A recognised badge of good hygiene
A CSA-backed mark that signals to customers, partners and government buyers that you observe good cyber hygiene — increasingly expected in Singapore procurement.
Singapore's baseline cybersecurity certification.
The Cyber Essentials mark, from the Cyber Security Agency of Singapore (CSA), is a baseline certification for organisations starting their cybersecurity journey. It prioritises the essential, high-impact measures that protect against the most common, non-targeted cyberattacks — organised into five categories: Assets, Secure/Protect, Update, Backup and Respond.
The standard
CSA Cyber Essentials mark (Singapore)
Who needs it
Singapore SMEs and organisations early in their cybersecurity journey — especially those that need a recognised mark to win business or reassure customers, but don't yet have the resources for a full ISO 27001 programme.
9
measures, pre-mapped to ISO 27001
The basics
Cyber Essentials is a prescriptive, pass/fail certification built for resource-constrained organisations and SMEs. It focuses on the '80/20' of cyber hygiene: know your people, hardware, software and data; protect them with anti-malware, access control and secure configuration; keep everything patched and backed up offline; and be ready to respond to an incident.
You complete a guided self-assessment against nine measures (A.1–A.9), then a CSA-appointed certification body independently assesses you. You must meet every requirement to certify, and the mark is valid for two years.
It's derived from ISO/IEC 27001 and CIS Controls, so the measures map cleanly to those frameworks — and it forms the Supporter/Practitioner rungs of the higher Cyber Trust mark, giving a clear upgrade path as your risk grows.
Why it matters
A CSA-backed mark that signals to customers, partners and government buyers that you observe good cyber hygiene — increasingly expected in Singapore procurement.
A focused set of essential measures makes it attainable for small teams, without the overhead of a full management system.
The measures feed directly into the Cyber Trust mark and ISO 27001, so nothing you do is wasted as you mature.
Know your people, hardware, software and data — inventory and protect them.
Anti-malware, access control and secure configuration for your systems.
Patch promptly and back up essential data offline, tested regularly.
A basic incident-response plan to detect, respond to and recover from incidents.
Even a 'baseline' mark means producing an asset inventory, a data inventory, access registers, secure-configuration baselines, backup and incident-response plans — and evidencing all nine measures for the assessor. Assembling that from scratch, and keeping it current, is where small teams stall.
Do it once, reuse it everywhere. Evidence you collect for Cyber Essentialsis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps Cyber Essentials to your environment in a 30-minute walkthrough — and how much of it we handle for you.