Singapore legislation
Regulation 2
of Cybersecurity (Cybersecurity Service Providers) Regulations 2022
Regulation 2
Applications for grant or renewal of licence
Subregulation 1
Subject to paragraph (4), every application for the grant or renewal of a cybersecurity service provider’s licence under section 26 of the Act must be made electronically using the electronic application service provided by the licensing officer mentioned in section 25 of the Act at https://www.gobusiness.gov.sg/licences.
Subregulation 2
The application for the grant or renewal of a licence must include the following:
where the applicant is an individual —
the applicant’s name;
the applicant’s identity card number, work pass number, passport number or foreign identification number;
the applicant’s nationality;
the applicant’s residential address and, if different, the applicant’s correspondence address;
the applicant’s contact telephone number and email address;
information relating to —
the applicant’s qualification or experience (if any) relating to the licensable cybersecurity service for which a licence is sought;
where the applicant does not have any qualification or experience relating to the licensable cybersecurity service for which a licence is sought — the qualification or experience of the applicant’s employees or proposed employees having supervisory responsibility relating to the licensable cybersecurity service; or
where sub-paragraphs (A) and (B) are not applicable — the business partnership, consortium or other legal arrangement (if any) through which the applicant proposes to provide the licensable cybersecurity service;
information as to whether the applicant has been convicted in Singapore or elsewhere of —
an offence involving fraud, dishonesty or moral turpitude; or
an offence the conviction for which involves a finding that the applicant had acted fraudulently or dishonestly;
information as to whether the applicant has had a judgment entered against the applicant in civil proceedings that involves a finding of fraud, dishonesty or breach of fiduciary duty on the part of the applicant;
information as to whether the applicant is or was suffering from a mental disorder;
information as to whether the applicant is an undischarged bankrupt or has entered into a composition with any creditor of the applicant;
information as to whether the applicant has had a licence revoked by the licensing officer previously; and
any other information that may be specified by the licensing officer in the electronic application service mentioned in paragraph (1);
where the applicant is a business entity —
the applicant’s name;
the applicant’s —
Singapore unique entity number; or
business entity registration number in the foreign country or territory that the applicant is incorporated or registered in;
the address of the applicant’s registered office or principal place of business;
if the address in sub-paragraph (iii) is outside Singapore, the address of the applicant’s principal place of business or address for service in Singapore;
the applicant’s contact telephone number and email address;
the particulars mentioned in sub‑paragraph (a) (except sub‑paragraph (a)(vi)(B) and (C)) in respect of every director or partner of the applicant or other person who is responsible for the management of the applicant, with each reference in sub‑paragraph (a) to the applicant substituted with a reference to the director, partner or other person, as the case may be;
where no director or partner of the applicant or other person who is responsible for the management of the applicant has any qualification or experience relating to the licensable cybersecurity service for which a licence is sought — information relating to the qualification or experience of the applicant’s employees or proposed employees having supervisory responsibility relating to the licensable cybersecurity service for which a licence is sought;
information as to whether the applicant has been convicted in Singapore or elsewhere of —
an offence involving fraud, dishonesty or moral turpitude; or
an offence the conviction for which involves a finding that the applicant had acted fraudulently or dishonestly;
information as to whether the applicant has had a judgment entered against the applicant in civil proceedings that involves a finding of fraud, dishonesty or breach of fiduciary duty on the part of the applicant;
information as to whether the applicant is in liquidation or is the subject of a winding up order, or there is a receiver appointed in relation to the applicant, or the applicant has entered into a composition or scheme of arrangement with any creditor of the applicant;
information as to whether the applicant has had a licence revoked by the licensing officer previously; and
any other information that may be specified by the licensing officer in the electronic application service mentioned in paragraph (1).
Subregulation 3
An application for the renewal of a licence must be made no later than 2 months before the date of expiry of the licence.
Subregulation 4
If the electronic application service is not operating or available, an application for the grant or renewal of a licence must be made in such written form as the licensing officer may require.
Subregulation 5
If an application for the renewal of a licence cannot be submitted in accordance with paragraph (1) within the time specified in paragraph (3) due to the unavailability of the electronic application service, an application in such written form mentioned in paragraph (4) must be submitted on the next working day to the licensing officer.
Subregulation 6
In this regulation, “employee having supervisory responsibility relating to the licensable cybersecurity service”, in relation to an applicant, means an employee of the applicant who is responsible for supervising or managing the provision of a licensable cybersecurity service or any part of a licensable cybersecurity service by any other employee of the applicant.