Back to Insights
Technology Risk7 min readSeptember 2026

Cyber Trust Mark Level 5 Is Mandatory for Critical Infrastructure Boards — Most Haven't Absorbed What That Means

RC

Raymond Cheung

Chartered Actuary · CRO · Board Adviser · Singapore

Since 2 March 2026, boards of Critical Information Infrastructure owners in Singapore are legally required to undergo cybersecurity training at least annually and receive cyber threat briefings every six months. CIIOs — covering banking, telcos, hospitals, power, and nine other sectors — also have a two-year window (end 2027) to certify their non-CII systems to Cyber Trust Mark Level 5. Most boards have the circular. Far fewer have translated it into a board-level governance obligation that the chairman actually owns.

When I advised on risk governance for a Singapore-listed financial institution after the Cybersecurity Act's 2018 enactment, the board's instinct was to route every cybersecurity matter through the CISO and note it in the risk committee's minutes. That was defensible then. It is not defensible now. Since 2 March 2026, the Cyber Security Agency has imposed a specific, named, board-level obligation on every Critical Information Infrastructure owner: the board must participate in cybersecurity training at least once every twelve months and receive cyber threat briefings at least once every six months. This is not a best-practice recommendation. It is a compliance requirement under the updated Cybersecurity Code of Practice for Critical Information Infrastructure.

What the mandate actually covers

Singapore has eleven designated CII sectors: banking and finance, commerce, education, energy, government, healthcare, infocommunications, land transport, maritime, security and emergency services, and water. If you sit on the board of a bank, insurer regulated under the Financial Services and Markets Act's CII provisions, a hospital, a power utility, or any of the other designated operators in those sectors, your board is now a named participant in Singapore's national cybersecurity architecture — not just a governance observer of it. The specific obligations: annual board participation in cybersecurity training, half-yearly cyber threat briefings delivered to the board level, and a two-year window from March 2026 to certify the organisation's non-CII operational systems to Cyber Trust Mark Level 5, the highest certification tier under CSA's scheme.

“The board must participate in cybersecurity training at least once every twelve months. Not 'be briefed by.' Participate in. That is a different word choice, and it is not accidental.”

The word 'participate' is doing a lot of work in that sentence

The standard board response to a new regulatory requirement is to add it to the agenda, receive a management paper, ask two or three questions, and pass a resolution. That is not what 'participate in cybersecurity training' means. CSA's language is specific: the board participates. That implies directors engaging with content designed to test their own understanding of cyber risk, not just receiving information produced by management for board consumption. The distinction matters because the board training obligation was designed to close a specific gap: the 67% of non-executive directors who — according to Gartner's 2025 survey — believed their current board practices were inadequate to oversee cyber risk. A briefing from the CISO does not close that gap. A training exercise designed to challenge what directors actually understand does.

What Cyber Trust Mark Level 5 certification actually involves for the board

CTM Level 5 is an external certification programme run by CSA for organisations with elevated risk profiles. For CIIOs, it applies not just to the designated CII system itself — which is already subject to the Cybersecurity Code of Practice — but to the non-CII operational systems that support the organisation's business operations. Achieving certification involves a structured assessment of cyber governance, risk management processes, supply chain security, incident response capability, and security testing rigour. The board is relevant to all of those. Governance of cyber risk begins at board level — the risk appetite, the resourcing commitment, the consequence management framework if an incident occurs. A certification assessor examining CTM Level 5 compliance will look at whether the board owns those parameters, not just whether the IT team has implemented the technical controls.

What a board should be doing before end 2027

  • Confirm whether your organisation is classified as a CIIO under the Cybersecurity Act — for financial institutions, the MAS Technology Risk Management guidelines already carry adjacent obligations, but the CII classification is separate and CSA administers it.
  • Schedule the mandatory annual board cybersecurity training as a standing agenda item — not a one-off management presentation, but a structured exercise with external facilitation that tests board-level understanding.
  • Ensure the half-yearly threat briefing is a genuine intelligence brief on current threat actors and attack surfaces relevant to your sector, not a recycled industry risk report.
  • Map which non-CII systems fall in scope for CTM Level 5 certification by end 2027 — the assessment preparation takes 12–18 months for complex organisations and starts with a governance-layer review, not a technical audit.
  • Board minutes should reflect actual deliberation on cyber risk parameters — risk appetite, incident response authority, and what the board will and won't delegate to management — not just a notation that the CISO presented.

The two-year window to achieve CTM Level 5 for non-CII systems sounds like runway. It isn't, for any organisation that treats governance preparation as something that happens after the technical remediation is done. In my experience advising boards on regulatory readiness, the governance layer — board risk appetite for cyber, incident response authority, escalation protocols, and the documentation trail that shows these exist and are used — takes as long to build credibly as any technology fix. Boards that start the governance work now will find the certification assessment manageable. Boards that start it in late 2027 will find it painful.

Common Questions

Is Cyber Trust Mark Level 5 certification mandatory for all Singapore companies?

No. The mandatory CTM Level 5 obligation applies specifically to Critical Information Infrastructure owners (CIIOs) — organisations designated under the Cybersecurity Act as operators of CII in Singapore's eleven critical sectors. The deadline for their non-CII operational systems is end 2027. CII auditors face an earlier deadline of end 2026 at the organisation level. For non-CIIO organisations, CTM certification is voluntary, though it signals a strong cyber governance baseline.

What exactly must a CIIO board do under CSA's March 2026 requirements?

Two specific obligations: participate in cybersecurity training at least once every 12 months, and receive cyber threat briefings at least once every six months. Both are board-level requirements — not delegated to a management committee — under the updated Cybersecurity Code of Practice for Critical Information Infrastructure.

How does the Cyber Trust Mark Level 5 board obligation interact with MAS Technology Risk Management guidelines for Singapore insurers and banks?

MAS TRM guidelines already require financial institutions to maintain board-level oversight of technology and cyber risk, including documented risk appetite and accountability for technology risk governance. For MAS-regulated CIIOs — banks and designated insurers — the CSA Cyber Trust Mark obligation sits on top of existing TRM requirements, not instead of them. The governance infrastructure MAS expects should, if properly implemented, give a financial institution a meaningful head start on the CTM Level 5 governance assessment, but the two regimes use different frameworks and both need to be addressed on their own terms.

About the author

Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.

All insights