All frameworks
CybCertification · risk-based

Cyber Trust compliance

Singapore's risk-based mark of distinction.

The Cyber Trust mark, from the Cyber Security Agency of Singapore (CSA), is a risk-based, tiered certification for larger and more digitally mature organisations. Rather than prescribing a fixed checklist, it asks you to implement the cybersecurity preparedness measures that match your own risk profile — across 22 domains, five tiers, and the full modern technology stack: classical IT, cloud, OT and AI.

Start from the basics

The standard

CSA Cyber Trust mark (Singapore)

Who needs it

Larger or more digitally mature Singapore organisations that have progressed beyond basic cyber hygiene, hold higher risk, and want a recognised mark of distinction — especially those operating cloud, OT or AI systems, or working toward ISO 27001/27017/42001.

22

preparedness domains, 5 tiers

The basics

What is Cyber Trust?

Cyber Trust adopts a risk-based approach: a guided risk assessment determines your preparedness tier (Supporter, Practitioner, Promoter, Performer or Advocate), and each tier requires a growing number of the 22 domains — from 10 at Supporter up to all 22 at Advocate.

The 22 domains span five pillars: cyber governance and oversight, cyber education, information asset protection, secure access and environment, and cybersecurity resilience. Crucially, the 2025 edition addresses every domain across four technology contexts — classical IT, cloud, OT and AI security.

It's independently audited by a CSA-approved third party, valid for three years, and is explicitly positioned as a pathway to international standards: ISO/IEC 27001, ISO/IEC 27017, IEC 62443 and ISO/IEC 42001.

Why it matters

What Cyber Trust does for your business

A mark of distinction

A CSA-backed, independently audited credential that signals mature, risk-based cybersecurity to enterprise customers, boards and regulators.

Covers modern technology

One framework that addresses cloud, OT and AI security — not just classical IT — so your certification reflects how you actually operate.

A pathway to ISO

Maps to ISO 27001, ISO 27017, IEC 62443 and ISO 42001, so the work compounds toward international certifications.

What it covers

Five tiers

Supporter → Advocate, chosen by a guided risk assessment; higher tiers require more of the 22 domains.

22 preparedness domains

Across governance, education, information asset protection, secure access & environment, and resilience.

IT · Cloud · OT · AI

Every domain is addressed across the four technology contexts, aligned to ISO 27017, IEC 62443 and ISO 42001.

Independent audit

Assessed by a CSA-approved auditor; the mark is valid for three years.

The hard way

Cyber Trust's strength — a risk-based, tier-and-technology matrix — is also its complexity. Working out your tier, which of the 22 domains apply, and which cloud/OT/AI statements are in scope, then implementing and evidencing hundreds of clause statements, is a major undertaking done by hand.

The easier way, with Compliance One

  • Ships all 22 domains across the five tiers and the four technology contexts (IT, cloud, OT, AI) as a structured control library.
  • A tier-aware Statement of Applicability: the baseline is applicable by default, and higher-tier or cloud/OT/AI statements are one click to promote as your scope grows.
  • Pre-fills the mandatory documents — governance charter, risk register, policies, BCP/DR, and cloud/OT/AI security addenda.
  • Cross-maps every domain to ISO 27001, ISO 27017, IEC 62443 and ISO 42001, so your evidence carries across.

Do it once, reuse it everywhere. Evidence you collect for Cyber Trustis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

How is my tier decided?
Through a guided risk assessment that considers your risk profile and digital maturity. It places you at Supporter, Practitioner, Promoter, Performer or Advocate — each requiring more of the 22 domains.
Does it really cover cloud, OT and AI?
Yes. The 2025 edition addresses every domain across classical IT, cloud, OT and AI security, aligned to ISO 27017, IEC 62443 and ISO 42001 respectively. Compliance One tags each statement by technology context.
How does it relate to ISO 27001?
Cyber Trust is a pathway to international standards and cross-maps to ISO 27001, 27017, IEC 62443 and ISO 42001 — so evidence you produce for one counts toward the others.

Ready to tackle Cyber Trust?

See exactly how Compliance One maps Cyber Trust to your environment in a 30-minute walkthrough — and how much of it we handle for you.