Singapore Cybersecurity Act 2018
The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity. It designates Critical Information Infrastructure (CII) sectors, establishes the Cyber Security Agency of Singapore (CSA) as the regulatory authority, and provides for incident reporting, cybersecurity audits, and penetration testing. The 2024 amendments expand coverage to encompass entities of special cybersecurity interest and foundational digital infrastructure.
Singapore Cybersecurity Act 2018 is a compliance framework from Singapore with 10 domains and 27 controls that map to 214 other frameworks. The largest domains are Cybersecurity Act: CII Technical Safeguards (8 controls), Cybersecurity Act: CII Designation and Owner Duties (5 controls), Cybersecurity Act: Administration and Definitions (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
CII
| Code | Title |
|---|---|
| SGCYBER-1 | Critical Information Infrastructure (CII) Designation and Registration |
Cybersecurity Act: Administration and Definitions
Cybersecurity Act: CII Designation and Owner Duties
Cybersecurity Act: CII Technical Safeguards
| Code | Title |
|---|---|
| SCA-AC-1 | Access Control and Privileged Access for CII |
| SCA-DR-1 | Disaster Recovery and Continuity for the CII |
| SCA-IR-1 | Incident Response Plan Aligned to Sector Requirements |
| SCA-IR-2 | 24x7 Detection and Response Capability |
| SCA-LOG-1 | Logging, Monitoring, and Retention |
| SCA-NSC-1 | Network Segmentation and Zoning of the CII |
| SCA-SC-1 | Supply Chain Cybersecurity for CII |
| SCA-VM-1 | Vulnerability and Threat Management for CII |
Cybersecurity Act: Investigation, Emergency Powers and Penalties
Cybersecurity Act: Licensing of Cybersecurity Service Providers
Enforcement
| Code | Title |
|---|---|
| SGCYBER-5 | Investigation, Enforcement, Cooperation |
Incident Reporting
| Code | Title |
|---|---|
| SGCYBER-3 | Cyber Incident Reporting |
Licensing
| Code | Title |
|---|---|
| SGCYBER-4 | Licensing of Cybersecurity Services |
Standards
| Code | Title |
|---|---|
| SGCYBER-2 | Codes of Practice, Standards, Audits |
Your Compliance Coverage
If you comply with Singapore Cybersecurity Act 2018, you already cover:
FTC GLBA Safeguards Rule (16 CFR Part 314)
11%
3 controls mapped
Compare →AICPA Privacy Management Framework (PMF)
11%
3 controls mapped
Compare →Kuwait National Cybersecurity Framework
11%
3 controls mapped
Compare →+ 211 more: Singapore Government Instruction Manual on ICT&SS Management (IM8) (11%), ISO/IEC 30111:2019 (11%)
See all 214 mapped frameworks ↓Maps to 214 other frameworks
What is Singapore Cybersecurity Act 2018 and who does it apply to?
Singapore Cybersecurity Act 2018 is a compliance framework from Singapore with 10 domains and 27 controls. The Singapore Cybersecurity Act 2018 establishes a legal framework for the oversight and maintenance of national cybersecurity. It designates Critical Information Infrastructure (CII) sectors, establishes the Cyber Security Agency of Singapore (CSA) as the regulatory authority, and provides for incident reporting, cybersecurity audits, and penetration testing. The 2024 amendments expand coverage to encompass entities of special cybersecurity interest and foundational digital infrastructure. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Singapore Cybersecurity Act 2018 actually require?
Singapore Cybersecurity Act 2018 has 27 controls organised across 10 domains. The largest domains are Cybersecurity Act: CII Technical Safeguards (8 controls), Cybersecurity Act: CII Designation and Owner Duties (5 controls), Cybersecurity Act: Administration and Definitions (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Singapore Cybersecurity Act 2018 do I already cover?
Singapore Cybersecurity Act 2018 maps to 214 other compliance frameworks. The top mapping partners are FTC GLBA Safeguards Rule (16 CFR Part 314) (11% coverage), AICPA Privacy Management Framework (PMF) (11% coverage), Kuwait National Cybersecurity Framework (11% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Singapore Cybersecurity Act 2018?
Start your Singapore Cybersecurity Act 2018 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Cybersecurity Act 2018 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 27 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required