Which cybersecurity frameworks apply to your business? Singapore today, internationals next.
Most SG SMEs see three or four unfamiliar acronyms on their cyberscan and want one question answered. Which of these actually applies to me? Here is the map, including the international standards we are adding next.
The shortest version
For most SG SMEs: PDPA applies by default. CSA Cyber Essentials is the realistic starting cert. Trust marks (DPE, Cyber Trust) are tender and customer-facing signals. The Health Information Act (HIA) will apply to licensed healthcare providers, with deadlines by batch from September 2027 to March 2030. MAS-TRM is sector-mandatory for licensed financial institutions and on our roadmap. International equivalents (UK Cyber Essentials, EU NIS2 + CyFun, and Australia Essential 8) are on the way as we expand outside Singapore.
The frameworks at a glance
| Framework | Who it is for | Mandatory? | Renewal cadence | What StrongKeep automates |
|---|---|---|---|---|
| PDPA | All SG businesses handling personal data | Yes (law) | Ongoing | Privacy policy template, DPO contact, breach response runbook, evidence checklist |
| CSA Cyber Essentials | SG SMEs, often required by tenders | Voluntary (often de facto) | Every 2 years | Most evidence; remainder is operator attestation |
| CSA Cyber Trust Mark | SG SMEs signalling beyond CE | Voluntary | Every 2 years | CE controls plus extended monitoring |
| CSA Cyber Trust Mark (Level 3) | SG SMEs in regulated supply chains | Voluntary (higher tier) | Every 2 years | Coming soon |
| DPE Trust Mark | Customer-facing SMEs (B2C) | Voluntary | Every 2 years | PDPA controls plus customer-trust signals |
| Health Information Act (HIA) | Licensed healthcare providers (every HCSA licensee) | Yes (law) From early 2027, with deadlines by batch: September 2027, September 2028, March 2030 | Self-attested to MOH by your batch deadline. The certifiable mark is CSA's Cyber Essentials (HIA) | HIA readiness: security tools, generated policies and the evidence behind your attestation |
| MAS-TRM | MAS-licensed financial institutions | Yes (sector mandate) | Continuous | Coming soon |
| UK Cyber Essentials | UK SMEs and government supply chain | Voluntary (often required for tenders) | Annual | Coming soon |
| EU NIS2 | Essential and important entities in the EU | Yes (EU directive) | Continuous | Coming soon |
| EU CyFun | EU SMEs (Belgium-led cyber-fundamentals framework) | Voluntary baseline | Continuous | Coming soon |
| Australia Essential Eight | AU businesses and Commonwealth supply chain | Voluntary (mandatory for federal contractors) | Continuous (maturity-based) | Coming soon |
Coverage percentages and exact automation scope vary by framework version. Check with a StrongKeep consultant before submission to confirm what is and is not auto-collected for your sector. "Coming soon" frameworks are on our roadmap as we expand outside Singapore.
One paragraph per framework
Personal Data Protection Act
The baseline law. Applies to every SG business handling personal data. Covers consent, purpose, accuracy, protection, retention, and notification obligations.
The realistic starting cert
Voluntary in principle, often required in practice by government tenders, MNCs, and larger customers. Renews every two years. Most SMEs we work with start here.
The next step up
For SMEs that want to signal cybersecurity maturity beyond Cyber Essentials. Adds monitoring and risk-based controls. Level 3 (deeper assurance for regulated supply chains) is on our roadmap.
Data Protection Essentials
A customer-facing trust signal under PDPC for businesses handling personal data. Useful for B2C SMEs that want to show data-handling discipline on their website.
Health Information Act
MOH's law for licensed healthcare providers. It takes effect from early 2027, and deadlines run by batch from September 2027 to March 2030 (see which batch you are in). Providers self-attest their readiness to MOH; the certifiable mark is CSA's Cyber Essentials (HIA). Read our plain-English HIA guide.
Technology Risk Management (coming soon)
Mandatory for MAS-licensed financial institutions. Sets continuous expectations on technology risk, third-party management, and incident response. On our roadmap.
UK starting baseline (coming soon)
NCSC's foundational scheme. Increasingly required in UK government tenders and supply chains. Close equivalent to CSA Cyber Essentials.
EU directive on essential entities (coming soon)
Requires essential and important entities across the EU to implement cybersecurity risk-management measures and report incidents. Significant scope expansion compared with NIS1.
Cyber Fundamentals (coming soon)
The Belgian-led Cyber Fundamentals framework, increasingly used as a practical baseline for EU SMEs. Maps cleanly to NIS2 obligations.
ACSC's eight mitigation strategies (coming soon)
The Australian Cyber Security Centre's prioritised list of eight mitigation strategies. Mandatory for federal contractors and de facto for AU SMEs in regulated supply chains.
Phased path: get HIA-ready before your batch deadline
For clinics working towards the HIA specifically. Protection plan fixes technical posture today. The Compliance plan adds policies, evidence tracking, and gap monitoring so your readiness evidence is in place well before your batch deadline. If you also want a certificate to show, CSA's Cyber Essentials (HIA) mark is the route.
The pattern is the same for international frameworks on our roadmap: register on Protection now to fix the controls, layer on Compliance when the local cert opens for your market.
What StrongKeep automates per framework
Per framework, the platform collects most of the evidence and produces submission-ready documents. Operator attestations remain manual by design (no platform can attest on behalf of a Director). For Cyber Essentials, this typically means most of the work happens in the platform and the remainder is a half-day of owner attestations and supporting documents.
Be honest about limits. No platform can promise 100 percent automation across every framework: some controls require human judgement on business processes. We tell you exactly which ones before you submit.
Get the compliance map turned into a checklist
The Compliance plan turns the framework that applies to you into a guided submission pack: policies generated, evidence collected, gaps flagged, and a clear list of operator attestations.
Read our HIA readiness guideAlready on Protection? Compliance layers on top: your existing evidence carries forward.