MTCS - Multi-Tier Cloud Security (Singapore)
The Multi-Tier Cloud Security (MTCS) Standard (SS 584) is Singapore's national cloud security standard developed by the Infocomm Media Development Authority (IMDA). Based on ISO 27001, it provides a three-tier framework (Level 1-3) for cloud security certification with increasing requirements. Level 1 covers basic security, Level 2 adds governance and risk management, and Level 3 addresses the most stringent requirements for highly regulated data. Mandatory for Singapore government cloud procurement.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Access Control
| Code | Title |
|---|---|
| MTCS.IAM-05 | Identity and Access Controls |
Cloud Governance and Compliance
Governance, risk management, and legal compliance for cloud services
| Code | Title |
|---|---|
| MTCS-GOV-01 | Cloud Governance Framework |
| MTCS-GOV-02 | Risk Assessment and Management |
| MTCS-GOV-03 | Legal and Regulatory Compliance |
| MTCS-GOV-04 | Service Level Management |
Data Protection
| Code | Title |
|---|---|
| MTCS.CRY-06 | Cryptographic Controls |
| MTCS.DAT-16 | Customer Data Lifecycle |
Development
| Code | Title |
|---|---|
| MTCS.SDL-12 | Secure Development Lifecycle |
Governance
| Code | Title |
|---|---|
| MTCS.AUD-19 | Audit, Assurance and Reporting |
| MTCS.GOV-01 | Cloud Governance Framework |
| MTCS.POL-02 | Cloud Security Policy Suite |
Network
| Code | Title |
|---|---|
| MTCS.NET-11 | Network Security |
Operations
| Code | Title |
|---|---|
| MTCS.ASM-04 | Asset Management for Cloud |
| MTCS.CHM-09 | Change Management |
| MTCS.LOG-17 | Logging, Monitoring and Forensics |
| MTCS.OPS-08 | Operations Management |
| MTCS.VLM-10 | Vulnerability Lifecycle Management |
People
| Code | Title |
|---|---|
| MTCS.HRS-03 | Personnel Security |
Physical
| Code | Title |
|---|---|
| MTCS.PHY-07 | Physical Security |
Privacy
| Code | Title |
|---|---|
| MTCS.PRI-18 | Privacy and Cross Border Data |
Resilience
| Code | Title |
|---|---|
| MTCS.BCM-15 | Business Continuity and Disaster Recovery |
| MTCS.INC-14 | Incident and Breach Management |
Third Party
| Code | Title |
|---|---|
| MTCS.SUP-13 | Supplier and Subservice Management |
Tiering
| Code | Title |
|---|---|
| MTCS.TER-20 | Tier Specific Differentiating Controls |
Your Compliance Coverage
If you comply with MTCS - Multi-Tier Cloud Security (Singapore), you already cover:
ISO 27017
17%
4 controls mapped
Compare →NIS2 Directive
17%
4 controls mapped
Compare →DORA
17%
4 controls mapped
Compare →+ 623 more: Vietnam Law on Cybersecurity (No. 24/2018/QH14) (17%), Montenegro Law on Personal Data Protection (2023) (17%)
See all 626 mapped frameworks ↓Maps to 626 other frameworks
Frequently Asked Questions
What is MTCS - Multi-Tier Cloud Security (Singapore)?
MTCS - Multi-Tier Cloud Security (Singapore) is a compliance framework from Singapore with 13 domains and 24 controls. The Multi-Tier Cloud Security (MTCS) Standard (SS 584) is Singapore's national cloud security standard developed by the Infocomm Media Development Authority (IMDA). Based on ISO 27001, it provides a three-tier framework (Level 1-3) for cloud security certification with increasing requirements. Level 1 covers basic security, Level 2 adds governance and risk management, and Level 3 addresses the most stringent requirements for highly regulated data. Mandatory for Singapore government cloud procurement. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does MTCS - Multi-Tier Cloud Security (Singapore) have?
MTCS - Multi-Tier Cloud Security (Singapore) has 24 controls organised across 13 domains. The largest domains are Operations (5 controls), Cloud Governance and Compliance (4 controls), Governance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does MTCS - Multi-Tier Cloud Security (Singapore) map to?
MTCS - Multi-Tier Cloud Security (Singapore) maps to 626 other compliance frameworks. The top mapping partners are ISO 27017 (17% coverage), NIS2 Directive (17% coverage), DORA (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with MTCS - Multi-Tier Cloud Security (Singapore) compliance?
Start your MTCS - Multi-Tier Cloud Security (Singapore) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about MTCS - Multi-Tier Cloud Security (Singapore) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required