
Cyber Essentials
For organisations still putting the basics in place: assets, secure configuration, patching, access control, backups, antivirus and awareness. Valid for two years.
It usually starts with a customer, not a regulator: a tender question, a vendor form, a renewal that now asks for a mark you do not have. The Cyber Trust Mark Singapore buyers ask for is a risk-based certification, and Cyber Essentials is the rung below it — we get you onto the right one rather than the flattering one.
Gap analysis against the named standard, the evidence pack built while the work happens, and liaison with the assessment body through to the audit. Delivered under the same accountable scope as the rest of your security programme.
ANSWER THREE QUESTIONS BELOW — THE LADDER LIGHTS YOUR RUNG
Certification goes wrong in one of two ways: aiming too low for the customer asking, or too high for the organisation you actually are. Answer three questions and the ladder lights the rung that fits — then read what that rung will really ask you to show.
Indicative rung: Cyber EssentialsBasics first — it is the fastest mark to hold and the cheapest to keep.

For organisations still putting the basics in place: assets, secure configuration, patching, access control, backups, antivirus and awareness. Valid for two years.

The first Cyber Trust tier, for organisations with limited digitalisation. Risk-based rather than checklist-based: you have to show the domains are governed, not just present.

For organisations whose operations depend on digital systems day to day. Governance, policy and incident response start to be examined rather than asserted.

The tier most mid-sized Singapore firms with enterprise customers end up at. Third-party risk, cyber strategy and training become explicit requirements.

For organisations with significant digital operations or regulated customers. Expect the assessor to test how decisions are made, not only that documents exist.

The full set, for organisations whose customers or regulators expect leading practice across every domain, including advanced monitoring and third-party assurance.
Tier names, domain counts, validity periods and the SS 712:2025 standard reference: csa.gov.sg, checked 2026-09-04. Rezolva prepares and supports the certification; the assessment itself is carried out by an independent certification body.
Most failed assessments are not failures of security. They are failures of evidence: the control exists, but nothing shows when it was last reviewed or who owns it. These four workstreams are how that gap gets closed before the assessor arrives.
Most failed assessments are not failures of security but failures of evidence. Arm the workstreams you have actually completed.
Ask the person requesting it. A tender or vendor form nearly always names the mark and sometimes the tier, and that answer beats any internal opinion. Where nothing is named, Cyber Essentials first is usually the honest answer: it is faster to hold, cheaper to keep, and it builds most of the evidence a Cyber Trust tier will later ask for.
Four stages, with the date the audit is booked agreed at the start rather than hoped for at the end.
Confirm which mark and tier the requesting party actually needs, and which entities and systems fall inside the certification boundary.
Implement what is missing and document what exists, in the order that unblocks the most domains first.
The pack is indexed to the domains, reviewed internally, and dry-run against the questions an assessor will ask.
Assessment day support, non-conformity closure, then the surveillance and renewal calendar so the mark stays live.
Cyber Trust is risk-based: the tier decides how many preparedness domains are assessed, and every domain has to show governance rather than good intentions. [Source: csa.gov.sg, checked 2026-09-04]
A mark is not a legal shield. What it does is answer, in one line on a vendor form, a question that otherwise costs your sales team a fortnight — and it forces the internal discipline that keeps the answer true a year later.
Two numbers make up the total: our preparation work, and the certification body’s own assessment fee, which is billed by them directly. Ours is fixed once the gap analysis is done, so nobody is estimating in the dark.
The baseline mark, for organisations with a straightforward IT estate.
Supporter, Practitioner or Promoter — where most enterprise-facing SMEs land.
Performer or Advocate, and multi-entity groups with regulated customers.
Indicative preparation fees for a Singapore SME, fixed once the gap analysis is done. The certification body charges its assessment fee separately.
Certification is a photograph of one week. What keeps it honest is the surveillance audit, the review dates in the evidence pack, and someone owning the controls between audits — which is exactly what a retained security programme does. Organisations that treat the certificate as the finish line are the ones that scramble a year later.
One accountable team across all three — the same engineers enterprises like NTU, Prudential and China Telecom have trusted with their infrastructure since 2012.
The room · the copy · the camerasThe evidence an assessor wants is produced by the layers below. Same Singapore team, one scope, one invoice.

The five layers a certification body will ask to see, plus the fractional CISO who owns them between audits.

Higher tiers expect testing evidence. A scoped test with a retest is the cleanest way to produce it.

Your PDPA register and policy set answer several certification domains outright — if they are current.

Monitoring, alerting and restore-tested backups are domains in their own right at the higher tiers.
Cyber Essentials is a baseline mark covering the fundamentals — assets, secure configuration, patching, access control, backups, antivirus and awareness. Cyber Trust is risk-based and tiered: the tier decides how many preparedness domains are assessed, and the assessor looks for governance, not just presence. [Source: csa.gov.sg, checked 2026-09-04]
Whichever the party asking for it names. Cyber Essentials Singapore buyers ask for by name is the baseline; the CSA Cyber Trust Mark is the risk-based one above it. Tenders and vendor forms usually say which. Where nothing is specified, we size it to your digitalisation and customer profile — the picker above gives the indicative answer we would start from.
For Cyber Essentials with a straightforward estate, typically a few weeks of preparation before the assessment. For Cyber Trust tiers it is normally two to three months, because governance evidence has to accumulate over time rather than be produced in a day.
Cyber Trust certification runs for three years with an annual surveillance audit; Cyber Essentials runs for two years. Both need the underlying controls to stay true in between — that is what the surveillance audit checks.
No, and no consultancy should. The assessment is carried out by an independent certification body. We prepare you, build the evidence pack, and support you through the audit.
Support schemes for cybersecurity certification have existed and change over time; eligibility depends on your organisation and the scheme in force at the time. We will point you at the current CSA guidance rather than promise a subsidy — and Rezolva makes no claim about grant eligibility.
Often not for the same buyer, but the two answer different questions and some Singapore tenders name the CSA marks specifically. Where you hold ISO 27001, much of the evidence carries over and the preparation is considerably shorter.
Assessments normally end with non-conformities rather than a hard fail. We close them with you and go back to the assessor. The way to avoid them is the dry run before audit day, which is part of the engagement.
Tell us which mark your customer named and we will score the domains against what you have today — you get the real distance, the realistic date, and a fixed preparation fee before anything starts.