ISO 27001 · Singapore

ISO 27001 Certification Requirements in Singapore

The Short Answer

Singapore’s PDPA requires ‘reasonable security arrangements’, assessment of suspected breaches, and notification to the PDPC within 3 calendar days of assessing a breach as notifiable. The Cybersecurity Act 2018 adds incident-reporting duties for designated CII owners. Neither mandates a certificate, and an ISO 27001 ISMS is how reasonable arrangements are evidenced to a regulator.

What the PDPA and its breach regime require

Singapore’s Personal Data Protection Act 2012 requires “reasonable security arrangements”, technology-neutral and with no standard named. The 2020 amendments added the mandatory breach-notification duty, with the mechanics set out in the Personal Data Protection (Notification of Data Breaches) Regulations 2021. The regulator is the Personal Data Protection Commission (PDPC).

The breach regime turns on two triggers and one clock.

Question The PDPA’s answer
When is a breach notifiable? Where it causes or is likely to cause significant harm to affected individuals, or is of significant scale — 500 or more individuals
When do you tell the PDPC? No later than 3 calendar days after assessing the breach as notifiable
When do you tell individuals? Where significant harm is likely

The clock is anchored to the assessment rather than to the breach. On suspecting a breach, the duty is to assess whether it meets a trigger, and once assessed as notifiable, notification to the PDPC is due within 3 calendar days. Both triggers are evidence questions: significant harm requires knowing what data was exposed, and the 500-individual threshold requires a count. Neither can be answered for an incident that cannot be reconstructed.

Beyond the PDPA, the Cybersecurity Act 2018 governs Singapore’s critical information infrastructure regime, under which designated CII owners report prescribed incidents to the Commissioner of Cybersecurity at the Cyber Security Agency of Singapore. On data location, the PDPA imposes no residency rule; its transfer-limitation obligation requires comparable protection for personal data sent overseas.

How an ISO 27001 ISMS evidences “reasonable security arrangements”

Reasonableness is assessed after an incident, so it has to be documented before one. A certified ISMS provides that record: a risk assessment across all 93 Annex A controls, applicability recorded in the Statement of Applicability, and an independent auditor’s confirmation that the controls operate.

Singapore obligation Where the ISMS answers it
“Reasonable security arrangements” (PDPA) The risk assessment and Statement of Applicability — a documented, independently audited case for what is reasonable
Assessing suspected breaches Logging and monitoring that can reconstruct what happened, whose data was involved, and how many people are affected
PDPC notification within 3 days of assessment Incident management with the assessment step built in and evidenced, so the notifiable determination is a record
CII incident reporting (Cybersecurity Act 2018) Monitoring and reporting discipline scoped over the designated systems
Transfer limitation Supplier and transfer controls, with records of where personal data flows and what protects it there

Where Vanta or Drata is already in place, we run the security those platforms report on: the platform tracks the tasks, and the monitoring the assessment duty depends on still has to be operated.

Certification: SAC and scope

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Singapore Accreditation Council (SAC), administered under Enterprise Singapore, and not by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system, followed by annual surveillance audits and recertification every three years.

Singapore is frequently the anchor entity for a regional scope: one certification with a multi-country boundary answers questionnaires from Bangkok to Auckland. Secure60 has delivery infrastructure in Singapore via Rackcorp, with a datacentre in-country, so collection and monitoring can run locally on our security platform where that is required.

The three-day clock starts after an assessment that is itself a duty

Three calendar days reads as more generous than the region’s 72-hour deadlines, and the Singapore clock starts once the breach has been assessed as notifiable. The assessment is itself the obligation, and it cannot extend indefinitely: an assessment that takes weeks because nothing was logged relocates the failure earlier in the timeline rather than excusing it.

The regime rewards the ability to establish what happened, whose data was involved and how many people are affected, quickly and from records. With that capability the 3-day window is comfortable, and without it no notification window would be.

How Secure60 handles this

We build the ISMS, implement the controls, and operate what the assessment duty depends on — logging, monitoring, and incident management with an evidenced assessment step — with delivery on Singapore infrastructure via Rackcorp. The certification audit belongs to an SAC-accredited certification body, and our work is making sure everything it samples is operating on arrival. Secure60 holds ISO 27001:2022 certification, so the questions your auditor asks are questions we answer about our own system annually.

Frequently Asked Questions

Is ISO 27001 legally mandatory in Singapore?

No. The PDPA requires ‘reasonable security arrangements’ without naming a standard. A certified ISMS is the practical way to establish, for the PDPC and for enterprise customers, what reasonable means for your organisation and that those arrangements are operating.

When is a data breach notifiable in Singapore?

Where it causes or is likely to cause significant harm to affected individuals, or where it is of significant scale — 500 or more individuals. Notification to the PDPC is due no later than 3 calendar days after assessing the breach as notifiable, and to affected individuals where significant harm is likely.

Does the Cybersecurity Act apply to us?

Only where you are a designated critical information infrastructure owner. The Cybersecurity Act 2018 requires designated CII owners to report prescribed incidents to the Commissioner of Cybersecurity at the Cyber Security Agency of Singapore.

Does data have to stay in Singapore?

No. The PDPA has no residency rule. Its transfer-limitation obligation requires comparable protection for personal data moved overseas, which is a controls-and-contracts question the ISMS records and evidences.

Who performs the ISO 27001 certification audit in Singapore?

A certification body accredited by the Singapore Accreditation Council (SAC), administered under Enterprise Singapore, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified.

Can Secure60 deliver in Singapore?

Yes. We have delivery infrastructure in Singapore via Rackcorp, with a datacentre in-country, so collection and monitoring can run locally. We have no local offices, and we do not perform the certification audit.

Singapore PDPA Readiness

A readiness call maps the PDPA and the Cybersecurity Act against the environment and sets out what an ISMS engagement covers.

30 days, every feature switched on. No credit card.