All resources
Guide 9 min read

Cyber Essentials vs Cyber Trust: choosing Singapore's CSA marks

C1The Compliance One team27 August 2026

If you do business in Singapore, two letters keep coming up in procurement questionnaires: the Cyber Security Agency's Cyber Essentials mark and its Cyber Trust mark. They're often mentioned in the same breath, but they're different animals — one is a baseline you either meet or you don't, the other is a risk-based mark of distinction that scales with how big and how digital you are. Picking the right one (and not over-buying) is the first decision.

Cyber Essentials — the baseline that stops the common attacks

Cyber Essentials is designed for organisations that are early in their cybersecurity journey — typically SMEs without a dedicated security team. It follows the 80/20 rule: implement the handful of measures that stop the overwhelming majority of non-targeted attacks, and skip the heavyweight machinery for now. The mark is organised into five categories — Assets, Secure/Protect, Update, Backup and Respond — across nine measures.

In practice that means: know your people, hardware, software and data; protect them with anti-malware, access control and secure configuration; patch promptly; back up essential data offline and test the restore; and keep a basic incident-response plan. You complete a guided self-assessment, a CSA-appointed body verifies it, and the mark is valid for two years. You must meet every requirement — it's pass/fail, not a maturity score.

Cyber Trust — risk-based, tiered, and built for modern tech

Cyber Trust is the step up for larger or more digitally mature organisations. Instead of a fixed checklist, it starts with a guided risk assessment that places you in one of five preparedness tiers — Supporter, Practitioner, Promoter, Performer or Advocate — and each tier requires progressively more of its 22 cybersecurity preparedness domains, from 10 at Supporter to all 22 at Advocate.

The 22 domains sit under five pillars: cyber governance and oversight, cyber education, information asset protection, secure access and environment, and cybersecurity resilience. What makes the 2025 edition stand out is that it addresses every domain across four technology contexts — classical IT, cloud, operational technology (OT) and AI security — mapping to ISO 27017, IEC 62443 and ISO 42001 respectively. It's independently audited, valid for three years, and explicitly positioned as a pathway to ISO 27001.

Why it matters

In Singapore, these marks increasingly show up as procurement requirements and trust signals — a way for buyers to filter suppliers on cyber hygiene without running their own audit. For an SME, Cyber Essentials is often the fastest route to unblocking a deal. For a larger provider handling cloud, OT or AI, Cyber Trust is the credential that says your security is mature and risk-based, not box-ticked.

The good news: the two marks are a ladder, not a fork. Cyber Essentials maps onto Cyber Trust's Supporter and Practitioner tiers, and both derive from ISO 27001 and CIS Controls. Start where you are and climb — nothing you build for one is wasted on the next.

How Compliance One helps

Compliance One ships both marks as full control libraries — all nine Cyber Essentials measures, and all 22 Cyber Trust domains across the five tiers and the four technology contexts. A tier-aware Statement of Applicability keeps your baseline applicable by default and lets you promote higher-tier or cloud/OT/AI controls with one click as your scope grows.

The mandatory documents — scope statements, asset and data inventories, secure-configuration baselines, backup and incident-response plans, governance charters, BCP/DR and the cloud/OT/AI addenda — come pre-filled. And every control cross-maps to ISO 27001 (and, for Cyber Trust, ISO 27017, IEC 62443 and ISO 42001), so evidence you already hold counts toward the mark instead of a fresh project.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.