Contact
CSA MARKS · SS 712:2025 · RUNG 01-06

Cyber Trust Mark Singapore

It usually starts with a customer, not a regulator: a tender question, a vendor form, a renewal that now asks for a mark you do not have. The Cyber Trust Mark Singapore buyers ask for is a risk-based certification, and Cyber Essentials is the rung below it — we get you onto the right one rather than the flattering one.

Gap analysis against the named standard, the evidence pack built while the work happens, and liaison with the assessment body through to the audit. Delivered under the same accountable scope as the rest of your security programme.

Right rung firstScoped to what buyers ask for
Evidence packBuilt as you go, not the week before
Assessor liaisonThrough to the audit day
Gap analysis before anything is promised
Evidence pack you keep
Renewal calendar included
CSA marks · SS 712:2025SG
  1. Tier 5Advocate22
  2. Tier 4Performer19
  3. Tier 3Promoter16
  4. Tier 2Practitioner13
  5. Tier 1Supporter10
  6. BaseCyber Essentials5
Preparedness domains assessedYOUR RUNG
• valid 3 years • annual surveillance

ANSWER THREE QUESTIONS BELOW — THE LADDER LIGHTS YOUR RUNG

[ 01 · marks ]
Two
Cyber Essentials, then Cyber Trust — different questions entirely
[ 02 · tiers ]
Five
Cyber Trust tiers, from 10 up to 22 preparedness domains
[ 03 · validity ]
3 years
Cyber Trust, with an annual surveillance audit (Essentials: 2 years)
[ 04 · standard ]
SS 712
The Singapore Standard the marks are certified against
[ 05 · us ]
End to end
Gap analysis, evidence, assessor liaison, renewal calendar
The ladder, not the logo

Cyber Trust Mark Singapore — six rungs, and only one of them is yours

Certification goes wrong in one of two ways: aiming too low for the customer asking, or too high for the organisation you actually are. Answer three questions and the ladder lights the rung that fits — then read what that rung will really ask you to show.

Staff in Singapore
How much of the business runs on digital systems
Who is asking for the mark

Indicative rung: Cyber EssentialsBasics first — it is the fastest mark to hold and the cheapest to keep.

Small Singapore team reviewing their Cyber Essentials baseline
Rung 01 · Baseline

Cyber Essentials

For organisations still putting the basics in place: assets, secure configuration, patching, access control, backups, antivirus and awareness. Valid for two years.

5 areasValid 2 years
Team agreeing which Cyber Trust tier fits the business
Rung 02 · Tier 1

Cyber Trust · Supporter

The first Cyber Trust tier, for organisations with limited digitalisation. Risk-based rather than checklist-based: you have to show the domains are governed, not just present.

10 domainsValid 3 years · annual surveillance audit
Review session on Cyber Trust preparedness domains
Rung 03 · Tier 2

Cyber Trust · Practitioner

For organisations whose operations depend on digital systems day to day. Governance, policy and incident response start to be examined rather than asserted.

13 domainsValid 3 years · annual surveillance audit
Mid-sized Singapore firm preparing certification evidence
Rung 04 · Tier 3

Cyber Trust · Promoter

The tier most mid-sized Singapore firms with enterprise customers end up at. Third-party risk, cyber strategy and training become explicit requirements.

16 domainsValid 3 years · annual surveillance audit
Assessment evidence organised domain by domain
Rung 05 · Tier 4

Cyber Trust · Performer

For organisations with significant digital operations or regulated customers. Expect the assessor to test how decisions are made, not only that documents exist.

19 domainsValid 3 years · annual surveillance audit
Certification mark awarded after a successful audit
Rung 06 · Tier 5

Cyber Trust · Advocate

The full set, for organisations whose customers or regulators expect leading practice across every domain, including advanced monitoring and third-party assurance.

22 domainsValid 3 years · annual surveillance audit

Tier names, domain counts, validity periods and the SS 712:2025 standard reference: csa.gov.sg, checked 2026-09-04. Rezolva prepares and supports the certification; the assessment itself is carried out by an independent certification body.

What certification support means

Cyber Essentials Singapore — four things we do so the audit is boring

Most failed assessments are not failures of security. They are failures of evidence: the control exists, but nothing shows when it was last reviewed or who owns it. These four workstreams are how that gap gets closed before the assessor arrives.

0/4 CLOSED
Not started

Most failed assessments are not failures of security but failures of evidence. Arm the workstreams you have actually completed.

Cyber Essentials or Cyber Trust — how to choose without guessing

Ask the person requesting it. A tender or vendor form nearly always names the mark and sometimes the tier, and that answer beats any internal opinion. Where nothing is named, Cyber Essentials first is usually the honest answer: it is faster to hold, cheaper to keep, and it builds most of the evidence a Cyber Trust tier will later ask for.

Gap · build · evidence · audit — one accountable scopeREZOLVA PTE LTD · SG
How it works

CSA Cyber Trust Mark — how the certification programme runs

Four stages, with the date the audit is booked agreed at the start rather than hoped for at the end.

opened
01

Scope the rung

Confirm which mark and tier the requesting party actually needs, and which entities and systems fall inside the certification boundary.

in progress
02

Close the gaps

Implement what is missing and document what exists, in the order that unblocks the most domains first.

delivered
03

Assemble evidence

The pack is indexed to the domains, reviewed internally, and dry-run against the questions an assessor will ask.

closed ✓
04

Audit & renew

Assessment day support, non-conformity closure, then the surveillance and renewal calendar so the mark stays live.

CSA · Certification at a glanceSG
22
— domains at the top tier —
10 at Tier 1

Cyber Trust is risk-based: the tier decides how many preparedness domains are assessed, and every domain has to show governance rather than good intentions. [Source: csa.gov.sg, checked 2026-09-04]

Compliance

Cyber Essentials mark Singapore — what the mark is worth, and to whom

A mark is not a legal shield. What it does is answer, in one line on a vendor form, a question that otherwise costs your sales team a fortnight — and it forces the internal discipline that keeps the answer true a year later.

EssentialsThe baseline mark, valid two years, for organisations starting out.
Cyber TrustRisk-based, five tiers, valid three years with an annual surveillance audit.
SS 712:2025The Singapore Standard the marks are certified against.
AssessmentCarried out by an independent certification body, not by us.
Pricing

Cyber Trust Mark cost — the preparation, priced before it starts

Two numbers make up the total: our preparation work, and the certification body’s own assessment fee, which is billed by them directly. Ours is fixed once the gap analysis is done, so nobody is estimating in the dark.

Scope sheet · M-01CSA

Cyber Essentials readiness

The baseline mark, for organisations with a straightforward IT estate.

Preparation feefrom S$4,800
  • Gap analysis across the five areas
  • Controls implemented and documented
  • Evidence pack assembled
  • Assessment-day support
Get a fixed quote
Most requested
Scope sheet · M-02CSA

Cyber Trust — Tier 1 to 3

Supporter, Practitioner or Promoter — where most enterprise-facing SMEs land.

Preparation feefrom S$12,000
  • 10 to 16 domains, scored and closed
  • Governance and policy set built
  • Indexed evidence pack
  • Assessor liaison to audit day
Get a fixed quote
Scope sheet · M-03CSA

Cyber Trust — Tier 4 to 5

Performer or Advocate, and multi-entity groups with regulated customers.

Programme feefrom S$24,000
  • 19 to 22 domains across entities
  • Third-party assurance included
  • Board reporting pack
  • Surveillance and renewal managed
Talk to us

Indicative preparation fees for a Singapore SME, fixed once the gap analysis is done. The certification body charges its assessment fee separately.

After the certificate

The mark is a claim you have to keep true

Certification is a photograph of one week. What keeps it honest is the surveillance audit, the review dates in the evidence pack, and someone owning the controls between audits — which is exactly what a retained security programme does. Organisations that treat the certificate as the finish line are the ones that scramble a year later.

Certification evidence reviewed control by control before the surveillance audit

One accountable team across all three — the same engineers enterprises like NTU, Prudential and China Telecom have trusted with their infrastructure since 2012.

Control owners and review dates mapped out so the mark stays trueThe room · the copy · the cameras
DigitalFirewall, EDR, VPN, email — watched daily
PhysicalCCTV & door access on the server room itself
RecoverableProtected backups the attacker cannot reach
The debrief

Frequently asked questions

Cyber Essentials is a baseline mark covering the fundamentals — assets, secure configuration, patching, access control, backups, antivirus and awareness. Cyber Trust is risk-based and tiered: the tier decides how many preparedness domains are assessed, and the assessor looks for governance, not just presence. [Source: csa.gov.sg, checked 2026-09-04]

Whichever the party asking for it names. Cyber Essentials Singapore buyers ask for by name is the baseline; the CSA Cyber Trust Mark is the risk-based one above it. Tenders and vendor forms usually say which. Where nothing is specified, we size it to your digitalisation and customer profile — the picker above gives the indicative answer we would start from.

For Cyber Essentials with a straightforward estate, typically a few weeks of preparation before the assessment. For Cyber Trust tiers it is normally two to three months, because governance evidence has to accumulate over time rather than be produced in a day.

Cyber Trust certification runs for three years with an annual surveillance audit; Cyber Essentials runs for two years. Both need the underlying controls to stay true in between — that is what the surveillance audit checks.

No, and no consultancy should. The assessment is carried out by an independent certification body. We prepare you, build the evidence pack, and support you through the audit.

Support schemes for cybersecurity certification have existed and change over time; eligibility depends on your organisation and the scheme in force at the time. We will point you at the current CSA guidance rather than promise a subsidy — and Rezolva makes no claim about grant eligibility.

Often not for the same buyer, but the two answer different questions and some Singapore tenders name the CSA marks specifically. Where you hold ISO 27001, much of the evidence carries over and the preparation is considerably shorter.

Assessments normally end with non-conformities rather than a hard fail. We close them with you and go back to the assessor. The way to avoid them is the dry run before audit day, which is part of the engagement.

Your move first

Book a certification gap analysis

Tell us which mark your customer named and we will score the domains against what you have today — you get the real distance, the realistic date, and a fixed preparation fee before anything starts.