What Changed in CSA's Cybersecurity Code of Practice 2026
Published 8 August 2026
CSA released the Cybersecurity Code of Practice (CCoP) 2026 on 29 July. It supersedes the 2022 version. After doing a full clause-by-clause comparison, here are the changes CII owners in Singapore need to prepare for.
The Scope Expansion
The 2022 Code secured the CII itself. The 2026 Code secures everything the CII touches. That is the fundamental shift.
Attackers do not target CII directly in most cases. They compromise enterprise systems first, then pivot. CSA has rewritten the Code to reflect that reality. If you operate CII, the regulatory perimeter just expanded beyond your CII boundary.
Securing CII Interconnected Systems (Section 12, Clauses 12.1 – 12.7)
This section did not exist in the 2022 Code. It is entirely new.
Section 12 applies to systems that communicate with or connect to CII, owned, operated, or controlled by the CIIO, but not designated as CII themselves. Think enterprise networks, management VLANs, jump servers, any system that can reach the CII.
Seven control domains now apply to these interconnected systems:
- Asset Management (12.1.1 – 12.1.2): full inventory of interconnected systems, updated on change
- Account Management (12.2.1 – 12.2.4): account lifecycle, shared account restrictions, periodic review
- Privileged Account Management (12.3.1 – 12.3.3): PAM controls, jump servers and bastion hosts, session recording
- Network Segmentation (12.4.1 – 12.4.3): documented segmentation rules between CII and interconnected systems, periodic review
- System Hardening (12.5.1 – 12.5.2): baseline configurations, removal of unnecessary services
- Patch Management (12.6.1): patch interconnected systems on the same cadence as CII
- Monitoring and Detection (12.7.1 – 12.7.6): six sub-clauses covering log collection, SIEM coverage, threat detection, IOC scanning, baseline monitoring, and alert tuning
Compliance date: 29 July 2027.
If your interconnected systems are currently managed under general enterprise IT policies without CII-grade controls, this section will require the most work.
Cyber Trust Mark Tier 5 (Clause 3.3.1)
Previously: no certification requirement.
Now: Clause 3.3.1 requires CII owners to attain Cyber Trust Mark Advocate (Tier 5) certification or its equivalent. Existing CII owners must certify by 31 December 2027. New CII designations must certify within 24 months.
The rationale from CSA: enterprise systems beyond CII are increasingly targeted as initial entry points for compromising critical operations. The Cyber Trust Mark framework covers the enterprise environment, not just the CII itself.
Board Accountability (Clauses 3.1.2 – 3.1.5)
Previously: Clause 3.1.2 of the 2022 Code required the Board to include at least one member with cybersecurity knowledge. That was it.
Now: The entire Board owns a documented cyber resilience framework with four pillars.
Clause 3.1.2 requires the Board to maintain a cyber resilience framework covering:
- Risk Tolerance: a cyber risk appetite statement reviewed at least every 12 months
- Risk Mitigation: oversight of cybersecurity budget and resource adequacy every 12 months
- Risk Transfer: oversight of cyber insurance and third-party indemnities every 12 months
- Risk Recovery: oversight of BCP/DRP strategy defining maximum tolerable downtime every 12 months
All updates must be documented in Board minutes or equivalent written records.
Clause 3.1.3 requires the Board to participate in cybersecurity training covering strategic oversight, governance, and regulatory compliance.
Clause 3.1.4 requires that training to be contextualised to the CIIO's operating environment, delivered by an internal or external subject matter expert, conducted at least every 12 months. New Board members must complete training within 12 months of appointment. Records of attendance and curriculum must be maintained.
Clause 3.1.5 requires the Board to receive a cyber threat briefing at least every 6 months covering threats relevant to the CII, threats actively targeting the organisation since the last briefing, and implications for the CIIO's cyber risk posture including recommended changes to controls, risk appetite, and budget.
Senior Management Responsibility (Clauses 3.2.1 – 3.2.5)
Previously: Clause 3.1.3 of the 2022 Code required senior management to include at least one member with cybersecurity knowledge. The risk management clauses (old 3.2.1 – 3.2.5) covered risk framework, assessment methodology, OT-specific controls, risk register, and risk monitoring.
Now: the old risk management clauses have moved to Section 3.4. The 3.2 slot is five new clauses focused on senior management accountability.
Clause 3.2.1: at least one senior management member (or designated individual, e.g. CISO) must have the knowledge to manage cyber risks across CII, interconnected systems, and the enterprise network. Must be vested with authority and competencies.
Clause 3.2.2: written role definitions covering organisational structure, what each role is authorised to do including incident reporting and escalation, incident investigation authority, cyber risk trade-off decision thresholds, and policy and resource approval authority. Conflict of interest prevention required. Formally approved.
Clause 3.2.3: senior management must brief the Board with cyber threat briefings at least every 6 months.
Clause 3.2.4: senior management must provide the Board with regular reports on cybersecurity posture, risks, and reportable incidents at least every 6 months, and promptly upon occurrence of a reportable incident or material change to the cyber risk profile.
Clause 3.2.5: senior management must allocate adequate resources and budget for cybersecurity. Reviewed at least every 12 months or after material changes.
Cloud Computing (Clause 3.9)
Previously: cloud was bundled under general outsourcing (Clause 3.8 in the 2022 Code).
Now: cloud computing has a dedicated clause (3.9). This is a structural precursor to the CCoP for Cloud Services, which CSA announced will be released in 2H 2026 with companion guides co-developed with AWS, Google Cloud, and Microsoft Azure.
Compliance Timeline
Most new requirements take effect on 29 July 2027. Cyber Trust Mark Tier 5 certification is due by 31 December 2027. During the transition period between the effective date (29 July 2026) and the compliance dates, existing CII owners must continue complying with the previous version of the Code.
What This Means for CII Owners
If your Board is not currently receiving structured cyber threat briefings every 6 months, that process needs to be built. If your interconnected systems are not held to CII-grade controls, Section 12 is your largest gap. If you have not started the Cyber Trust Mark Tier 5 certification process, the clock is running.
CSA has given roughly 12 months. For most CII owners, the gap between current state and Code requirements is significant. Start with the gap assessment.
Bravix Infosecurity provides CCoP gap assessment and compliance advisory services for CII owners in Singapore. Contact us to schedule a consultation.