SG Cyber Essentials: Cyber Essentials mark
The Cyber Essentials mark is the Cyber Security Agency of Singapore's (CSA) cybersecurity certification for organisations, especially SMEs. It certifies baseline measures across nine areas, from people and assets to backup and incident response. Komply maps the 2nd edition (April 2025) as 75 requirements and recommendations.
Last updated · By the Faseel compliance team · Not legal advice
SG Cyber Essentials at a glance
- Issued by
- Cyber Security Agency of Singapore (CSA)
- Version mapped
- Cyber Essentials mark, 2nd edition (April 2025)
- Structure
- 9 sections (A.1–A.9), grouped under Assets, Secure/Protect, Update, Backup and Respond
- Certification
- Assessed by CSA-appointed certification bodies; valid for 2 years
- In Komply
- 75 requirements ('shall') and recommendations ('should'), all mapped to ISO 27001:2022
Who must comply with SG Cyber Essentials
SMEs in Singapore
Organisations that want a recognised baseline certification.
Suppliers
Vendors asked by customers or government buyers to show baseline cyber hygiene.
Organisations growing toward ISO 27001
A stepping stone to the fuller Cyber Trust mark or ISO 27001.
What SG Cyber Essentials requires
- People: awareness and training.
- Hardware & software asset inventory.
- Data identification and protection.
- Virus & malware protection.
- Access control.
- Secure configuration.
- Software updates.
- Backup.
- Incident response.
SG Cyber Essentials domains and control counts
75 controls across 9 areas, as mapped in Komply.
| Domain | Controls |
|---|---|
| A.1 People | 5 |
| A.2 Hardware & Software | 12 |
| A.3 Data | 5 |
| A.4 Virus & Malware Protection | 10 |
| A.5 Access Control | 16 |
| A.6 Secure Configuration | 10 |
| A.7 Software Updates | 4 |
| A.8 Backup | 9 |
| A.9 Incident Response | 4 |
| Total | 75 |
How SG Cyber Essentials maps to ISO 27001
All 75 requirements map to ISO/IEC 27001:2022 Annex A, so the mark is a natural first step toward ISO 27001.
Komply tracks every Cyber Essentials mark requirement with evidence, so your certification-body assessment goes smoothly and the work carries over to ISO 27001. See how Komply works.
SG Cyber Essentials FAQ
What is the Singapore Cyber Essentials mark?
It is a cybersecurity certification from the Cyber Security Agency of Singapore that recognises organisations, especially SMEs, for putting baseline measures in place across nine areas, including access control, secure configuration, updates, backup and incident response.
How long is the Cyber Essentials mark valid?
Certification is performed by CSA-appointed certification bodies and is valid for two years.
Is Singapore's Cyber Essentials the same as the UK's?
No. They share a name and a baseline philosophy, but they are separate schemes run by different agencies (CSA in Singapore, NCSC/IASME in the UK) with different requirements. Komply supports both.
How does Komply help?
Komply maps all 75 requirements and recommendations to ISO 27001, tracks your evidence, and prepares you for the certification-body assessment.
Official sources
Do ISO 27001 once. Prove SG Cyber Essentials too.
Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.