Country guide · Singapore

Cyber security compliance in Singapore

Singapore regulates cyber security through three authorities whose instruments overlap on the same organisations: the Cyber Security Agency's Cybersecurity Act and Code of Practice for critical information infrastructure, the Monetary Authority's technology-risk guidelines and binding notices for financial institutions, and the Personal Data Protection Commission's PDPA for everyone. 2026 brought a new edition of the Code, a consultation on stronger MAS notices and a Digital Infrastructure Bill. This page sets out what applies and from when, from the instruments themselves.

At a glance
  • Frameworks listed7
  • Issuing bodies4
  • Framework pages4
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
SingaporeChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Singapore

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

Cyber Security Agency of Singapore (CSA)

Cybersecurity Code of Practice for Critical Information Infrastructure (2026), Release 1

Designated owners of critical information infrastructure in the eleven CII sectors. In force 29 July 2026, superseding CCoP 2.0; new requirements for existing owners by 29 July 2027

Open the framework page →
Cyber Security Agency of Singapore (CSA)

Cybersecurity Act 2018 and Cybersecurity (Amendment) Act 2024

CII owners (audit at least every two years, risk assessment yearly, incident reporting to CSA), licensed penetration testing and managed SOC providers; the 2024 amendments' CII provisions commenced 31 October 2025, with the entities of special cybersecurity interest and foundational digital infrastructure parts still to commence

Monetary Authority of Singapore (MAS)

Technology Risk Management Guidelines and Notices FSM-N05 / FSM-N06

All MAS-regulated financial institutions, as supervisory guidance (Guidelines, unamended since 18 January 2021). Banks in Singapore are directly bound by Notices FSM-N05 (Technology Risk Management) and FSM-N06 (Cyber Hygiene), effective 10 May 2024; MAS issues equivalent FSM-N-numbered Notices to merchant banks, finance companies, insurers, capital markets services licensees and digital token service providers

Open the framework page →
Cyber Security Agency of Singapore (CSA)

CSA Cyber Trust mark and Cyber Essentials mark

Any organisation seeking cybersecurity certification in Singapore. Both marks relaunched 15 April 2025 with cloud, OT and AI security; critical information infrastructure owners must reach Cyber Trust's top tier, Advocate, by 31 December 2027 under the Cybersecurity Code of Practice (2026)

Open the framework page →
Personal Data Protection Commission (PDPC)

Personal Data Protection Act 2012 (PDPA), 2020 Revised Edition

Organisations collecting, using or disclosing personal data in Singapore, other than individuals acting personally, employees in the course of employment, or public agencies. 2020 amendments in force in stages from 1 Feb 2021; enhanced financial penalty regime from 1 Oct 2022

Open the framework page →
Monetary Authority of Singapore (MAS)

Guidelines on Business Continuity Management (June 2022)

All MAS-regulated financial institutions: critical business services, service recovery time objectives, dependency mapping, testing, a BCM audit at least every three years and an annual senior-management attestation

Ministry of Health (MOH)

Cybersecurity and Data Security Essentials under the Health Information Act

Licensed healthcare providers and other HIA entities; the Act was passed 12 January 2026 and is being brought into force progressively

Which cyber security rules apply in Singapore?

Three regulators cover almost everyone. The Cyber Security Agency administers the Cybersecurity Act 2018: designated owners of critical information infrastructure in eleven sectors follow the Cybersecurity Code of Practice, are audited every two years and must now hold the Cyber Trust mark at Advocate level; every other organisation can use the same agency's Cyber Essentials and Cyber Trust marks as a voluntary, certified baseline. The Monetary Authority of Singapore holds banks, insurers, capital-markets and payment institutions to its Technology Risk Management Guidelines and to two binding Notices — Technology Risk Management and Cyber Hygiene — plus its business continuity and outsourcing rules. The Personal Data Protection Commission enforces the Personal Data Protection Act on every organisation handling personal data.

A Singapore bank is therefore a CII owner under CSA, an FI under MAS and a data controller under the PDPC at once, which is why GRCLens runs the four Singapore catalogues on one control model.

What does the CSA Code of Practice require of a CII owner?

The 2026 Code has twelve sections, of which sections 2 to 12 are audited under section 15 of the Act: audit remediation, governance (Board training every 12 months and a threat briefing every 6 months, a named senior cybersecurity officer, risk management, cloud and outsourcing oversight), asset identification, protection, detection and threat hunting, incident response and cybersecurity exercises, backup and business continuity, training, operational technology security for OT CII, DNSSEC where the CII exposes DNS, and — new in 2026 — the security of systems interconnected with the CII.

Most of it applied from 29 July 2026. Forty-two clauses — the new Board and senior-management duties, asset management, one monitoring clause, most of the exercise requirements and all of section 12 — have a Compliance Date of 29 July 2027 for existing owners, and every CII owner must hold the Cyber Trust mark at Advocate level by 31 December 2027. Non-compliance is enforced through a written direction from the Commissioner; breaching the direction is the offence.

What does MAS require for technology risk management?

Two layers. The Technology Risk Management Guidelines, unchanged since 18 January 2021, are MAS's own supervisory expectations rather than a standard of care — para 2.2 says implementation should be commensurate with the FI's risk and complexity, but MAS considers an FI's observance of them in supervision. On top of the Guidelines sit two binding Notices issued under section 29(1) of the Financial Services and Markets Act 2022, both effective 10 May 2024: FSM-N05 (Technology Risk Management) and FSM-N06 (Cyber Hygiene).

FSM-N05 fixes numbers the Guidelines leave to judgement: identify critical systems, cap cumulative unscheduled downtime at 4 hours per critical system per rolling 12 months (not an availability percentage), validate a 4-hour recovery time objective at least every 12 months, notify MAS within 1 hour of a relevant incident, and file a root cause and impact report within 14 days. FSM-N06 makes six cyber hygiene practices binding: administrative account security, patch timeliness, written security standards, network perimeter defence, malware protection, and multi-factor authentication for administrative accounts on critical systems and for internet access to customer information. MAS is separately consulting (10 June to 31 July 2026) on adding IT asset management, capacity management, immutable backups and continuous monitoring duties, expected in force around 2027.

What are Singapore's Cyber Trust and Cyber Essentials marks?

CSA runs two voluntary cybersecurity certification marks, both relaunched on 15 April 2025 to add cloud, OT and AI security to what was previously classical-IT-only scope. Cyber Essentials is prescriptive and aimed at resource-constrained SMEs: a fixed set of 75 requirements and recommendations across nine sub-domains (people, hardware and software, data, virus and malware protection, access control, secure configuration, software updates, backups, incident response), certifying for two years, and an organisation must meet every requirement to pass. Cyber Trust is risk-based and tiered for more digitalised organisations: a guided risk assessment places the organisation into one of five cybersecurity preparedness tiers — Supporter, Practitioner, Promoter, Performer, Advocate — each requiring more of Cyber Trust's 22 cybersecurity preparedness domains, certifying for three years with annual surveillance audits.

The two marks interlock rather than sit side by side: Cyber Trust's own text maps the Cyber Essentials requirements to its Supporter tier and the recommendations to Practitioner, so an SME that has Cyber Essentials has already met the bottom two tiers of Cyber Trust in the domains that carry hygiene content. Certification is independent, run by CSA-appointed certification bodies in two stages — a documentation review, then an on-site check of roughly three months of operating evidence — and Cyber Trust is only issued where at least 80% of applicable statements are answered Yes, under 20% are Not applicable and none are No.

What does Singapore's PDPA require?

The Personal Data Protection Act 2012, as amended by the Personal Data Protection (Amendment) Act 2020, requires a designated Data Protection Officer with published contact details, a lawful basis (consent, deemed consent, or a named First Schedule exception) for every collection, use and disclosure, purpose limitation and notice, access and correction rights, reasonable security and retention limitation, and — since 1 February 2021 — a mandatory notifiable-data-breach regime.

A data breach that results in, or is likely to result in, significant harm, or affects 500 or more individuals, must be assessed in a reasonable and expeditious manner and notified to the Commission no later than 3 calendar days after that assessment, with affected individuals notified as soon as practicable. Financial penalties of up to 10% of Singapore annual turnover above S$10 million, or S$1 million, have applied since 1 October 2022. Data portability (Part 6B) was enacted in 2020 but has not been brought into force.

How GRCLens runs the Singapore frameworks together

MAS TRM (with the binding Notices), the CSA Code of Practice, the Cyber Trust and Cyber Essentials marks and the PDPA share one control model in GRCLens with ISO/IEC 27001, NIST CSF and the Australian and Malaysian frameworks, so a bank that is also a CII owner evidences a control once for MAS, CSA and its auditors. The MAS one-hour and four-hour clocks, the CCoP's 2027 compliance dates, the Cyber Trust tier the organisation is pursuing and the PDPC's three-day breach clock are tracked as their own indicators. The platform can be hosted in Singapore or fully on-premises.

Questions

Cyber compliance in Singapore: common questions

Which version of Singapore's CCoP applies in 2026?

The Cybersecurity Code of Practice for Critical Information Infrastructure (2026), Release 1, issued 29 July 2026. It superseded CCoP 2.0 Revision 1 of December 2022. Existing CII owners have until 29 July 2027 for the clauses the Code's compliance timeline defers.

Do CII owners in Singapore need the Cyber Trust mark?

Yes. Clause 3.3 of the 2026 Code requires Cyber Trust mark Advocate (Tier 5) certification within 24 months of designation, and by 31 December 2027 for existing owners; the firm that performs the section 15 audit must hold it too.

Are MAS's Technology Risk Management Guidelines legally binding on their own?

No — para 2.2 says they are not a statement of the standard of care and should be applied commensurate with risk and complexity. What is binding is the pair of Notices issued alongside them: FSM-N05 (Technology Risk Management) and FSM-N06 (Cyber Hygiene), both under section 29(1) of the Financial Services and Markets Act 2022 and effective 10 May 2024.

How fast must a bank notify MAS of a technology incident?

Within 1 hour of discovering a relevant incident (Notice FSM-N05 para 7), followed by a root cause and impact analysis report within 14 days (para 8). Separately, critical systems carry a 4-hour cumulative unscheduled-downtime ceiling per rolling 12 months and a 4-hour recovery time objective validated at least every 12 months.

What is the difference between Cyber Essentials and Cyber Trust?

Cyber Essentials is a fixed, prescriptive checklist for SMEs with limited cybersecurity resources — meet all 75 requirements/recommendations or you are not certified. Cyber Trust is risk-based: an organisation is assessed against one of five tiers matched to its own risk profile, with the tier determining how many of the 22 cybersecurity preparedness domains apply.

By when must a critical information infrastructure owner in Singapore hold Cyber Trust's Advocate tier?

31 December 2027, under the compliance timeline in Singapore's Cybersecurity Code of Practice for Critical Information Infrastructure (CCoP), 2026 edition.

How fast must a data breach be reported under Singapore's PDPA?

The organisation must assess a suspected breach in a reasonable and expeditious manner — PDPC's own guide treats 30 days as the outer limit — then notify the Commission no later than 3 calendar days after making that assessment, and notify affected individuals as soon as practicable.

Is data portability in force under the PDPA?

No. Part 6B was enacted by the 2020 amendment Act but has not been commenced as of September 2026.

Run Singapore's frameworks on one platform

See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security and compliance services in Singapore from Security Solution Consultants.