Singapore – The Cyber Security Agency of Singapore (CSA) will update its Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and introduce a new Cybersecurity Code of Practice for Cloud Services later this year, as the government responds to evolving cyber threats, including advanced persistent threats (APTs) and AI-enabled attacks.
The announcement was made by Josephine Teo, Minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group, during the Operational Technology Cybersecurity Expert Panel Forum 2026.
According to CSA, the updated CCoP will reflect changes in the cyber threat landscape since the framework’s last revision in 2022. The agency said advances in artificial intelligence, particularly frontier AI, have enabled threat actors to identify vulnerabilities more quickly and launch attacks at greater speed and scale. In response, the revised code will include additional technical guidance covering adversarial attack simulation, penetration testing, and threat hunting.
The updated requirements are also intended to align with recent amendments to Singapore’s Cybersecurity Act and strengthen governance, detection capabilities, operational readiness, and oversight of enterprise networks connected to critical infrastructure.
Among the new measures, CII owners will be required to strengthen board and senior management accountability for cybersecurity by maintaining a documented cyber resilience framework that outlines risk tolerance, mitigation, risk transfer, and recovery strategies, with annual reviews.
Organisations designated as CII owners will also be required to obtain Cyber Trust Mark Level 5 certification, maintain oversight of interconnected systems that communicate with critical infrastructure, and develop comprehensive cybersecurity exercise plans to improve incident response preparedness.
In addition, CSA said it will work with CII owners to deploy threat detection systems across network segments to improve visibility into malicious activities. The revised code will also require stronger network management, monitoring, and detection measures to support secure network architecture.
Separately, CSA will introduce a new CCoP for Cloud Services in the second half of 2026 to address the growing adoption of cloud technologies by operators of critical information infrastructure.
The cloud-focused code will establish cybersecurity requirements for the secure deployment, operation, and management of CII systems hosted in cloud environments.
To develop the framework, CSA conducted closed-door consultations with auditors and CII owners that have adopted or are considering cloud services. Feedback from these engagements was used to refine the proposed controls and accompanying implementation guidance.
CSA has also partnered with Amazon Web Services, Google Cloud, and Microsoft Azure to produce cloud provider-specific Companion Guides. The guides will provide practical recommendations on implementing the cloud code’s controls using each provider’s native security capabilities and configuration options and will be released alongside the new CCoP for Cloud Services.

