← Articles

Articles

Cyber Trust Mark Requirements for Critical Information Infrastructure 2026

CSA requires Critical Information Infrastructure owners and CII auditors to meet Cyber Trust Mark requirements, with transition deadlines at the end of 2027 and 2026 respectively.

Last verified: 2026-09-10 Status: verified

Cyber Trust Mark Requirements for Critical Information Infrastructure 2026

The Cyber Security Agency of Singapore (CSA) requires Critical Information Infrastructure owners (CIIOs) and auditors conducting audits for CIIOs to meet Cyber Trust Mark requirements matched to their risk profile. CSA announced the measure on 2 March 2026 as part of a broader effort to raise baseline cybersecurity standards and address supply-chain risks (CSA, 2 March 2026).

The announcement covers three separate regulated or designated populations. CIIOs must meet the stated requirement for qualifying non-CII systems under their control; approved auditors conducting CII audits must obtain the mark at organisation level for systems supporting their own operations; and licensed cybersecurity service providers supplying penetration testing or managed security operations centre monitoring must meet a separate CTM Promoter (Tier 3) requirement. These groups should not be collapsed into one universal “CII company” category (CSA, 2 March 2026).

Certification transition

CIIOs are given a two-year transition period, ending 31 December 2027, to obtain Cyber Trust Mark Level 5 for non-CII systems under their control that support business operations or services. CII auditors are given a one-year transition period, ending 31 December 2026, to obtain the mark at organisation level for systems supporting their operations (CSA, 2 March 2026).

The licensed-provider deadline is also 31 December 2026, but it applies to the active CTM Promoter (Tier 3) certification requirement implemented for licensed providers, not to the CIIO Level 5 transition. CSA explains that the CTM has five cybersecurity-preparedness tiers and that the appropriate tier is matched to an organisation’s risk profile. A deadline is therefore a transition requirement, not proof that an organisation has already attained the relevant mark or that all three populations face identical controls (CSA, 2 March 2026).

Scope and interpretation boundary

The requirement concerns the categories and systems specified by CSA’s announcement; it is not a universal Cyber Trust Mark requirement for every Singapore business. CSA says the Cyber Trust Mark has five cybersecurity-preparedness tiers and was enhanced to address cloud, operational-technology and AI-security risks. These certification requirements are distinct from the separate Tier 3 Cyber Trust Mark requirement for licensed penetration-testing and managed-SOC providers (CSA, 2 March 2026).

The release also records that the CTM was enhanced to address newer risks in cloud, operational technology and artificial-intelligence security. That explains why the mark can appear in several CSA contexts while still referring to different obligations: the common tiered framework is not the same thing as a single blanket certificate for every business, and the licensed-provider rule is not a second deadline for every CIIO. Operational compliance details should be checked against CSA’s implementation materials and the organisation’s actual designation or licence (CSA, 2 March 2026).

Record details

Also known as
["Cyber Trust Mark CII requirements","CTM for CII owners","CII auditor Cyber Trust Mark"]
Jurisdiction
SG

Dates describe this record’s own period and applicability. A verification date does not mean a rule is currently in force.

Sources

Collection as of 2026-10-07 · An expanding collection. Published counts show available knowledge, not complete coverage of Singapore.