Cybersecurity Code of Practice for Critical Information Infrastructure to be Updated to Address APT and AI-enabled Threats
22 July 2026
A New Code of Practice for Cloud Services will be launched in the later part of this year.
1 The Cyber Security Agency of Singapore (CSA) will be releasing the updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII)[1] and a new CCoP for Cloud Services in the later part of this year. This was announced by Mrs Josephine Teo, Minister for Digital Development and Information and Minister-in-charge of Cybersecurity and Smart Nation Group at the Operational Technology Cybersecurity Expert Panel Forum 2026.
Upcoming Launch of CCoP 2026
2 Since the last update of the CCoP in 2022, the cyber threat landscape has shifted with new AI-enabled threats, allowing threat actors to launch attacks faster and at a greater scale. With the emergence of Frontier AI, threat actors can now discover vulnerabilities faster, thus shortening the window period for exploitation. As part of Singapore’s efforts to deal with Advanced Persistent Threats (APTs) and AI-enabled threats, the Government is working together with CII owners to raise their cybersecurity posture. The CCoP will be further updated later this year with technical guidance covering adversarial attack simulation, penetration testing, and threat hunting.
3 The updates to CCoP focus on strengthening CII governance, visibility, detection and readiness, and broader enterprise networks that are interconnected with the CIIs to align with the amendments made to the Cybersecurity Act[2]. The key changes are:
CII owners are required to strengthen Board and senior management accountability and oversight for cybersecurity. Boards must maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery – reviewed at least annually
CII owners are required to attain Cyber Trust Mark Level 5 certification to elevate the cybersecurity posture of CIIs
CII owners are required to maintain oversight of interconnected systems that connects with and communicates with CII to strengthen visibility of the broader network architecture and improve cybersecurity risk management
CSA will work with CII owners to deploy threat detection systems across CII owners’ network segments to detect malicious activities.
CII owners are required to develop a comprehensive cybersecurity exercise plan, to ensure coordinated and effective response to cyber incidents.
CII owners are required to have robust management measures to maintain network architecture, for example, in the areas of network management, monitoring, and detection management.
Planned Launch of the CCoP (Cloud) in 2H 2026
4 With CII owners increasingly adopting cloud technologies to support their operations, there is a need to ensure that these environments are secured against evolving cyber threats. The CCoP (Cloud) aims to establish cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud.
5 CSA conducted a series of closed-door consultations with key stakeholders, including auditors as well as CII owners that have or are exploring the adoption of cloud services. The purpose is to understand the operating environment and ensure that the proposed controls are practical and implementable. Feedback gathered through these engagements was incorporated into the refinement of both the controls and the accompanying guidance statements, resulting in a more robust, practical, and operationally applicable set of requirements.
6 CSA has partnered with leading Cloud Service Providers (CSPs), namely, Amazon Web Services, Google Cloud and Microsoft Azure, to jointly develop CSP-specific Companion Guides. These Companion Guides will provide practical guidance on how the CCoP (Cloud) controls can be implemented within their respective cloud environments through appropriate configurations and the effective use of cloud-native services and security capabilities. The Companion Guides will be published alongside the CCoP (Cloud).
*****
[1] The CCoP is intended to specify the minimum requirements that the CII Owner shall implement to ensure the cybersecurity of its CII in accordance with the Cybersecurity Act.
[2] The Cybersecurity Act establishes a legal framework for the oversight and maintenance of national cybersecurity in Singapore. The Act has been amended to ensure that CII owners remain responsible for the cybersecurity and cyber resilience of the CII, even as they embrace new technological and business models, like the use of cloud computing.
About the Cyber Security Agency of Singapore
Established in 2015, the Cyber Security Agency of Singapore (CSA) seeks to keep Singapore’s cyberspace safe and secure to underpin our National Security, power a Digital Economy and protect our Digital Way of Life. It maintains oversight of national cybersecurity functions and works with sector leads to protect Singapore’s Critical Information Infrastructure. CSA also engages various stakeholders to heighten cyber security awareness, build a vibrant cybersecurity ecosystem supported by a robust workforce, pursue international partnerships, and drive regional cybersecurity capacity building programmes. CSA is part of the Prime Minister’s Office and is managed by the Ministry of Digital Development and Information. For more news and information, please visit www.csa.gov.sg.
For media queries, please contact:
Goh Jing Xian
Senior Assistant Director, Communications and Engagement Division
Email: goh_jing_xian@csa.gov.sg
Cassandra Yeo
Manager, Communications and Engagement Division
Email: cassandra_yeo@csa.gov.sg
