Singapore Cybersecurity Act 2018
The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity. It designates Critical Information Infrastructure (CII) sectors, establishes the Cyber Security Agency of Singapore (CSA) as the regulatory authority, and provides for incident reporting, cybersecurity audits, and penetration testing. The 2024 amendments expand coverage to encompass entities of special cybersecurity interest and foundational digital infrastructure.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Access Control
| Code | Title |
|---|---|
| SCA-AC-1 | Access Control and Privileged Access for CII |
Audit
| Code | Title |
|---|---|
| SCA-13 | Cybersecurity Audits and Risk Assessments |
CII Designation
| Code | Title |
|---|---|
| SCA-7 | Designation of Critical Information Infrastructure |
Change Notification
| Code | Title |
|---|---|
| SCA-10 | Notification of Material Changes to the CII |
Compliance
| Code | Title |
|---|---|
| SCA-11 | Codes of Practice and Standards of Performance |
Due Process
| Code | Title |
|---|---|
| SCA-16 | Appeals Against Designation or Directions |
Exercises
| Code | Title |
|---|---|
| SCA-15 | Cybersecurity Exercises Participation |
Incident Reporting
| Code | Title |
|---|---|
| SCA-14 | Reporting of Prescribed Cybersecurity Incidents |
Incident Response
| Code | Title |
|---|---|
| SCA-IR-1 | Incident Response Plan Aligned to Sector Requirements |
Information Provision
| Code | Title |
|---|---|
| SCA-8 | Furnishing of Information About the CII |
Investigations
| Code | Title |
|---|---|
| SCA-19 | Powers of Investigation by Authorised Officers |
Logging
| Code | Title |
|---|---|
| SCA-LOG-1 | Logging, Monitoring, and Retention |
Network Security
| Code | Title |
|---|---|
| SCA-NSC-1 | Network Segmentation and Zoning of the CII |
Operations
| Code | Title |
|---|---|
| SCA-IR-2 | 24x7 Detection and Response Capability |
Part 1 - Preliminary
Definitions, objects and application of the Act
| Code | Title |
|---|---|
| CSA24-OBJ | Objects of the Act |
| SCA-S2 | Interpretation and Definitions |
| SCA-S3 | Appointment of Commissioner |
Part 2 - Administration
| Code | Title |
|---|---|
| SCA-S4 | Commissioner Functions and Duties |
| SCA-S5 | Cybersecurity Codes and Standards |
Part 3 - CII Designation and Obligations
| Code | Title |
|---|---|
| SCA-S10 | Annual Risk Assessment |
| SCA-S11 | Annual Audit |
| SCA-S14 | Incident Notification |
| SCA-S7 | CII Designation |
| SCA-S9 | Compliance with Codes and Directions |
Part 4 - Cybersecurity Service Provider Licensing
| Code | Title |
|---|---|
| SCA-S26 | Licensing Framework |
| SCA-S28 | License Conditions |
Part 5 - Investigation and Enforcement
| Code | Title |
|---|---|
| SCA-S32 | Investigation of Cybersecurity Threats |
| SCA-S35 | Emergency Measures |
| SCA-S36 | Penalties for Non-Compliance |
Record-Keeping
| Code | Title |
|---|---|
| SCA-30 | Record-Keeping by Licensees |
Regulatory Direction
| Code | Title |
|---|---|
| SCA-12 | Directions Issued by the Commissioner |
Resilience
| Code | Title |
|---|---|
| SCA-DR-1 | Disaster Recovery and Continuity for the CII |
Service Provider Licensing
| Code | Title |
|---|---|
| SCA-26 | Licensing of Cybersecurity Service Providers |
Supply Chain
| Code | Title |
|---|---|
| SCA-SC-1 | Supply Chain Cybersecurity for CII |
Vulnerability Management
| Code | Title |
|---|---|
| SCA-VM-1 | Vulnerability and Threat Management for CII |
Your Compliance Coverage
If you comply with Singapore Cybersecurity Act 2018, you already cover:
ISO/IEC 29147:2018
11%
4 controls mapped
Compare →AICPA Privacy Management Framework (PMF)
11%
4 controls mapped
Compare →Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
11%
4 controls mapped
Compare →+ 331 more: RBI Cybersecurity Framework for Banks (11%), Singapore Government Instruction Manual on ICT&SS Management (IM8) (11%)
See all 334 mapped frameworks ↓Maps to 334 other frameworks
Frequently Asked Questions
What is Singapore Cybersecurity Act 2018?
Singapore Cybersecurity Act 2018 is a compliance framework from Singapore with 25 domains and 35 controls. The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity. It designates Critical Information Infrastructure (CII) sectors, establishes the Cyber Security Agency of Singapore (CSA) as the regulatory authority, and provides for incident reporting, cybersecurity audits, and penetration testing. The 2024 amendments expand coverage to encompass entities of special cybersecurity interest and foundational digital infrastructure. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Singapore Cybersecurity Act 2018 have?
Singapore Cybersecurity Act 2018 has 35 controls organised across 25 domains. The largest domains are Part 3 - CII Designation and Obligations (5 controls), Part 1 - Preliminary (3 controls), Part 5 - Investigation and Enforcement (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Singapore Cybersecurity Act 2018 map to?
Singapore Cybersecurity Act 2018 maps to 334 other compliance frameworks. The top mapping partners are ISO/IEC 29147:2018 (11% coverage), AICPA Privacy Management Framework (PMF) (11% coverage), Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016) (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Singapore Cybersecurity Act 2018 compliance?
Start your Singapore Cybersecurity Act 2018 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Cybersecurity Act 2018 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required