SWIFT CSP · CSCF · Independent assessment & continuous ownership
Your SWIFT CSP attestation has a fixed date, met one of two ways.
A findings report and an attestation-ready summary for your KYC-SA submission, from an independent assessment starting at €4,000, or built into ongoing ICT-risk ownership.
CyAdvisoled by Andrey Gubarev, Founder & vCISOCISM, CDPSE, SABSA
20+ years in cybersecurity2x former CISO at EU-licensed financial institutions10+ engagements across Europe
Your attestation date is fixed. Ownership of the gap between now and then usually is not.
On the file
- Your assessor from last cycle re-signs without a fresh look, or your internal audit team is stretched to cover CSCF on top of the financial perimeter it already owns.
- Evidence for last year’s clean findings sits in someone’s inbox, not a place your next assessor, or a supervisor, can find quickly.
- Nobody has confirmed whether last cycle’s findings can carry any weight this year, or whether everything gets re-tested from zero.
- The window is short and the deadline does not move once it is close.
On you personally
- You are the named point of accountability, and you cannot yet say with confidence whether this cycle is on track.
- You do not have the bandwidth to become the CSCF expert while running the rest of the business.
- Your non-compliance status, if it happens, is visible to counterparties through Swift’s KYC-SA application and to supervisors on a recurring basis, whether or not anyone asks you directly.
If even one of these is you, the fastest way to find out what applies is the same short call.
Run a 15-minute scoping call →
Independent assessment, or continuous ownership. One question decides which.
We run the independent assessment for you this cycle, or take on the ICT-risk function that keeps CSP, DORA evidence and board reporting current every year after.
| Independent assessment | Readiness + continuous ownership | |
|---|---|---|
| Who it is for | Teams we don’t currently work with | Teams that want CSP handled inside continuous ICT-risk ownership |
| What we do | Scope your connection architecture, review applicable CSCF controls, hand you a findings report and an attestation-ready summary | Prepare evidence, close last cycle’s findings, coordinate with a genuinely independent third party for the assessment opinion itself |
| What we don’t do | Fix what we find, that’s a separate engagement, and we won’t re-assess our own remediation work | Certify what we build ourselves, a conflict of interest we hold ourselves to |
| Term | One bounded cycle, fixed to your date | Ongoing, monthly billing, CSP is one deliverable among others (DORA evidence, board reporting) |
| Available to you if… | You are not currently a CyAdviso client this cycle | Same routing question, either direction |
One routing question decides which, asked on the first call: are we already working with you in another capacity? If yes, independent assessment is not available to you this cycle. That is a conflict-of-interest rule we hold ourselves to, not a sales pitch: the same team that builds your controls cannot be the one that independently certifies them.
The bridge between the two: if you start with independent assessment and want to move into continuous ownership afterward, that choice is yours to make once the cycle closes, not something the engagement quietly turns into. If you do move, your next cycle’s independent verification goes to a third-party assessor, never back to us for the same client in the same capacity, the same rule that keeps the routing question honest in the first place.
Our commitment on reliance
If we run your independent assessment this cycle, our engagement agreement explicitly permits you, and whichever assessor you work with next, to rely on our findings in the following cycle, within the two-cycle rule and the per-control conditions Swift’s assessment framework sets for reliance on prior conclusions. We commit to this in writing, in the agreement itself, not as a verbal reassurance.
This matters because reliance on a prior assessment’s conclusions is only available if the assessor’s own agreement allows it. Some engagement letters are silent on this, or written to discourage it, a way of making it costlier to leave. Ours is written the other way around: switching to us, or away from us later, does not have to mean starting from zero.
What each part of the work gets you
| What we deliver | What you get, by route |
|---|---|
| A scoped connection-architecture review | You know exactly which CSCF controls actually apply to you, before anything is re-tested |
| A control-by-control findings report | An attestation-ready summary, built for your KYC-SA submission, either route |
| The reliance-eligibility screen (see below) | What still carries weight from last cycle (see the reliance screen, below) |
| Coordination with an independent assessor | (Continuous ownership route) CSP handled without us certifying our own work |
| Findings tracked between cycles | (Continuous ownership route) next year starts with less debt, not the same gap rediscovered |
What still counts from last cycle
Before anything gets re-tested from scratch, we run it through a short screen: can last cycle’s finding still carry the weight this year, in part or in full? Below is a redacted excerpt from our working sheet, applied to an illustrative first-time client. No real client data.
| Control area (illustrative) | Prior-cycle finding | Version drift since | Design/config change since | Screen verdict |
|---|---|---|---|---|
| Access control for the SWIFT-related operator PC | Clean, no exceptions | None material | None reported | Carry forward, no re-test needed |
| Logging and anomaly detection | One open finding (partial coverage) | None material | Coverage extended, not yet fully proven | Full re-test, finding not closed and change not yet evidenced |
- Prior-cycle finding
- Clean, no exceptions
- Version drift since
- None material
- Design/config change since
- None reported
- Screen verdict
- Carry forward, no re-test needed
- Prior-cycle finding
- One open finding (partial coverage)
- Version drift since
- None material
- Design/config change since
- Coverage extended, not yet fully proven
- Screen verdict
- Full re-test, finding not closed and change not yet evidenced
Show the full working sheet
| Control area (illustrative) | Prior-cycle finding | Version drift since | Design/config change since | Screen verdict |
|---|---|---|---|---|
| Network segmentation of the secure zone | Clean, with one compensating control noted | Framework guidance tightened | Compensating control still in place | Carry forward, confirmed by limited re-test of the compensating control only |
| Vulnerability and patch management | Clean | None material | Patching tool replaced | Full re-test, control design changed even though outcome likely unchanged |
| Physical and environmental security of the data centre | Clean, third-party report on file | None material | None reported | Carry forward, third-party report still current |
- Prior-cycle finding
- Clean, with one compensating control noted
- Version drift since
- Framework guidance tightened
- Design/config change since
- Compensating control still in place
- Screen verdict
- Carry forward, confirmed by limited re-test of the compensating control only
- Prior-cycle finding
- Clean
- Version drift since
- None material
- Design/config change since
- Patching tool replaced
- Screen verdict
- Full re-test, control design changed even though outcome likely unchanged
- Prior-cycle finding
- Clean, third-party report on file
- Version drift since
- None material
- Design/config change since
- None reported
- Screen verdict
- Carry forward, third-party report still current
The screen runs per control, not as a blanket “same as last year.” A clean prior finding does not automatically clear this year’s assessment if the control’s design changed, or if the framework tightened around it. Reliance is real, but it is narrow by design: whoever is screening still has to justify each carry-forward line, not just cite last year’s report.
Not sure which of your controls would carry forward?
Run a 15-minute scoping call →What happens, by route
Independent assessment (one cycle):
-
1
Scoping call: architecture type, BICs, what’s already in place.
-
2
Evidence checklist: what you need to pull together, and why.
-
3
Control-by-control review against the applicable CSCF requirements, at the same standard we apply to PCI DSS Level 1 and ISO 27001/27002 work.
-
4
Findings report and an attestation-ready summary, built for your KYC-SA submission.
-
5
You keep the report and the evidence pack either way.
Readiness and continuous ownership:
-
1
Same scoping call, plus a look at what’s already owned inside your current ICT-risk setup.
-
2
Gap analysis and an evidence pack, prepared alongside your internal audit where one exists.
-
3
Coordination with an independent third-party assessor for the actual opinion. We don’t certify what we build.
-
4
Findings from this cycle get tracked and closed before the next one starts, instead of resurfacing on the same date next year.
-
5
CSP sits alongside DORA evidence and board reporting as one deliverable inside the same relationship, not a separate procurement every year.
What’s true at the three moments that keep you up now
- When you submit to KYC-SA The attestation is filed, on the date you had, with a report you keep regardless of what happens next. Not a gap you have to explain to your board.
- At next cycle’s assessment Whoever picks it up, us or someone else, can build on this year’s findings where the reliance conditions allow it. Instead of starting from zero (see the commitment above).
- When your board or a counterparty asks who owns this You have a specific answer. For the continuous-ownership route, the same point of contact who already knows your architecture, your evidence, and what’s still open from last time.
The attestation is filed, findings package in hand, no requirement to decide about anything ongoing.
CSP stops being a separate scramble every year. One item inside ICT-risk ownership you already have, next to DORA evidence and board reporting.
Not sure which of these two positions is realistically yours this cycle?
See if this fits your setup →What we bring, honestly
We are running our first SWIFT CSP engagements this season. What we bring is not a SWIFT-specific case history yet, it is the same standard we already hold ourselves to on adjacent work:
-
PCI DSS Level 1, ISO 27001/27002 and NIST CSF delivery as a matter of course, the exact benchmark standards Swift itself points to when it defines who is qualified to assess CSCF without being a listed Certified Assessor.
-
CISM, CDPSE and SABSA certifications held by our lead.
-
A model Swift itself recognises: where a client already runs an internal audit function, we lead or join a mixed team (internal plus external specialists), the CSCF-specific gap is ours, your team keeps owning the financial perimeter.
-
20+ years in cybersecurity, former CISO at two EU-licensed financial institutions, 10+ engagements across Europe under EU and UK financial-sector supervision.
We are naming this directly rather than implying a SWIFT-specific track record we don’t yet have. What you can verify today: the credential proof above, and the reliance-eligibility screen you saw a section back, an actual working tool, not a claim about one.
Instead of what? Your alternatives, honestly
Each of these is a real way teams close this cycle today, and where each one runs out.
| Current approach | Where it helps | Where it runs out |
|---|---|---|
| Internal audit extends its SOX/financial-controls scope to cover it | One function owns everything | CSCF is a specialised framework generalist auditors don’t usually cover |
| A Big4 or mid-tier firm runs it as a line item inside the annual audit | Familiar relationship, one invoice | Fixed scope, no owner for gaps between cycles |
| The same assessor gets rehired every year without a fresh look | Continuity, less onboarding | Reads as a red flag to due diligence, not stability (a pattern we are seeing, not a formal Swift rule) |
| IT or Ops fills out the self-attestation with no independent involvement | Fastest, cheapest on paper | Fails the independence requirement by design (Swift’s own condition, see sources, below) |
| Waiting until the deadline is close | Buys short-term focus elsewhere | The window is fixed; standing still becomes visible |
| CyAdviso: independent assessment or continuous ownership | Qualification test met, reliance in writing, Swift-recognised mixed team | See “What we bring,” above; final tier set on the call |
- Helps
- Qualification test met, reliance written into the agreement, mixed-team model recognised by Swift.
- Gap
- See What we bring, above; final tier still set on the scoping call.
- Helps
- Keeps everything under one existing function.
- Gap
- CSCF is a specialised payment-messaging security framework (network segmentation, HSM/PKI messaging), usually outside what a generalist auditor covers.
- Helps
- Familiar relationship, one invoice.
- Gap
- Scope is fixed at engagement; anything surfacing outside it needs a new change request, and nobody owns the gap between cycles when the framework updates mid-year.
- Helps
- Continuity, less onboarding each cycle.
- Gap
- Due-diligence expectations increasingly read “same assessor, year after year” as a flag, not stability (a pattern we are seeing, not a formal Swift rule); a small firm’s methodology can lag a framework update.
- Helps
- Fastest, cheapest on paper.
- Gap
- The independence requirement is tied to your connection architecture, not a one-time exemption, and whoever configured a control cannot formally review its own work; this is Swift’s own condition, not ours (see sources, below).
- Helps
- Buys short-term focus elsewhere.
- Gap
- The window is fixed and short; standing still inside it converts into a status your counterparties and supervisors can already see, with less runway to close what’s found.
Recognise your team in one of the rows above? The FAQ below answers the questions most often asked next.
What we won’t ask you to accept
Four things we won’t ask you to take on faith
“We already have an assessor / internal audit, why pay for overlap?”
We don’t ask you to replace what you have. Scope is bounded to the CSCF-specific gap your current setup structurally doesn’t cover. The reliance screen you saw above shows exactly what that gap is before we touch anything.
“You’re not a listed Swift Certified Assessor.”
Correct, and we don’t claim to be, or claim a listing in Swift’s assessor directory. Swift’s own published rules say the directory is optional for the client. We meet Swift’s qualification bar for a non-listed assessor, see What we bring, above.
“Will this turn into a long-term commitment?”
Not for independent assessment: bounded scope, ends with a report you keep. If continuous ownership is what you actually want, that’s a separate, explicit choice you make, not something the engagement quietly turns into.
“If we switch assessor, do we lose everything we already built?”
No, see the commitment on reliance, above.
The sources this page relies on
Show the five sources
-
Swift, Customer Security Programme document (2024-07-01): use of the assessor directory is not mandatory; Swift users can choose an assessment provider not listed in the directory, or an internal one, provided they hold assessment experience to an industry standard (PCI DSS, ISO 27002, NIST CSF, as examples) and the lead assessor holds a relevant professional certification.
-
Swift, Assessment Providers and Certified Assessors Directory notice (2023-11-06): customers are not required to use CSP Assessment Providers listed in the directory, and are free to make their own choice.
-
Swift’s published guidance recognises a mixed assessment team (internal plus external specialists) as a valid model, stated as a way to contain the cost of subsequent assessments.
-
Reliance on a prior assessment’s conclusions, and the conditions that apply to it, follow Swift’s current Independent Assessment Framework; the specific per-control conditions are commercially restricted and are not reproduced here, they inform our engagement terms directly.
-
Swift treats internal, external and mixed assessment teams as equally valid, on one condition: the assessment itself is carried out independently. This is the condition the self-assessment row in “Instead of what?” above refers to.
Subject matter, not a credential claim. CyAdviso is independent of, and not endorsed by, Swift. Confirm the current framework text directly with Swift for your own assessment planning.
What this engagement is, and what it is not
Independent assessment
Scoping call and connection-architecture classification; evidence checklist; control-by-control review against applicable CSCF requirements; findings report; attestation-ready summary for your KYC-SA submission; written qualification disclosure of our lead assessor; a reusable working template (see the reliance screen above).
Fixing what we find (a separate engagement); continuing advisory in the same cycle; any claim of Certified Assessor status or directory listing; your existing auditor’s SOX/financial-perimeter scope; the formal tender segment (see “Who this is not for,” below).
Continuous ownership
Ongoing ICT-risk ownership; annual CSP readiness cycle as one deliverable inside it (gap analysis, evidence preparation, findings closure); coordination with an independent third-party assessor; the mixed-team model where your internal audit already exists.
CyAdviso does not perform the formal independent attestation for this same client, that is routed to a third-party assessor partner, the same conflict-of-interest rule stated above. Ad hoc work outside the agreed retainer scope goes through a change order, not silently absorbed.
The tender segment (banks, depositories, public-sector entities formally requiring an official Certified Assessor status); anyone expecting a guarantee that Swift or KYC-SA will accept the result, no honest assessor can promise that, acceptance stays with Swift and your counterparties.
Fixed tiers, published up front
Independent assessment (one cycle, fixed fee):
One BIC, standard architecture
You’ve already prepared most of the evidence yourself.
Full evidence review
One BIC, standard architecture, findings report, attestation-ready summary.
Multi-BIC or complex
Multi-BIC or complex architecture, compressed timeline.
Continuous ownership (monthly retainer, CSP as one deliverable inside it):
Continuous ICT-risk ownership
- First quarter runs as a bounded onboarding step before the full ongoing commitment, so you’re not signing a multi-year agreement on the first call
Final tier is set on the scoping call, based on your connection architecture and how much evidence you already have in order, not a fixed rate card. We don’t guarantee that Swift or your counterparty will accept the result, that decision stays with them, we build a complete, defensible submission either way.
Ready to find out which route fits?
One 15-minute call tells you whether this is a one-off independent assessment or something that folds into ongoing ownership, and whether your timeline is realistic before you commit to either.
Or email info@cyadviso.com · No commitment. No sales pressure.