In brief

On 22 July 2026, the Cyber Security Agency of Singapore (CSA) announced that it would be releasing an updated Cybersecurity Code of Practice (CCoP) for Critical Information Infrastructure (CII) and a new CCoP for cloud services in the later part of 2026.

In more detail

Updates to the CCoP for CIIs

Since the last update of the CCoP in 2022, the cyber threat landscape has shifted with new AI-enabled threats, allowing threat actors to launch attacks faster and at a greater scale. CSA highlighted that with the emergence of Frontier AI (i.e., the most advanced AI models currently available), threat actors now discover vulnerabilities faster, thereby shortening the window period for exploitation.

As part of Singapore’s efforts to address Advanced Persistent Threats and AI-enabled threats, the Government is working with CII owners to raise their cybersecurity posture. The CCoP will be further updated later in 2026 with technical guidance covering adversarial attack simulation, penetration testing, and threat hunting.

The updates to the CCoP focus on strengthening CII governance, visibility, detection and readiness, and broader enterprise networks that are interconnected with the CIIs, to align with the amendments made to the Cybersecurity Act. Notable key changes are as follows:

  • CII owners are required to strengthen Board and senior management accountability and oversight for cybersecurity. Boards must maintain a documented cyber resilience framework covering their organisation’s risk tolerance, mitigation, transfer, and recovery measures, which must be reviewed at least annually.
  • CII owners are required to attain Cyber Trust Mark Level 5 certification (Singapore's highest-tier national cybersecurity certification) to elevate the cybersecurity posture of CIIs.
  • CII owners are required to maintain oversight of interconnected systems that connect with and communicate with CII, to strengthen visibility of the broader network architecture and improve cybersecurity risk management.
  • CSA will work with CII owners to deploy threat detection systems across CII owners’ network segments to detect malicious activities.
  • CII owners are required to develop a comprehensive cybersecurity exercise plan, to ensure coordinated and effective response to cyber incidents.
  • CII owners are required to have robust management measures to maintain network architecture, for example, in the areas of network management, monitoring, and detection management.

New CCoP for cloud services

With CII owners increasingly adopting cloud technologies to support operations, such environments need to be secured against evolving cyber threats. The CCoP for Cloud Services aims to establish cybersecurity requirements governing the secure deployment, operation, and management of CII systems hosted on the cloud.

CSA has also partnered with leading Cloud Service Providers (CSPs) to jointly develop CSP-specific Companion Guides. These Companion Guides will provide practical guidance on how the CCoP for Cloud Services controls can be implemented within their respective cloud environments through appropriate configurations and the effective use of cloud-native services and security capabilities. The Companion Guides will be published alongside the CCoP for Cloud Services.

Key takeaways

With the increasing danger of threat actors and AI-enabled threats, CII owners have to ensure that their cybersecurity posture is sufficiently robust. In particular, CIIs should ensure that their governance, visibility, detection and readiness, broader enterprise networks and cloud technologies meet the requirements under the CCoPs that will be published.

Related content

Our previous client alert on the last update on the CCoP for CIIs in 2022 can be accessed here.

© 2026 Baker & McKenzie. Wong & Leow. All rights reserved. Baker & McKenzie. Wong & Leow is incorporated with limited liability and is a member firm of Baker & McKenzie International, a global law firm with member law firms around the world. In accordance with the common terminology used in professional service organizations, reference to a "principal" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as "Attorney Advertising" requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.

Explore More Insight