Policy Briefing — Singapore readies Cybersecurity Act amendments for expanded sector oversight
Singapore’s Cyber Security Agency is finalising amendments to the Cybersecurity Act to cover more critical information infrastructure, introduce new licensing classes, and mandate reporting from key digital service providers.
Executive briefing: The Cyber Security Agency of Singapore (CSA) closed consultation in May 2024 on amendments to the Cybersecurity Act 2018. Draft legislation expected to reach Parliament in late 2024 would broaden critical information infrastructure (CII) designations, add a new class licensing regime, and extend reporting obligations to providers of essential digital services.
Proposed reforms
- Expanded CII coverage. CSA plans to designate cloud infrastructure, data centres, and key digital utilities as CII, requiring risk assessments, incident reporting, and audit submissions.
- Class licensing. A new licensing class for critical information infrastructure service providers would set baseline security controls, personnel vetting, and audit frequencies.
- Digital service duties. Providers of managed security, SOC monitoring, and other essential digital services must notify CSA of significant cyber incidents and maintain service continuity plans.
Program actions
- Scope assessment. Identify Singapore operations that could fall under expanded CII definitions and align asset inventories with CSA templates.
- Licensing readiness. Prepare compliance documentation—incident runbooks, personnel vetting records, and third-party contracts—to meet new class licensing criteria.
- Incident reporting drills. Test the ability to deliver preliminary incident reports within the proposed 2-hour notification window and follow-on updates within 24 hours.
Sources
- Public Consultation on the Proposed Cybersecurity (Amendment) Bill 2024
- CSA press release on Cybersecurity Act amendments consultation
Continue in the Policy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Semiconductor Industrial Strategy Policy Guide — Zeph Tech
Coordinate CHIPS and Science Act, EU Chips Act, and Defense Production Act programmes with capital planning, compliance, and supplier readiness.
-
Digital Markets Compliance Guide — Zeph Tech
Implement EU Digital Markets Act, EU Digital Services Act, UK Digital Markets, Competition and Consumers Act, and U.S. Sherman Act requirements with cross-functional operating…
-
Export Controls and Sanctions Policy Guide — Zeph Tech
Integrate U.S. Export Control Reform Act, International Emergency Economic Powers Act, and EU Dual-Use Regulation requirements into trade compliance, engineering, and supplier…




