CSA Cyber Trust mark and Cyber Essentials mark compliance software
CSA's risk-based Cyber Trust mark and prescriptive Cyber Essentials mark, relaunched 15 April 2025 with cloud, OT and AI security — one catalogue of 250 controls across 22 domains, tagged by the tier or marks each applies to.
- Regulator/certifierCSA-appointed certification bodies, under CSA programme rules
- InstrumentsCyber Trust mark v202504 and Cyber Essentials mark v202504, both eff. 15 Apr 2025
- Structure22 domains, 5 preparedness tiers (Cyber Trust) + 9 sub-domains (Cyber Essentials); 250 controls
- ValidityCyber Trust: 3 years + annual surveillance audit · Cyber Essentials: 2 years
What SG Cyber Trust requires
Who it applies to
- SMEs seeking the Cyber Essentials baseline before investing in a full risk-based programme
- Digitalised organisations of any size choosing a Cyber Trust preparedness tier that matches their risk profile
- Providers of cloud, OT or AI products/services seeking certification scoped to those technology pillars
- Critical information infrastructure owners who must reach Cyber Trust Advocate tier by 31 December 2027 under the CCoP (2026)
The Cyber Security Agency of Singapore relaunched both cybersecurity certification marks on 15 April 2025, adding cloud, OT and AI security to each. Cyber Trust is risk-based and tiered: an organisation completes a guided risk assessment, lands on one of five cybersecurity preparedness tiers — Supporter, Practitioner, Promoter, Performer, Advocate — and is assessed against the domains Table 7 requires for that tier (10, 13, 19, 21 or 22 of the 22 domains respectively). Cyber Essentials is prescriptive and SME-oriented: a fixed set of 75 requirements and recommendations across 9 sub-domains that every certifying organisation must meet in full.
The two marks are not separate catalogues here: Cyber Trust's own text says the Cyber Essentials requirements map to the Supporter tier and its recommendations to the Practitioner tier. GRCLens carries every Cyber Trust Annex B preparedness statement as a control tagged with the tier(s) it applies to, and every Cyber Essentials Annex A item that Cyber Trust does not restate as a control tagged supporter/practitioner and essentials — 250 controls in total across the 22 domains Cyber Trust's own Table 7 defines, from Governance through Business continuity and disaster recovery.
Certification runs through CSA-appointed certification bodies in two stages — documentation review, then on-site verification of roughly three months of operating evidence — and issuance requires at least 80% of applicable statements answered Yes, under 20% Not applicable and zero No (Cyber Trust clause 4.9.3). Cyber Trust certification is valid three years with annual surveillance audits; Cyber Essentials is valid two years. Under Singapore's Cybersecurity Code of Practice (2026), critical information infrastructure owners must hold Cyber Trust's top tier, Advocate, by 31 December 2027.
How GRCLens supports SG Cyber Trust
SG Cyber Trust runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
One catalogue, six tags
Every control carries every tier it applies to — essentials, supporter, practitioner, promoter, performer, advocate — so a Cyber Essentials-only assessment and a full Cyber Trust Advocate assessment share the same 250 controls rather than living in separate catalogues.
Cloud, OT and AI pillars in guidance
Where Cyber Trust or Cyber Essentials gives distinct wording for cloud, OT or AI, GRCLens carries it in the control's guidance, so an assessor scoping in one or more digital-technology pillars sees exactly what changes for that pillar.
Tier gap analysis
Because tiers are cumulative — Cyber Trust clause 4.9.3 requires every lower-tier statement to still be met — GRCLens can show precisely which of the 250 controls stand between an organisation's current answers and its next preparedness tier.
Six key risk indicators
Governance and strategy, the Cyber Essentials baseline, access control, third-party risk, business continuity and breach/incident notification are each tracked as an indicator, so a domain answered 'Yes' on paper but never evidenced still shows as a gap.
SG Cyber Trust frequently asked questions
Do we need Cyber Essentials before Cyber Trust?
No, but the two are related: Cyber Trust's own text maps Cyber Essentials' requirements to its Supporter tier and its recommendations to Practitioner. An organisation can go straight for a Cyber Trust tier; GRCLens shows which controls it shares with Cyber Essentials either way.
How many domains and controls does GRCLens track for this catalogue?
250 controls across the 22 domains Cyber Trust's own Table 7 defines — Governance through Business continuity and disaster recovery — built from Annex B's preparedness statements and, in the eight domains Cyber Essentials maps into, Annex A's 75 requirements and recommendations.
What does a certification body actually check?
Two stages: stage 1 reviews the organisation's documentation and design; stage 2 verifies implementation and effectiveness on-site, expecting roughly three months of operating evidence — logs, records and reports, not just policies — before issuing the tier applied for.
One platform, many obligations
See all supported frameworks → Every framework that applies in Singapore →

Talk to us about SG Cyber Trust
Security Solution Consultants provides Singapore cybersecurity certification advisory alongside the platform, so you can combine tooling with hands-on expertise.