Cybersecurity Code of Practice for Critical Information Infrastructure (2026) compliance software
CSA's mandatory code for critical information infrastructure owners, in force from 29 July 2026 — 220 assessable clauses across 11 sections, with the 2027 compliance dates, the Cyber Trust Advocate requirement and the audit cycle tracked as indicators.
- RegulatorCSA — Commissioner of Cybersecurity, under the Cybersecurity Act 2018
- EditionCCoP (2026) Release 1, issued 29 July 2026; supersedes CCoP 2.0 Rev 1 (Dec 2022)
- Structure12 sections; sections 2–12 audited — 220 assessable controls in 11 domains
- DatesIn force 29 Jul 2026 · 42 clauses by 29 Jul 2027 · Cyber Trust Advocate by 31 Dec 2027 · audit every 2 years
What SG CSA CCoP requires
Who it applies to
- Designated owners of critical information infrastructure in the eleven CII sectors
- Providers of essential services responsible for third-party-owned CII under the 2024 amendments
- Owners of OT CII, for whom Section 10 applies in addition to the IT clauses
- Audit firms performing the section 15 audit, who must themselves hold Cyber Trust Advocate
The Cybersecurity Code of Practice for Critical Information Infrastructure (2026), Release 1, was issued by the Commissioner of Cybersecurity on 29 July 2026 under section 35A of the Cybersecurity Act 2018, superseding CCoP 2.0 Revision 1 of December 2022. It binds every designated owner of critical information infrastructure in Singapore's eleven CII sectors — energy, water, banking and finance, healthcare, transport (land, maritime, aviation), infocomm, media, security and emergency services, and government — and is the standard the two-yearly audit under section 15 of the Act tests against.
The Code has twelve sections. Sections 2 to 12 are the auditable clauses: audit remediation, governance, identification, protection, detection, response and recovery, cyber resiliency, training and awareness, operational technology security (OT CII only), domain-specific practices for DNS, and — new in 2026 — the security of systems interconnected with the CII. GRCLens carries 220 assessable controls in 11 domains, splitting only the lettered items the Code treats as separately evidenced artefacts, with guidance from the Code's own preambles and compliance timeline.
Dates matter. Most clauses applied from 29 July 2026; forty-two — the new Board and senior-management duties, asset management, one monitoring clause, most cybersecurity-exercise requirements and all of section 12 — have a Compliance Date of 29 July 2027 for existing owners, and every CII owner must hold the Cyber Trust mark at Advocate (Tier 5) level by 31 December 2027. Vulnerability assessments run at least yearly for IT CII and every two years for OT CII; penetration tests likewise. Non-compliance is enforced through a written direction from the Commissioner, and breaching the direction carries a fine of up to S$100,000.
How GRCLens supports SG CSA CCoP
SG CSA CCoP runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Clause-level assessment with the Code's own dates
Every auditable clause is a control carrying its effective or compliance date in the reference, so the forty-two 2027 requirements are visible as a set and tracked as an indicator rather than lost in the whole.
IT and OT CII scoped correctly
The tenant's CII type selects Section 10 (OT only) and the one IT-only clause, and the clauses whose cadence differs between IT and OT state both, so an OT owner is not assessed against an IT cadence or vice versa.
Dated duties as indicators
Audit-finding remediation, Cyber Trust Advocate certification, the incident response plan on request, and the vulnerability assessment and penetration test cadence are one key risk indicator with amber at the first missed duty.
Beside Cyber Trust and MAS TRM
Runs under the same Singapore folder as the Cyber Trust and Cyber Essentials marks the Code now requires, MAS TRM for CII owners in banking and finance, and the PDPA, on one shared evidence base with ISO/IEC 27001.
SG CSA CCoP frequently asked questions
Is CCoP 2.0 still the applicable code?
No. The Cybersecurity Code of Practice for CII (2026), Release 1, took effect on 29 July 2026 and supersedes CCoP 2.0 Revision 1. GRCLens carries the 2026 edition with its own compliance timeline.
What must an existing CII owner do by 29 July 2027?
Meet the clauses the Code's compliance timeline defers: Board-level accountability and senior-management responsibility, asset management, a monitoring clause, most cybersecurity-exercise requirements and all of Section 12 on interconnected systems. The catalogue tags each of them and reports them as one indicator.
Does GRCLens cover the Cybersecurity Act's incident reporting?
The Code's incident-management clauses are assessed in the catalogue, and the guidance records the reporting clock under the Cybersecurity (Critical Information Infrastructure) Regulations as amended in 2025. Confirm the current timeframes with CSA, as the Regulations are amended separately from the Code.
One platform, many obligations
See all supported frameworks → Every framework that applies in Singapore →

Talk to us about SG CSA CCoP
Security Solution Consultants provides Singapore CII cyber advisory alongside the platform, so you can combine tooling with hands-on expertise.