Follow us on LinkedInfor the latest from Zavior
Zavior
For CII
Zavior for CII

CCoP 2026 started
the clock. 29 July 2027 ends it.

Every regulation a CII owner answers to, in one platform

The Code took effect on 29 July 2026. Existing CII owners have until 29 July 2027 for the new board, asset, detection, exercise and interconnected-systems clauses, and until 31 December 2027 for Cyber Trust Mark Tier 5. Zavior holds the clause set, the gap position, the evidence and the board minutes in one place.

zavior · CCoP 2026 coverage
Z
CCoP 2026 Release 112 sections · effective 29 Jul 2026
3 · Governance71%
5 · Protection88%
10 · OT Security46%
12 · Interconnected33%
Open against the deadline3 of 47
3.1.4Board cybersecurity training29 Jul 2027
12.4.1Network segmentation29 Jul 2027
7.3.2Cybersecurity exercise plan29 Jul 2027
CCoP 2026 plus 30+ frameworks
CCoP 2026Cybersecurity Act 2018Cyber Trust Mark Tier 5ISO/IEC 27001MAS TRMIM8IEC 62443NIST CSF 2.0PDPASOC 2CIS BenchmarksISO 22301Your internal standardsCCoP 2026Cybersecurity Act 2018Cyber Trust Mark Tier 5ISO/IEC 27001MAS TRMIM8IEC 62443NIST CSF 2.0PDPASOC 2CIS BenchmarksISO 22301Your internal standards

Singapore just tightened the rules.

Singapore tightens rules governing critical services sectors to counter AI, cyber threats

Lee Li Ying · Published 22 July 2026 · Updated 27 July 2026

Minister for Digital Development and Information Josephine Teo, speaking at the sixth Operational Technology Cybersecurity Expert Panel Forum.

Read it on The Straits Times

AI has challenged the longstanding assumption that the complexity of operational technology systems keeps them safe from attack.

Josephine Teo, Minister for Digital Development and Information

Ultimately, cybersecurity is a business risk that requires sustained leadership and oversight from the board, rather than being viewed solely as a technical or operational issue.

Cybersecurity Agency of Singapore, quoted in The Straits Times

This was not a consultation. CSA issued the Code the same week, and it took effect on 29 July 2026.

The board is now named in the Code rather than assumed. Clause 3.1 puts documented duties on the whole board, where previously one director with cybersecurity knowledge was enough. Teo also confirmed Cyber Trust Mark Tier 5 by the end of 2027 for the enterprise systems that support your CII without being the CII, and a separate cloud code of practice later in the year.

The forum context matters. UNC3886, a state-sponsored espionage group, was detected inside Singapore's four major telcos in July 2025. Section 12 of the new Code, covering interconnected systems, reads like a direct answer to that.

The compliance clock

Four dates decide your next eighteen months.

One has passed. Three have not. The gap between them is the whole programme.

29 Jul 2026

CCoP 2026 took effect

Release 1 superseded CCoP 2.0 Revision 1. Twelve sections, plus a new Section 12 covering the interconnected systems you own, operate or control.

Clause 1.1.1
31 Dec 2026

Your auditor needs certifying

CII auditors need organisation-level Cyber Trust Mark certification. Licensed providers doing penetration testing or managed SOC monitoring need Promoter, Tier 3. If your usual firm is not certified, you are booking a different firm.

MDDI factsheet, 2 Mar 2026
29 Jul 2027

The main compliance date

Board accountability and training, senior management duties, asset management, monitoring and detection, the cybersecurity exercise clauses, and the whole of Section 12. Until then you minimally comply with the previous version.

Clauses 3.1.4 to 3.2.5, 4.1.2, 6.2.4, 7.3, Section 12
31 Dec 2027

Cyber Trust Mark Advocate, Tier 5

All 22 domains, covering the enterprise systems that support your CII without being the CII. New CII owners get 24 months from designation instead.

Clause 3.3.1

Breaching the Code is not itself an offence. Section 35A(5) of the Cybersecurity Act says a code of practice has no legislative effect. What follows non-compliance is a written direction from the Commissioner under section 12(1), and failing that direction carries a fine of up to $100,000.

Eleven sectors. More systems than most owners expect.

CSA designates critical information infrastructure across eleven sectors. Most CII owners are private operators, not agencies, and the 2024 amendments widened what can be designated in ways that catch people out.

Aviation
Healthcare
Land transport
Maritime
Media
Security and emergency services
Water
Banking and finance
Energy
Info-communications
Government

You may be in scope and not know it

The Cybersecurity (Amendment) Act 2024 commenced on 31 October 2025. Five changes matter here.

Cloud-hosted systems count

The definitions of computer and computer system now include virtual computers and virtual computer systems. A system running on infrastructure you do not own can be designated CII.

So can systems outside Singapore

Section 7(1A) lets the Commissioner designate a computer system located wholly outside Singapore as provider-owned CII.

You can be responsible for CII you do not own

Part 3A makes an essential service provider responsible for the cybersecurity of CII owned by a third party, and requires legally binding commitments from that owner covering design information, security standards and notification of material changes.

Your supplier's incident is your report

Section 14 reporting extends to incidents on systems under a supplier's control that are interconnected with, or communicate with, your CII.

Designation can be temporary

Part 3B lets the Commissioner designate a System of Temporary Cybersecurity Concern for up to a year, renewable. CSA's own examples are systems supporting elections and vaccine distribution.

Six instruments. One control set.

No CII owner answers to the Code alone. The stack below is what a single operator carries at once, and today it usually lives in six different trackers maintained by people who never meet.

Assessed once. Counted everywhere it applies. Evidence attached to all of it.

What you carry

CCoP 2026

12 sections, board through OT

Cybersecurity Act 2018

s15 audit every 2 years, risk assessment every year

S 678/2025

2 hours, 72 hours, 30 days

Cyber Trust Mark

Advocate Tier 5, all 22 domains

Your sector regulator

MAS TRM, IM8 or your own

Customer demands

ISO/IEC 27001, SOC 2, IEC 62443

In Zavior

Privileged access management

assessed once

One control satisfies the CCoP clause, the MAS TRM requirement and the ISO 27001 control at the same timeOne piece of evidence answers all threeOne owner, one due date, one status

Six capabilities. Each one earning its place under the Code.

CCoP 2026

Clause 12.4.1

Network segmentation

Controls

satisfy it

Risks

threaten it

Policies

state it

Evidence

proves it

Change the policy and the clause status moves.

01 · One graph

Every obligation on one connected record

Most CII owners run the Code out of a spreadsheet, the annual risk assessment out of a second one, the audit out of a shared drive, and the board pack out of slides somebody rebuilds every six months. Nothing reconciles. Reconciling it is the job.

Zavior holds all of it as one connected record. A CCoP clause knows which controls satisfy it, which risks threaten it, which policy states the position and which evidence proves it. Change the policy and the clause status moves. Close a risk and the control it was blocking clears.

The difference shows up under section 15. An audit every two years and a risk assessment every year both need the same underlying facts. When those facts live in one place, the second exercise stops being a second data-gathering project.

CCoP 2026 clauses linked to controls, risks, policies and evidenceSection 15 audit and annual risk assessment run off the same recordSupplier-controlled interconnected systems tracked as vendors, not email threadsThe 30-day report deadline held as a date, not a reminder

Assessed once

Privileged access management

CCoP 202612.3.1
MAS TRM11.1.3
ISO/IEC 27001A.5.15
Cyber Trust MarkDomain 9
IM8AC-2

One piece of evidence. Five frameworks satisfied.

02 · 30+

Map a control once, count it in every framework

No CII owner answers to the Code alone. A bank carries MAS TRM on top of it. An agency carries IM8. Almost everyone carries ISO 27001 because a customer asked for it. From 31 December 2027 every CII owner also carries Cyber Trust Mark Advocate across all 22 domains, for the enterprise systems that support the CII without being the CII.

These frameworks overlap heavily and are worded differently. That is why the same access control gets assessed four times, by four teams, none of whom see each other's work.

Zavior maps a control once and counts it everywhere it applies. Assess privileged access management once and it satisfies the CCoP clause, the MAS TRM requirement, the ISO 27001 Annex A control and the Cyber Trust Mark domain, with the same evidence attached to all four.

CCoP 2026 in the library beside ISO 27001, MAS TRM, IM8 and NIST CSF 2.0Cyber Trust Mark Advocate, all 22 domains, due 31 December 2027Your own internal standard added as a framework in daysOne piece of evidence, counted in every framework that asks for it

Multi-cloud

Private cloud

On premise

Air-gapped

Clause 3.9 says

Inform the Commissioner before migratingRisk assessment submitted within 30 daysProvider names a person in Singapore for service of process
03 · 4 modes

Deployed where a CII system is allowed to live

Clause 3.9 is blunt about cloud. You stay accountable for the cybersecurity of the CII even when it runs wholly or partly on someone else's infrastructure. You must inform the Commissioner before putting any part of the CII on cloud, whatever the deployment or service model. You must submit a risk assessment within 30 days of completing it, and if the Commissioner is not satisfied, you rectify at your own cost.

Clause 3.9.4 adds a requirement that quietly rules out a lot of tooling: the cloud service provider has to appoint a person within Singapore authorised to accept service of legal process.

Zavior is one product packaged for four environments. Same codebase, same upgrade path, no forked build per deal. For an OT environment answering Section 10, air-gapped is a supported mode rather than an exception you negotiate into a contract.

Multi-cloud, private cloud, on premise or air-gapped, one codebaseProduction hosting in Singapore and Australia todayKubernetes microservices with Helm-managed, versioned releasesEncryption keys stay under your ownership model
BoardClause 3.1
Senior managementClause 3.2
OT ownersSection 10
IT and securitySections 5, 6
Interconnected systemsSection 12
Section 15 auditorRead-only

One control set

Six views of it

04 · 9+ roles

The board, the CISO, OT and IT on one control set

CCoP 2026 does not hand compliance to one team. Clause 3.1 puts named duties on the board. Clause 3.2 puts them on at least one senior manager with authority across the CII, its interconnected systems and the enterprise network. Section 10 belongs to whoever runs OT. Section 12 belongs to whoever owns the interconnected systems, which is frequently nobody until somebody asks.

What those people share is not a tool. It is the control set.

Zavior gives each of them a role profile and a task stack scoped to what they actually own, sitting on one record. The section 15 auditor gets a read-only profile of their own, which is how an audit stops being a document request exercise and starts being a review.

Role profiles for board, senior management, OT, IT, compliance and auditFocus Mode task stacks scoped to what each person ownsRead-only auditor profile for the section 15 auditSection 12 interconnected systems get a named owner, often for the first time
Your boundary

Zavior AI

sandboxed by default

Clause evidence

retrieval scoped to you

Architecture, incidents

never leaves

Third-party model

Isolation enforced in the application layer, so a security review can probe it.

05 · No egress

AI that never sends your evidence outside

CSA published its Securing Agentic AI addendum on 17 June 2026, covering supply chain security, model and system hardening, authorisation, limiting system autonomy and continuous monitoring. It rests on a plain position: start with a risk assessment, and treat the model as part of the system rather than a tool beside it.

For a CII owner that has a sharp practical edge. The documents an AI assistant would be most useful against are the documents you are least able to send anywhere.

Zavior's AI runs sandboxed by default inside your deployment, or fully air-gapped where there is no network path. Retrieval is scoped to your organisation, so a model answering your question can only ever see your corpus. Isolation is enforced in the application layer at the organisation boundary, which means a security review can probe it instead of taking a policy document's word for it.

Sandboxed by default, or air-gapped where requiredRetrieval scoped to your organisation's corpus onlyIsolation enforced in code at the organisation boundaryAligned to CSA's Securing Agentic AI addendum, June 2026
Clause 3.1.5 · every 6 months

What is our position on privileged access in OT?

OT Access Policy v4 · approved

What changed since the last briefing?

12 controls · 3 new risks

Which clauses are still open against 29 Jul 2027?

Section 12 · 9 clauses

Board guidance arising gets minuted against the clause it satisfies.

06 · 6 months

The board briefing that falls due twice a year

Clause 3.1.5 requires a threat briefing to the board at least once every six months. It has to cover threats relevant to the CII and the sector, threats that have actively targeted you since the last briefing, and what that means for risk posture, including recommended changes to controls, risk appetite, budget or resourcing. Board guidance arising from it has to be minuted.

Clause 3.2.4 adds a posture report at least every six months, and promptly whenever a reportable incident occurs. Most organisations build these from scratch each cycle, which is why they arrive late and read like the last one.

Ask a plain-language question and Zavior answers from your approved documents with the source attached. What is our position on privileged access in OT. What changed since the last briefing. Which clauses are still open against 29 July 2027. The answer is cited, so it survives the follow-up question.

Plain-language questions, answers cited to approved documentsSix-monthly board briefing built from the live recordBoard minutes and guidance held against the clause they satisfyRuns inside the same boundary as everything else

Zavior is not your auditor.

There is a version of this page that claims Zavior runs your CCoP audit, tests your network and drills your response team. It would be easier to sell. It would also not be true. Those are engagements, performed by people carrying their own certifications, and from 31 December 2026 your CII auditor needs organisation-level Cyber Trust Mark certification while your penetration testing provider needs Promoter, Tier 3.

What breaks in most CII programmes is not the assessment. It is what happens to the assessment afterwards. The gap analysis is a PDF by March. The pen test report is an attachment nobody reopens. The exercise after-action items live in one person's inbox until that person changes jobs. Then the auditor arrives and the whole thing gets reconstructed from memory and calendar invites.

Zavior is where all of it lands and stays connected. The clause set, the gap position, the findings from whoever produced them, the evidence, the owners, the dates, the board minutes. Bring your own assessor. Bring four. The record is yours either way, and it is still standing in two years when section 15 comes round again.

29 July 2027 is closer than it reads.

Book a scoping call. We map your CCoP position, the frameworks stacked beside it, and where the gaps actually sit.

Eight things a CII owner has to get done.

Zavior performs none of them. Zavior is where every one of them lands, and what proves afterwards that it happened.

01

CCoP gap and readiness assessment

Where you stand today against every clause of CCoP 2026, and what has to change before 29 July 2027.

All 12 sections. Annex A is voluntary and sits outside audit scope.

What Zavior holds

The clause set as a live framework. Every clause carries a status, an owner, a target date and the evidence gathered so far. The gap is a view you open, not a document that goes stale the week after it is signed off.

02

CCoP audit

The independent assessment. Section 15 of the Act requires one at least once every two years, by an auditor the Commissioner approves.

Section 15 of the Act. Clause 3.3.3 on the auditor's own certification.

What Zavior holds

A read-only auditor profile with evidence attached clause by clause, so the audit runs against the live record instead of a document request list. Findings become tracked items with owners. The 30-day deadline for the report to the Commissioner sits on the dashboard as a date.

03

CII cybersecurity risk assessment

Your posture against the threats that are actually moving. Section 15 requires one at least once a year.

Section 15 of the Act. Section 3 risk management.

What Zavior holds

The risk register, mapped to the CII assets each risk threatens and the clauses each one puts at risk. Last assessed and next due sit on every entry, so an annual cadence is visible well before it lapses.

04

Security architecture review

Whether the design and the build still match, and whether the segmentation holds.

Section 5 protection requirements, network segmentation. Section 12 interconnected systems.

What Zavior holds

Architecture documents under version control with approval history. Review findings attach to the controls they affect and become remediation tasks, so the next reviewer starts from what changed rather than from nothing.

05

OT and ICS security assessment and architecture review

The specialised work on operational technology and industrial control systems, where a bad afternoon stops the service rather than leaking a file.

Section 10: OT architecture and security, secure coding, field controllers.

What Zavior holds

Section 10 as its own control set, with OT owners assigned separately from IT. Field controllers and OT segments sit in the same asset register as everything else, which is usually where an operator first sees the gap between two inventories nobody had compared.

06

Penetration testing and red teaming

Authorised simulated attack, from a network penetration test through to a full-scope red team exercise.

Section 5: vulnerability assessment, penetration testing, adversarial attack simulation.

What Zavior holds

The report lands as evidence against the clause it satisfies. Exploitable findings become risks with owners and retest dates. When the next auditor asks what happened to finding four, the answer lives beside the finding.

07

Cybersecurity simulation

Tabletop discussion through to full technical drill, validating the response plan and the people who have to run it at 3am.

Clauses 7.3.1, 7.3.2, 7.3.7 and 7.3.10, all due 29 July 2027.

What Zavior holds

The exercise plan, the scenario, who attended and every after-action item tracked to closure. The 2 hour, 72 hour and 30 day reporting clock can be drilled against the real escalation path rather than a diagram of it.

08

Cybersecurity awareness and training

Customised programmes for staff, and a separate one for the board.

Section 9 for staff. Clause 3.1.4 for the board.

What Zavior holds

Clause 3.1.4 wants records of attendance and curriculum, refreshed every 12 months, with newly appointed directors trained within 12 months of joining. Zavior keeps the roster, the curriculum and the dates, and flags the director who is coming due.

Zavior does not perform audits, penetration tests, red team exercises or OT assessments. Bring your own assessor, or ask us who we work with.

CCoP 2026, answered.

The Cybersecurity Code of Practice for Critical Information Infrastructure (2026), Release 1. CSA issued it on 29 July 2026 under section 35A(1)(a)(i) of the Cybersecurity Act 2018. Clause 1.1.1 supersedes every previous version, including CCoP 2.0 Revision 1 from December 2022. There has never been a CCoP 2.1.

This page summarises published Singapore regulation as at August 2026 and is not legal advice. CCoP 2026 Release 1, the Cybersecurity Act 2018 and S 678/2025 are the operative documents. Confirm your own obligations with the Commissioner of Cybersecurity or your legal adviser.

cii

Book a scoping call

We map your position against CCoP 2026 clause by clause, the frameworks stacked beside it, and what has to close before 29 July 2027.

Where you stand against CCoP 2026 today
The frameworks layered on top, and where they overlap
Deployment options, from multi-cloud to air-gapped
Board and senior management evidence under clauses 3.1 and 3.2
1

Your Details

2

Your Organisation

Optional, expand to add more detail

Protect your organisation from threats with penetration testing, monitoring, and incident response.

Which specific areas are you interested in?

Achieve recognised security certifications and align with leading compliance frameworks.

Which specific areas are you interested in?

We don't share your details. No spam.