
Singapore Now Regulates the Cloud Behind Critical Services
Singapore’s amended Cybersecurity Act expands oversight beyond traditional critical infrastructure and recognises that essential services may depend on virtual systems, cloud providers and data centres.
Key provisions of Singapore’s Cybersecurity (Amendment) Act commenced on 31 October 2025. The original Act focused on Critical Information Infrastructure: computer systems directly involved in providing essential services.
The amendments respond to an architectural reality. Critical services increasingly run on infrastructure that the regulated organisation does not own, and some nationally important systems may matter only during a particular event.
Virtual infrastructure does not remove responsibility
Critical Information Infrastructure owners remain responsible for cybersecurity and resilience when they adopt new operating models such as cloud computing. The Commissioner of Cybersecurity can address virtual computers and systems used to provide essential services rather than treating physical ownership as the boundary.
That changes supplier conversations. A critical-service operator cannot outsource its statutory responsibility along with the workload. It needs contractual and technical visibility into the systems supporting the service, even where the underlying infrastructure is shared.
Architecture documentation should identify which cloud accounts, regions, control planes, identity systems and managed services are essential to delivery. A diagram containing only the organisation’s own network is no longer enough.
More incidents become reportable
The amendment broadens reporting for CII owners, including specified incidents affecting supply chains and systems under the owner’s control. Singapore’s commencement guidance also identifies reporting within two hours for relevant incidents, including suspected advanced persistent threat activity and disruption involving certain non-interconnected systems.
Two hours is not an investigation deadline. It is an escalation deadline. The organisation needs a route for reporting the information known at the time while the investigation continues.
That requires:
- continuous monitoring of regulated systems;
- supplier notification periods measured in minutes, not days;
- an on-call decision maker who understands the legal threshold;
- a pre-agreed report format and secure submission route;
- follow-up procedures as facts change.
New classes of regulated systems
The amended framework allows oversight of systems beyond conventional CII.
Systems of Temporary Cybersecurity Concern may be designated during events or situations in which compromise could harm national interests. Election systems or systems used during a public-health emergency are useful examples.
Entities of Special Cybersecurity Interest may be designated because they hold sensitive information or perform functions of national interest.
Foundational Digital Infrastructure covers services on which the digital economy depends, including cloud and data-centre providers. These providers may be required to follow cybersecurity codes and report prescribed incidents.
The common theme is consequence. Regulation follows the function and dependency, not merely the owner of a physical server.
What organisations should do
Critical-service operators and infrastructure providers should:
- Map essential services to owned and third-party systems.
- Identify virtual and non-interconnected systems that could enter scope.
- Rewrite supplier incident clauses to support Singapore’s reporting clock.
- Test an escalation from provider telemetry to the statutory decision maker.
- Maintain current contact and system information for the regulator.
- Align sector codes with the broader enterprise security programme.
- Exercise a scenario in which a critical cloud dependency is unavailable or compromised.
Cloud concentration becomes a regulatory concern
The amendment is a reminder that moving to cloud changes the distribution of responsibility, not the importance of the service. A single provider can support many critical entities at the same time, creating national concentration risk even when every customer believes it has outsourced only one workload.
Singapore’s response is to extend visibility and accountability into the foundational layer. Other jurisdictions are likely to face the same question.
Official sources
- Cyber Security Agency of Singapore: commencement on 31 October 2025
- Cyber Security Agency of Singapore: Cybersecurity Act overview
This article provides general information and is not legal advice.
Continue the series: APAC Cyber & Digital Law Series index



