Skip to content

Singapore Cybersecurity Act

Amended Singapore · In force Aug 31, 2018 · no upcoming deadlines

Deadlines

DateWhat happens
Oct 31, 202511 months ago2024 amendments commence
Apr 11, 20224 years agoCybersecurity service provider licensing commences
Aug 31, 20188 years agoCybersecurity Act main provisions commence

Summaries for reference, not legal advice. Check the official text.

What it does

Singapore's framework for protecting critical information infrastructure (CII). CII owners must meet codes of practice, run audits and risk assessments, and report prescribed cybersecurity incidents to the Commissioner of Cybersecurity. Providers of licensable services (penetration testing and managed SOC) need a licence. The 2024 amendments extend oversight to foundational digital infrastructure providers, entities of special cybersecurity interest, systems of temporary cybersecurity concern, and CII located overseas, and add civil penalties.

Who it applies to
Owners of designated CII, licensed cybersecurity service providers, and since 2025 foundational digital infrastructure providers (such as cloud and data centre operators), entities of special cybersecurity interest and owners of systems of temporary cybersecurity concern.
Penalties
For some offences, fines up to the greater of SGD 200,000 or 10% of the person's annual turnover in Singapore, plus up to SGD 5,000 a day for continuing offences. The Commissioner may seek a court-ordered civil penalty instead of prosecution (section 37A).
Enforced by
Commissioner of Cybersecurity (Cyber Security Agency of Singapore)
Official name
Cybersecurity Act 2018
Citation
Act No. 9 of 2018; amended by Cybersecurity (Amendment) Act 2024 (Act No. 19 of 2024)
Topics
cybersecurity, breach-notification
Verified 2026-09-25 sso.agc.gov.sg sso.agc.gov.sg
Research notes

Passed 2018-02-05 and assented 2018-03-02. The 2024 amendment was passed 2024-05-07 and assented 2024-05-23. Some sections of the 2024 Act are not listed in the 2025-10-31 commencement. SSO blocks automated fetch but loads in a browser.

Related

Questions about Singapore Cybersecurity Act
What are the Singapore Cybersecurity Act compliance deadlines?
Aug 31, 2018: Cybersecurity Act main provisions commence. Apr 11, 2022: Cybersecurity service provider licensing commences. Oct 31, 2025: 2024 amendments commence.
When does Singapore Cybersecurity Act take effect?
Singapore Cybersecurity Act took effect on Aug 31, 2018.
Who does Singapore Cybersecurity Act apply to?
Owners of designated CII, licensed cybersecurity service providers, and since 2025 foundational digital infrastructure providers (such as cloud and data centre operators), entities of special cybersecurity interest and owners of systems of temporary cybersecurity concern.
What are the penalties under Singapore Cybersecurity Act?
For some offences, fines up to the greater of SGD 200,000 or 10% of the person's annual turnover in Singapore, plus up to SGD 5,000 a day for continuing offences. The Commissioner may seek a court-ordered civil penalty instead of prosecution (section 37A).

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.