Demonstrate your commitment to cybersecurity with recognised cybersecurity certifications
As cyber threats continue to evolve, organisations must strengthen their cybersecurity practices to protect business operations, customer information, and digital assets. Under the SG Cyber Safe Programme, the Cyber Essentials Mark and Cyber Trust Mark developed by the Cyber Security Agency of Singapore (CSA) help organisations demonstrate their commitment to cybersecurity resilience. Intertek provides independent assessment and certification support to help organisations achieve the CSA cybersecurity mark that best aligns with their cybersecurity maturity and business needs.
What are the CSA Cyber Essentials Mark and Cyber Trust Mark?
The CSA Cyber Essentials Mark and Cyber Trust Mark are cybersecurity certifications designed to help organisations strengthen their cybersecurity capabilities based on their level of digital maturity and risk exposure.
CSA Cyber Essentials Mark
The Cyber Essentials Mark recognises organisations that have implemented fundamental cybersecurity practices to protect against common cyber threats.
Designed for organisations with limited IT and cybersecurity resources, the certification provides a practical framework covering essential cybersecurity areas such as asset management, protection, system updates, backups, and incident response.
It enables organisations to establish a strong cybersecurity foundation and demonstrate their commitment to protecting business operations and customer information.
CSA Cyber Trust Mark
The Cyber Trust Mark is designed for organisations with more mature cybersecurity capabilities or those operating in environments with higher cybersecurity requirements.
It recognises organisations that have implemented cybersecurity practices aligned with their risk profile and evaluates broader cybersecurity capabilities across governance, people, processes, and technology.
The Cyber Trust Mark helps organisations demonstrate stronger cybersecurity governance, resilience, and readiness against evolving cyber threats.
Which CSA cybersecurity mark is right for your organisation?
|
|
CSA Cyber Essentials Mark |
CSA Cyber Trust Mark |
|
Target organisations |
Organisations beginning their cybersecurity journey or with limited IT resources |
Organisations with more mature cybersecurity capabilities or higher cybersecurity requirements |
|
Objective |
Establish foundational cyber hygiene practices |
Demonstrate advanced cybersecurity governance and resilience |
|
Assessment scope |
Five key areas: Assets, Secure / Protect, Update, Backup, Respond |
Up to 22 domains covering Governance, People, Process, and Technology |
|
Assessment approach |
Self-assessment with independent validation |
Independent assessment and verification |
|
Certification validity |
Two years |
Three years with annual surveillance audits |
Why pursue CSA Cyber Essentials Mark or Cyber Trust Mark Certification?
Achieving a CSA cybersecurity mark demonstrates an organisation’s commitment to protecting its digital assets and strengthening cybersecurity resilience.
Benefits include:
- Strengthening protection against common cyber threats
- Improving cybersecurity awareness and risk management practices
- Demonstrating commitment to protecting customer and business data
- Enhancing stakeholder confidence and business credibility
- Supporting alignment with Singapore’s national cybersecurity initiatives
For organisations seeking to strengthen their cybersecurity foundation or demonstrate advanced cybersecurity maturity, CSA Cyber Essentials Mark and Cyber Trust Mark provide recognised pathways to improve cyber resilience.
What does the CSA Cyber Essentials Mark assess?
The Cyber Essentials Mark focuses on five key cybersecurity practice areas:
Assets
Identify and manage important IT assets, systems, and information.
Secure / Protect
Implement measures to safeguard systems, accounts, and data.
Update
Maintain updated software and systems to reduce vulnerabilities.
Backup
Establish appropriate backup practices to support business continuity.
Respond
Develop processes to detect, manage, and respond to cybersecurity incidents.
What does the CSA Cyber Trust Mark assess?
The Cyber Trust Mark evaluates cybersecurity capabilities across broader organisational areas, including:
Governance
Establish cybersecurity policies, responsibilities, and risk management practices.
People
Develop cybersecurity awareness, training, and responsibilities among employees.
Process
Implement structured cybersecurity processes for managing risks and incidents.
Technology
Strengthen technical controls, protection measures, and security monitoring capabilities.
The assessment covers up to 22 cybersecurity domains based on the organisation’s risk profile.
Intertek’s cybersecurity certification services
Intertek supports organisations in strengthening cybersecurity resilience through independent assessment, certification, and assurance services.
Our experienced cybersecurity professionals help businesses understand CSA certification requirements, prepare for assessment, and implement effective cybersecurity practices aligned with recognised frameworks.
Beyond CSA Cyber Essentials Mark and Cyber Trust Mark Certification, Intertek provides a comprehensive range of cybersecurity solutions, including:
- Information Security Management System (ISO 27001)
- Privacy Information Management System (ISO 27701)
- Cloud Security Assessment (ISO 27017 and ISO 27018)
- Vulnerability Assessment and Penetration Testing (VAPT)
- Artificial Intelligence Management System (ISO 42001)
- Artificial Intelligence Assurance and Testing (AI Red Teaming)
With expertise across cybersecurity testing, assessment, and certification, Intertek helps organisations build resilience against evolving cyber risks.
Frequently Asked Questions
The CSA Cyber Essentials Mark is valid for two years. Organisations should continue maintaining their cybersecurity practices throughout the validity period to ensure ongoing protection against common cyber threats.
The certification cost depends on factors such as the organisation’s size, number of endpoints, scope of assessment, and applicable cybersecurity requirements. Contact Intertek to understand the certification fees and available funding support options.
Eligible Singapore-based organisations may receive funding support from the Cyber Security Agency of Singapore (CSA) to offset certification costs. Funding eligibility and support amounts are subject to CSA’s prevailing requirements.
The CSA Cyber Essentials Mark is designed for organisations that are beginning their cybersecurity journey or have limited IT and cybersecurity resources. It helps businesses establish essential cybersecurity practices to protect their operations, systems, and customers against common cyber threats.
The assessment focuses on five key cybersecurity areas:
- Assets – Identifying and managing important systems, devices, and information
- Secure / Protect – Implementing measures to safeguard systems and data
- Update – Maintaining updated software and systems to reduce vulnerabilities
- Backup – Ensuring appropriate backup practices are in place for recovery
- Respond – Establishing processes to detect and respond to cybersecurity incidents
Organisations should prepare relevant information demonstrating their cybersecurity practices, including details on their IT assets, security controls, update management, backup procedures, and incident response processes.
The Cyber Essentials Mark follows a self-assessment approach based on CSA’s guided framework. Intertek independently reviews the submitted information to validate that the organisation has implemented the required cybersecurity practices.
The certification timeline depends on the organisation’s readiness, the completeness of submitted information, and the assessment process. Organisations with established cybersecurity practices may complete the process more efficiently.
The Cyber Essentials Mark focuses on establishing foundational cybersecurity practices to protect against common cyber threats. The Cyber Trust Mark is designed for organisations with more mature cybersecurity capabilities and evaluates broader risk-based cybersecurity measures across governance, people, processes, and technology.
|
|
CSA Cyber Essentials Mark |
CSA Cyber Trust Mark |
|---|---|---|
|
Target organisations |
Organisations with limited IT or cybersecurity resources |
Organisations with more mature cybersecurity capabilities or higher cybersecurity requirements |
|
Focus |
Establishes essential cyber hygiene practices |
Demonstrates advanced cybersecurity governance and resilience |
|
Assessment scope |
Five key areas: Assets, Secure / Protect, Update, Backup, Respond |
Broader assessment across governance, people, processes, and technology |
|
Certification approach |
Self-assessment with independent validation |
Independent assessment and verification |
Contact Intertek today. Our cybersecurity experts can help your organisation understand the certification requirements, assess your readiness, and support you throughout the certification process.
Organisations should select the certification pathway that best matches their cybersecurity maturity, resources, and risk profile. Intertek can support organisations in determining the most suitable CSA cybersecurity certification based on their current cybersecurity posture and business requirements.
The certification cost depends on the selected certification pathway, organisation size, number of endpoints, and assessment scope.
|
Cyber Essentials |
||||
|---|---|---|---|---|
|
Quantity of end-points |
Classical Cybersecurity |
Cloud Security |
OT Security |
AI Security |
|
1 – 10 |
$500 - $250 = $250 |
+$100 - $50 = $50 |
+$100 - $50 = $50 |
+$100 - $50 = $50 |
|
11 – 20 |
$600 - $350 = $250 |
+$100 - $50 = $50 |
+$100 - $50 = $50 |
+$100 - $50 = $50 |
|
21 – 50 |
$700 - $450 = $250 |
+$150 - $50 = $100 |
+$150 - $50 = $100 |
+$150 - $50 = $100 |
|
51 – 100 |
$800 - $600 = $200 |
+$150 - $100 = $50 |
+$150 - $100 = $50 |
+$150 - $100 = $50 |
|
101 – 200 |
$1000 - $650 = $350 |
+$150 - $100 = $50 |
+$150 - $100 = $50 |
+$150 - $100 = $50 |
|
Cyber Essentials sub-schemes |
|||
|---|---|---|---|
|
Quantity of end-points |
Cyber Essentials for HIA entities (Cybersecurity & Data Security) |
Cyber Essentials for HIMS vendors |
Cyber Essentials for ICT vendors |
|
1 – 5 |
$750 - $250 = $500 |
$600 - $250 = $350 |
$750 - $250 = $500 |
|
6 – 10 |
$900 - $250 = $650 |
$750 - $300 = $450 |
|
|
11 – 20 |
$1050 - $350 = $700 |
$900 - $400 = $500 |
$900 - $350 = $550 |
|
21 – 50 |
$1200 - $450 = $750 |
$1050 - $500 - $550 |
$1050 - $450 = $600 |
|
51 – 100 |
$1350 - $650 = $700 |
$1200 - $675 = $525 |
$1200 - $600 = $600 |
|
101 – 200 |
$1500 - $725 = $775 |
$1350 - $725 = $625 |
$1350 - $650 = $700 |
|
Cyber Trust |
||||||
|---|---|---|---|---|---|---|
|
Quantity of end-points |
Classical Cybersecurity
|
CSA Grant (Classic) |
Cloud Security |
OT Security |
AI Security |
CSA Grant (Pillars) |
|
1 – 10 |
Supporter: $3,200 Practitioner: $3,200 Promoter: $4,800 Performer: $5,600 Advocate: $5,600 |
-$1,375 |
Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
-$225 |
|
11 – 20 |
Supporter: $3,200 Practitioner: $4,000 Promoter: $4,800 Performer: $5,600 Advocate: $6,400 |
-$1,375 |
Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
+ Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
Supporter: +$200 Practitioner: +$200 Promoter: +$400 Performer: +$600 Advocate: +$800 |
-$225 |
|
21 – 50 |
Supporter: $3,200 Practitioner: $4,800 Promoter: $6,400 Performer: $8,000 Advocate: $8,800 |
-$1,625 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
-$225 |
|
51 – 100 |
Supporter: $5,400 Practitioner: $6,300 Promoter: $7,200 Performer: $9,000 Advocate: $10,800 |
-$1,875 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
Supporter: +$400 Practitioner: +$400 Promoter: +$600 Performer: +$800 Advocate: +$1000 |
-$225 |
|
101 – 200 |
Supporter: $6,000 Practitioner: $7,000 Promoter: $8,000 Performer: $10,000 Advocate: $12,000 |
-$2,250 |
Supporter: +$600 Practitioner: +$600 Promoter: +$800 Performer: +$1000 Advocate: +$1200 |
Supporter: +$600 Practitioner: +$600 Promoter: +$800 Performer: +$1000 Advocate: +$1200 |
Supporter: +$600 Practitioner: +$600 Promoter: +$800 Performer: +$1000 Advocate: +$1200 |
-$450 |
Eligible Singapore-based organisations may receive funding support from the Cyber Security Agency of Singapore (CSA) to offset certification costs. Funding eligibility and support amounts are subject to CSA’s prevailing requirements.
Contact Intertek to understand the applicable certification fees and available funding support options for your organisation.
Note: Prices mentioned above for single site and single entity organisations. Prices may vary based on complexity, multi-sites, multi companies, multi scope of certification etc.