The SWIFT Customer Security Programme was launched in response to a series of high-profile financial attacks targeting SWIFT-connected institutions. The Customer Security Controls Framework (CSCF) defines mandatory and advisory cybersecurity controls that every SWIFT user must attest against annually via the KYC-SA portal. The current version, CSCF v2026, comprises 32 controls (26 mandatory, 6 advisory) and applies to the attestation window running 1 July to 31 December 2026; it makes back-office data flow security (Control 2.4) mandatory and brings customer connectors formally into scope.
For Saudi financial institutions, CSP compliance sits alongside SAMA's own cybersecurity expectations. SAMA's Cyber Security Framework (CSF) requirements, and NCA Essential Cybersecurity Controls where applicable, align closely with CSP control objectives, particularly around privileged access, transaction monitoring, and incident response. Since 2021, every attestation must be supported by an independent assessment, and correspondent banks reviewing your KYC-SA submission increasingly scrutinise the quality of that assessment.
Independent annual attestation suitable for KYC-SA submission
Evidence aligned to both SWIFT CSCF and SAMA expectations
Reduced correspondent banking due-diligence friction
Clear remediation roadmap for any partial-compliance areas
Defensible audit trail for board and regulator review
Continuous improvement programme between attestation cycles
RedSecLabs has supported financial institutions across the GCC region through CSP attestation since the programme's inception, with a track record of clean submissions and zero reattestation requests.
The Saudi financial sector is increasingly visible to sophisticated threat actors targeting SWIFT-connected institutions. Compromise of SWIFT operator credentials has been the entry point for some of the largest financial cyber attacks recorded. Saudi institutions handling SAR clearing and US-dollar correspondent banking are particularly exposed to wire-fraud schemes targeting the SWIFT messaging layer.
Beyond cyber risk, CSP attestation is increasingly checked by correspondent banks during their own due diligence. A weak attestation can lead to lifted transaction scrutiny, reduced correspondent lines, or, in serious cases, service withdrawal. the Saudi Central Bank (SAMA) expects local institutions to demonstrate strong CSP compliance as part of broader operational resilience supervision.
Correspondent banking relationship friction or withdrawal
SAMA supervisory action and reputational damage
Direct cyber risk to SWIFT operator workstations and messaging
Failed independent assessment requirement under current CSCF
Wire fraud and unauthorised payment incidents
Board-level visibility on operational resilience failures
CSP compliance is now a baseline expectation for any institution operating on the SWIFT network in Saudi Arabia, and the bar for independent assessment quality has risen sharply.
Every Saudi Arabia-licensed institution that maintains a SWIFT BIC and exchanges messages over the network must comply with the CSP. RedSecLabs delivers assessments across the full breadth of Saudi Arabia SWIFT users:
A structured methodology aligned to SWIFT CSCF v2026, tuned for Saudi institutional context and SAMA supervisory expectations.
We map your SWIFT footprint. A1, A2, A3, A4, or B architecture, and confirm the applicable mandatory and advisory controls under CSCF v2026, including whether the expanded customer-connector scope changes your architecture classification.
Detailed review of every applicable CSCF control with evidence sampling, producing a clear remediation roadmap before any attestation work begins.
Hands-on guidance on the most commonly weak control areas: privileged access, multi-factor authentication for operator accounts, segregation of SWIFT environments, transaction monitoring.
On-site or remote evidence collection, control testing, and operator interviews to substantiate compliance with each in-scope CSCF control.
Findings reviewed with you in advance of submission, with management response and corrective action plans for any partial-compliance items.
We support submission of your annual attestation in the SWIFT KYC Security Attestation (KYC-SA) portal by the 31 December deadline.
Where required, we liaise with your domestic regulator to ensure their notification and reporting obligations are met alongside SWIFT submission.
Quarterly health checks and CSCF-year-update advisory to keep you compliant year-round, not just at attestation deadline.
Most Saudi Arabia engagements complete in 6-10 weeks depending on SWIFT architecture complexity and current control maturity, with attestation submitted well before the 31 December deadline.
Every Saudi Arabia SWIFT CSP engagement with RedSecLabs includes:
We deliver this service across these industries:
CSP assessment quality has become a board-level concern. Correspondent banks now pull attestations and scrutinise them, a weak submission can damage long-standing relationships. Our assessments produce evidence that withstands that scrutiny, with assessors who understand Saudi banking operations and SAMA supervisory context as well as the SWIFT CSCF itself.
Book a free 30-minute scoping call. We will scope your CSP attestation requirements and quote a fixed fee within a week.
