How to Secure a System of Temporary Cybersecurity Concern (STCC) Under Singapore’s Cybersecurity (Amendment) Act?
A system of temporary cybersecurity concern (STCC) is a computer or system that Singapore’s Commissioner of Cybersecurity designates as high risk for a limited period because its loss or compromise would seriously harm national interests. A designated owner must supply system information on request, follow the Commissioner’s written directions, and report cybersecurity incidents. Designation runs for up to one year and can be extended.
The STCC regime came into force on 31 October 2025, so it is live, not proposed. It reaches any organization that runs a system tied to a time-bound national event: an election, a major diplomatic or sporting event, a public health campaign, or a large one off government program. This guide explains what the designation means, what it requires of the owner, and how to prepare before a notice arrives.

What a System of Temporary Cybersecurity Concern is
A system of temporary cybersecurity concern is a computer or computer system that faces heightened cybersecurity risk because of a temporary event or situation and that the Commissioner of Cybersecurity has formally designated for a fixed period. The Cyber Security Agency of Singapore (CSA) gives two examples: systems that support government election processes and systems that support the distribution of vaccines during a pandemic. Both are critical for a defined window, then fall away.
The Commissioner can designate a system as an STCC only when two conditions are met. First, there is a high risk that a cybersecurity threat or incident may occur during the limited period. Second, the loss or compromise of the system would have a serious detrimental effect on Singapore’s national security, defense, foreign relations, economy, public health, public safety, or public order (Allen & Gledhill’s reading of the new Part 3B sets out both limbs).

The distinction that matters for planning is time. A system becomes an STCC because a temporary situation raises its risk, and the designation is meant to last only as long as that situation does.
Where System of Temporary Cybersecurity Concern (STCC) Fits in the Cybersecurity (Amendment) Act
The Cybersecurity (Amendment) Act was passed in Parliament on 7 May 2024, and its first set of provisions commenced on 31 October 2025. The amendments do two broad things. They update the existing rules for critical information infrastructure (CII), and they widen CSA’s oversight to cover new classes of systems and entities that sit outside the traditional CII definition.
STCC is one of those new classes. The same Act also introduces other new categories, including Foundational Digital Infrastructure and Entities of Special Cybersecurity Interest, which are being brought into force separately. For an owner trying to work out what applies to them, the useful mental model is that CII covers systems that are critical on a standing basis, while STCC covers systems that become critical for a defined period.
How a System Gets Designated, and for How Long
Designation happens by written notice from the Commissioner. The system must be located wholly or partly in Singapore, and the Commissioner must be satisfied that the two conditions above are met for a limited period.
That period runs for up to one year for the initial designation and up to one year again for each subsequent extension. In practice this means a designation can carry across more than one year if the underlying situation persists, but each extension is a fresh decision rather than an open-ended status.

The practical consequence for owners is timing. A system that was procured and built without STCC in mind can be designated months or years later, once a triggering event appears on the horizon. An owner may then receive a request to reconfigure or harden the system on short notice.
What an System of Temporary Cybersecurity Concern (STCC) Owner Must Do
Once a system is designated, Part 3B places three main duties on the owner:
- Furnish information on request. The owner must provide information on the design, configuration, security, and operation of the STCC when the Commissioner asks for it. This means the documentation needs to exist and be current before a request lands, not be assembled in a hurry afterward.
- Comply with written directions. The Commissioner can direct the owner to take specific actions to address cybersecurity threats, and can require the owner to meet technical or other cybersecurity standards, codes of practice, standards of performance, or audits. Directions can arrive with short lead times, so the owner needs the ability to make changes to the system quickly and safely.
- Report cybersecurity incidents. The owner must report cybersecurity incidents affecting the STCC, and incidents affecting other computers or systems that are interconnected with or communicating with the STCC. That second part is easy to underestimate, because it pulls adjacent systems into the reporting scope.
The STCC requirement is set case by case rather than by a single published clock. Under Part 3B, the Commissioner specifies the reporting obligation, the designation period, and the owner’s other duties in the written designation notice, and the owner reports incidents during the period the Commissioner specifies. These duties track the CII approach where practicable, so plan for a CII-style pace and confirm the exact window against your own designation notice. As of CSA’s July 2026 forms update, no standalone STCC incident-reporting form has been published.
How STCC designation differs from CII designation
The two regimes share a shape, and it helps to see where they diverge.
CII designation applies to systems that deliver essential services on an ongoing basis, such as those in energy, water, healthcare, banking, and transport. The obligations are standing obligations. STCC designation applies to systems that are critical only for a bounded period, and the obligations end when the designation lapses.
The obligation sets look similar because the risk they manage is similar: a system whose compromise would seriously harm the country. What changes is duration and trigger. An STCC owner is preparing for a defined stretch of elevated scrutiny rather than a permanent one, which affects how you resource compliance, how you write vendor contracts, and how quickly you need to be able to prove a control works.
If you are mapping your own estate, it is worth checking whether any system could plausibly fall under either regime, because the preparation overlaps. Our guide on what MAS auditors look for in identity and access architecture covers the access-control evidence that both regimes tend to probe.
How to prepare before a designation notice arrives
You cannot choose whether the Commissioner designates your system. You can choose how ready you are when it happens. The following moves shorten the gap between a notice and a defensible response.
- Keep current documentation of design, configuration, security, and operation.
Because the Commissioner can request this information, treat it as a living record rather than a project artifact. If your architecture diagrams and configuration baselines are out of date, the request itself becomes the trigger for a scramble. - Map interconnections and communicating systems.
Incident reporting reaches beyond the STCC itself to systems that connect to or communicate with it. Knowing that boundary in advance tells you which incidents you would need to report and which teams need to be in the loop. - Review vendor contracts for short-notice changes.
If a third party builds or operates the system, you may need them to reconfigure it, meet a new standard, or produce evidence quickly. Contracts written without that expectation can leave you unable to comply on the Commissioner’s timeline. This is the same contractual pressure that CII owners now face with third-party-owned infrastructure. - Rehearse incident reporting.
The value of a reporting obligation is only realized if the reporting path works under pressure. A short tabletop that walks an incident from detection to notification will surface the gaps. - Verify controls rather than assume them.
A direction to meet a standard or pass an audit is easier to satisfy when you already hold evidence that your controls hold up against a real attacker. Human-led penetration testing, where a named researcher reproduces a finding and then verifies that the fix closes it, gives you that evidence in a form you can put in front of a regulator. Our explainer on manual versus automated penetration testing covers when reproduced, verified findings matter most. Scope is set per engagement based on the system’s size and interconnections.
Readiness Checklist for STCC Owners
The steps below turn a designation notice from a disruption into a routine response. Work through them for any system that could plausibly be designated, rather than waiting for a notice to arrive.
Readiness checklist
A candidate system readiness checklist
Use this checklist as a fast self-assessment for any system that could be designated. Work through it before designation or a review.
You have run the full checklist. The system is documented, mapped, owned, and rehearsed from detection to reporting. The line that has to come from outside the organisation is recent, independent evidence that your key controls work.
If item 05 is the gap, a human-led engagement can produce recent independent evidence that your key controls work, with every finding reproduced, verified, and signed by the researcher who found it.
Scope a penetration testFrequently Asked Questions (FAQs) About Systems of Temporary Cybersecurity Concern in Singapore
These are the questions owners raise most often once a designation starts to look likely.
The relevant provisions of the Cybersecurity (Amendment) Act commenced on 31 October 2025. The Act itself was passed in Parliament on 7 May 2024.
The Commissioner of Cybersecurity designates a system by written notice, after being satisfied that the system is at high risk for a limited period and that its loss or compromise would seriously harm Singapore’s national interests.
Up to one year for the initial designation, and up to one year for each extension. Each extension is a separate decision, so the total can exceed a year if the situation persists.
Provide information on the system’s design, configuration, security, and operation on request; comply with the Commissioner’s written directions, including standards, codes of practice, and audits; and report cybersecurity incidents affecting the STCC and any interconnected or communicating systems.
No. CII covers systems that are critical on a standing basis, while an STCC is critical only for a defined period. The obligations are similar in shape, but the STCC obligations end when the designation lapses.
An STCC must be located wholly or partly in Singapore. This differs from the updated CII rules, under which systems located wholly outside Singapore can now be designated in some cases.
Bring documentation up to date, map interconnected systems, and confirm that vendor contracts allow short-notice changes and evidence production. These steps make a designation notice manageable rather than disruptive.