assessment booked early
One call confirms your architecture type, your control scope and your fixed fee. Assess in the middle of the window and remediation stops being a race.