Part of the AI Regulation News hub.
Singapore's Cyber Security Agency announced it will release an updated Cybersecurity Code of Practice for critical information infrastructure and a new Code for cloud services later in 2026.
An announcement of a Code is not a Code. What CSA did publish is the list of changes it intends to make, and one of them, mandatory Cyber Trust Mark Level 5 certification, is an assessment process rather than a document you can write in the window before the Code lands.
Bottom line: This is a press release announcing forthcoming instruments. Neither CCoP 2026 nor CCoP (Cloud) has been released. Nothing in the announcement binds anyone today; the binding force will come from the Cybersecurity Act once the Codes are issued.
Who this affects: CISOs, heads of infrastructure and board risk committees at designated CII owners in Singapore, and the cloud service providers hosting CII workloads for them.
Issue date: 22 July 2026, announced by Minister Josephine Teo at the Operational Technology Cybersecurity Expert Panel Forum 2026. Both Codes are stated for the later part of 2026; CCoP (Cloud) is specified as 2H 2026.
What changed: CSA set out six key changes to the CII Code and confirmed a separate cloud Code with vendor companion guides. The current CII Code dates from 2022.
Analysis: Read the board item first. CSA is requiring a documented cyber resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually. That is a governance artefact with a named owner, and it is the one change that cannot be delegated to a security team.
Primary sources: CSA press release, 22 July 2026
- Instrument (EN)
- Cybersecurity Code of Practice for Critical Information Infrastructure (CCoP 2026); Cybersecurity Code of Practice for Cloud Services
- Authority
- Cyber Security Agency of Singapore (CSA), part of the Prime Minister's Office and managed by MDDI
- Jurisdiction
- Singapore
- Status
- Announced, not yet released
- Bindingness
- The announcement binds nobody. The Codes, when issued, specify minimum requirements a CII owner is to implement under the Cybersecurity Act.
- Issue date / next deadline
- Announced 22 July 2026. Release stated for the later part of 2026; CCoP (Cloud) for 2H 2026. No compliance date given.
- Predecessor
- The CCoP was last updated in 2022
- Cloud partners
- Amazon Web Services, Google Cloud and Microsoft Azure, for CSP-specific companion guides
- Primary source
- https://www.csa.gov.sg/news-events/press-releases/cybersecurity-code-of-practice-for-critical-information-infrastructure-to-be-updated-to-address-apt-and-ai-enabled-threats/
The six changes CSA named
Board and senior management accountability comes first. CII owners are to strengthen Board and senior management accountability and oversight, and Boards must maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer and recovery, reviewed at least annually.
Certification is next: CII owners are required to attain Cyber Trust Mark Level 5. Then oversight of interconnected systems that connect to and communicate with the CII, so the broader network architecture becomes visible rather than assumed.
The remaining three cover detection and readiness. CSA will work with owners to deploy threat detection systems across their network segments. Owners must develop a comprehensive cybersecurity exercise plan. And they must maintain management measures for network architecture across network management, monitoring and detection management.
Why CSA says it is doing this now
The stated reason is a change in the threat side rather than in the technology stack. Since the 2022 update, on CSA's account, AI-enabled threats have let attackers move faster and at greater scale, and frontier AI lets them discover vulnerabilities faster, which shortens the window in which a vulnerability can be patched before it is exploited.
That framing matters for how the requirements should be read. A shortened exploitation window is an argument about time to detect and time to respond, which is why four of the six changes are about visibility, detection and exercising rather than about controls at the perimeter.
CSA also ties the update to amendments made to the Cybersecurity Act, noting the Act was amended so that CII owners remain responsible for cybersecurity and cyber resilience even as they adopt new technological and business models such as cloud computing.
The cloud Code and the companion guides
CCoP (Cloud) is a separate instrument aimed at CII systems hosted on cloud. Its stated purpose is to establish cybersecurity requirements governing secure deployment, operation and management of those systems.
CSA says it ran closed-door consultations with auditors and with CII owners that have adopted or are exploring cloud, and folded that feedback into both the controls and the guidance statements.
The operationally interesting part is the companion guides. CSA has partnered with AWS, Google Cloud and Microsoft Azure to produce provider-specific guidance on implementing the controls through configuration and cloud-native security capabilities, published alongside the Code. CSA names three partners and no others, so a CII owner running on a fourth provider has no announced companion guide.
What a CII owner can do before the text lands
Two of the six items have procurement or calendar dependencies that outlast the announcement window. Cyber Trust Mark Level 5 certification is an assessment process, not a document you write, and an exercise plan needs participants booked across business units.
The interconnected-systems requirement is the one most likely to surface unpleasant facts. Many CII owners maintain an accurate inventory of the CII itself and a much vaguer picture of what talks to it. Building that map is useful regardless of the final drafting.
None of this is a compliance obligation yet. It is preparation against a published intention, and the intention is specific enough to act on.
What we did not verify
We opened the CSA press release dated 22 July 2026 in full, including both footnotes.
We did not open the current 2022 CCoP, the Cybersecurity Act or the Cybersecurity (Amendment) Act 2024, the Cyber Trust Mark scheme documentation, or any draft of CCoP 2026 or CCoP (Cloud), because no draft of either Code has been published.
We will not state what the Codes will actually require, what the compliance deadline will be, or which entities are designated CII. The press release describes intended changes and gives no dates beyond the later part of 2026.
Treat this as a dated notice of intent, not a requirement. The board resilience framework and the interconnected-systems inventory are the two items worth starting before the text exists, because both take months and neither depends on final drafting. If your CII workloads sit with a provider outside AWS, Google Cloud and Azure, note now that CSA has announced no companion guide covering you.
Source File
Open the CSA press release of 22 July 2026 and confirm three points: it announces CCoP 2026 and a separate CCoP for Cloud Services for release later in the year, it lists six key changes including Cyber Trust Mark Level 5 and an annually reviewed cyber resilience framework, and it names AWS, Google Cloud and Microsoft Azure as companion guide partners.
Since the last update of the CCoP in 2022, the cyber threat landscape has shifted with new AI-enabled threats, allowing threat actors to launch attacks faster and at a greater scale. ยท Cyber Security Agency of Singapore, 22 July 2026
FAQ
Is CCoP 2026 in force?
No. As of the 22 July 2026 announcement neither CCoP 2026 nor the cloud Code had been released. CSA stated release for the later part of 2026.
What is the Code's legal basis?
CSA describes the CCoP as specifying the minimum requirements a CII owner is to implement to ensure the cybersecurity of its CII in accordance with the Cybersecurity Act.
Does the update mention AI specifically?
Yes. CSA cites AI-enabled threats and frontier AI as reasons attackers can find vulnerabilities faster, shortening the exploitation window, and says the Code will be updated with technical guidance covering adversarial attack simulation, penetration testing and threat hunting.
Will cloud providers publish implementation guidance?
CSA says it has partnered with AWS, Google Cloud and Microsoft Azure on CSP-specific companion guides, to be published alongside the cloud Code.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.