Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Change in renewal application deadline

Cybersecurity Services Regulation Office

FAQ

Find answers to frequently asked questions about the licensing framework and processes.

Last updated 30 July 2026

A. Licensing Requirements

1. Who needs to apply for cybersecurity service provider's licence?
2. What is considered as providing licensable cybersecurity services to the Singapore market?
3. Could you give me examples of the third-party vendors and resellers of the licensable cybersecurity services that are regulated under the licensing framework?
4. Are all companies under the same corporate group required to apply for separate licences in order to provide licensable cybersecurity services?
5. For companies providing both managed security operations centre monitoring services and penetration testing services, how many licence should they apply?
6. Are the employees of cybersecurity service providers required to apply for an individual licence?
7. Will CSRO consider licensing other cybersecurity services in the future?

B. Licence Application

8. What do I need to ensure prior to applying for a licence?
9. How can an overseas company or individual apply for a licence?
10. Who are the Key Executive Officer and Key Officer of a business entity applicant?
11. Do I need to list down all the employees providing the licensable cybersecurity services in the licence application form?
12. How does the Licensing Officer determine whether the officers of a business entity applicant are fit and proper?
13. What happens if any of the officers fails to meet the fit and proper criteria?
14. Is it a requirement to include relevant qualification or experience relating to the licensable cybersecurity service in the licence application?
15. Who would require a Certificate of Clearance?
16. What is the format for a Certificate of Clearance?
17. By when and how will I receive the notification on the outcome of a licence application?
18. I have difficulties in submitting my application to GoBusiness Licensing, who can I contact for help?

C. Licence Fees and Validity

19. How long is the validity period of a licence and what are the fees payable for a licence?

D. Licence Renewal

20. When should a licence renewal application be submitted?
21. How is the licence renewal application process like?
22. Are licensees able to renew the licences before obtaining the Cyber Trust Mark (“CTM”) Promoter (Tier 3) certification?
23. If a licence renewal application has not been approved before the existing licence's expiry date, can licensees continue to provide licensable cybersecurity services?

E. Licence Conditions and Obligations

24. What are the conditions of the licence?
25. Are there guidelines for the type(s) of records a licensee should maintain/keep?
26. Will quality requirements be imposed on licensees?
27. What are the changes to business details that a licensee is required to inform the Licensing Officer?
28. When should I inform the Licensing Officer in the event of changes to key officer of my business?
29. Can I use the CSRO or CSA logo in our publicity materials?
30. My company is undergoing restructuring. Is the existing licence transferable?
31. How do I request to terminate a licence?

F. Requirement for Cyber Trust Mark (“CTM”) Promoter (Tier 3) Certification

32. Am I required to obtain Cyber Trust Mark (“CTM”) Promoter (Tier 3) or equivalent certification?
33. What are the requirements for Cyber Trust Mark (“CTM”) Promoter (Tier 3) or equivalent certification?
34. What would be considered as a Cyber Trust Mark (“CTM”) Promoter (Tier 3) equivalent certification?
35. Is there a grace period for licensees to obtain Cyber Trust Mark (“CTM”) Promoter (Tier 3) or equivalent certification?
36. What happens if a licensee does not hold an active Cyber Trust Mark (“CTM”) Promoter (Tier 3) or equivalent certificate by the end of the grace period?
37. How should licensee submit their Cyber Trust Mark (“CTM”) Promoter (Tier 3) or equivalent certification for assessment?

G. Consumer Guidance

38. Will it be an offence to use unlicensed cybersecurity service providers?
39. Where can I find the list of licensed cybersecurity service providers?

H. About CSRO

40. What is the difference between CSA and CSRO?
41. Who can I contact for further details?