Compare · Compliance frameworks

Which cybersecurity frameworks apply to your business? Singapore today, internationals next.

Most SG SMEs see three or four unfamiliar acronyms on their cyberscan and want one question answered. Which of these actually applies to me? Here is the map, including the international standards we are adding next.

The shortest version

For most SG SMEs: PDPA applies by default. CSA Cyber Essentials is the realistic starting cert. Trust marks (DPE, Cyber Trust) are tender and customer-facing signals. The Health Information Act (HIA) will apply to licensed healthcare providers, with deadlines by batch from September 2027 to March 2030. MAS-TRM is sector-mandatory for licensed financial institutions and on our roadmap. International equivalents (UK Cyber Essentials, EU NIS2 + CyFun, and Australia Essential 8) are on the way as we expand outside Singapore.

The frameworks at a glance

Framework Who it is for Mandatory? Renewal cadence What StrongKeep automates
PDPA All SG businesses handling personal data Yes (law) Ongoing Privacy policy template, DPO contact, breach response runbook, evidence checklist
CSA Cyber Essentials SG SMEs, often required by tenders Voluntary (often de facto) Every 2 years Most evidence; remainder is operator attestation
CSA Cyber Trust Mark SG SMEs signalling beyond CE Voluntary Every 2 years CE controls plus extended monitoring
CSA Cyber Trust Mark (Level 3) SG SMEs in regulated supply chains Voluntary (higher tier) Every 2 years Coming soon
DPE Trust Mark Customer-facing SMEs (B2C) Voluntary Every 2 years PDPA controls plus customer-trust signals
Health Information Act (HIA) Licensed healthcare providers (every HCSA licensee) Yes (law) From early 2027, with deadlines by batch: September 2027, September 2028, March 2030 Self-attested to MOH by your batch deadline. The certifiable mark is CSA's Cyber Essentials (HIA) HIA readiness: security tools, generated policies and the evidence behind your attestation
MAS-TRM MAS-licensed financial institutions Yes (sector mandate) Continuous Coming soon
UK Cyber Essentials UK SMEs and government supply chain Voluntary (often required for tenders) Annual Coming soon
EU NIS2 Essential and important entities in the EU Yes (EU directive) Continuous Coming soon
EU CyFun EU SMEs (Belgium-led cyber-fundamentals framework) Voluntary baseline Continuous Coming soon
Australia Essential Eight AU businesses and Commonwealth supply chain Voluntary (mandatory for federal contractors) Continuous (maturity-based) Coming soon

Coverage percentages and exact automation scope vary by framework version. Check with a StrongKeep consultant before submission to confirm what is and is not auto-collected for your sector. "Coming soon" frameworks are on our roadmap as we expand outside Singapore.

One paragraph per framework

PDPA

Personal Data Protection Act

The baseline law. Applies to every SG business handling personal data. Covers consent, purpose, accuracy, protection, retention, and notification obligations.

CSA Cyber Essentials

The realistic starting cert

Voluntary in principle, often required in practice by government tenders, MNCs, and larger customers. Renews every two years. Most SMEs we work with start here.

CSA Cyber Trust Mark

The next step up

For SMEs that want to signal cybersecurity maturity beyond Cyber Essentials. Adds monitoring and risk-based controls. Level 3 (deeper assurance for regulated supply chains) is on our roadmap.

DPE Trust Mark

Data Protection Essentials

A customer-facing trust signal under PDPC for businesses handling personal data. Useful for B2C SMEs that want to show data-handling discipline on their website.

HIA

Health Information Act

MOH's law for licensed healthcare providers. It takes effect from early 2027, and deadlines run by batch from September 2027 to March 2030 (see which batch you are in). Providers self-attest their readiness to MOH; the certifiable mark is CSA's Cyber Essentials (HIA). Read our plain-English HIA guide.

MAS-TRM

Technology Risk Management (coming soon)

Mandatory for MAS-licensed financial institutions. Sets continuous expectations on technology risk, third-party management, and incident response. On our roadmap.

UK Cyber Essentials

UK starting baseline (coming soon)

NCSC's foundational scheme. Increasingly required in UK government tenders and supply chains. Close equivalent to CSA Cyber Essentials.

EU NIS2

EU directive on essential entities (coming soon)

Requires essential and important entities across the EU to implement cybersecurity risk-management measures and report incidents. Significant scope expansion compared with NIS1.

EU CyFun

Cyber Fundamentals (coming soon)

The Belgian-led Cyber Fundamentals framework, increasingly used as a practical baseline for EU SMEs. Maps cleanly to NIS2 obligations.

Australia Essential 8

ACSC's eight mitigation strategies (coming soon)

The Australian Cyber Security Centre's prioritised list of eight mitigation strategies. Mandatory for federal contractors and de facto for AU SMEs in regulated supply chains.

Phased path: get HIA-ready before your batch deadline

For clinics working towards the HIA specifically. Protection plan fixes technical posture today. The Compliance plan adds policies, evidence tracking, and gap monitoring so your readiness evidence is in place well before your batch deadline. If you also want a certificate to show, CSA's Cyber Essentials (HIA) mark is the route.

The pattern is the same for international frameworks on our roadmap: register on Protection now to fix the controls, layer on Compliance when the local cert opens for your market.

What StrongKeep automates per framework

Per framework, the platform collects most of the evidence and produces submission-ready documents. Operator attestations remain manual by design (no platform can attest on behalf of a Director). For Cyber Essentials, this typically means most of the work happens in the platform and the remainder is a half-day of owner attestations and supporting documents.

Be honest about limits. No platform can promise 100 percent automation across every framework: some controls require human judgement on business processes. We tell you exactly which ones before you submit.

Get the compliance map turned into a checklist

The Compliance plan turns the framework that applies to you into a guided submission pack: policies generated, evidence collected, gaps flagged, and a clear list of operator attestations.

Read our HIA readiness guide

Already on Protection? Compliance layers on top: your existing evidence carries forward.

Compliance does not have to feel like a maze. Start with the cyberscan.

Start with a Free Scan