Who does Singapore’s CCoP 2.0 apply to and what is its scope?
The Cybersecurity Code of Practice (CCoP) 2.0 sets the minimum mandatory cybersecurity requirements for Critical Information Infrastructure Owners (CIIOs) in Singapore. Issued by the Cyber Security Agency of Singapore (CSA) under the Cybersecurity Act, it covers the 11 sectors designated as critical to Singapore’s essential services, including energy, water, banking and finance, healthcare, transport, and government.
In practice, the formal scope applies strictly to the CII systems themselves, meaning the computer systems, network components, and endpoint devices within the digital boundary of the CII. However, CSA strongly encourages CIIOs to extend the same cybersecurity capabilities to the rest of the organisation, because attackers rarely respect the digital boundary of a CII.
What is the compliance timeline for CCoP 2.0?
CIIOs receive a 12-month grace period to achieve full compliance with CCoP 2.0 requirements. For existing CIIs, the 12-month window runs from the Effective Date of the Code. However, for newly designated CIIs, it runs instead from the official Designation Date issued by CSA.
During the transition period, existing CIIs must continue to meet the requirements of the previous version of the Code at a minimum. In fact, CCoP 2.0 introduced significant changes around supply chain security, operational technology (OT) cybersecurity, and cybersecurity resilience. As a result, CIIOs that start late in the 12-month window typically end up racing against the clock on remediation work.
Can CIIOs host Critical Information Infrastructure in the cloud under CCoP 2.0?
Yes. CIIOs can implement parts or the entirety of their CII on cloud computing systems. However, accountability stays with the CIIO, not the cloud provider. In other words, using a Cloud Service Provider does not transfer the CIIO’s responsibility to manage cybersecurity risks.
Before moving CII workloads to the cloud, a CIIO must complete four steps:
- Notify the Commissioner of Cybersecurity in advance of the cloud adoption
- Conduct a detailed cybersecurity risk assessment covering the workload, the provider, data residency, and exit arrangements
- Formally accept the risk assessment at an appropriate senior level within the CIIO
- Submit the accepted assessment to the Commissioner for review within 30 days
What happens if a CIIO finds non-compliance during an audit?
When a cybersecurity audit identifies non-compliance with the Cybersecurity Act or CCoP, the CIIO must submit a remediation plan to the Commissioner within 30 working days of receiving the audit report. In addition, implementation is at the CIIO’s own cost, and the Commissioner expects progress updates as each remediation action completes.
The remediation plan must include:
- Specific remediation actions for each non-compliance finding
- Clear timelines for implementing each action
- Ownership and accountability for each remediation step
- Interim risk mitigation measures where the full fix will take time
Can you get a waiver if you cannot meet a specific CCoP 2.0 requirement?
Yes. If a CIIO cannot comply with specific provisions of the Code, it can submit a written waiver request to the Commissioner with clear justification. However, the waiver regime is deliberately strict, because CSA wants waivers to drive continuous improvement rather than create permanent exceptions.
Key characteristics of the CCoP 2.0 waiver regime:
- No permanent waivers: all waivers are time-bound or tied to a specific triggering event, such as a technology refresh
- Compensating controls are mandatory: you must implement them both during the review period and throughout any active waiver
- Continuous reassessment: CIIOs must monitor the risk environment and revisit the waiver when circumstances change
- Commissioner discretion: CSA can approve, deny, or revoke waivers at its discretion, so waiver submissions tied to concrete plans to eliminate the underlying constraint are far stronger than open-ended requests