CSA to publish new Cybersecurity Code of Practice for Cloud Services and update Cybersecurity Code of Practice for Critical Information Infrastructure to address emergent threats
27 August 2026
On 22 July 2026, the Cyber Security Agency of Singapore (“CSA”) announced that it will release a new Cybersecurity Code of Practice for Cloud Services (“Cloud CCoP”) and an updated Cybersecurity Code of Practice for Critical Information Infrastructure (“CII CCoP”) in the later part of 2026.
New Cloud CCoP
With critical information infrastructure (“CII”) owners increasingly adopting cloud technologies to support their operations, there is a need to ensure that these environments are secured against evolving cyber threats. The new Cloud CCoP aims to establish cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud.
CSA has also partnered with leading cloud service providers (“CSPs”) to jointly develop CSP-specific companion guides (“Companion Guides”). The Companion Guides will provide practical guidance on how the Cloud CCoP controls can be implemented within their respective cloud environments through appropriate configurations and the effective use of cloud-native services and security capabilities. The Companion Guides will be published alongside the Cloud CCoP.
Updated CII CCoP
Since the CII CCoP was last updated in 2022, the cyber threat landscape has evolved, with new threats enabled by artificial intelligence (“AI”) and frontier AI enabling threat actors to launch attacks faster and at greater scale. To deal with advanced persistent threats and AI-enabled threats, the Government is working with CII owners to raise their cybersecurity posture. The CII CCoP will be further updated this year with technical guidance covering adversarial attack simulation, penetration testing, and threat hunting.
The updates to the CII CCoP focus on strengthening CII governance, visibility, detection, and readiness, and broader enterprise networks that are interconnected with the CIIs to align with the amendments made to the Cybersecurity Act 2018. CII owners will be required to:
- strengthen board and senior management accountability and oversight for cybersecurity, and their boards must maintain a documented cyber resilience framework, to be reviewed at least annually, covering risk tolerance, mitigation, transfer, and recovery;
- attain Cyber Trust Mark Level 5 certification to elevate the cybersecurity posture of CIIs;
- maintain oversight of interconnected systems that connect with and communicate with CII to strengthen visibility of the broader network architecture and improve cybersecurity risk management;
- develop a comprehensive cybersecurity exercise plan to ensure a coordinated and effective response to cyber incidents; and
- have robust management measures to maintain network architecture, for example, in the areas of network management, monitoring, and detection management.
In addition, CSA will work with CII owners to deploy threat detection systems across CII owners’ network segments to detect malicious activities.
Reference materials
The press release is available on the CSA website www.csa.gov.sg.