Cyber Trust mark
CSA's risk-based cybersecurity certification
The Cyber Trust mark is the Cyber Security Agency of Singapore's (CSA) certification for organisations that manage cybersecurity by risk. It has five tiers, and an independent certification body checks your controls before the mark is awarded. We assess your risk, find your tier, close the gaps and get you through the audit.
What is the Cyber Trust mark?
The Cyber Trust mark is part of CSA's SG Cyber Safe Programme. Where the Cyber Essentials mark sets baseline protections for smaller organisations, the Cyber Trust mark scales with your risk: the more complex your operations, the higher the tier and the more you need to show.
Certification has two parts. First, you self-assess your cyber risk profile and how prepared you are, which sets your tier. Then an independent certification body audits you in two stages: a review of your documents, then a check that your controls work in practice. In April 2025, CSA expanded the mark to cover cloud security, AI security and operational technology (OT) security.
Who needs it, and by when
Announced at the Committee of Supply debate in March 2026 and phased in over two years. For everyone else the mark is voluntary, and a recognised way to show clients and tender panels that you manage cyber risk properly.
| Who | What they need | Deadline |
|---|---|---|
| CII owners | Advocate (Tier 5), the highest tier, for the non-CII systems they control | By end 2027 |
| Auditors of CII systems | Advocate (Tier 5) at organisation level, for the systems that run their business | By end 2026 |
| CSA-licensed cybersecurity service providers (penetration testing, managed SOC) | An active Promoter (Tier 3) certification | By 31 December 2026 |
| Government vendors managing critical systems or sensitive government data | Cyber Trust mark requirements set by GovTech | Phased in from 2026 |
The five tiers
Your tier comes from CSA's risk assessment: the higher your cyber risk, the higher the tier and the more domains you cover. Select a tier to see who it suits.
Tier 3 Promoter 19 of 22 domains
For organisations with a higher risk profile, such as those that run important systems or services for clients.
Minimum tier for CSA-licensed penetration testing and managed SOC providers from 31 December 2026.
Find your likely tier
Four questions for an indicative answer. Your actual tier comes from CSA's self-assessment, which we run with you in the first month.
Your likely tier
Answer the first two questions
Company size and how you use technology set the starting point.
What it covers
22 domains in five groups. Your tier sets how many apply: 10 at Supporter, 13 at Practitioner, 19 at Promoter, 21 at Performer and all 22 at Advocate. Since April 2025 the mark also covers cloud, AI and OT security where those apply to you.
Cyber governance and oversight 6
- Governance
- Policies and procedures
- Risk management
- Cyber strategy
- Compliance
- Audit
Cyber education 1
- Training and awareness
Information asset protection 7
- Asset management
- Data protection and privacy
- Backups
- Bring your own device (BYOD)
- System security
- Anti-virus and anti-malware
- Secure software development life cycle
Secure access and environment 6
- Access control
- Cyber threat management
- Third-party risk and oversight
- Vulnerability assessment
- Physical and environmental security
- Network security
Cybersecurity resilience 2
- Incident response
- Business continuity and disaster recovery
How we get you there
Month 1
Assess
Run CSA's risk and preparedness self-assessment with your team and confirm the tier you're aiming for.
Months 2 to 4
Close the gaps
Write the policies, fix controls and collect evidence across the domains your tier needs, including cloud, AI and OT where they apply.
Months 4 to 6
Get certified
Choose a certification body, prepare your team, and support both audit stages: the document review and the check of your controls in practice.
Years 2 and 3
Stay certified
Keep evidence current and pass the yearly audits until renewal.
What you receive
- Risk assessment and recommended tier
- Gap analysis across the domains your tier covers
- Policies and procedures your tier needs
- Evidence pack for the certification body
- Support through both stages of the audit
- Plan for the yearly audits
Ways to engage
Readiness check
Risk assessment, likely tier, gap analysis and a costed plan.
Best when you need to know where you stand.
Certification programme
Everything from assessment to the mark, run by a senior security lead.
Best when you have a deadline or a client asking.
Fractional CISO
Keeps the mark current, prepares for the yearly audits and owns cyber risk.
Best for keeping certification year after year.
Questions about the Cyber Trust mark
How is the Cyber Trust mark different from Cyber Essentials?
Cyber Essentials covers baseline measures and suits smaller organisations starting out. The Cyber Trust mark is risk-based, has five tiers, and suits organisations with more complex operations.
Who does the assessment?
An independent certification body appointed under the scheme. It audits in two stages: first your documents, then whether your controls work in practice.
How many domains apply to us?
It depends on your tier: 10 at Supporter, 13 at Practitioner, 19 at Promoter, 21 at Performer and all 22 at Advocate.
How long does certification last?
Three years, with an audit each year.
Does it cover cloud, AI and OT?
Yes. Since April 2025, the mark covers cloud security, AI security and operational technology security where they apply to you.
Is there funding?
Eligible SMEs can get up to 70% co-funding through CSA's CISO-as-a-Service scheme, which covers Cyber Essentials preparation and vulnerability testing. Larger companies usually fund Cyber Trust certification themselves. We check what applies to you.
We have a deadline. Can you work back from it?
Yes. We plan back from your audit date, leaving time for new controls to run and build up evidence, and set out what has to happen by when.
Pairs well with
Talk to us about the Cyber Trust mark
A 30-minute call to confirm your likely tier, your deadline and what it will take.