All frameworks
CybCertification · baseline

Cyber Essentials compliance

Singapore's baseline cybersecurity certification.

The Cyber Essentials mark, from the Cyber Security Agency of Singapore (CSA), is a baseline certification for organisations starting their cybersecurity journey. It prioritises the essential, high-impact measures that protect against the most common, non-targeted cyberattacks — organised into five categories: Assets, Secure/Protect, Update, Backup and Respond.

Start from the basics

The standard

CSA Cyber Essentials mark (Singapore)

Who needs it

Singapore SMEs and organisations early in their cybersecurity journey — especially those that need a recognised mark to win business or reassure customers, but don't yet have the resources for a full ISO 27001 programme.

9

measures, pre-mapped to ISO 27001

The basics

What is Cyber Essentials?

Cyber Essentials is a prescriptive, pass/fail certification built for resource-constrained organisations and SMEs. It focuses on the '80/20' of cyber hygiene: know your people, hardware, software and data; protect them with anti-malware, access control and secure configuration; keep everything patched and backed up offline; and be ready to respond to an incident.

You complete a guided self-assessment against nine measures (A.1–A.9), then a CSA-appointed certification body independently assesses you. You must meet every requirement to certify, and the mark is valid for two years.

It's derived from ISO/IEC 27001 and CIS Controls, so the measures map cleanly to those frameworks — and it forms the Supporter/Practitioner rungs of the higher Cyber Trust mark, giving a clear upgrade path as your risk grows.

Why it matters

What Cyber Essentials does for your business

A recognised badge of good hygiene

A CSA-backed mark that signals to customers, partners and government buyers that you observe good cyber hygiene — increasingly expected in Singapore procurement.

Fast, achievable and affordable

A focused set of essential measures makes it attainable for small teams, without the overhead of a full management system.

A stepping stone

The measures feed directly into the Cyber Trust mark and ISO 27001, so nothing you do is wasted as you mature.

What it covers

Assets

Know your people, hardware, software and data — inventory and protect them.

Secure / Protect

Anti-malware, access control and secure configuration for your systems.

Update & Backup

Patch promptly and back up essential data offline, tested regularly.

Respond

A basic incident-response plan to detect, respond to and recover from incidents.

The hard way

Even a 'baseline' mark means producing an asset inventory, a data inventory, access registers, secure-configuration baselines, backup and incident-response plans — and evidencing all nine measures for the assessor. Assembling that from scratch, and keeping it current, is where small teams stall.

The easier way, with Compliance One

  • Ships the full Cyber Essentials control set (all nine measures, every requirement) with the self-assessment built in.
  • Pre-fills the mandatory documents — scope statement, asset and data inventories, cyber-hygiene guidelines, access registers, backup and incident-response plans.
  • Cross-maps every measure to ISO 27001, so evidence counts toward both — and to the Cyber Trust mark for when you level up.
  • Tracks the 2-year validity and keeps your evidence audit-ready for the certification body.

Do it once, reuse it everywhere. Evidence you collect for Cyber Essentialsis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Who issues the Cyber Essentials mark?
The Cyber Security Agency of Singapore (CSA). You self-assess, then a CSA-appointed certification body independently assesses you; the mark is valid for two years.
How is it different from Cyber Trust?
Cyber Essentials is the prescriptive baseline; Cyber Trust is the risk-based, tiered 'mark of distinction' for larger or more digitally mature organisations. Cyber Essentials maps to Cyber Trust's Supporter/Practitioner tiers.
Do we need ISO 27001 first?
No. Cyber Essentials is designed to be achievable without a full ISMS — but because it's derived from ISO 27001, the work carries over if you pursue ISO 27001 later.

Ready to tackle Cyber Essentials?

See exactly how Compliance One maps Cyber Essentials to your environment in a 30-minute walkthrough — and how much of it we handle for you.