Meeting Singapore's 2026 CCoP Requirements With Picus

Umut Bayram | 8 MIN READ

| August 04, 2026

What Is the Cybersecurity Code of Practice (CCoP)?

The CCoP is the code of practice issued by Singapore's Commissioner of Cybersecurity under the Cybersecurity Act. It sets the minimum cybersecurity requirements that an owner of designated Critical Information Infrastructure (CII) must implement, and compliance is audited rather than voluntary.

Designation spans 11 essential-service sectors, from energy and water to banking and finance, healthcare, transport, media, and government.

What Is Changing in Singapore's CCoP for CII in 2026?

Two things are landing in the later part of 2026. The CCoP for CII is being updated, and a separate CCoP for Cloud Services is being introduced for the first time. This is the first major revision since CCoP 2.0, which took effect on 4 July 2022.

The updated code reflects a shift away from relying on perimeter defences toward actively defending against threats, and the cloud code extends that baseline to CII systems that owners now run on public cloud.

Why Is Singapore Updating the CCoP Now?

The threat landscape has moved since 2022, and CSA points to two forces.

The first is AI. Frontier AI models help threat actors find vulnerabilities faster, which shortens the window between disclosure and exploitation, and attackers can work through weak links such as poor credentials and unpatched software within hours, often surfacing vulnerabilities by the hundreds or thousands.

The second is advanced persistent threat activity against Singapore itself, most visibly the UNC3886 campaign against the telecommunications sector.

What Did UNC3886 Do and How Did It Shape Singapore's New CCoP?

UNC3886 is an advanced persistent threat actor that targeted Singapore's telecommunications sector in a methodical campaign that hit all four major telcos.

CSA, government agencies, and the telcos mounted a coordinated response named Operation Cyber Guardian, the largest of its kind in Singapore, which contained the intrusion before service disruption or theft of sensitive customer data.

The campaign shaped the updated code in three ways:

  • It showed that collective resilience is bounded by its weakest link, since one exposed vendor or unmonitored segment gives a patient actor a route into interconnected systems.
  • It retired the assumption that OT complexity keeps systems safe.
  • It made the case for the requirements now being introduced, including continuous monitoring, threat detection across CII network segments, and mandatory exercise plans, all aimed at catching slow, quiet intrusions earlier.

What Are the Requirements of the Updated CCoP?

Based on the Minister for Digital Development and Information's remarks at the Operational Technology Cybersecurity Expert Panel (OTCEP) forum 2026, the updated CCoP for CII owners is expected to cover the following [1] [2]:

  • Board and senior management accountability for cyber resilience, backed by a documented cyber resilience framework spanning risk tolerance, mitigation, transfer, and recovery, reviewed annually.
  • Cyber Trust Mark Level 5 certification for CII owners, together with oversight of the interconnected systems that communicate with CII, which is intended to improve visibility of the wider network architecture.
  • Threat detection deployed across CII network segments, with CSA working alongside owners on rollout.
  • A comprehensive cybersecurity exercise plan to ensure coordinated and effective incident response.
  • Robust management measures for network architecture, specifically in network management, monitoring, and detection management.

A separate CCoP (Cloud) will set out cybersecurity requirements for the secure deployment, operation, and management of CII systems hosted on cloud.

How Picus Supports the New CCoP Requirements

Picus supports the new requirements with three validation engines. Breach and Attack Simulation (BAS) proves whether controls prevent and detect real attacker behaviour. Autonomous Penetration Testing executes real exploit chains to show what an attacker can reach and do. Exposure Validation proves exploitability without firing an exploit, using TTP chain validation and control inference to reach the assets a live test cannot.

Below we show how Picus supports each new requirement.

Requirement: Threat Detection Across CII Network Segments

CSA will work with CII owners to deploy threat detection systems across CII owners’ network segments to detect malicious activities.

How Picus Helps

Picus BAS continuously tests what your EDR, SIEM, firewall, and WAF actually block and detect against the newest attacker techniques, then ships the mitigation content and re-validates that the gap is closed.

Detection coverage stops being an assertion and becomes a measured number per control and per segment, improved with vendor-specific and vendor-neutral mitigation content.

The simulations draw on the Picus Threat Library, which holds over 30,000 threats mapped to MITRE ATT&CK and is continuously updated, while the Picus Mitigation Library supplies the prevention signatures and detection rules that close the gaps it finds.

Figure 1. Picus Mitigation Library providing vendor-specific prevention signatures

Figure 1. Picus Mitigation Library providing vendor-specific prevention signatures

Requirement: Adversarial Attack Simulation, Penetration Testing, and Threat Hunting

CSA has said the code will be updated further later this year with technical guidance covering all three practices [2].

How Picus Helps

Picus Autonomous Pentesting executes real exploit chains against reachable assets to discover the paths that lead to crown-jewel systems , showing what an attacker can actually reach and do, and runs safely in production.

Figure 2. Picus attack path graph from compromised endpoint to crown jewels

Figure 2. Picus attack path graph from compromised endpoint to crown jewels

It also makes the judgment-driven manual pentest stronger, since accredited testers no longer spend their engagement re-covering baseline ground and can put their judgment into novel, creative attack paths instead.

On the hunting side, Picus BAS shows which attacker behaviours generate alerts and logs and which pass unnoticed, which tells hunt teams where visibility is genuinely missing.

Requirement: Oversight of Interconnected Systems, Vendors, and OT

CII owners are required to maintain oversight of interconnected systems that connect with and communicate with CII to strengthen visibility of the broader network architecture and improve cybersecurity risk management.

How Picus Helps

Picus Autonomous Pentesting evidences the attack paths through interconnected systems, including paths that begin at a vendor-facing or partner-facing asset.

For the parts of the estate no live test can touch, Picus Exposure Validation proves exploitability without firing an exploit, validating the TTP chain an exploit would require and inferring control coverage from it.

That covers restricted OT and safety-critical assets as well as CVEs with no public or safe exploit, and returns a defensible verdict on day one of disclosure.

Requirement: A Security Baseline for Cloud-Hosted CII

CSA's cloud code will set the cybersecurity requirements for how CII systems hosted on cloud are deployed, operated, and managed [2].

How Picus Helps

Picus Platform audits core AWS, Azure, Google Cloud, and Kubernetes resources against best practice using read-only permissions, then safely simulates real attacks against what it finds.

Figure 3. Picus cloud security assessment dashboard showing an Azure Kubernetes audit with critical and high-severity findings

Figure 3. Picus cloud security assessment dashboard showing an Azure Kubernetes audit with critical and high-severity findings

Cloud identities are run through a policy simulator to expose which roles and entitlements can genuinely be abused for privilege escalation, and attack path simulation shows how a single foothold chains toward critical systems.

Findings return with severity, affected resources, and policy-level mitigation guidance, so fixing one policy closes many exposures at once.

Audits run on a schedule or on demand after any change, which keeps the evidence current in an environment that moves daily.

Requirement: Board Accountability and a Documented Cyber Resilience

CII owners are required to strengthen Board and senior management accountability and oversight for cybersecurity. Boards must maintain a documented cyber resilience framework covering risk tolerance, mitigation, transfer, and recovery – reviewed at least annually.

How Picus Helps

Picus BAS measures how effectively controls prevent and detect current attacker techniques, while Picus Exposure Validation establishes which exposures are genuinely exploitable. Both keep revalidating, with BAS re-testing controls after every decision and Exposure Validation updating its verdicts whenever the environment changes.

Accepting a risk becomes defensible when the acceptance is backed by a proven broken chain. Picus Platform gives board tested outcomes rather than assumptions, so decisions on risk tolerance, mitigation, and transfer rest on evidence. Re-validation shows whether the verdict still holds at the next annual review.

Requirement: A Comprehensive Cybersecurity Exercise Plan

CII owners are required to develop a comprehensive cybersecurity exercise plan, to ensure coordinated and effective response to cyber incidents.

How Picus Helps

Picus BAS safely runs real adversary behaviour against production controls continuously, which turns the exercise plan from an annual set piece into a standing practice. Picus Autonomous Pentesting extends the same cadence to full exploit chains, so response workflows are exercised against an intrusion that behaves like a real attacker would execute.

Every run is recorded at action and threat level, showing what was executed, blocked, logged, and alerted, with the underlying logs and alerts kept as evidence. Picus Platform generates, stores, filters, and exports that history to PDF or CSV, so reporting runs from practitioner detail through to board-ready answers with an audit-ready chain of custody. Results map to MITRE ATT&CK, so each report names the techniques the estate withstood and the ones it missed.

Figure 4. Picus Risk Dashboard tracking MITRE ATT&CK detection score, prevention score for emerging threats, and open vulnerabilities

Figure 4. Picus Risk Dashboard tracking MITRE ATT&CK detection score, prevention score for emerging threats, and open vulnerabilities

The insights those reports surface then feed back into planning, so each round of exercises is more accurate and more effective than the last, scoped around the gaps the previous round exposed.

Get Ready for the Updated CCoP Today

The final control text lands in the second half of 2026, but the work that makes compliance provable starts now. Owners who wait for publication will have a single snapshot of evidence when the first board review comes around. Owners who start now will have a trend.

That is where validation earns its place. Picus proves which controls hold, which exposures an attacker could genuinely reach, and which fixes actually closed the path, so the record the updated code asks for is built continuously rather than reconstructed the week before an audit.

Compliance will be judged on evidence, not intent. The earlier validation starts, the more evidence there is to show. Book a demo and watch Picus validate a real exposure end to end, from exploit to fix to re-test.

References

[1] A. R. Choudhury, “Singapore to hold senior management of CIIs responsible for future breaches.” Accessed: Aug. 01, 2026. [Online]. Available: https://govinsider.asia/intl-en/article/singapore-to-hold-senior-management-of-ciis-responsible-for-future-breaches

[2] “Website.” [Online]. Available: https://www.csa.gov.sg/news-events/press-releases/cybersecurity-code-of-practice-for-critical-information-infrastructure-to-be-updated-to-address-apt-and-ai-enabled-threats/

Table of Contents

Ready to start? Request a demo