Singapore Cybersecurity Act
Amended Singapore · In force Aug 31, 2018 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Singapore's framework for protecting critical information infrastructure (CII). CII owners must meet codes of practice, run audits and risk assessments, and report prescribed cybersecurity incidents to the Commissioner of Cybersecurity. Providers of licensable services (penetration testing and managed SOC) need a licence. The 2024 amendments extend oversight to foundational digital infrastructure providers, entities of special cybersecurity interest, systems of temporary cybersecurity concern, and CII located overseas, and add civil penalties.
- Who it applies to
- Owners of designated CII, licensed cybersecurity service providers, and since 2025 foundational digital infrastructure providers (such as cloud and data centre operators), entities of special cybersecurity interest and owners of systems of temporary cybersecurity concern.
- Penalties
- For some offences, fines up to the greater of SGD 200,000 or 10% of the person's annual turnover in Singapore, plus up to SGD 5,000 a day for continuing offences. The Commissioner may seek a court-ordered civil penalty instead of prosecution (section 37A).
- Enforced by
- Commissioner of Cybersecurity (Cyber Security Agency of Singapore)
- Official name
- Cybersecurity Act 2018
- Citation
- Act No. 9 of 2018; amended by Cybersecurity (Amendment) Act 2024 (Act No. 19 of 2024)
- Topics
- cybersecurity, breach-notification
Research notes
Passed 2018-02-05 and assented 2018-03-02. The 2024 amendment was passed 2024-05-07 and assented 2024-05-23. Some sections of the 2024 Act are not listed in the 2025-10-31 commencement. SSO blocks automated fetch but loads in a browser.
Related
Questions about Singapore Cybersecurity Act
- What are the Singapore Cybersecurity Act compliance deadlines?
- Aug 31, 2018: Cybersecurity Act main provisions commence. Apr 11, 2022: Cybersecurity service provider licensing commences. Oct 31, 2025: 2024 amendments commence.
- When does Singapore Cybersecurity Act take effect?
- Singapore Cybersecurity Act took effect on Aug 31, 2018.
- Who does Singapore Cybersecurity Act apply to?
- Owners of designated CII, licensed cybersecurity service providers, and since 2025 foundational digital infrastructure providers (such as cloud and data centre operators), entities of special cybersecurity interest and owners of systems of temporary cybersecurity concern.
- What are the penalties under Singapore Cybersecurity Act?
- For some offences, fines up to the greater of SGD 200,000 or 10% of the person's annual turnover in Singapore, plus up to SGD 5,000 a day for continuing offences. The Commissioner may seek a court-ordered civil penalty instead of prosecution (section 37A).