Updates on Cybersecurity Code of Practice for Critical Information Infrastructure and Cloud Services

The Cyber Security Agency of Singapore (“CSA“) has on 29 July 2026 issued the updated Cybersecurity Code of Practice for Critical Information Infrastructure 2026 (“CII CCoP 2026“). It will also be releasing a new Cybersecurity Code of Practice for Cloud Services (“Cloud CCoP“) in the later part of 2026.

CII CCoP 2026

The updated CII CCoP 2026 seeks to strengthen Critical Information Infrastructure (“CII“) governance, visibility, detection and readiness, and broader enterprise networks that are interconnected with the CIIs to align with amendments made to the Cybersecurity Act 2018. The enforcement of the new provisions will be in phases.

By 29 July 2027, all CII owners (“CIIOs“) must comply with the following provisions in the CII CCoP 2026:

  1. Governance Requirements
    • Board-level accountability: CIIO Board shall participate in cybersecurity training at least once every 12 months and receive cyber threat briefings at least once every six months.
    • Senior management responsibility: At least one member of senior management shall possess the knowledge and awareness necessary to manage cyber risks across the CII.
  1. Identification Requirements
    • Asset management: The CIIO shall identify and maintain an inventory of systems that it owns, operates, and/or controls that interconnects with or communicates with the CII.
  1. Detection Requirements
    • Monitoring and detection: The CIIO shall facilitate the deployment of CSA-supported threat detection systems.
  1. Response and Recovery Requirements
    • Cybersecurity exercise: The CIIO shall develop a cybersecurity exercise plan.
  1. Securing CII Interconnected Systems Owned, Operated, and/or Controlled by the CIIO
    • Asset management: The CIIO shall establish mechanisms and processes to identify interconnected systems that are owned, managed or controlled by the CIIO.
    • Account management: The CIIO shall grant only the minimum privileges necessary and review all accounts at least once every 12 months.
    • Privileged account management: The CIIO shall implement multi-factor authentication and prohibit the sharing of privileged accounts.
    • Network segmentation: The CIIO shall segment the interconnected systems into different network segments based on their different security and risk levels.
    • System hardening: The CIIO shall enable only ports, services or protocols that are necessary for the operations of the interconnected systems.
    • Patch management: The CIIO shall establish and implement security patch management processes.
    • Monitoring and detection: The CIIO shall establish and implement the prescribed monitoring and detection mechanisms and processes.

By 31 December 2027, CIIOs must comply with the following provisions in the CII CCoP 2026:

  1. Governance Requirements
    • Cyber Trust Mark certification: The CIIO shall be certified with Cyber Trust Mark Advocate (Tier 5) or its equivalent within 24 months of its designation (or by the date stipulated by CSA for existing CIIO).

Cloud CCoP

CSA is looking to publish a Cloud CCoP in the later half of 2026 to establish cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud. This is in recognition of the increasing adoption of cloud technologies by CIIOs and the need to ensure that these environments are secured against evolving cyber threats. 

CSA has also partnered with leading Cloud Service Providers (“CSPs“) to develop CSP-specific Companion Guides that will provide practical guidance on how the Cloud CCoP controls can be implemented within their respective cloud environments. The Companion Guides will be published alongside the Cloud CCoP.

Click on the following links for more information (available on the CSA website at www.csa.gov.sg): 

If you have any queries on the above, please reach out to our team set out on this page.

For regional Technology, Media & Telecommunications and Data & Digital Economy matters, please see Rajah & Tann Asia’s Technology, Media & Telecommunications Practice and Data & Digital Economy Practice, respectively, for more information.


 

Disclaimer

Rajah & Tann Asia is a network of member firms with local legal practices in Cambodia, Indonesia, Lao PDR, Malaysia, Myanmar, the Philippines, Singapore, Thailand and Vietnam. Our Asian network also includes our regional office in China as well as regional desks focused on Brunei, Japan and South Asia. Member firms are independently constituted and regulated in accordance with relevant local requirements.

The contents of this publication are owned by Rajah & Tann Asia together with each of its member firms and are subject to all relevant protection (including but not limited to copyright protection) under the laws of each of the countries where the member firm operates and, through international treaties, other countries. No part of this publication may be reproduced, licensed, sold, published, transmitted, modified, adapted, publicly displayed, broadcast (including storage in any medium by electronic means whether or not transiently for any purpose save as permitted herein) without the prior written permission of Rajah & Tann Asia or its respective member firms.

Please note also that whilst the information in this publication is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as legal advice or a substitute for specific professional advice for any particular course of action as such information may not suit your specific business and operational requirements. You should seek legal advice for your specific situation. In addition, the information in this publication does not create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on the information in this publication.

CONTACTS

Brunei, Singapore,
+65 6232 0751
Singapore,
+65 6232 0786
China, Singapore,
+65 6232 0738

Country

Share

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This website is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this website.

© 2024 Rajah & Tann Singapore LLP. All rights reserved. Rajah & Tann Singapore LLP (UEN T08LL0005E) is registered in Singapore under the Limited Liability Partnerships Act (Chapter 163A) with limited liability.