The KYC-SA attestation window for CSCF v2026 opened on 1 July 2026 and closes 31 December 2026. Control 2.4, back-office data flow security, has moved from advisory to mandatory, and customer connectors are now explicitly in scope, which means some institutions that assumed Type B architecture are finding they reclassify to A4 with additional mandatory controls attached. Confirming where you stand before assessor capacity tightens in Q4 is the difference between a planned remediation and a scramble under deadline.
This checklist walks you through the four things that determine whether your 2026 attestation goes smoothly:
Written for the people who own the attestation, not just the compliance file:
All 32 CSCF v2026 controls mapped by architecture type, with the 26 mandatory controls flagged separately from the 6 advisory ones.
How to confirm your architecture type first, and what pushes a Type B user to A4 under the v2026 rules.
What to check on service bureau and L2BA connectors now that they're explicitly in the secure zone conversation.
Key dates across the 1 July–31 December 2026 window and why booking your independent assessment before Q4 matters.
Takes 30 seconds. No spam, just the PDF delivered to your inbox.
A 4-page, consultant-written checklist covering architecture type, Control 2.4 readiness, connector scope and attestation submission.
SWIFT CSCF v2026 Assessment Readiness Checklist (4-page PDF)
You'll leave with a clear read on your architecture type, your gap list against v2026, and a fixed-scope proposal, usually the same day.