The Answer in 60 Seconds
The Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) was passed by Parliament on 7 May 2024, amending the Cybersecurity Act 2018. Specified provisions commenced on 31 October 2025 by Commencement Notification 2025 (published 15 October 2025). Key changes now in force: (1) virtual computers and cloud workloads explicitly within the CII definition; (2) extraterritorial designation - a computer or system located wholly outside Singapore that is owned by a person in Singapore may be designated as Provider-Owned CII (PO CII) if it would have met CII criteria had it been located in Singapore; (3) new Part 3A - Third-Party-Owned CII (3PO CII) - the Commissioner of Cybersecurity may designate an essential service provider as responsible for the cybersecurity of a CII used by it but owned by a third party; the designated provider must obtain legally binding commitments from the third-party owner covering information rights, incident notification, cybersecurity standards, and audit cooperation; designation lasts 5 years renewable; (4) expanded incident reporting - CII owners must report prescribed incidents affecting the CII, any system under the owner's control, and any supplier systems interconnected with the CII; (5) new Part 3B - Systems of Temporary Cybersecurity Concern (STCCs); (6) expanded audit and inspection powers. Pending commencement: Part 3C (Entities of Special Cybersecurity Interest, "ESCI" - autonomous universities, sensitive-research entities) and Part 3D (Major Foundational Digital Infrastructure providers, "FDI" - cloud service providers and data-centre operators). The 11 CII sectors remain unchanged: Energy, Water, Banking and Finance, Healthcare, Land Transport, Maritime, Aviation, Info-Communications, Media, Security and Emergency Services, Government.

The Sourced Detail
The Cybersecurity (Amendment) Act 2024 substantially expands the Cybersecurity Act 2018 framework, bringing virtual systems, offshore-located but Singapore-owned systems, and third-party-owned essential-service infrastructure within the Commissioner of Cybersecurity's regulatory perimeter. The amendments respond to operational realities of cloud-hosted essential services, supply-chain dependencies, and the growing role of third-party Foundational Digital Infrastructure (cloud, data centres) in supporting critical national services.
For Singapore SMEs, the practical question is whether their systems or operations fall within the expanded CII perimeter, either by direct designation (CII owner), by section 16A designation as designated provider responsible for a 3PO CII, or (when the relevant parts commence) as an ESCI or Major FDI.
Commencement timeline
7 May 2024: Cybersecurity (Amendment) Bill passed by Parliament.
15 October 2025: Cybersecurity (Amendment) Act 2024 (Commencement) Notification 2025 published.
31 October 2025: specified provisions commenced (sections 2 to 15, 18, 19, 22, 23(b), 24, 25, 28(a) to (g), 29, 31, and 32(1) to (4), (6), and (7) of the Amendment Act).
Pending as at 15 May 2026: Part 3C (ESCI) and Part 3D (Major FDI). Future commencement notification expected.
The 11 CII sectors
The 11 CII sectors as designated by the Cybersecurity Act 2018 remain unchanged:
Energy, Water, Banking and Finance, Healthcare, Land Transport, Maritime, Aviation, Info-Communications, Media, Security and Emergency Services, Government.
CII designation under section 7 requires the computer or computer system to be necessary for the continuous delivery of an essential service in one of these 11 sectors, and the loss or compromise of which would have a debilitating effect on the availability of the essential service in Singapore.
The substantive changes in force from 31 October 2025
Change 1: Virtual computers and cloud workloads within CII definition. The amended definitions in section 2 explicitly capture virtual systems: for the CII provisions in Parts 3 and 3A (except the offshore designation in section 7(1A)), a "computer" includes a virtual computer and a "computer system" includes a virtual computer system. A cloud-hosted application supporting an essential service can be designated CII even though the underlying physical infrastructure is shared. This closes a prior interpretive gap where CII designation was unclear for cloud-hosted workloads.
Change 2: Extraterritorial designation (PO CII). A computer or system located wholly outside Singapore, owned by a person in Singapore, may be designated as Provider-Owned CII (PO CII) if it would have met CII criteria had it been located in Singapore. This applies to Singapore-domiciled providers operating critical infrastructure for Singapore essential services from offshore locations (e.g., regional data centres in nearby ASEAN jurisdictions).
Change 3: New Part 3A - Third-Party-Owned CII (3PO CII). The Commissioner may designate an essential service provider (rather than the third-party owner) as responsible for the cybersecurity of a 3PO CII used by one or more essential service providers. The designated provider must obtain legally binding commitments from the third-party owner covering:
Information rights (access to system status, configuration, and incident data).
Incident notification (timely notification of cyber incidents).
Compliance with prescribed cybersecurity standards.
Audit cooperation (allowing audit and inspection as required by the Cybersecurity Act framework).
Designation under section 16A lasts 5 years, renewable for additional 5-year periods.
Change 4: Expanded incident reporting under section 14. CII owners must report prescribed cybersecurity incidents affecting:
The CII itself.
Any computer or system under the owner's control.
Any supplier system interconnected with or communicating with the CII.
The expanded reporting scope brings supply-chain incidents within the CII reporting framework. A cybersecurity incident at a CII owner's cloud provider, software vendor, or managed services partner that affects the CII must be reported.
Change 5: New Part 3B - Systems of Temporary Cybersecurity Concern (STCCs). Short-term oversight of systems elevated by temporary events. The mechanism allows the Commissioner to impose short-duration cybersecurity obligations on systems whose criticality is temporary (e.g., systems supporting a specific major event).
Change 6: Expanded audit and inspection powers. The Commissioner may order audits and inspections under the amended Act framework.
Pending commencement: Parts 3C and 3D
Part 3C - Entities of Special Cybersecurity Interest (ESCI). Entities holding sensitive information or performing functions of national interest (e.g., autonomous universities, sensitive-research entities) may be designated ESCI. The Amendment Act already sets out a designated ESCI's obligations, to furnish information, comply with written directions and applicable codes of practice, and report prescribed cybersecurity incidents; they apply once Part 3C commences. Pending commencement as at 15 May 2026.
Part 3D - Major Foundational Digital Infrastructure providers (FDI). Providers of the two foundational digital infrastructure services listed in the Third Schedule that the Amendment Act will insert, cloud computing services and data centre facility services, whom the Commissioner may designate where the loss or impairment of the service is likely to disrupt the operation of a large number of businesses or organisations. The Amendment Act already sets out a designated provider's obligations, to furnish information, comply with written directions and applicable codes of practice, and report prescribed cybersecurity incidents; they apply once Part 3D commences. Pending commencement as at 15 May 2026.
Verbatim regulatory text - primary-source routing
The primary-source URLs:
Cybersecurity Act 2018 consolidated text on SSO.
Cybersecurity (Amendment) Act 2024 (Act 19 of 2024) on SSO.
Cybersecurity (Amendment) Act 2024 (Commencement) Notification 2025 on SSO.
The provisions that matter here:
Section 7, CA 2018 (as amended) - designation of computer or computer system as CII, including the amended scope covering virtual systems and offshore systems owned by a person in Singapore.
Section 8, CA 2018: power to obtain information to ascertain whether a computer or computer system meets the CII criteria.
Section 10, CA 2018 - duty of CII owner to notify changes.
Section 35A, CA 2018: codes of practice and standards of performance, and the duty to comply with them (this replaced section 11, which was deleted on 31 October 2025).
Section 12, CA 2018: written directions issued by the Commissioner.
Section 13, CA 2018: duty to inform the Commissioner of a change in ownership of the CII within 7 days.
Section 14, CA 2018 (as amended) - duty to report cybersecurity incidents, with the expanded scope from 31 October 2025.
Section 15, CA 2018: cybersecurity audit (at least once every two years) and cybersecurity risk assessment (at least once a year).
Section 16, CA 2018: cybersecurity exercises (Commissioner may direct).
Section 16A (new, Part 3A) - designation of designated provider responsible for 3PO CII.
Part 3B, CA 2018 - STCCs.
Part 3C, CA 2018 (pending) - ESCIs.
Part 3D, CA 2018 (pending) - Major FDI service providers.
CSA Code of Practice for Critical Information Infrastructure (current edition) at csa.gov.sg/legislation/codes-of-practice.
The substantive obligations on CII owners
A designated CII owner under section 7 is subject to:
Section 35A obligations: compliance with codes of practice and standards of performance issued by the Commissioner. The Code prescribes minimum cybersecurity controls (access management, encryption, patching, logging, incident response, business continuity).
Sections 10 and 13 obligations: furnish information the Commissioner requires by notice and, once it has been furnished, notify any material change to the design, configuration, security or operation of the CII within 30 days (section 10), and inform the Commissioner of a change in ownership within 7 days (section 13).
Section 12 obligations: comply with written directions issued by the Commissioner.
Section 15 obligations: cause a cybersecurity audit to be carried out at least once every two years by an auditor approved or appointed by the Commissioner.
Section 15 obligations (continued): conduct a cybersecurity risk assessment at least once a year.
Section 14 obligations (expanded from 31 October 2025) - report prescribed cybersecurity incidents within prescribed timelines.
Section 16 obligations: participate in cybersecurity exercises directed by the Commissioner.
Part 3A obligations (sections 16E to 16L, for providers designated under section 16A) - obtain and police legally binding commitments from third-party owners covering information rights, incident notification, cybersecurity standards, and audit cooperation.
The cyber insurance interaction
Singapore cyber insurance policies respond to several components of CII-related cybersecurity risk:
First-party incident response - forensic investigation, breach coach, legal counsel, public relations, technical remediation. Policies may include an incident hotline and a panel of pre-approved vendors.
CSA-imposed remediation costs. Some wordings exclude "betterment" or "regulator-mandated remediation"; SMEs designated CII or 3PO CII designated providers must specifically test the wording. Where a Code of Practice gap requires remediation imposed by CSA, the cost may be substantial and may not be covered without explicit endorsement.
Regulatory defence costs. CSA investigations under the Cybersecurity Act and any prosecutions. Wordings that cover regulatory defence may do so under a sub-limit.
CSA financial penalties. For a CII owner, the financial penalties in force under the Cybersecurity Act are fines on conviction for an offence; the civil penalties enacted by the 2024 amendments have not commenced. Whether a fine or penalty can be insured depends on the law and the policy wording, including whether the penalty is punitive or compensatory.
Third-party liability. Customer and downstream claims arising from cybersecurity incidents on the CII or 3PO CII.
Business interruption. Loss of gross profit and increased cost of working following a cyber-triggered operational shutdown, and, where the wording extends to it, a shutdown ordered by a regulator.
Section 16A flow-down liability. For designated providers of 3PO CII, the obligation to obtain and police binding commitments from third-party owners creates contractual liability exposure. Standard cyber wordings may not explicitly address this; coverage should be tested at placement.
Claim-time worked example
A healthcare SME ("MedTech F") provides acute hospital care services, an essential service under the Act's First Schedule, and relies on an electronic medical records system that a major cloud provider owns and runs for it in its Singapore region. From 31 October 2025, the workload is potentially 3PO CII under section 16A. The Commissioner designates MedTech F as the designated provider responsible.
MedTech F's section 16A obligations:
- Obtain legally binding commitments from the cloud provider covering: information rights; maintenance of prescribed technical standards; incident notification; audit cooperation.
- Implement controls and monitoring per the CSA Code of Practice for the CII.
- Report prescribed cybersecurity incidents in respect of the CII, any system under the cloud provider's or MedTech F's control that is interconnected with or communicates with the CII, and MedTech F's other systems (section 16I(4), the Part 3A counterpart of section 14).
A cybersecurity incident occurs at the cloud provider affecting the CII (data exfiltration of approximately 4,200 patient records).
Response workflow:
- Day 1: cloud provider notifies MedTech F under the binding commitment required by section 16I(1), which allows the owner up to 72 hours.
- Day 1: MedTech F's incident response engaged via cyber policy 24/7 hotline.
- Day 1 to 3: forensic assessment confirms scope.
- Day 3: PDPA section 26C assessment finds a notifiable data breach under the 3-day notification rule (4,200 affected individuals exceeds the significant-scale threshold of 500, and records of certain diagnoses, such as HIV infection, linked to a patient's name are also deemed to cause significant harm). PDPC notification due within 3 calendar days of assessment.
- Day 1 (before the PDPA step above): CSA notification under section 16I(4) of the Cybersecurity Act, within 2 hours after MedTech F becomes aware of the incident, with supplementary details within 72 hours; the incident is in respect of the third-party-owned CII.
- Days 4 to 30: forensic investigation, customer notification, regulatory engagement.
Insurance response:
- Cyber policy responds to incident response, forensic, breach coach, legal counsel, public relations costs.
- Notification cost cover funds the patient notification logistics.
- Regulatory defence cover funds CSA and PDPC engagement defence.
- Third-party liability cover responds to patient claims under PDPA section 48O and general tort.
- Business interruption cover responds if MedTech F suspends operations during forensic investigation.
- CSA financial penalty (if any) responds only to the extent insurable by law.
- Cost of obtaining and policing the section 16A binding commitments is typically not covered as part of standard incident-response cover.
Common Mistakes / What Goes Wrong
-
Assuming CII designation only applies to physical infrastructure. The 31 October 2025 amendments explicitly bring virtual systems and cloud workloads within scope. SMEs operating essential-service applications on cloud platforms can be designated.
-
Not considering offshore-located systems. Provider-Owned CII (PO CII) designation can apply to systems located wholly outside Singapore but owned by a person in Singapore.
-
Treating section 16A 3PO CII designation as the third-party owner's problem. Section 16A places the responsibility on the essential service provider (the SME), not the third-party owner. The SME must obtain binding commitments from the third-party owner.
-
Underestimating expanded section 14 incident-reporting scope. From 31 October 2025, incident reporting extends to incidents affecting the CII, any system under the owner's control, and supplier systems interconnected with the CII. The scope is materially broader than pre-amendment.
-
Buying cyber cover without testing CSA-imposed remediation cost treatment. Standard wordings may exclude "betterment" or "regulator-mandated remediation"; SMEs in CII or 3PO CII positions should specifically test and request endorsements where standard wording is silent.
-
Failing to coordinate PDPA section 26D and Cybersecurity Act section 14 reporting. A cyber incident may trigger both regimes with different timelines and recipients. The two should be coordinated, not duplicated.
-
Ignoring upcoming Parts 3C and 3D. ESCI and Major FDI designations are pending commencement. SMEs in autonomous universities, sensitive-research entities, cloud-service provision, and data-centre operation should monitor commencement notifications.
-
Not maintaining the section 16A binding-commitment documentation. The binding commitments are the SME's compliance evidence. Documentation should be auditable.
-
Treating cybersecurity audit (section 15(1)(a)) and risk assessment (section 15(1)(b)) as interchangeable. Section 15(1)(a) requires an audit by an auditor approved or appointed by the Commissioner at least once every two years. Section 15(1)(b) requires a risk assessment at least once a year. Both are required and serve different purposes.
-
Failing to participate in cybersecurity exercises (section 16). Commissioner-directed exercises are mandatory for CII owners. Non-participation is a regulatory breach.
What This Means for Your Business
For a Singapore SME operating in or adjacent to the 11 CII sectors, the structural priority is: identify whether any system supporting essential service delivery could be designated CII; if cloud-hosted, recognise that 31 October 2025 amendments explicitly capture virtual systems; if relying on third-party-owned infrastructure for essential service delivery, prepare for potential section 16A designation as designated provider responsible.
For SMEs in healthcare, financial services, transport, and other essential-service sectors, the practical immediate step is to engage with CSA's published Code of Practice for Critical Information Infrastructure and assess compliance gaps. Even where the SME is not yet designated, the Code provides the operational baseline against which any future designation would be measured.
For SMEs supplying cloud, data-centre, or IT outsourced services to CII owners, the section 16A flow-down obligations will increasingly appear in customer contracts. Vendor SMEs should prepare standard contractual terms that align with the section 16A binding-commitment framework.
For cyber insurance procurement, the wording should explicitly address: CSA Code of Practice gap-remediation costs; incident-reporting cost cover; regulatory defence cover; section 16A flow-down liability; CSA cybersecurity audit costs; cybersecurity exercise participation costs.
Questions to Ask Your Adviser
- Are any of our systems supporting essential-service delivery potentially within CII designation criteria under the amended section 7 (including virtual systems and offshore systems)?
- If we rely on third-party-owned infrastructure for essential service delivery, could we be designated under section 16A as designated provider responsible?
- For our cyber policy, does the wording cover CSA-imposed remediation costs, or is this excluded as "betterment" or "regulator-mandated remediation"?
- Does our cyber policy respond to CSA cybersecurity audit costs and cybersecurity exercise participation costs?
- For section 14 expanded incident reporting from 31 October 2025, are our incident response procedures aligned with the broader scope (CII, owner's systems, supplier systems)?
- For section 16A flow-down obligations, do our vendor contracts include the binding-commitment framework, and does our cyber policy cover the cost of policing these commitments?
- Are we monitoring CSA announcements for the commencement of Parts 3C (ESCI) and 3D (Major FDI) that may bring additional SMEs within scope?
Related Information
- PDPC Mandatory Data Breach Notification (PDPA Section 26D): The 3-Day Clock Decoded for Singapore SMEs
- Ransomware Active Negotiation Phase: Data Exfiltration, Sanctions Screening, Payment Decision
- Business Email Compromise / Vendor Email Compromise: Wire Fraud Discovered
- Cyber Architecture Tower vs Monoline Policy Comparison
- How to File a Notice of Circumstance Under a Claims-Made Policy: D&O, PI, Cyber, and EPL Mechanics for Singapore SMEs
- Business Interruption Deductible: Hours-Based vs Day-Based vs Dollar-Based Waiting Period
