Articles
CSA Cybersecurity Codes of Practice for CII and Cloud Services
CSA plans an updated Cybersecurity Code of Practice for Critical Information Infrastructure and a new Cloud Services Code of Practice in the second half of 2026, with stronger governance, detection, resilience and cloud controls.
CSA Cybersecurity Codes of Practice for CII and Cloud Services
The Cyber Security Agency of Singapore (CSA) announced on 22 July 2026 that it will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and a new CCoP for Cloud Services in the later part of 2026. The CCoP is intended to specify minimum requirements that CII owners must implement under the Cybersecurity Act; the announcement describes planned updates, not a code already in force (CSA, 22 July 2026).
Updated CII requirements
CSA says the CII update responds to advanced persistent threats and AI-enabled attacks and will strengthen governance, visibility, detection and readiness, including interconnected enterprise networks. The announced changes include stronger Board and senior-management accountability; a documented cyber-resilience framework reviewed at least annually; Cyber Trust Mark Level 5 certification for CII owners; oversight of interconnected systems; threat-detection deployment across CII network segments; a comprehensive cybersecurity exercise plan; and robust network-architecture management.
These are requirements described for CII owners within the CCoP framework, not a claim that every Singapore business must obtain Cyber Trust Mark Level 5. The scope and legal effect depend on whether an organisation owns designated CII and on the final code and applicable Cybersecurity Act arrangements (CSA, 22 July 2026).
New Cloud Services Code
CSA says the new Cloud Services CCoP will govern the secure deployment, operation and management of CII systems hosted on cloud services. CSA consulted CII owners, prospective cloud adopters and auditors through closed-door engagements and used that feedback to refine the controls and guidance statements. It also worked with Amazon Web Services, Google Cloud and Microsoft Azure on provider-specific Companion Guides, which are planned for publication alongside the Cloud CCoP.
The Cloud CCoP therefore concerns cloud-hosted CII systems and does not by itself mean that every cloud customer in Singapore is regulated as a CII owner. Both CCoPs were announced for launch in the second half of 2026; the announcement should not be read as the final published text or as a new universal cloud-certification requirement (CSA, 22 July 2026).
Legal responsibility and implementation status
The CCoP is intended to specify minimum requirements that a CII owner must implement under the Cybersecurity Act. CSA's announcement also makes clear that the Act preserves the CII owner's responsibility for the cybersecurity and cyber resilience of its CII when the owner adopts new technological or business models, including cloud computing: the CII owner remains responsible. A cloud provider's platform or a Companion Guide can support implementation, but it does not transfer the CII owner's statutory responsibility to the provider or to CSA (CSA, 22 July 2026).
As of the source page rechecked on 11 September 2026, the updated CII CCoP and Cloud Services CCoP were still described as upcoming releases for the later part of 2026. The announcement is therefore useful for the direction and named control areas—governance, interconnected systems, threat detection, exercises, network architecture and cloud deployment—but it is not a substitute for the final code, the Cybersecurity Act or any CSA implementation guidance issued later. Agents should not infer a universal cloud certification, a fixed compliance deadline or a CII designation merely from an organisation's use of a commercial cloud service (CSA, 22 July 2026).
Record details
- Also known as
- ["CII CCoP 2026","Cybersecurity Code of Practice for Cloud Services","CSA Cloud CCoP","CCoP 2026"]
- Jurisdiction
- SG
Dates describe this record’s own period and applicability. A verification date does not mean a rule is currently in force.
Sources
- CSA — Cybersecurity Code of Practice for CII to be updated Accessed 2026-09-11
- CSA — Cybersecurity Act Accessed 2026-09-11
Collection as of 2026-10-07 · An expanding collection. Published counts show available knowledge, not complete coverage of Singapore.