Singapore is updating its Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and introducing a dedicated code for cloud services later this year. Announced by Minister for Digital Development and Information Josephine Teo at the Operational Technology Cybersecurity Expert Panel (OTCEP) forum 2026, the regulatory changes are designed to fortify the nation’s digital defenses against Advanced Persistent Threats (APTs) and AI-enabled cyberattacks.
Singapore Announces Major Overhaul of Critical Infrastructure and Cloud Cybersecurity Rules
The Cyber Security Agency of Singapore (CSA) stated that the evolving cyber threat landscape has shifted since the last CCoP update in 2022. With the emergence of Frontier AI, malicious actors can discover vulnerabilities faster and launch attacks at a greater scale, shortening the window available for organizations to respond. To counter these risks, the revised framework shifts the national strategy from traditional perimeter defenses to active threat mitigation across all 11 CII sectors: aviation, healthcare, land transport, maritime, media, security and emergency services, water, banking and finance, energy, info-communications, and government.

Elevated Board Accountability and Mandatory Cyber Resilience Frameworks
Under the updated CCoP, corporate governance requirements are significantly tightened. Rather than requiring only a single designated director to understand cyber risks, the entire board and senior management of CII owners are now held directly accountable for cyber resilience.

Boards must maintain a documented cyber resilience framework that establishes the organization’s risk tolerance, mitigation strategies, risk transfer arrangements, and recovery measures. This framework must be reviewed at least annually. Furthermore, CII operators are required to attain Cyber Trust Mark Level 5 certification—Singapore’s highest-tier national cybersecurity certification—for their non-CII systems supporting business operations. Level 5 certification mandates preparedness across all 22 domains, including asset protection, secure access, and governance.
The revised rules also mandate advanced technical guidance, incorporating requirements for adversarial attack simulation, penetration testing, threat hunting, and the strengthening of broader enterprise networks interconnected with CII systems.
New Cloud Security Code and Local Threat Detection Tools
To address the growing adoption of cloud technologies, the CSA will launch a separate CCoP for Cloud Services in the second half of 2026. This new framework establishes baseline cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on cloud platforms. To assist operators, the CSA conducted closed-door consultations with auditors and CII users and will publish accompanying companion guides detailing practical implementation configurations alongside the cloud code.
The regulatory push follows major real-world incidents, including a methodical cyber-espionage campaign in July 2025 by the state-sponsored group UNC3886 that targeted Singapore’s four major telecom operators: Singtel, StarHub, M1, and Simba Telecom. That breach triggered Govinsider, described as the largest coordinated government and industry response of its kind in Singapore. In response, authorities have deployed a homegrown intrusion detection tool developed by the Ministry of Defence’s Centre for Strategic Infocomm Technologies to selected CII systems, with a wider rollout planned across all critical sectors to deny adversaries an easy win.
Worth a look