Framework guide • Singapore

SG Cyber Essentials: Cyber Essentials mark

The Cyber Essentials mark is the Cyber Security Agency of Singapore's (CSA) cybersecurity certification for organisations, especially SMEs. It certifies baseline measures across nine areas, from people and assets to backup and incident response. Komply maps the 2nd edition (April 2025) as 75 requirements and recommendations.

Last updated · By the Faseel compliance team · Not legal advice

SG Cyber Essentials at a glance

Issued by
Cyber Security Agency of Singapore (CSA)
Version mapped
Cyber Essentials mark, 2nd edition (April 2025)
Structure
9 sections (A.1–A.9), grouped under Assets, Secure/Protect, Update, Backup and Respond
Certification
Assessed by CSA-appointed certification bodies; valid for 2 years
In Komply
75 requirements ('shall') and recommendations ('should'), all mapped to ISO 27001:2022

Who must comply with SG Cyber Essentials

SMEs in Singapore

Organisations that want a recognised baseline certification.

Suppliers

Vendors asked by customers or government buyers to show baseline cyber hygiene.

Organisations growing toward ISO 27001

A stepping stone to the fuller Cyber Trust mark or ISO 27001.

What SG Cyber Essentials requires

  • People: awareness and training.
  • Hardware & software asset inventory.
  • Data identification and protection.
  • Virus & malware protection.
  • Access control.
  • Secure configuration.
  • Software updates.
  • Backup.
  • Incident response.

SG Cyber Essentials domains and control counts

75 controls across 9 areas, as mapped in Komply.

SG Cyber Essentials domains with number of controls
DomainControls
A.1 People5
A.2 Hardware & Software12
A.3 Data5
A.4 Virus & Malware Protection10
A.5 Access Control16
A.6 Secure Configuration10
A.7 Software Updates4
A.8 Backup9
A.9 Incident Response4
Total75

How SG Cyber Essentials maps to ISO 27001

All 75 requirements map to ISO/IEC 27001:2022 Annex A, so the mark is a natural first step toward ISO 27001.

Komply tracks every Cyber Essentials mark requirement with evidence, so your certification-body assessment goes smoothly and the work carries over to ISO 27001. See how Komply works.

SG Cyber Essentials FAQ

What is the Singapore Cyber Essentials mark?

It is a cybersecurity certification from the Cyber Security Agency of Singapore that recognises organisations, especially SMEs, for putting baseline measures in place across nine areas, including access control, secure configuration, updates, backup and incident response.

How long is the Cyber Essentials mark valid?

Certification is performed by CSA-appointed certification bodies and is valid for two years.

Is Singapore's Cyber Essentials the same as the UK's?

No. They share a name and a baseline philosophy, but they are separate schemes run by different agencies (CSA in Singapore, NCSC/IASME in the UK) with different requirements. Komply supports both.

How does Komply help?

Komply maps all 75 requirements and recommendations to ISO 27001, tracks your evidence, and prepares you for the certification-body assessment.

Do ISO 27001 once. Prove SG Cyber Essentials too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.