A code built for a different threat model
On 29 July 2026, Singapore's Cyber Security Agency (CSA) issued the updated Cybersecurity Code of Practice for Critical Information Infrastructure (CCoP), the binding technical standard that operationalises the Cybersecurity Act 2018 for the roughly nine sectors CSA designates as critical — energy, water, banking and finance, healthcare, transport, infocomm, media, security and emergency services, and government (CSA, Cybersecurity Act). The last major revision predates the current wave of AI-accelerated intrusion tooling and the deep interlinking of IT and operational technology (OT) networks that now defines most utilities and financial infrastructure. CSA's own framing is blunt: "frontier AI" lets threat actors "discover vulnerabilities faster, thus shortening the window period for exploitation" (CSA press release, 22 July 2026).
What actually changed
Three elements of the update matter more than the rest. First, board-level accountability: Critical Information Infrastructure Owners (CIIOs) must now maintain a documented cyber resilience framework — covering risk tolerance, mitigation, transfer and recovery — reviewed at least annually, and boards must sit through contextualised cybersecurity training at least once every 12 months plus threat briefings roughly every six months (Stephenson Harwood). Second, certification: CIIOs and their auditors must attain Cyber Trust Mark Advocate (Tier 5) or its equivalent, with existing CIIOs given until 31 December 2027 to do so (MDDI factsheet). Third, scope: the Code now reaches "interconnected" IT/OT systems and network infrastructure owned or controlled by a CIIO even when those systems are not themselves designated CII — with seven mandatory control categories including asset inventories, privileged account management and network segmentation (Stephenson Harwood). The Code took effect on issuance, but most new obligations carry a compliance date of 29 July 2027 (Rajah & Tann Asia).
The case for it
The strongest argument for this update is that it corrects a governance failure that shows up everywhere cyber incidents get post-mortemed: security stays a CISO-level problem until a board treats it as an enterprise risk with budget and personal attention attached. Power grids, banks and hospitals are precisely the environments where the fallout from a serious breach is not measured in fines but in blackouts, frozen payment rails or disrupted care. Regulators elsewhere have reached similar conclusions — the U.S. SEC's 2023 cyber disclosure rules made board oversight a reportable item for public companies, and the EU's NIS2 Directive imposes personal liability exposure on management bodies of essential entities. Extending controls to interconnected-but-undesignated systems also closes a real gap: attackers don't respect the line between a CII asset and the corporate network sitting next to it, and CSA is right that visibility has to follow the actual architecture, not the org chart of what got formally designated a decade ago.
Where the design gets ahead of itself
The problem is less the substance than the sequencing. A 24-month runway from designation — or by 31 December 2027 for existing CIIOs — to reach Tier 5 of the Cyber Trust Mark assumes an accredited-auditor market that can absorb every CIIO and its auditors converging on the same certification tier in the same compliance window. CSA has already had to stagger auditor deadlines ahead of owner deadlines precisely because of this bottleneck risk (MDDI factsheet); if capacity doesn't scale, the practical effect is that well-resourced incumbents secure audit slots first and smaller or newer CIIOs — including foreign cloud and infrastructure operators serving Singapore's market — queue behind them or slip into technical non-compliance for reasons unrelated to their actual security posture.
The interconnected-systems extension carries a similar risk in miniature. Asset inventories and segmentation controls are good practice regardless of designation status, but writing them into a compliance regime with a fixed date means CIIOs will spend the next year mapping and documenting network boundaries defensively — to satisfy an auditor — rather than purely to reduce risk. That's not wasted effort, but it is a real compliance cost that CSA has not, in the public materials to date, quantified for the range of CIIO sizes it now covers.
The proportionate version
None of this argues against the core reform. Board accountability and broader visibility into interconnected systems are sound responses to how attacks actually happen now. The fix is calibration, not retreat: CSA should publish auditor-capacity data alongside the certification deadline, consider a staggered compliance schedule by sector size similar to what it already applied between auditors and owners, and make clear that documentation burden on interconnected non-CII systems scales with genuine risk exposure rather than blanket application. Singapore has generally been a comparatively disciplined regulator on tech policy — proportionate scoping here would keep this update a model rather than a cautionary tale about certification bottlenecks eating the compliance runway it was meant to allow.