Regulation 1
Citation and commencement
These Regulations are the Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025 and come into operation on 31 October 2025.
/akn/sg/act/sub_leg/2018/CA-S680-2025
The full official text, structured for quick navigation. Copy any provision or jump straight to a section.
Quick answer
Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025 is Singapore Subsidiary Legislation, cited as Subsidiary Legislation CA-S680-2025 2018, currently marked in force and first recorded in 2018.
Citation and commencement
These Regulations are the Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025 and come into operation on 31 October 2025.
Information to ascertain if computer, etc., fulfils criteria of system of temporary cybersecurity concern
For the purposes of section 17A(2) of the Act, a notice to provide relevant information to the Commissioner under that provision must be given in writing in the form set out on the Internet website at https://www.csa.gov.sg.
The Commissioner may by notice under section 17A(2) of the Act require a person who appears to be exercising control over a computer or computer system, to provide to the Commissioner the following information relating to that computer or computer system as is relevant for the purpose of ascertaining whether the computer or computer system fulfils the criteria of a system of temporary cybersecurity concern:
the name and location of the computer or computer system;
the function that the computer or computer system is employed to serve;
the type of service (if applicable) that the computer or computer system has a role in making available in Singapore, and the role performed by the computer or computer system;
the person or persons, or other computer or computer systems, that the computer or computer system mentioned in the notice serves;
information relating to the design of the computer or computer system, including the parameters and key components of the computer system, as specified in the notice;
if the computer or computer system is a virtual computer or virtual computer system, information relating to the physical computing resources used for the simulation of the virtual computer or virtual computer system, including identifying information relating to the cloud computing service provider where the physical computing resources used for the simulation of the virtual computer or virtual computer system are provided by a cloud computing service provider;
the name, address, contact and business registration number (if applicable) of the person to whom the notice is given;
if the person to whom the notice is given is not the owner of the computer or computer system, the name, address, contact and business registration number (if applicable) of the owner;
any other information that the Commissioner may require in order to ascertain whether the computer or computer system fulfils the criteria of a system of temporary cybersecurity concern.
In this regulation, “location”, in relation to a computer or computer system that is a virtual computer or virtual computer system, means the location of the physical computing resources deployed for the simulation of the virtual computer or virtual computer system.
Information relating to system of temporary cybersecurity concern
For the purposes of section 17D(1) of the Act, a notice to the owner of a system of temporary cybersecurity concern to furnish information required under that provision must be given in writing in the form set out on the Internet website at https://www.csa.gov.sg.
The Commissioner may by notice under section 17D(1) of the Act require the owner of the system of temporary cybersecurity concern to provide to the Commissioner —
the following information on the design, configuration and security of the system of temporary cybersecurity concern:
a network diagram depicting every key component and interconnection in the system of temporary cybersecurity concern, and any external connection and dependency that the system of temporary cybersecurity concern may have;
for every key component in the system of temporary cybersecurity concern, the following details:
its name and description;
its physical location;
any operating system and version;
any key software and version;
its internet protocol address and any open port, if the component is internet facing;
the name and address of the operator, if the owner is not the operator;
the types of data processed on or stored in the system of temporary cybersecurity concern;
the name and contact of every individual having overall responsibility for the cybersecurity of the system of temporary cybersecurity concern;
the following information on the design, configuration and security of any other computer or computer system under the owner’s control that is interconnected with or that communicates with the system of temporary cybersecurity concern:
the name and description of that other computer or computer system;
the physical location of that other computer or computer system;
the name and address of its operator, if the owner is not the operator;
a description of any function provided by that other computer or computer system;
the types of data exchanged with the system of temporary cybersecurity concern;
the operating system and version;
the key software and version;
how that other computer or computer system is interconnected with or communicates with the system of temporary cybersecurity concern, including the communication protocol of that other computer or computer system with the system of temporary cybersecurity concern;
the name of any outsourced service provider supporting the system of temporary cybersecurity concern, and the nature of the outsourced service; and
any other information that the Commissioner may require in order to ascertain the level of cybersecurity of the system of temporary cybersecurity concern.
In this regulation, “physical location” —
in relation to a key component of a system of temporary cybersecurity concern that is a virtual computer or virtual computer system, means the physical location of the physical computing resources deployed for the simulation of the key component of the virtual computer or virtual computer system; or
in relation to a computer or computer system that is a virtual computer or virtual computer system, means the physical location of the physical computing resources deployed for the simulation of the virtual computer or virtual computer system.
Report of cybersecurity incident in respect of system of temporary cybersecurity concern
For the purposes of section 17F(1) of the Act, where a cybersecurity incident mentioned in section 17F(1)(a), (b) or (c) of the Act occurs, the owner of a system of temporary cybersecurity concern must notify the Commissioner of the occurrence of the cybersecurity incident in the following form and manner:
by submitting the following details in the manner specified in paragraph (2), within 2 hours after becoming aware of the occurrence:
the system of temporary cybersecurity concern which the cybersecurity incident relates to;
the name and contact number of the owner of the system of temporary cybersecurity concern;
the nature of the cybersecurity incident, whether it was in respect of the system of temporary cybersecurity concern or an interconnected computer or computer system, and when and how it occurred;
the resulting effect that has been observed, including how the system of temporary cybersecurity concern or any interconnected computer or computer system has been affected;
the name, designation, organisation and contact number of the individual submitting the notification;
by providing to the fullest extent practicable the following supplementary details in writing in the form set out on the Internet website at https://www.csa.gov.sg within 72 hours after becoming aware of the occurrence:
any updates and supplementary details in respect of the details submitted under sub‑paragraph (a);
the cause of the cybersecurity incident;
the impact of the cybersecurity incident on the system of temporary cybersecurity concern or any interconnected computer or computer system, or on the business operations of the owner of the system of temporary cybersecurity concern;
what remedial measures have been taken;
by providing a final incident report containing the following details in writing in the form set out on the Internet website at https://www.csa.gov.sg within 30 days (including any Sunday and public holiday) after the submission mentioned in sub‑paragraph (b) is made:
the details submitted under sub‑paragraphs (a) and (b);
to the fullest extent practicable, any updates and supplementary details in respect of the information submitted under sub‑paragraphs (a) and (b).
The details mentioned in paragraph (1)(a) must be submitted —
by calling the telephone number specified by the Commissioner; or
if the owner is unable to submit the details in the manner set out in sub‑paragraph (a) within a reasonable time —
by text message to the telephone number specified by the Commissioner; or
in writing, in the form set out on the Internet website at https://www.csa.gov.sg, to the electronic address specified by the Commissioner.
For the purposes of section 17F(1)(a), (b) and (c) of the Act, the following are prescribed cybersecurity incidents in respect of a system of temporary cybersecurity concern or an interconnected computer or computer system:
any unauthorised hacking of the system of temporary cybersecurity concern or the interconnected computer or computer system to gain unauthorised access to or control of the system of temporary cybersecurity concern or interconnected computer or computer system;
any installation or execution of unauthorised software, or computer code, of a malicious nature on the system of temporary cybersecurity concern or the interconnected computer or computer system;
any man‑in‑the‑middle attack, session hijack or other unauthorised interception by means of a computer or computer system of communication between the system of temporary cybersecurity concern or the interconnected computer or computer system, and an authorised user of the system of temporary cybersecurity concern or the interconnected computer or computer system, as the case may be;
any denial of service attack or other unauthorised act or acts carried out through a computer or computer system that adversely affects the availability or operability of the system of temporary cybersecurity concern or the interconnected computer or computer system.
In this regulation —
“interception”, in relation to a communication to or from a system of temporary cybersecurity concern or an interconnected computer or computer system, includes —
listening to or the recording of the communication; and
acquiring the substance, meaning or purport of that communication;
“interconnected computer or computer system” means any computer or computer system under the control of the owner of a system of temporary cybersecurity concern, or under the control of a supplier to the owner, that is interconnected with or that communicates with the system of temporary cybersecurity concern.