CCoP 2026 started
the clock. 29 July 2027 ends it.
Every regulation a CII owner answers to, in one platform
The Code took effect on 29 July 2026. Existing CII owners have until 29 July 2027 for the new board, asset, detection, exercise and interconnected-systems clauses, and until 31 December 2027 for Cyber Trust Mark Tier 5. Zavior holds the clause set, the gap position, the evidence and the board minutes in one place.
Singapore just tightened the rules.
Singapore tightens rules governing critical services sectors to counter AI, cyber threats
Lee Li Ying · Published 22 July 2026 · Updated 27 July 2026
Minister for Digital Development and Information Josephine Teo, speaking at the sixth Operational Technology Cybersecurity Expert Panel Forum.
Read it on The Straits Times“AI has challenged the longstanding assumption that the complexity of operational technology systems keeps them safe from attack.”
“Ultimately, cybersecurity is a business risk that requires sustained leadership and oversight from the board, rather than being viewed solely as a technical or operational issue.”
This was not a consultation. CSA issued the Code the same week, and it took effect on 29 July 2026.
The board is now named in the Code rather than assumed. Clause 3.1 puts documented duties on the whole board, where previously one director with cybersecurity knowledge was enough. Teo also confirmed Cyber Trust Mark Tier 5 by the end of 2027 for the enterprise systems that support your CII without being the CII, and a separate cloud code of practice later in the year.
The forum context matters. UNC3886, a state-sponsored espionage group, was detected inside Singapore's four major telcos in July 2025. Section 12 of the new Code, covering interconnected systems, reads like a direct answer to that.
Read the primary sources
Four dates decide your next eighteen months.
One has passed. Three have not. The gap between them is the whole programme.
CCoP 2026 took effect
Release 1 superseded CCoP 2.0 Revision 1. Twelve sections, plus a new Section 12 covering the interconnected systems you own, operate or control.
Clause 1.1.1Your auditor needs certifying
CII auditors need organisation-level Cyber Trust Mark certification. Licensed providers doing penetration testing or managed SOC monitoring need Promoter, Tier 3. If your usual firm is not certified, you are booking a different firm.
MDDI factsheet, 2 Mar 2026The main compliance date
Board accountability and training, senior management duties, asset management, monitoring and detection, the cybersecurity exercise clauses, and the whole of Section 12. Until then you minimally comply with the previous version.
Clauses 3.1.4 to 3.2.5, 4.1.2, 6.2.4, 7.3, Section 12Cyber Trust Mark Advocate, Tier 5
All 22 domains, covering the enterprise systems that support your CII without being the CII. New CII owners get 24 months from designation instead.
Clause 3.3.1Breaching the Code is not itself an offence. Section 35A(5) of the Cybersecurity Act says a code of practice has no legislative effect. What follows non-compliance is a written direction from the Commissioner under section 12(1), and failing that direction carries a fine of up to $100,000.
Eleven sectors. More systems than most owners expect.
CSA designates critical information infrastructure across eleven sectors. Most CII owners are private operators, not agencies, and the 2024 amendments widened what can be designated in ways that catch people out.
You may be in scope and not know it
The Cybersecurity (Amendment) Act 2024 commenced on 31 October 2025. Five changes matter here.
Cloud-hosted systems count
The definitions of computer and computer system now include virtual computers and virtual computer systems. A system running on infrastructure you do not own can be designated CII.
So can systems outside Singapore
Section 7(1A) lets the Commissioner designate a computer system located wholly outside Singapore as provider-owned CII.
You can be responsible for CII you do not own
Part 3A makes an essential service provider responsible for the cybersecurity of CII owned by a third party, and requires legally binding commitments from that owner covering design information, security standards and notification of material changes.
Your supplier's incident is your report
Section 14 reporting extends to incidents on systems under a supplier's control that are interconnected with, or communicate with, your CII.
Designation can be temporary
Part 3B lets the Commissioner designate a System of Temporary Cybersecurity Concern for up to a year, renewable. CSA's own examples are systems supporting elections and vaccine distribution.
Six instruments. One control set.
No CII owner answers to the Code alone. The stack below is what a single operator carries at once, and today it usually lives in six different trackers maintained by people who never meet.
Assessed once. Counted everywhere it applies. Evidence attached to all of it.
What you carry
CCoP 2026
12 sections, board through OT
Cybersecurity Act 2018
s15 audit every 2 years, risk assessment every year
S 678/2025
2 hours, 72 hours, 30 days
Cyber Trust Mark
Advocate Tier 5, all 22 domains
Your sector regulator
MAS TRM, IM8 or your own
Customer demands
ISO/IEC 27001, SOC 2, IEC 62443
In Zavior
Privileged access management
assessed once
Six capabilities. Each one earning its place under the Code.
CCoP 2026
Clause 12.4.1
Network segmentation
Controls
satisfy it
Risks
threaten it
Policies
state it
Evidence
proves it
Change the policy and the clause status moves.
Every obligation on one connected record
Most CII owners run the Code out of a spreadsheet, the annual risk assessment out of a second one, the audit out of a shared drive, and the board pack out of slides somebody rebuilds every six months. Nothing reconciles. Reconciling it is the job.
Zavior holds all of it as one connected record. A CCoP clause knows which controls satisfy it, which risks threaten it, which policy states the position and which evidence proves it. Change the policy and the clause status moves. Close a risk and the control it was blocking clears.
The difference shows up under section 15. An audit every two years and a risk assessment every year both need the same underlying facts. When those facts live in one place, the second exercise stops being a second data-gathering project.
Assessed once
Privileged access management
One piece of evidence. Five frameworks satisfied.
Map a control once, count it in every framework
No CII owner answers to the Code alone. A bank carries MAS TRM on top of it. An agency carries IM8. Almost everyone carries ISO 27001 because a customer asked for it. From 31 December 2027 every CII owner also carries Cyber Trust Mark Advocate across all 22 domains, for the enterprise systems that support the CII without being the CII.
These frameworks overlap heavily and are worded differently. That is why the same access control gets assessed four times, by four teams, none of whom see each other's work.
Zavior maps a control once and counts it everywhere it applies. Assess privileged access management once and it satisfies the CCoP clause, the MAS TRM requirement, the ISO 27001 Annex A control and the Cyber Trust Mark domain, with the same evidence attached to all four.
Multi-cloud
Private cloud
On premise
Air-gapped
Clause 3.9 says
Deployed where a CII system is allowed to live
Clause 3.9 is blunt about cloud. You stay accountable for the cybersecurity of the CII even when it runs wholly or partly on someone else's infrastructure. You must inform the Commissioner before putting any part of the CII on cloud, whatever the deployment or service model. You must submit a risk assessment within 30 days of completing it, and if the Commissioner is not satisfied, you rectify at your own cost.
Clause 3.9.4 adds a requirement that quietly rules out a lot of tooling: the cloud service provider has to appoint a person within Singapore authorised to accept service of legal process.
Zavior is one product packaged for four environments. Same codebase, same upgrade path, no forked build per deal. For an OT environment answering Section 10, air-gapped is a supported mode rather than an exception you negotiate into a contract.
One control set
Six views of it
The board, the CISO, OT and IT on one control set
CCoP 2026 does not hand compliance to one team. Clause 3.1 puts named duties on the board. Clause 3.2 puts them on at least one senior manager with authority across the CII, its interconnected systems and the enterprise network. Section 10 belongs to whoever runs OT. Section 12 belongs to whoever owns the interconnected systems, which is frequently nobody until somebody asks.
What those people share is not a tool. It is the control set.
Zavior gives each of them a role profile and a task stack scoped to what they actually own, sitting on one record. The section 15 auditor gets a read-only profile of their own, which is how an audit stops being a document request exercise and starts being a review.
Zavior AI
sandboxed by default
Clause evidence
retrieval scoped to you
Architecture, incidents
never leaves
Isolation enforced in the application layer, so a security review can probe it.
AI that never sends your evidence outside
CSA published its Securing Agentic AI addendum on 17 June 2026, covering supply chain security, model and system hardening, authorisation, limiting system autonomy and continuous monitoring. It rests on a plain position: start with a risk assessment, and treat the model as part of the system rather than a tool beside it.
For a CII owner that has a sharp practical edge. The documents an AI assistant would be most useful against are the documents you are least able to send anywhere.
Zavior's AI runs sandboxed by default inside your deployment, or fully air-gapped where there is no network path. Retrieval is scoped to your organisation, so a model answering your question can only ever see your corpus. Isolation is enforced in the application layer at the organisation boundary, which means a security review can probe it instead of taking a policy document's word for it.
What is our position on privileged access in OT?
What changed since the last briefing?
Which clauses are still open against 29 Jul 2027?
Board guidance arising gets minuted against the clause it satisfies.
The board briefing that falls due twice a year
Clause 3.1.5 requires a threat briefing to the board at least once every six months. It has to cover threats relevant to the CII and the sector, threats that have actively targeted you since the last briefing, and what that means for risk posture, including recommended changes to controls, risk appetite, budget or resourcing. Board guidance arising from it has to be minuted.
Clause 3.2.4 adds a posture report at least every six months, and promptly whenever a reportable incident occurs. Most organisations build these from scratch each cycle, which is why they arrive late and read like the last one.
Ask a plain-language question and Zavior answers from your approved documents with the source attached. What is our position on privileged access in OT. What changed since the last briefing. Which clauses are still open against 29 July 2027. The answer is cited, so it survives the follow-up question.
Zavior is not your auditor.
There is a version of this page that claims Zavior runs your CCoP audit, tests your network and drills your response team. It would be easier to sell. It would also not be true. Those are engagements, performed by people carrying their own certifications, and from 31 December 2026 your CII auditor needs organisation-level Cyber Trust Mark certification while your penetration testing provider needs Promoter, Tier 3.
What breaks in most CII programmes is not the assessment. It is what happens to the assessment afterwards. The gap analysis is a PDF by March. The pen test report is an attachment nobody reopens. The exercise after-action items live in one person's inbox until that person changes jobs. Then the auditor arrives and the whole thing gets reconstructed from memory and calendar invites.
Zavior is where all of it lands and stays connected. The clause set, the gap position, the findings from whoever produced them, the evidence, the owners, the dates, the board minutes. Bring your own assessor. Bring four. The record is yours either way, and it is still standing in two years when section 15 comes round again.
29 July 2027 is closer than it reads.
Book a scoping call. We map your CCoP position, the frameworks stacked beside it, and where the gaps actually sit.
Eight things a CII owner has to get done.
Zavior performs none of them. Zavior is where every one of them lands, and what proves afterwards that it happened.
CCoP gap and readiness assessment
Where you stand today against every clause of CCoP 2026, and what has to change before 29 July 2027.
All 12 sections. Annex A is voluntary and sits outside audit scope.
What Zavior holds
The clause set as a live framework. Every clause carries a status, an owner, a target date and the evidence gathered so far. The gap is a view you open, not a document that goes stale the week after it is signed off.
CCoP audit
The independent assessment. Section 15 of the Act requires one at least once every two years, by an auditor the Commissioner approves.
Section 15 of the Act. Clause 3.3.3 on the auditor's own certification.
What Zavior holds
A read-only auditor profile with evidence attached clause by clause, so the audit runs against the live record instead of a document request list. Findings become tracked items with owners. The 30-day deadline for the report to the Commissioner sits on the dashboard as a date.
CII cybersecurity risk assessment
Your posture against the threats that are actually moving. Section 15 requires one at least once a year.
Section 15 of the Act. Section 3 risk management.
What Zavior holds
The risk register, mapped to the CII assets each risk threatens and the clauses each one puts at risk. Last assessed and next due sit on every entry, so an annual cadence is visible well before it lapses.
Security architecture review
Whether the design and the build still match, and whether the segmentation holds.
Section 5 protection requirements, network segmentation. Section 12 interconnected systems.
What Zavior holds
Architecture documents under version control with approval history. Review findings attach to the controls they affect and become remediation tasks, so the next reviewer starts from what changed rather than from nothing.
OT and ICS security assessment and architecture review
The specialised work on operational technology and industrial control systems, where a bad afternoon stops the service rather than leaking a file.
Section 10: OT architecture and security, secure coding, field controllers.
What Zavior holds
Section 10 as its own control set, with OT owners assigned separately from IT. Field controllers and OT segments sit in the same asset register as everything else, which is usually where an operator first sees the gap between two inventories nobody had compared.
Penetration testing and red teaming
Authorised simulated attack, from a network penetration test through to a full-scope red team exercise.
Section 5: vulnerability assessment, penetration testing, adversarial attack simulation.
What Zavior holds
The report lands as evidence against the clause it satisfies. Exploitable findings become risks with owners and retest dates. When the next auditor asks what happened to finding four, the answer lives beside the finding.
Cybersecurity simulation
Tabletop discussion through to full technical drill, validating the response plan and the people who have to run it at 3am.
Clauses 7.3.1, 7.3.2, 7.3.7 and 7.3.10, all due 29 July 2027.
What Zavior holds
The exercise plan, the scenario, who attended and every after-action item tracked to closure. The 2 hour, 72 hour and 30 day reporting clock can be drilled against the real escalation path rather than a diagram of it.
Cybersecurity awareness and training
Customised programmes for staff, and a separate one for the board.
Section 9 for staff. Clause 3.1.4 for the board.
What Zavior holds
Clause 3.1.4 wants records of attendance and curriculum, refreshed every 12 months, with newly appointed directors trained within 12 months of joining. Zavior keeps the roster, the curriculum and the dates, and flags the director who is coming due.
Zavior does not perform audits, penetration tests, red team exercises or OT assessments. Bring your own assessor, or ask us who we work with.
CCoP 2026, answered.
The Cybersecurity Code of Practice for Critical Information Infrastructure (2026), Release 1. CSA issued it on 29 July 2026 under section 35A(1)(a)(i) of the Cybersecurity Act 2018. Clause 1.1.1 supersedes every previous version, including CCoP 2.0 Revision 1 from December 2022. There has never been a CCoP 2.1.
By 29 July 2027 for the bulk of the new requirements: board accountability and training under clauses 3.1.4 and 3.1.5, senior management duties under 3.2.1 to 3.2.5, asset management under 4.1.2 to 4.1.4, monitoring and detection under 6.2.4, the cybersecurity exercise clauses under 7.3, and the whole of Section 12 on interconnected systems. Cyber Trust Mark Advocate certification under clause 3.3 is due by 31 December 2027. During the transition period, clause 1.4.4 says you minimally comply with the previous version of the Code.
Clause 3.1.2 requires a documented cyber resilience framework covering four pillars: risk tolerance, risk mitigation, risk transfer and risk recovery. Each is reviewed at least once every 12 months and documented in board minutes or equivalent written records. Risk transfer explicitly includes cyber insurance and material third-party indemnities. Risk recovery requires a business continuity and disaster recovery strategy defining maximum tolerable downtime after a cyber incident. Clause 3.1.4 adds board cybersecurity training at least every 12 months, contextualised to your operating environment, with records of attendance and curriculum maintained. Newly appointed directors must complete it within 12 months of appointment. Clause 3.1.5 requires a threat briefing at least every six months.
Three deadlines, set by the Cybersecurity (CII) (Amendment) Regulations 2025 (S 678/2025), in operation from 31 October 2025. Initial notification by telephone within 2 hours of becoming aware. Written supplementary details within 72 hours of becoming aware. A final written report within 30 days of the supplementary submission. The 72-hour deadline replaced the previous 14-day deadline, which regulation 6(f) deleted. Lower-severity incidents on owner-controlled systems that are not interconnected with the CII can go on a quarterly track, unless one of four escalation triggers applies: a publicly observable effect, exploitation of a zero-day, detection of a Commissioner-notified APT indicator of compromise, or suspected APT involvement.
Breaching the Code is not itself an offence. Section 35A(5) of the Cybersecurity Act states that a code of practice has no legislative effect. Under clause 1.4.7, non-compliance allows the Commissioner to issue a written direction under section 12(1) of the Act. Failing to comply with that direction is an offence, carrying a fine of up to $100,000. Separately, failing to report a prescribed cybersecurity incident under section 14(3) carries a fine of up to $100,000, imprisonment of up to 2 years, or both.
Yes. Since 31 October 2025 the definitions of computer and computer system in the Cybersecurity Act include virtual computers and virtual computer systems, so cloud-hosted systems can be designated. Section 7(1A) also allows designation of a system located wholly outside Singapore as provider-owned CII. Clause 3.9 of CCoP 2026 keeps the owner accountable regardless: you must inform the Commissioner before putting any part of the CII on cloud, submit a risk assessment within 30 days of completing it, and rectify at your own cost if the Commissioner is not satisfied. A separate Cybersecurity Code of Practice for cloud services was announced for the second half of 2026 and has not been published yet.
No. Zavior is a platform, not an assessor. Audits, penetration tests, red team exercises and OT assessments are performed by firms carrying their own certifications, and from 31 December 2026 your CII auditor needs organisation-level Cyber Trust Mark certification while a licensed penetration testing provider needs Promoter, Tier 3. What Zavior does is hold the CCoP clause set, track your gap position, keep the evidence those engagements produce attached to the clauses they satisfy, and turn it into board reporting. Bring your own assessor, or ask us who we work with.
This page summarises published Singapore regulation as at August 2026 and is not legal advice. CCoP 2026 Release 1, the Cybersecurity Act 2018 and S 678/2025 are the operative documents. Confirm your own obligations with the Commissioner of Cybersecurity or your legal adviser.
Get Started
Book a scoping call
We map your position against CCoP 2026 clause by clause, the frameworks stacked beside it, and what has to close before 29 July 2027.