CSA strengthens cyber rules for critical infrastructure and cloud
New cloud security code will launch in 2H2026.
The Cyber Security Agency of Singapore (CSA) will release an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and a new CCoP for Cloud Services later this year.
The announcement was made by Minister for Digital Development and Information Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026.
The revised CII code is the first update since 2022 and comes amid the rise of AI-enabled cyber threats. According to CSA, frontier AI is enabling threat actors to identify vulnerabilities and launch attacks more quickly, shortening the window for organisations to respond.
To address these risks, the updated code will include new technical guidance on adversarial attack simulation, penetration testing and threat hunting.
“The updates to CCoP focus on strengthening CII governance, visibility, detection and readiness, and broader enterprise networks that are interconnected with the CIIs to align with the amendments made to the Cybersecurity Act,” the agency said.
Under the updated code, organisations will be required to strengthen board and senior management accountability by maintaining an annually reviewed cyber resilience framework covering risk tolerance, mitigation, transfer and recovery.
CII owners must also obtain Cyber Trust Mark Level 5 certification, maintain oversight of interconnected systems linked to critical infrastructure, participate in CSA-led deployment of threat detection systems across network segments, develop comprehensive cybersecurity exercise plans, and implement stronger network management, monitoring and detection measures.
Alongside the revised CII code, CSA will launch a new CCoP for Cloud Services in the second half of 2026 to establish cybersecurity requirements for the secure deployment, operation and management of CII systems hosted on cloud platforms.
The agency said the new code reflects the increasing adoption of cloud technologies by critical infrastructure operators and aims to ensure cloud environments remain protected against evolving cyber threats.
CSA developed the framework following consultations with auditors and CII owners that are using or considering cloud services. Feedback from these engagements was incorporated into the final controls and implementation guidance.
To support adoption, CSA has partnered with Amazon Web Services, Google Cloud and Microsoft Azure to develop cloud provider-specific Companion Guides.