Blog post

Singapore Tightens Critical Infrastructure Security with Updated CCoP 2026 and New Cloud Code

Singapore CSA updates the Cybersecurity Code of Practice for CII operators with three proactive defense pillars, executive accountability mandates, Cyber Trust Mark Level 5, and a new CCoP for Cloud Services — with AWS, Google Cloud, and Azure Companion Guides.

On 22 July 2026, Mrs Josephine Teo, Singapore’s Minister for Digital Development and Information and Minister-in-charge of Cybersecurity, announced a major update to the Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) operators at the Operational Technology Cybersecurity Expert Panel (OTCEP) Forum 2026.

The updated CCoP 2026 is the most significant revision since the 2022 edition. It introduces three proactive defense pillars, binding executive governance accountability, a mandatory Cyber Trust Mark Level 5 certification pathway, and — for the first time — a dedicated CCoP for Cloud Services developed in partnership with AWS, Google Cloud, and Microsoft Azure.

Here is what the changes mean for CII operators, cloud adoption strategies, and the broader global cybersecurity landscape.

Three Proactive Defense Pillars: Beyond Compliance Checklists

The updated CCoP replaces static compliance requirements with what the Minister described as a “Lock down, find first, fix fast” approach. Three new technical guidance areas form the backbone of this shift:

Adversarial Attack Simulation

CII operators must now simulate real-world attacker techniques (TTPs) against their environments. This goes beyond conventional vulnerability scanning — operators are expected to test detection and response capabilities against realistic threat scenarios that mirror advanced persistent threat (APT) activity.

Penetration Testing

Structured, authorized simulated attacks on CII systems remain a core requirement, but the updated CCoP expands the scope of mandatory penetration testing. Alignment with the March 2026 regulatory framework that classifies penetration testing as a licensed activity under the Cybersecurity Act reinforces that this is a regulated, not ad-hoc, practice.

Threat Hunting

The new code mandates proactive, hypothesis-driven threat hunting — a continuous search for indicators of compromise and adversary activity that has evaded existing defenses. This moves threat detection from a reactive (alert-based) model to a permanent, intelligence-led posture.

These three pillars collectively shift the compliance burden from “did you run a scan this quarter” to “can you demonstrate that you actively find threats before they find you.”

Executive Governance Accountability: Board-Level Cyber Responsibility

“Lock down, find first, fix fast.”

— Minister Josephine Teo, OTCEP Forum 2026

Under CCoP 2026, cybersecurity governance is no longer a CISO-only matter. Boards and senior management must:

  • Maintain a documented cyber resilience framework that covers risk tolerance, mitigation strategies, risk transfer arrangements, and recovery planning.
  • Review the framework at least annually.
  • Maintain enterprise-wide oversight of all interconnected systems that communicate with the CII — not just the CII itself. This broadens the accountability boundary to include the entire network architecture surrounding critical assets.

This governance mandate aligns with the Cybersecurity Act amendments passed in May 2024, which reinforced that CII owners remain fully responsible for cybersecurity and cyber resilience even as they adopt new technologies such as cloud services.

Cyber Trust Mark Level 5: Certification Deadlines

The Cyber Trust Mark (CTM) Level 5 certification — the highest of five tiers, covering 22 cybersecurity domains under the enhanced SS 712:2025 standard — has been integrated into the CCoP with staggered deadlines:

EntityCertificationDeadline
CII owners (non-CII systems supporting core operations)CTM Level 531 December 2027
CII auditors (approved auditors conducting CII audits)CTM Level 531 December 2026
Licensed cybersecurity service providers (pentesting, managed SOC)CTM Level 3 (minimum)31 December 2026

CII systems themselves are already required to meet CTM Level 5-equivalent standards under the Cybersecurity Act. The SS 712:2025 enhancement added three new security domains — Cloud Security, OT Security, and AI Security — making the certification framework more relevant to today’s threat landscape.

New CCoP for Cloud Services: Cloud-Native Security Requirements

A landmark addition in the 2026 update is a dedicated Code of Practice for Cloud Services (CCoP Cloud), launching in the second half of 2026. This establishes cybersecurity requirements for the secure deployment, operation, and management of CII systems hosted on cloud infrastructure.

Companion Guides from the Big Three Hyperscalers

Crucially, CSA co-developed Companion Guides with all three major cloud providers:

ProviderRole
Amazon Web Services (AWS)CSP-specific guidance on implementing CCoP Cloud controls using AWS-native services
Google CloudCSP-specific implementation guidance aligned with Google Cloud’s security architecture
Microsoft AzureCSP-specific guidance for Azure-native security capabilities

These Companion Guides map CCoP requirements to each provider’s native security services — GuardDuty and Security Hub for AWS, Security Command Center for Google Cloud, and Defender for Cloud for Azure — rather than prescribing abstract controls without an implementation path.

The CCoP Cloud was developed through closed-door consultations with auditors and CII owners already using or evaluating cloud services. The resulting controls reflect real-world cloud adoption patterns, not theoretical segregation models.

Why This Matters for CII Cloud Adoption

CII operators have been cautious about cloud migration due to regulatory uncertainty around shared responsibility models, data sovereignty, and incident reporting across provider boundaries. The CCoP Cloud — published alongside hyperscaler-specific Companion Guides — provides a clear compliance framework that should accelerate responsible cloud adoption in regulated sectors while maintaining the security posture the Cybersecurity Act demands.

Implications for Global Cloud Security Standards

Singapore’s CCoP Cloud is not an isolated development. It parallels similar regulatory work in other jurisdictions:

  • European Union — The Cyber Resilience Act (CRA) and sector-specific NIS2 implementing acts are establishing cloud security requirements for critical entities across member states.
  • United States — CISA’s cloud security guidance and the expanding FedRAMP equivalence framework for critical infrastructure.
  • Australia — The Security of Critical Infrastructure (SOCI) Act amendments extending cloud oversight.
  • Japan — METI’s cloud security guidelines for critical infrastructure sectors.

The CCoP Cloud’s structure — a dedicated code plus hyperscaler-specific Companion Guides — offers a reference model that other regulators may adopt. By collaborating directly with AWS, Google Cloud, and Azure on implementation guidance, CSA has created a template that reduces ambiguity for operators who use multiple cloud providers, without forcing a single-vendor security model.

What CII Operators Should Do Now

  • Assess readiness for CTM Level 5 — If your organisation provides CII audit services or licensed cybersecurity services, the end-2026 deadline for CTM Level 5 (or Level 3) certification is approaching rapidly.
  • Map interconnected systems — The expanded oversight boundary means you need visibility into every system that communicates with your CII, not just the CII assets themselves.
  • Build proactive defense capabilities — Adversarial attack simulation, enhanced penetration testing, and continuous threat hunting require both tooling and skilled personnel. Start the capability-building process now rather than waiting for the published code text.
  • Evaluate cloud compliance readiness — If you operate CII systems on cloud infrastructure or are considering cloud migration, the CCoP Cloud and its Companion Guides will define your compliance path when published later in 2026.

What This Article Does Not Cover

The CCoP 2026 text had not been published as of 28 July 2026 — the official CSA Codes of Practice page still lists the 2022 edition. Exact compliance deadlines for the CCoP itself (separate from the CTM certification deadlines), detailed control statements, and effective dates for individual requirements will be confirmed when CSA publishes the full code later in 2026. Watch the CSA Codes of Practice page for the publication.

This article focuses on Singapore’s Cybersecurity Act jurisdiction. CCoP requirements do not apply outside Singapore, and other jurisdictions have separate regulatory frameworks.

Sources

Related What I Do

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.