# Introduction

### Pre-Approved Solutions' ICM Vendor Onboarding Process and Maintaining Contract Status

### What is Pre-Approved Solutions?

Pre-Approved Solutions is an initiative under the SMEs Go Digital programme that helps Singapore SMEs access trusted digital solutions for their business needs.

#### What is the ICM Vendor Onboarding Process?

The onboarding process for ICM vendors is designed to ensure only high-quality, reliable solutions reach SMEs. Through a structured evaluation journey that typically spans 4-5 months, each solution's capabilities, technical standards, and the vendor's track record in serving SMEs are carefully evaluated and assessed. This rigorous process helps maintain the quality and reliability of solutions available to SMEs, ensuring they receive value for their digital transformation investments. Successful solutions are then featured on GoBusiness and SMEs Go Digital platforms, making them easily accessible to SMEs looking to digitalise their operations.

The [eligibility criteria](/pre-approval-guide/eligibility-criteria) are divided into&#x20;

* Vendor eligibility
* Solution eligibility

The SMEs Go Digital Pre-Approval process has 4 stages:&#x20;

* Stage 1: [Vendor Self-Assessment](/pre-approval-guide/stage-1-vendor-self-assessment)
* Stage 2: [Vendor Application](/pre-approval-guide/stage-2-vendor-application)
* Stage 3: [Evaluation](/pre-approval-guide/stage-3-evaluation); and
* Stage 4: [Approval](/pre-approval-guide/stage-3-evaluation)

#### \[Post Pre-Approved] [Maintaining Pre-Approval status](/maintaining-your-contract-status/how-to-keep-my-status-as-a-pre-approved-vendor)

This section highlights critical compliance requirements from the [Terms and Conditions](/pre-approval-guide/terms-and-conditions-and-guide)[.](/pre-approval-guide/terms-and-conditions-and-guide) Key points have been extracted to help vendors maintain their pre-approval status effectively.

{% hint style="success" %}
**Are you ready to be a Pre-Approved Vendor?**

Pre-approval allows you to offer your solutions to SMEs with up to 50% grant support. Use our tool to check your perform a quick eligibility check and/or identify you suitable solution category.

**Option 1:** [**Solution Category Recommender** ](https://go.gov.sg/vendselfassessment)**(**&#x50;lease note that this tool is currently in beta testing, and your feedback during this trial phase will help us improve its functionality and user experience.)

or

**Option 2:** [**Self-assessment FormSG**](https://form.gov.sg/6840edbd36673ed8f32a15a9)
{% endhint %}


# Eligibility criteria

Learn about the eligibility criteria or onboarding criteria for SMEs Pre-Approval programme.

ICM Vendors with ready solutions that are market proven for SMEs must meet all the vendor and solution criteria to apply for SMEs Go Digital Pre-Approval.

<div align="left"><figure><img src="/files/rqTVGJwsrlohu0Vov6OB" alt="Image to show onboarding criteria"><figcaption></figcaption></figure></div>

### Vendor Eligibility Criteria

1. **ICM Vendor has proven track record with SMEs for the solution**

* At least [5 SMEs](/pre-approval-guide/stage-2-vendor-application/preparing-submission/create-new-draft-submission/customer-references)\* who have used the solution for a minimum period of 6 months, and are currently still using the solution.
* There must be no negative feedback from Customer Satisfaction Survey.
* ICM Vendor must be registered in Singapore.
* ICM Vendor's company must have been incorporated for a minimum of 18 months.

*\*Note: SMEs must not be from subsidiaries nor affiliated companies. SMEs must be from your solution's target sector. Click* [*here* ](/pre-approval-guide/stage-2-vendor-application/preparing-submission/create-new-draft-submission/customer-references)*to understand how to fulfill the SME track record requirement.*&#x20;

2. **ICM Vendor provides adequate resources to support local SMEs**

* At least 5 SME customers have indicated that they are satisfied with the ICM Vendor’s service.
* ICM Vendor must be able to offer at least 8 hours x 5 weekdays of post-sales support via on-site/teleconference and be reachable 24/7 via email/contact form.

3. **ICM Vendor is financially stable**

* &#x20;ICM Vendor must have a positive net equity in the latest financial year.
* &#x20;The current ratio derived from the latest financial year (current assets divided by current liabilities) must be greater than or equal to 1.

4. **ICM Vendor has good track record with government agencies.**

* ICM Vendor must have satisfactory track record with government agencies.
* ICM Vendor is not suspended from being considered for pre-approval due to breaches or non-compliances.

5. **ICM Vendor has a fully operational professional website that provide details of the solution.**

* ICM Vendor must have a functional Website URL

### Solution Eligibility Criteria

1. **Solution has a proven track record of helping SMEs achieve an increase in productivity.**

* At least 5 SME customers have indicated achieving 15%\* or more productivity gain from using the solution.

  *\*Note: For Built Environment Sector, the productivity gain indicated must be at least 20%.*

2. **Solution is affordable for SME adoption.**

* At least 5 SME customers have indicated that they are satisfied with the ICM Vendor’s solution price.

3. **Solution must meet SMEs’ needs.**

* At least 5 SME customers have indicated that they are satisfied with quality of the ICM Vendor’s solution.
* Solution must satisfy all criteria in the relevant solution category requirements

{% hint style="warning" %}
FAQ

**Q: What if I cannot meet one or more of the onboarding or eligibility criteria?**

**A:** Please do not proceed with your application until all criteria are met. If you have specific concerns, you may submit them through our enquiry [form](https://go.gov.sg/pareginterest). You are strongly encouraged to reach out to us.&#x20;
{% endhint %}

{% hint style="success" %}
Interested to become a pre-approved vendor?

[Submit](https://go.gov.sg/pareginterest) your details to help us know you better. Select the "Tell us more about your company and solution" option.

Starting from 1st December 2025, we have launched a new [Vendor Management Portal ](https://services2.imda.gov.sg/VMP)for Pre-Approval Application.&#x20;
{% endhint %}


# Stage 1 Vendor Self-Assessment

This stage helps you determine whether your solution and company meet the pre-approval eligibility criteria. By completing this stage, you can evaluate your readiness.

#### [Conduct a self-assessment](https://go.gov.sg/vendselfassessment)

&#x20;Complete a self-assessment to check your eligibility for onboarding. During this process, you will need to[ identify a suitable solution category](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category)[.](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category) &#x20;

{% hint style="success" %}
Interested to become a pre-approved vendor?

[Submit](https://go.gov.sg/pareginterest) your details to help us know you better. Select the "Tell us more about your company and solution" option.

Starting from 1st December 2025, we have launched a new [Vendor Management Portal ](https://services2.imda.gov.sg/VMP)for Pre-Approval Application.&#x20;
{% endhint %}

{% hint style="warning" %}
FAQ

**Q: Is it mandatory to go through Stage 1 as part of the pre-approval process?**

**A:** No, Stage 1 is not mandatory if you already understand the eligibility criteria, have identified a solution category, and are confident that you can fulfil its requirements. You are strongly recommended to[ reach out to us](https://go.gov.sg/pareginterest) if you are keen to be pre-approved.&#x20;

***

**Q: What should I do if I cannot fulfil the requirements or I cannot locate a suitable solution category?**

**A:** You should not apply and should wait until you are able to fulfil the requirements before applying. Alternatively, you are welcome to[ reach out to us](https://go.gov.sg/pareginterest) to discuss further.

***

**Q: What should I do if I cannot locate a suitable solution category?**

**A:** If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Conduct Self-Assessment

Learn how to conduct a self-assessment

{% stepper %}
{% step %}
If you are seeking a pre-approval appointment, please complete this self-assessment to evaluate your vendor and solution eligibility.

**Option 1:** **Solution Category Recommender**

This tool evaluates your readiness to join the Pre-Approval\@SMEsGoDigital Programme and helps you identify the appropriate solution category for your business. Please note that this tool is currently in beta testing, and your feedback during this trial phase will help us improve its functionality and user experience.

{% embed url="<https://go.gov.sg/vendselfassessment>" %}

**Option 2: Self-assessment FormSG**

{% embed url="<https://form.gov.sg/6840edbd36673ed8f32a15a9>" %}

Complete our straightforward self-check questionnaire to assess your business's readiness for the Pre-Approval\@SMEsGoDigital Programme without receiving any solution category recommendations.
{% endstep %}

{% step %}
[Identify suitable solution category](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category)

You will locate the most suitable solution category for the to-be approved solution by identifying the target sector, followed by reviewing if the solution meets the list of solution requirements.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
FAQ

**Q: What if I cannot meet one or more of the onboarding or eligibility criteria?**

**A:** Please do not proceed with your application until all criteria are met. If you have specific concerns, you may submit them through our enquiry [form](https://go.gov.sg/pareginterest). You are strongly encouraged to reach out to us.&#x20;
{% endhint %}

{% hint style="success" %}
Interested to become a pre-approved vendor?

[Submit](https://go.gov.sg/pareginterest) your details to help us know you better. Select the "Tell us more about your company and solution" option.

Starting from 1st December 2025, we have launched a new [Vendor Management Portal ](https://services2.imda.gov.sg/VMP)for Pre-Approval Application.&#x20;
{% endhint %}


# Identify suitable solution category

To ensure that you can fulfill the solution eligibility criteria "Solution must meet SMEs’ needs", please perform these steps below.

{% stepper %}
{% step %}

### Select your target sector from List of Sectors

First, identify your target sector. Then, locate the most suitable category for your solution
{% endstep %}

{% step %}

### Review the list of requirements&#x20;

After locating the solution category and sector that best fit your requirement, review the mandatory/preferred requirements of the selected solution category
{% endstep %}

{% step %}

### Ensure that your 5 reference customer meets the [satisfied customer requirement](/pre-approval-guide/stage-1-vendor-self-assessment/requirements-of-satisfied-customer)

Each sector has different requirements for 5 reference customers business activity. Read [more](/pre-approval-guide/stage-1-vendor-self-assessment/requirements-of-satisfied-customer) to understand how to fulfil this requirement.&#x20;
{% endstep %}
{% endstepper %}

## List of Sectors - Explore Solution Categories by Sector

<details>

<summary>Latest Updates of Solution Categories</summary>

* \[UPDATED 24-Jul-2026] - Essential Business - iERP has been launched!
* \[UPDATED 18-Mar-2026] - Essential Business - Gen-AI Digital Training System has been launched!
* \[UPDATED 06-Mar-2026] - Early Childhood - Vacancy and Waitlist Management has been launched!
* \[UPDATED 25-Feb-2026] Essential Business - Automated Order Management and E-Commerce Cross Border Packages has been introduced, ASR+ Accreditation for Accounting, Sales & Inventory and Accounting and Sales is no longer required.
* \[UPDATED 26-Dec-2025!] All Accountancy and Tourism(Hotel)Checklist have been removed.
* \[UPDATED 15-Dec-2025!] Essential Business Checklist Category, Carbon Accounting has been revised. Built Environment Checklist Category, FM Workflow Automation and Smart Inspection and Management – Digital Wearables for Workers' Health and Safety have been removed.&#x20;
* \[UPDATED 29-Aug-2025!] Essential Business Checklist Category 21,  AI Accounting Automation and Hotel Checklist Category 1, Digital Concierge have been added, Healthcare checklist has been removed.

</details>

<details>

<summary>💼🛡️Applicable to all sectors</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/Bb9oo7zwemGx6yOzKc10">/pages/Bb9oo7zwemGx6yOzKc10</a></td><td><p>Essential Business Sector represent digital solutions across four business functions: </p><ul><li>Human Capital Management</li><li>Customer Management &#x26; Marketing</li><li>Sales &#x26; Operations, and </li><li>Specialised Solutions. </li></ul></td><td><a href="/files/tHuzutc7Pu3QWRe6Psyh">/files/tHuzutc7Pu3QWRe6Psyh</a></td><td><strong>Checklist Version:</strong> 25-3.1</td><td><strong>Published on:</strong> 26 September 2025</td></tr><tr><td><a href="/pages/sFLNQWNQZokHpWgNyYbP">/pages/sFLNQWNQZokHpWgNyYbP</a></td><td><p>Cybersecurity solutions protect SMEs' digital assets and data across four key areas:</p><ul><li>Virus/Malware Protection</li><li>Firewall Security</li><li>Backup Systems</li><li>Integrated Security Suites </li></ul></td><td><a href="/files/LZ5PUqPsWGnXWKIPSQKG">/files/LZ5PUqPsWGnXWKIPSQKG</a></td><td><strong>Checklist Version:</strong> 25-2.0</td><td><strong>Published on:</strong> 01 May 2025</td></tr></tbody></table>

</details>

<details>

<summary>⚖️ Modern Services</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/dl2raQ20mI7ajbiO30UW">/pages/dl2raQ20mI7ajbiO30UW</a></td><td><p>Legal solutions encompass digital tools to help law firms streamline operations across four key areas:</p><ul><li>Practice and Document Management</li><li>Legal Research and Analysis</li><li>Compliance and Risk Management</li><li>Legal Support Tools</li></ul></td><td><a href="/files/t5NRLCK3wwMxxJdOqHas">/files/t5NRLCK3wwMxxJdOqHas</a></td><td><p><strong>Checklist Version:</strong> 25-3.0</p><p><strong>Published on:</strong> 31 July 2025</p></td></tr></tbody></table>

</details>

<details>

<summary>🍽️🛍️💅🎡🛏️Lifestyle</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/ZcO57OATaa66MHU3eyRB">/pages/ZcO57OATaa66MHU3eyRB</a></td><td><p>Food Services solutions provide digital tools to enhance F&#x26;B operations across key areas:</p><ul><li>Connected Business Suite</li></ul></td><td><a href="/files/Gv1jPkepLzFnVSTnd2PT">/files/Gv1jPkepLzFnVSTnd2PT</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr><tr><td><a href="/pages/JT2TEE8YfVqVEBg9FVGg">/pages/JT2TEE8YfVqVEBg9FVGg</a></td><td><p>Personal Care Services solutions provide digital tools to enhance salon operations across key areas:</p><ul><li>Salon Management System</li></ul></td><td><a href="/files/ljZMp25NCqJ4GOhqOwMQ">/files/ljZMp25NCqJ4GOhqOwMQ</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr><tr><td><a href="/pages/cQkujr4HAi8AZQFzW2jr">/pages/cQkujr4HAi8AZQFzW2jr</a></td><td><p>Retail solutions provide digital tools to enhance store operations across four key areas:</p><ul><li>Point-of-Sale Systems</li><li>Store Management</li><li>Digital Commerce</li></ul></td><td><a href="/files/uSrCBvydmPHvwLuu6BqN">/files/uSrCBvydmPHvwLuu6BqN</a></td><td><p><strong>Checklist Version:</strong> 25-3.0</p><p><strong>Published on:</strong> 26 September 2025</p></td></tr><tr><td><a href="/pages/pmR1IJ2snEmxDNWwaArn">/pages/pmR1IJ2snEmxDNWwaArn</a></td><td><p>Tourism solutions provide digital tools to enhance travel operations across key areas:</p><ul><li>Business Operations</li><li>Customer Service</li><li>Analytics &#x26; Processing</li></ul></td><td><a href="/files/Z7M6jG3lfPv7isI6M5Bu">/files/Z7M6jG3lfPv7isI6M5Bu</a></td><td><p><strong>Checklist Version:</strong> 25-32.0</p><p><strong>Published on:</strong> 26 September 2025</p></td></tr><tr><td><a href="/pages/1KP1SGuIsMCCdzpY6T73">/pages/1KP1SGuIsMCCdzpY6T73</a></td><td><p>Hotel solutions provide digitalise tools to enhance guest services operations across key areas:</p><ul><li>virtual concierge platforms</li></ul></td><td></td><td></td></tr><tr><td></td><td></td><td></td><td></td></tr></tbody></table>

</details>

<details>

<summary>🏗️🏢👮Built Environment</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/bqFZnZFZBo2NXP7EqNYy">/pages/bqFZnZFZBo2NXP7EqNYy</a></td><td><p>Built Environment solutions provide digital tools to enhance construction and facility management across four key areas:</p><ul><li>Design and Visualisation</li><li>Project Management</li><li>Safety and Inspection</li><li>Facility Management</li></ul></td><td><a href="/files/0gYQ4754iNBvIGvHA45H">/files/0gYQ4754iNBvIGvHA45H</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr><tr><td><a href="/pages/sJ1mn2qowyEI8NRCpDjJ">/pages/sJ1mn2qowyEI8NRCpDjJ</a></td><td><p>Estate Agency solutions provide digital tools to enhance property transaction management across key areas:</p><p></p><ul><li>Transaction Records</li></ul><p></p></td><td><a href="/files/Vs0KHcR0S7eMAlyC1QBK">/files/Vs0KHcR0S7eMAlyC1QBK</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr><tr><td><a href="/pages/u1nol9KhNTe2q1xtRUt7">/pages/u1nol9KhNTe2q1xtRUt7</a></td><td><p>Security solutions provide digital tools to enhance security operations across key areas:</p><ul><li>Operations Management</li><li>Access Control</li><li>Surveillance &#x26; Automation </li></ul></td><td><a href="/files/jUO5BSJhQxBTRFAyljXC">/files/jUO5BSJhQxBTRFAyljXC</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr></tbody></table>

</details>

<details>

<summary>👶Essential Domestic Services</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/vA6ci28B1cRvn583FqRc">/pages/vA6ci28B1cRvn583FqRc</a></td><td><p>Pre-School solutions provide digital tools to enhance early childhood education operations across key areas:</p><ul><li>Centre Administration</li><li>Analytics &#x26; Insights</li><li>Professional Development</li><li>Safety &#x26; Security</li></ul></td><td><a href="/files/yOf7h8wRfTHV56b9eYFE">/files/yOf7h8wRfTHV56b9eYFE</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr></tbody></table>

</details>

<details>

<summary>🏭🛠️🚢Manufacturing</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/HBR3xwtpn0dNenu3EoVI">/pages/HBR3xwtpn0dNenu3EoVI</a></td><td><p>Advanced Manufacturing solutions provide digital tools to enhance production operations across key areas:</p><ul><li>Production Management</li><li>Design &#x26; Engineering</li></ul></td><td><a href="/files/YqY39UCbFHu0JpN33i8S">/files/YqY39UCbFHu0JpN33i8S</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr></tbody></table>

</details>

<details>

<summary>🚚📦Trade and Connectivity</summary>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden></th></tr></thead><tbody><tr><td><a href="/pages/mlUK5EWmzPYL3I2qT3uN">/pages/mlUK5EWmzPYL3I2qT3uN</a></td><td><p>Logistics solutions provide digital tools to enhance supply chain operations across key areas:</p><ul><li>Trade Services</li><li>Warehouse Operations</li><li>Transport Operations</li></ul></td><td><a href="/files/XTwYkRzSRofRyRRx4h8Q">/files/XTwYkRzSRofRyRRx4h8Q</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr><tr><td><a href="/pages/ca6PgljVIN93a0ZxjYHb">/pages/ca6PgljVIN93a0ZxjYHb</a></td><td><p>Wholesale solutions provide digital tools to enhance distribution operations across key areas:</p><ul><li>Operations Management</li><li>Supply Chain</li></ul></td><td><a href="/files/3sRQ1tTRNOqZv0YoNhbz">/files/3sRQ1tTRNOqZv0YoNhbz</a></td><td><p><strong>Checklist Version:</strong> 25-2.0</p><p><strong>Published on:</strong> 01 May 2025</p></td></tr></tbody></table>

</details>

***

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}

Alternatively, you can also browse through this long list of solution categories by sector.&#x20;

**Pre-Approved Solution Category Directory**

1. **💼Sector: Essential Business**

a) [Human Resources Management System (HRMS)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/human-resource-management-system-hrms)

Manage a company's employee records in all the key HR administrative areas such as Personnel management, payroll, leave, employee benefits, employee claims and appraisal.

b) [Human Resource E-scheduling System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/human-resource-e-scheduling-system)

Track overall scheduling of employees, generate attendance and overtime reports and push notifications to employees on their work shifts.

c) [Human Resource Shared Services (HRSS) Needs Analysis + HR Administrative Support & Payroll Processing via HRMS](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/human-resource-shared-services-hrss-needs-analysis-+-hr-administrative-support-and-payroll-processin)

Review a company's internal HR process, offer a HRMS system and provide HR Administrative and payroll processing support such as issuing payslips, ePayment of Salaries, leave, attendance and claims.

d) [Employee Rewards and Recognition](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/employee-rewards-and-recognition)

Enable companies to reward employees for the purpose of appreciation and positive incentivisation, in a streamlined manner through the issuance and redemption of rewards from a wide merchant network on a single platform, that also allows employers to share words of appreciation, and track the rewards budget.

e) [Applicant Tracking & Sourcing System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/applicant-tracking-and-sourcing-system)

Help companies organise candidates for hiring and recruitment purposes. These systems allow businesses to collect information, organise prospects based on experience and skill set, and filter applicants. While these systems are excellent for storing candidate information, the best systems can track all communications with candidates.

f) [Customer Relationship Management (CRM)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/customer-relationship-management-crm)

Capture customer and prospect information, identify sales leads, generate sales funnel and manage marketing campaigns. This solution must cater to the sales needs of the entire business operations. Solution must be usable by a wide segment of SMEs, and not specific to SMEs in a specific industry/sector.

g) [E-loyalty & Marketing Automation](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/e-loyalty-and-marketing-automation)

Manage their customers through membership and loyalty program. Companies may set up campaigns or event-based marketing, and promotions. The e-loyalty CRM solution offers loyalty rewards, discounts, and other special incentives designed to reward customer's repeat business.

h) [E-Commerce - Online Shop (B2C)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/e-commerce-online-shop-b2c)

Provide businesses with secure online storefronts to sell products and services directly to consumers. The system includes secure payment processing, inventory management, and user-friendly interfaces for product listings, enabling businesses to establish and manage their digital retail presence.

i) [Inventory Management and Sales Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/inventory-management-and-sales-management-system)

Integrate product tracking, pricing, and transaction processing. The system manages inventory through RFID/barcode scanning, handles sales documentation, enables price group creation, and generates business reports, while seamlessly connecting with POS systems.

j) [Accounting Management and Sales Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/accounting-management-+-sales-management-system)

Streamline financial operations by integrating accounting processes and sales activities. The system manages general ledger, journal entries, tax calculations, cash flow tracking, and generates comprehensive financial reports alongside sales documentation and purchase orders.

k) [Accounting Management, Inventory Management and Sales Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/accounting-management-+-inventory-management-+-sales-management-system)

Provide comprehensive business control by integrating accounting, inventory and sales operations in a unified platform. The system combines financial management, inventory tracking with RFID/barcode capabilities, and sales processing, while offering detailed reporting and POS integration.

l) [Fleet Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/fleet-management-system)

Combine telematics and GPS technology to monitor vehicle locations and performance in real-time. The system provides comprehensive fleet visibility, tracking vehicle conditions, optimising routes, and enabling data-driven fleet maintenance and operational decisions.

m) [Fleet Safety Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/fleet-safety-management-system)

Enhance vehicle safety through advanced monitoring technologies. The system incorporates driver status monitoring, blind spot detection, and/or driver assistance features to prevent accidents, improve driver behaviour, and ensure safer fleet operations.

n) [Digital Marketing Packages](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/digital-marketing-packages)

Combine various vendor-provided marketing services including Search Engine Optimisation (SEO), Search Engine Marketing (SEM), and Social Media Marketing to enhance brand visibility, drive website traffic, and boost revenue generation through targeted digital campaigns.

o) [Document Management and Mobile Access System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/document-management-and-mobile-access-system)

Enable secure cloud-based file storage and synchronisation across devices. The system provides document access control, search functionality, version tracking, and automated backups while ensuring secure mobile access to business files.

p) [Multichannel E-commerce Software (MES)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/multichannel-e-commerce-software-mes)

Centralise management of multiple online sales channels through a single interface. The system synchronises inventory, orders, and listings across various marketplaces and webstores in real-time, while providing analytics dashboard for comprehensive sales performance monitoring.

q)[ Chatbots for Customer Engagement](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/chatbots-for-customer-engagement)

Automate customer interactions through AI-powered digital assistants. The system handles customer enquiries, provides personalised recommendations, collects feedback, and manages lead generation, enabling 24/7 customer engagement while streamlining sales conversions and service improvement.

r) [Marketing and Sales Content Generation](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/marketing-and-sales-content-generation)

Leverage AI to create customised marketing materials by automating creation of social media posts, advertisements, emails, and images, while providing campaign ideation support and market insights to enhance marketing effectiveness and sales strategies.

s) [Carbon Management Solution](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/carbon-management-solution)

Track and measure an organisation's greenhouse gas emissions from direct and indirect business activities by calculating carbon footprint using recognised emissions factors, enabling businesses to monitor, report, and manage their environmental impact effectively.

t) [Field service management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/field-service-management)

Optimise mobile workforce operations by coordinating technician scheduling, work order tracking, and customer communications. The system streamlines maintenance and repair services, enabling efficient dispatch, real-time job status updates, and service delivery management.

u) [AI Accounting Automation](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/ai-accounting-automation)

Enables companies to automate key accounting processes such as data extraction, data entry, categorisation, and reconciliation. The solution integrates with popular accounting systems to ensure seamless data flow, and features self-learning capabilities that allow it to improve over time based on user input.

v) [Automated Order Management ](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/automated-order-management)

Enables seamless customer order capturing and fulfillment via various mobile messaging platforms by automatically capturing and converting natural language text and/or voice orders directly into digital sales orders and automatically keeping customers updated on their orders.

w) [Cross Border E-Commerce Packages](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/cross-border-e-commerce-packages)

Provide third-party services to set up a presence on overseas online B2B or B2C marketplaces, handle the end-to-end e-commerce operations such as order management and customer service, and provide business advisory to the SMEs.

x) [Gen-AI Digital Training System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/gen-ai-digital-training-system)

Digitise staff training processes using Generative AI to convert company SOPs, guidelines, and procedures into automated training content, addressing the time-consuming nature of in-person training especially in high-turnover sectors. This ensures consistent, standardized training delivery across all locations while reducing manual effort during HR onboarding.

y) [iERP](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/essential-business/ierp)

Enables businesses to manage and integrate core operations through a unified platform. The solution connects key business functions — including finance, HR, sales, supply chain, manufacturing, and more - ensuring seamless data flow across modules, streamlining workflows, and supporting informed decision-making for the adopting organisation.

2. 🛡️**Sector: Cybersecurity**

a) [Secure/Protect - Virus/Malware Protection](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/cybersecurity/secure-protect-virus-malware-protection)

Safeguard computer systems, networks, and devices from malicious software threats such as viruses, worms, Trojans, ransomware, spyware, and other forms of malware. These solutions play a critical role in maintaining the security and integrity of digital assets, preventing unauthorized access, data breaches and system disruptions. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

b) [Secure/Protect - Firewall](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/cybersecurity/secure-protect-firewall)

Monitor and control incoming and outgoing network traffic based on predetermined security rules. Such solutions may be host-based, or network-based, and serve as a gatekeeper between trusted internal networks and untrusted external networks, effectively managing and filtering network communications to prevent unauthorized access and protect against cyber threats. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

c) [Backup](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/cybersecurity/backup)

Create and maintain copies of data to ensure its availability in the event of data loss, corruption or system failures. The solutions play a critical role in data protection, disaster recovery and business continuity by enabling the restoration of critical information and resources. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

d) [Integrated anti-malware, firewall and backup](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/cybersecurity/integrated-anti-malware-firewall-and-backup)

Integrated package of cybersecurity solutions including anti-malware, firewall and backup solutions to support organisations in addressing a subset of the requirements in CSA Cyber Essentials mark.

3. 🏭**Sector: Advanced Manufacturing**

a) [Real-time Production Scheduling and Job Tracking](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/real-time-production-scheduling-and-job-tracking)

Facilitate project management and resource planning, including the planning and coordination of the materials and equipment usage; track and display real-time work completion status, based on data collected from shopfloor.

b) [Equipment Monitoring and Manufacturing Data Collection](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/equipment-monitoring-and-manufacturing-data-collection)

Provide real-time visibility on the performance and status of machines to enable scheduling of maintenance.

c) [Manufacturing Quality Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/manufacturing-quality-management)

Allow defining quality checks and collection of quality data; trigger alarms when out-of-specifications and highlight issues; record causes and actions when problem arises, contributes to data analytics.

d) [Product and Manufacturing Process Configuration](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/product-and-manufacturing-process-configuration)

Provide source of information on the sequence of processes, and the technical drawing of components and materials, and this solution includes information on tools, equipment, manpower and instructions used in each process; manage revision to product design, and allow manufacturing process changes and configuration.

3\) [Machining Dynamics for Milling/Turning](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/machining-dynamics-for-milling-turning)

Optimise milling and turning operations through advanced computational modelling and sensor technology. The system analyses tool performance, monitors machining processes, and enhances surface quality using real-time diagnostics and 3D metrology for improved manufacturing precision.

f) [Computer-aided design & Computer-aided manufacturing (CAD/CAM)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/advanced-manufacturing/computer-aided-design-and-computer-aided-manufacturing-cad-cam)

Integrate design and manufacturing processes through unified software. The system converts CAD models into machine toolpaths, enabling direct translation of digital designs into manufacturing instructions for efficient and precise production of physical parts.

4. 🏗️**Sector: Built Environment**

a) [3D Modeling, Immersive Visualisation & Analysis](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/3d-modeling-immersive-visualisation-and-analysis)

Enable creation of detailed digital building models from concept to completion by supporting CORENET X submissions, facilitate immersive design validation, and perform simulations to analyse building performance. Features include virtual walkthroughs and environmental impact assessments.

b) [Digital Contract Management - Digital Payment](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/digital-contract-management-digital-payment)

Streamline payment processes by automating work verification against contract milestones and ensuring accurate tracking of deliverables, facilitates timely payment approvals, and maintains healthy project cash flow through digital documentation and verification workflows.

c) [Quantity Surveying and Valuation](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/quantity-surveying-and-valuation)

Leverage digital building models to automate quantity takeoffs and cost estimations throughout construction phases by proving accurate measurements and cost calculations, enabling efficient project budgeting and financial planning.

d) [Smart Inspection and Management - Worksite Inspection](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/smart-inspection-and-management)

Digitise worksite inspections through mobile apps and 3D imaging technology enabling real-time recording of site observations, automated documentation, and creation of digital twins for remote verification, while tracking corrective actions and compliance requirements.

e) [Smart Inspection and Management - e-Permit-to-work (e-PTW)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/smart-inspection-and-management-e-permit-to-work-e-ptw)

Digitise the permit application and approval process for construction activities and streamlines safety documentation, automates workflow approvals, and maintains digital records of work permits, ensuring compliance and efficient site safety management.

f) [Coordinated Regulatory Approvals and Rule-Based Model Checker](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/coordinated-regulatory-approvals-and-rule-based-model-checker)

Automate building code compliance verification through intelligent BIM model checking. The system performs automated quality assessments and regulatory compliance checks, streamlining the approval process and ensuring designs meet building code requirements before submission.

g) [Data and AI-driven Decision Support System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/data-and-ai-driven-decision-support-system)

Leverage analytics and machine learning to enhance construction project management. The system provides real-time dashboards monitoring cost, time, safety, quality, and productivity metrics, enabling data-driven decisions based on stakeholder-contributed information.

h) [Built Environment Digital Platform](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/built-environment/built-environment-digital-platform)

Provide a comprehensive project management ecosystem which integrates communication, carbon emissions tracking, approvals workflow, engineering collaboration, performance monitoring, defect management, safety compliance, and data sharing across stakeholders throughout the building lifecycle.

5. 👶**Sector: Early Childhood**

a) [Pre-School Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/pre-school-management-system)

Multi-functional system that streamlines preschool operations and administration (e.g. Finance Management, Staff and Child Records Keeping, Waitlist and Vacancy Matters).

b) [e-Forms for Pre-school](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/e-forms-for-pre-school)

Allow creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.

c) [Pre-School Management System + e-Forms for Pre-school](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/pre-school-management-system-+-e-forms-for-pre-school)

Provide the maintenance of pre-school centre operation and Finance management and allows creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.

d) [Data Mining & Analytics (Centre Operations)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/data-mining-and-analytics-centre-operations)

Help preschool operators analyse daily operational data. The system provides insights into parent preferences, predicts student dropout rates, and enables family profiling, supporting data-driven decisions for improved business management.

e) [Data Mining & Analytics (Child Development)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/data-mining-and-analytics-child-development)

Transform educational data into intuitive dashboards for tracking children's progress by enabling educators to monitor developmental milestones against benchmarks, evaluate teaching effectiveness, and efficiently assess individual learning outcomes through visual analytics.

f) [Data Mining & Analytics (Centre Operations and Child Development)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/data-mining-and-analytics-centre-operations-and-child-development)

Combine operational and developmental data analysis by using AI to optimise centre management and service quality while monitoring children's progress, providing data-driven recommendations for both business operations and individualised child development needs.

g) [Talent Attraction Platform](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/talent-attraction-platform)

Attract potential teachers to join the industry by leveraging digital platforms that are integrated with ECDA's systems.

h) [Learning Platform for CPD and Mentoring](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/learning-platform-for-cpd-and-mentoring)

Provide personalised professional development for early childhood educators and intervention specialists. The system delivers customised training content and mentoring support, enabling continuous professional growth and skill enhancement for teaching staff.

i) [Video Analytics for Preschool Safety](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/video-analytics-for-preschool-safety)

Equip surveillance systems with video analytics, centre leaders can receive alerts on potential risks or hazards, such as children who are left on their own without adult supervision in classrooms and intrusion. Preschool operators may also leverage data collected to identify areas for improvement in centre operations for enhanced safety and security measures.

j)[ Vacancy and Waitlist Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/early-childhood/vacancy-and-waitlist-management)

The solution streamlines real-time vacancy tracking, waitlist management, and enrolment allocation while generating capacity reports and\
threshold alerts.

6. 🏢**Sector: Estate Agency**

a) [Document Management & Transaction Records Submission for Estate Agents](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/estate-agency/document-management-and-transaction-records-submission-for-estate-agents)

Help estate agents and real estate salespersons to manage property transaction-related documents and submit transaction records to the Council for Estate Agencies (CEA) efficiently.

7. 🍽️**Sector: Food Services**

a) [Connected Business Suite](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/food-services/connected-business-suite)

Integrate front and back-of-house operations for F\&B businesses by unifying point-of-sale, kitchen management, inventory, and supplier management functions, enabling seamless coordination across the entire F\&B value chain.🛏️

8. ⚖️**Sector: Legal**

a) [P](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/practice-management-system-pms)[ractice Management System (PMS)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/practice-management-system-pms)

Integrate and automate various administrative, operational, client-related tasks, including billing, accounting, invoicing, time tracking and client contacts.

b) [Document Management System (DMS)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/document-management-system-dms)

Store, organise, and manage legal documents of various formats that can be accessed and shared securely with intended parties. Features include version control and audit trail.

c) [Matters Management and Collaboration Tool](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/matters-management-and-collaboration-tool)

Consolidate all documents and matter correspondences, including documents, emails, and notes, across different communication channels from both internal and external sources, into a single channel for correspondence.

d) [Online Legal Research System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/online-legal-research-system)

Provide law practices with access to legal research materials, precedents, legal opinions, journals, legislation, and other legal materials that they may harness.

e) [Document Assembly Software](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/document-assembly-software)

Streamline the process of creating complex documents by using pre-existing templates and clauses, to auto-generate documents such as contracts, agreements, legal forms, proposals, and reports.

f) [Document Review Software](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/document-review-software)

Enable law practices to manage, search, and review large volumes of electronic documents with advanced search and analytics features (e.g. concept searching, email threading, and anomaly discovery).

g) [eDiscovery Tool](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/ediscovery-tool)

Scan and analyse large volumes of electronic data, such as emails, documents, databases and more, to identify information relevant to a case or contract via intelligent search functions.

h)[ Legal Chatbot](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/legal-chatbot)

Provide basic legal information, compile information on the client's queries, and automate conversations with clients using natural language. This tool facilitates the collection of client data, arrangement of client appointments, and generate emails using information captured in conversations.

i) [Risk Assessment Solution (KYC/AML)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/risk-assessment-solution-kyc-aml)

Automate the compliance processes, perform ongoing due diligence, and enable law practices to comply with regulations related to KYC (Know Your Customer) /AML (Anti-Money Laundering) / CFT (Combating the Financing of Terrorism).

j)[ Evidence Management Platform](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/evidence-management-platform)

Concentrate evidence and court documents into a single hub, create an audit trail that tracks and records changes in court documents.

k) [Speech Transcription for Legal Matters](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/speech-transcription-for-legal-matters)

Transcribe speeches that include legal terms and lexicons which allow for creation of accurate timely records and references. May include sentiment analysis features to classify sentiments of the transcribed speeches.

l) [Translation Software](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/legal/translation-software)

Enable law practices to translate legal documents and other materials easily

9. 🚚**Sector: Logistics**

a) [Networked Trade Platform Value Added Services](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/networked-trade-platform-value-added-services)

Connect the trade and logistics communities for trade-related applications.

b) [Inventory Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/inventory-management)

Control and administer the movement of inventory, with real time data.

c) [Warehouse Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/warehouse-management)

Control and track the transfer and storage of materials in a warehouse. The system supports processes needed in the shipping and receiving of goods.

d) [Active Cold Chain Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/active-cold-chain-management)

Use digital sensors to monitor environmental conditions in warehouses by tracking and transmiting real-time temperature and humidity data, ensuring proper storage conditions and maintaining cold chain integrity for sensitive goods.

e) [Transport Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/transport-management)

Enable real-time visibility of the whereabouts of vehicles.

f) [Freight Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/logistics/freight-management)

Digitalise information flow in freight forwarding operations that can encompass import and export shipments over air, sea and land.

10. 💅**Sector: Personal Care Services**

a) [Salon Management System](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/personal-care-services/salon-management-system)

Streamline beauty and spa operations by integrating appointment scheduling, booking management, sales tracking, marketing campaigns, customer relationship management, and HR functions in one platform for efficient business administration.

11. 🛍️**Sector: Retail**

a) [Integrated POS (with mobile features)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/retail/integrated-pos-with-mobile-features)

Enable mobile transaction processing through portable devices by connecting point-of-sale operations with backend CRM and inventory management, allowing staff to complete sales anywhere in-store while maintaining real-time synchronisation with business systems.

b) [Electronic Shelf Label (ESL)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/retail/electronic-shelf-label-esl)

Automate price display through digital tags by enabling real-time updates of product pricing and information across store shelves, ensuring pricing accuracy and reducing manual labour while enabling dynamic price management.

c) [Self Checkout Solution](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/retail/self-checkout-solution)

Enable customers to independently scan and pay for purchases by streamlining the retail checkout process through automated scanning, payment processing, and security features, reducing queues and improving shopping convenience.

d) [In-Store Analytics](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/retail/in-store-analytics)

Use video technology and IoT sensors to gather retail intelligence by analysing customer behaviour, traffic patterns, and store performance metrics, providing actionable insights for optimising store layout, staffing, and merchandising decisions.

e) [Omnichannel Retail Management (OCRM)](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/retail/omnichannel-retail-management-ocrm)

Allows a retailer to deliver a seamless shopping experience across various customer touchpoints, and to have real-time product and inventory visibility, reducing stocking issues.

12. 👮**Sector: Security**

a) [Mobile-Enabled Patrol and Incident Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/security/mobile-enabled-patrol-and-incident-management)

Streamline patrol operations through real-time tracking and reporting and manage guard assignments, patrol routes, and incident documentation while enabling instant communication and digital reporting through mobile devices.

b) [Automated Visitor Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/security/automated-visitor-management)

Control facility access through digital registration by processing visitors using optional features like biometrics, car plate recognition, and integrating access control features, ensuring secure entry management while streamlining the check-in process.

c) [Onsite Surveillance and Analytics](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/security/surveillance-and-analytics)

Combine IP cameras with intelligent monitoring capabilities. The system uses video analytics to automatically detect security incidents, enhance surveillance coverage, and provide real-time alerts for improved site security management.

d) [Security Collaboration Platform](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/security/security-collaboration-platform)

Integrate multiple security systems into one unified interface by connecting visitor management, incident tracking, and video surveillance, enabling centralised monitoring, intelligent response coordination, and streamlined security operations management.

13. 🎡**Sector: Tourism(Travel Agent)**

a) [Travel Management System ](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/tourism-travel-agent/travel-management-system)

An integrated platform that connects back-office operations with customer-facing workflows, the solution enables travel agencies to manage suppliers, pricing, quotations, bookings, inventory, and content.&#x20;

b) [Travel e-Visa](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/tourism-travel-agent/travel-evisa)

Automate visa application processing through cloud-based technology by extracting passport data, integrating with ICA submissions, and providing real-time application tracking, enabling efficient visa processing across mobile and web platforms.

14. 🛌 **Sector: Tourism(Hotel)**

a)  [Digital Concierge](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/tourism-hotel/digital-concierge)

Provides guests with 24/7 virtual assistance for hotel requests, bookings, and information through their mobile, web, or messaging platforms in multiple languages. Digital Concierge streamlines hotel operations with task management, real-time staff notifications, and performance tracking while integrating seamlessly with existing hotel systems.

15. 📦 **Sector: Wholesale**

a) [Enterprise Resource Planning (ERP) Software for Wholesale](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/wholesale/enterprise-resource-planning-erp-software-for-wholesale)

Integrate core business functions by automating production planning, sales quotation, accounting, and other operational processes, enabling streamlined management of wholesale business activities.

b) [Sales Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/wholesale/sales-management)

Manage customers, sales orders, products and pricing information.

c) [Inventory Management](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/wholesale/inventory-management)

Manage inventory within a warehouse - receiving, putaway, picking, packing, stocktake and movement of products.

d) [Custom Clearance](/pre-approval-guide/stage-1-vendor-self-assessment/identify-suitable-solution-category/wholesale/custom-clearance)

Manage the customs clearance process in compliance with regulations.


# Essential Business

These solutions are applicable to all industries.

These pre-approved digital solutions are specifically curated for broad-based SME adoption, designed to help small and medium enterprises digitalise their operations efficiently and cost-effectively.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**iERP**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/cQOUDb7jDnX7iTX7bUuY">/pages/cQOUDb7jDnX7iTX7bUuY</a></td><td>Enables businesses to manage and integrate core operations through a unified platform. The solution connects key business functions — including finance, HR, sales, supply chain, manufacturing, and more - ensuring seamless data flow across modules, streamlining workflows, and supporting informed decision-making for the adopting organisation.</td></tr></tbody></table>

**Human Capital Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/1yJiC2CceQGTcMoFbHrY">/pages/1yJiC2CceQGTcMoFbHrY</a></td><td>Manage a company’s employee records in all the key HR administrative areas such as Personnel management, payroll, leave, employee benefits, employee claims and appraisal.</td></tr><tr><td><a href="/pages/Xe75nzyU6DeUwDqM8Z7A">/pages/Xe75nzyU6DeUwDqM8Z7A</a></td><td>Track overall scheduling of employees, generate attendance and overtime reports and push notifications to employees on their work shifts.</td></tr><tr><td><a href="/pages/DmDoLFW9PSOQrdhFhSiF">/pages/DmDoLFW9PSOQrdhFhSiF</a></td><td>Review a company’s internal HR process, offer a HRMS system and provide HR Administrative and payroll processing support such as issuing payslips, ePayment of Salaries, leave, attendance and claims.</td></tr><tr><td><a href="/pages/4SReU1j5JjWJoSykCyAo">/pages/4SReU1j5JjWJoSykCyAo</a></td><td>Enable companies to reward employees for the purpose of appreciation and positive incentivisation, in a streamlined manner through the issuance and redemption of rewards from a wide merchant network on a single platform, that also allows employers to share words of appreciation, and track the rewards budget.</td></tr><tr><td><a href="/pages/YhdDJ1JawgTTayyfYJ3P">/pages/YhdDJ1JawgTTayyfYJ3P</a></td><td>Help companies organise candidates for hiring and recruitment purposes. These systems allow businesses to collect information, organise prospects based on experience and skill set, and filter applicants. While these systems are excellent for storing candidate information, the best systems can track all communications with candidates.</td></tr></tbody></table>

**Customer Management & Marketing**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/E50FKZPaFx7RVBJASKjU">/pages/E50FKZPaFx7RVBJASKjU</a></td><td>Capture customer and prospect information, identify sales leads, generate sales funnel and manage marketing campaigns. This solution must cater to the sales needs of the entire business operations. Solution must be usable by a wide segment of SMEs, and not specific to SMEs in a specific industry/sector.</td></tr><tr><td><a href="/pages/10rtiNqxysCzYO3kGeMR">/pages/10rtiNqxysCzYO3kGeMR</a></td><td>Manage their customers through membership and loyalty program. Companies may set up campaigns or event-based marketing, and promotions. The e-loyalty CRM solution offers loyalty rewards, discounts, and other special incentives designed to reward customer's repeat business.</td></tr><tr><td><a href="/pages/of6hntQpQ6CBw5dJQpbS">/pages/of6hntQpQ6CBw5dJQpbS</a></td><td>Automate customer interactions through AI-powered digital assistants. The system handles customer enquiries, provides personalised recommendations, collects feedback, and manages lead generation, enabling 24/7 customer engagement while streamlining sales conversions and service improvement.</td></tr><tr><td><a href="/pages/1W4TnAZ2GtRBhREcSddt">/pages/1W4TnAZ2GtRBhREcSddt</a></td><td>Leverage AI to create customised marketing materials by automating creation of social media posts, advertisements, emails, and images, while providing campaign ideation support and market insights to enhance marketing effectiveness and sales strategies.</td></tr><tr><td><a href="/pages/YLdFP9rlRdeHOHuZ8t01">/pages/YLdFP9rlRdeHOHuZ8t01</a></td><td>Combine various vendor-provided marketing services including Search Engine Optimisation (SEO), Search Engine Marketing (SEM), and Social Media Marketing to enhance brand visibility, drive website traffic, and boost revenue generation through targeted digital campaigns.</td></tr></tbody></table>

**Sales and Operations**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/YdUlW3QQgRv3QbIyaFTY">/pages/YdUlW3QQgRv3QbIyaFTY</a></td><td>Provide businesses with secure online storefronts to sell products and services directly to consumers. The system includes secure payment processing, inventory management, and user-friendly interfaces for product listings, enabling businesses to establish and manage their digital retail presence</td></tr><tr><td><a href="/pages/cAnfO6L2GyKFj3DVowNl">/pages/cAnfO6L2GyKFj3DVowNl</a></td><td>Centralise management of multiple online sales channels through a single interface. The system synchronises inventory, orders, and listings across various marketplaces and webstores in real-time, while providing analytics dashboard for comprehensive sales performance monitoring.</td></tr><tr><td><a href="/pages/tMpEMh4HneUzeg88wT3l">/pages/tMpEMh4HneUzeg88wT3l</a></td><td>Enable secure cloud-based file storage and synchronisation across devices. The system provides document access control, search functionality, version tracking, and automated backups while ensuring secure mobile access to business files.</td></tr><tr><td><a href="/pages/XBseh272fMKa5IlncVzR">/pages/XBseh272fMKa5IlncVzR</a></td><td>Streamline financial operations by integrating accounting processes and sales activities. The system manages general ledger, journal entries, tax calculations, cash flow tracking, and generates comprehensive financial reports alongside sales documentation and purchase orders.</td></tr><tr><td><a href="/pages/u77fvJqhNnDYzFvaC2de">/pages/u77fvJqhNnDYzFvaC2de</a></td><td>Provide comprehensive business control by integrating accounting, inventory and sales operations in a unified platform. The system combines financial management, inventory tracking with RFID/barcode capabilities, and sales processing, while offering detailed reporting and POS integration</td></tr><tr><td><a href="/pages/EFTjo8CWS32Z6j5wpILo">/pages/EFTjo8CWS32Z6j5wpILo</a></td><td>Integrate product tracking, pricing, and transaction processing. The system manages inventory through RFID/barcode scanning, handles sales documentation, enables price group creation, and generates business reports, while seamlessly connecting with POS systems.</td></tr><tr><td><a href="/pages/tiaDrgJJNmTJK4Xmsa52">/pages/tiaDrgJJNmTJK4Xmsa52</a></td><td>Enables companies to automate key accounting processes such as data extraction, data entry, categorisation, and reconciliation. The solution integrates with popular accounting systems to ensure seamless data flow, and features self-learning capabilities that allow it to improve over time based on user input.</td></tr><tr><td><a href="/pages/xVMyFXj8TnD8g3zMlLM4">/pages/xVMyFXj8TnD8g3zMlLM4</a></td><td>Provide third-party services to set up a presence on overseas online B2B or B2C marketplaces, handle the end-to-end e-commerce operations such as order management and customer service, and provide business advisory to the SMEs.</td></tr><tr><td><a href="/pages/1827rqcfryIK41CDfT1l">/pages/1827rqcfryIK41CDfT1l</a></td><td>Automate customer interactions through AI-powered digital assistants. The system handles customer enquiries, provides personalised recommendations, collects feedback, and manages lead generation, enabling 24/7 customer engagement while streamlining sales conversions and service improvement.</td></tr><tr><td><a href="/pages/1f8jpqvp599gQx6HYa8d">/pages/1f8jpqvp599gQx6HYa8d</a></td><td>Digitize staff training processes using Generative AI to convert company SOPs, guidelines, and procedures into automated training content, addressing the time-consuming nature of in-person training especially in high-turnover sectors. This ensures consistent, standardized training delivery across all locations while reducing manual effort during HR onboarding.</td></tr></tbody></table>

**Specialised Solutions**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/1uR9mXJgzIyElhrf444j">/pages/1uR9mXJgzIyElhrf444j</a></td><td>Track and measure an organisation's greenhouse gas emissions from direct and indirect business activities by calculating carbon footprint using recognised emissions factors, enabling businesses to monitor, report, and manage their environmental impact effectively.</td></tr><tr><td><a href="/pages/rp1MssMakxKqc4xPI8XU">/pages/rp1MssMakxKqc4xPI8XU</a></td><td>Optimise mobile workforce operations by coordinating technician scheduling, work order tracking, and customer communications. The system streamlines maintenance and repair services, enabling efficient dispatch, real-time job status updates, and service delivery management.</td></tr><tr><td><a href="/pages/2uCj0I7jnmEtyy15h82L">/pages/2uCj0I7jnmEtyy15h82L</a></td><td>Combine telematics and GPS technology to monitor vehicle locations and performance in real-time. The system provides comprehensive fleet visibility, tracking vehicle conditions, optimising routes, and enabling data-driven fleet maintenance and operational decisions.</td></tr><tr><td><a href="/pages/vqxtiYx56eLfU6L3lWrp">/pages/vqxtiYx56eLfU6L3lWrp</a></td><td>Enhance vehicle safety through advanced monitoring technologies. The system incorporates driver status monitoring, blind spot detection, and/or driver assistance features to prevent accidents, improve driver behaviour, and ensure safer fleet operations.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Human Resource Management System (HRMS)

Manage a company’s employee records in all the key HR administrative areas such as Personnel management, payroll, leave, employee benefits, employee claims and appraisal.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

***

#### Q1 🔴 **Mandatory** - Employee Records Management

**Main Question:** **Can your solution manage a company's employee records in all the key HR administrative areas below?**

**Personnel Management:**

* i. Create employees records and details
* ii. Allow for employee self-service to maintain updates

**Payroll Management:**

* i. Process E-payroll
* ii. Generate MOM itemised payslip
* iii. Comply to policy and statutory requirements

**Leave Management:**

* i. Manage leave applications and approvals
* ii. Configure leave policy

**Benefits and Claims Management:**

* i. Process medical and transport claims
* ii. Support multiple payment processing: Payroll, GIRO, cheque, and cash payment

**Performance Appraisal Management:**

* i. Set KPIs for individual employees for each appraisal cycle
* ii. Provide online built-in self-service appraisal forms with employee tagging and manager routing for approval and scoring

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

#### Q2 🟡 **Preferred** - Time Attendance Tracking

**Main Question:** **Can your solution allow employees to clock-in and clock-out their time attendance for the purpose of Personnel management and Payroll calculations?**

🟡 **Answer:** ○ Yes \[Next: Q3] ○ No \[Next: Q3]

***

#### Q3 🟡 **Preferred** - Employee Health Status Tracking

**Main Question:** **Can your solution allow the tracking of vaccination status of employees and their test results for the purpose of Personnel management?**

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

#### Q4 🔴 **Mandatory** - Dashboards and Reports (HRMS)

**Main Question:** **Can your solution provide dashboard and reports to allow a company's management to view, analyse, and manage employees' activities?**

**Examples:** (e.g. Payroll reports, Leave Reports, Performance Appraisal Reports, Employee Attendance and Overtime Reports, etc)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

#### Q5 🔴 **Mandatory** - Cloud and Multi-Device Accessibility

**Main Question:** **Does your solution allow for cloud-based, mobile-based, and/or web-based usage?**

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

#### Q6 🔴 **Mandatory** - Integration with Existing Accounting Solution

**Main Question:** **Can your solution be integrated with user's existing accounting management solution to facilitate processing of employees' payroll?**

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

#### Q7 🔴 **Mandatory** - IRAS Auto Inclusion Scheme (AIS) Compliance

**Main Question:** **Is your solution listed on IRAS's List of Supporting Payroll Software Vendors for the Auto Inclusion Scheme (AIS) for employment income?**

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

#### Q8 🟡 **Preferred** - AI Features HR

**Main Question:** **Does your solution have any HR-Related AI Features?**

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

#### Q9 🔴 **Mandatory Follow-up** - AI Features HR - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** **Describe your HR-Related AI features. Examples are:**

**Example Features:**

* a. A HR chatbot to answer FAQs on company policies, allow Leave and Claims applications to be submitted and approved via the chatbot and for the Leave and Claims balance to be automatically updated on HRMS, and assist with the employee onboarding process
* b. Ability to identify irregularities in employee hours and payroll
* c. Ability to identify and assess characteristics and trends across the entire employee population
* e. Ability to predict future sources of staff turnover and employee performance
* f. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]&#x20;

**Text Elaboration Required:** \[Text Box for Description]

***

#### Q10 🔴 **Mandatory** - Business Data Extraction

**Main Question:** **Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?**

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

#### Q11 🔴 **Mandatory** - Personal Data Protection

**Main Question:** **Can your solution demonstrate compliance with the following Personal Data Protection requirements?**

**Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Instructions:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

#### Q12 🔴 **Mandatory** - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** **Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?**

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**For Resellers:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** Note: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

#### Q13 🟡 **Preferred** - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** **Are you the Product Principal of the solution that you are submitting for pre-approval?**

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

#### Q14 🟡 **Preferred** - CEM for Product Principal

*This question appears only if you answered "Yes" to Q13*

**Main Question:** **Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?**

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

#### Q15 🔴 **Mandatory Follow-up** - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** **Please specify the following information:**

**Required Information:**

* i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* i. The cybersecurity certification the organisation has met
* ii. The scope of the certification

**Upload Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]&#x20;

**Text Elaboration Required:** \[Text Box for Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

#### Q16 🟡 **Preferred** - CEM for Resellers

*This question appears only if you answered "No" to Q13*

**Main Question:** **Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?**

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

#### Q17 🔴 **Mandatory Follow-up** - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** **Please specify the following information:**

**Required Information:**

* i. The cybersecurity certification the organisation has met
* ii. The scope of the certification

**Upload Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]&#x20;

**Text Elaboration Required:** \[Text Box for Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Human Resource E-scheduling System

Manage a company’s employee records in all the key HR administrative areas such as Personnel management, payroll, leave, employee benefits, employee claims and appraisal

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - General Setup

**Main Question:** Does your solution enable the company to perform the following functions?

**Setup Requirements:** a. Set up admin and user accounts for all employees b. Set up and edit business units for different employee categories (e.g. geography, division, tenure, etc) c. Allow scheduling interface to be customisable by administrator

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Roster Scheduling

**Main Question:** Does your solution enable the company to perform the following functions?

**Roster Scheduling Requirements:** a. Grant access to all employees for mobile-based, web-based and cloud-based usage b. Track overall scheduling and generate attendance and overtime reports c. Push messages or notifications to employees automatically of own work shift d. Prompt and remind users of scheduling updates

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Dashboards and Reports (HR E-scheduling System)

**Main Question:** Does your solution come with a Dashboard and Report Module that enables the company to perform the following functions?

**Dashboard and Report Requirements:** a. Access dashboard showing overall scheduling status, attendance, and overtime report b. Generate attendance and overtime reports

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Staff and Skillsets Record

**Main Question:** Can your solution keep a record of the company's staff and corresponding skillsets in order to support the deployment of relevant staff to affected job functions during peak periods?

🟡 Answer: ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🔴 Mandatory - API Extension to HRMS

**Main Question:** Does your solution establish API connections with HRMS systems?

**Integration Requirements:** a. List the HRMS that the solution can integrate with b. List the features and functions that are integrated

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🟡 Preferred - AI Powered Roster Scheduling

**Main Question:** Does your solution have any AI Powered Roster Scheduling Features?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

### Q7 🔴 Mandatory Follow-up - AI Powered Roster Scheduling - Elaboration

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Describe your AI Powered Roster Scheduling features. Examples are:

**AI Features Examples:** a. Ability to automate and optimise roster scheduling b. Ability to perform data analytics on scheduling patterns and recommend predictive measures (e.g. prompt to schedule manpower ahead of peak hour in restaurant, etc) c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q8 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q14]

***

### Q12 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q13] ○ No \[Assessment Finished]

\--

### Q13 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Human Resource Shared Services (HRSS)Needs Analysis + HR Administrative Support & Payroll Processing

Review a company’s internal HR process, offer a HRMS system and provide HR Administrative and payroll processing support such as issuing payslips, ePayment of Salaries, leave, attendance and claims.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Needs Analysis

**Main Question:** Does your service include a robust methodology to assess the SME's current HR processes to identify outsourcing opportunities?

**Service Scope:** \*Capped at 1 man-day

**Submission Requirements:** Please submit the following documents: \[1] One needs analysis report for each of the 5 satisfied customers \[2] Overall methodology of the HRSS process

The documents should be named in this format: "Needs Analysis Customer Name 1", "Needs Analysis Customer Name 2", etc. and "Methodology". Do note that the documents submitted are to be vendors' benchmark for quality.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q2 🔴 Mandatory - HR Administrative Support and Payroll Processing

**Main Question:** Does your service include HR Administrative Support and Payroll processing via a HRMS with all the modules below?

**Required HRMS Modules:** a. Employee data module (i.e Maintain and update employee data) b. Attendance & leave module (i.e Manage attendance and leave (tracking & reports) ) c. Payroll module (i.e Prepare MOM itemised pay slips and payroll reports, E-payment of salaries to staff, assist in yearly IRAS filing, compy to policy and statutory requirements) d. Claims module (i.e Process expense, benefit, and medical claims)

State the HRMS software used to deliver this service.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

### Q5 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q4*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Features Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q12]

***

### Q10 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Assessment Finished]

\--

### Q11 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q13] ○ No \[Assessment Finished]

\--

### Q13 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Employee Rewards and Recognition

Enable companies to reward employees for the purpose of appreciation and positive incentivisation, in a streamlined manner through the issuance and redemption of rewards from a wide merchant network .

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Employee Rewards and Recognition

**Main Question:** Does your solution allow the company to perform the following functions?

**Core Functionality Requirements:** a. Create and edit occasions for Rewards and Recognition (e.g., Achieving KPIs, Events Attendance, Long Service Award, etc.) b. Allow employers to award points, or a dollar value, to employees (both on an ad-hoc basis or upon the above occasions), and send words of appreciation which can be tagged to the core values of the company c. Allow employees to utilise points, or a dollar value, to redeem Rewards from a merchant network of at least 100 Singapore-based merchants across a wide range of industries (e.g, Retail, F\&B, Recreation, etc.) d. Provide a posting board to announce appreciations

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - API Extension to HRMS

**Main Question:** Does your solution establish API connections with HRMS systems?

**Integration Requirements:** a. List the HRMS that the solution can integrate with b. List the features/functions that are integrated Note: There will not be support to fund development of API extension to any HRMS

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q4 🔴 Mandatory - Dashboards and Reports (Employee Rewards and Recognition)

**Main Question:** Does your solution come with these dashboards, analytics, and reports?

**Dashboard and Analytics Requirements:** a. Provide individual employee and employer admin dashboards to view and track the points awarded, redeemed, and the balance points b. Analytics or reports related to the utilisation of rewards c. Allow for download and export of dashboards and reports

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Employee Recognition and Rewards Automation

**Main Question:** Does your solution automate the awarding of points at key milestones (e.g., Work Anniversary, Birthday, Completion of Survey, etc.)

🟡 Answer: ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

### Q7 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Features Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q8 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q12]

\--

### Q10 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q13] ○ No \[Next: Q15]

***

### Q13 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Assessment Finished]

\--

### Q14 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Applicant Tracking & Sourcing System

Help companies organise candidates for hiring and recruitment purposes, allowing businesses to collect information, organise prospects based on experience and skill set, and filter applicants.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Recruitment Management

**Main Question:** Does your solution come with a Recruitment Module which allows the company to perform the following functions?

**Recruitment Module Requirements:** a. Create and edit new job hire positions with approval workflows b. Update and track candidate application status (e.g., New, Shortlisted, Scheduled, Interviewed, Offered, Rejected, etc) c. Send job offers to candidates via the system d. Publish job postings to multiple job boards (e.g., LinkedIn, Jobstreet, MyCareersFuture, IHLs, etc) e. Configure application form with custom questions, and accept document uploads from candidates f. Send customised emails with provided templates (e.g., for scheduling of interview, job offer, rejection, etc.) to multiple candidates at a time, with role-based privacy settings (i.e. HR can determine level of information visible to hiring managers and peer interviewers) g. Tag candidates and make recruitment notes on candidate in the system

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - API Extension to HRMS

**Main Question:** Does your solution establish API connections with HRMS systems?

🟡 Answer: ○ Yes \[Next: Q4] ○ No \[Next: Q5]

\--

### Q4 🔴 Mandatory Follow-up - API Extension to HRMS - Elaboration

*This question appears only if you answered "Yes" to Q3*

**Main Question:** a. List the HRMS that the solution can integrate b. List the features/functions that are integrated Note: There will not be support to fund development of API extension to any HRMS

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q5 🔴 Mandatory - Dashboards and Reports (Applicant Tracking and Sourcing System)

**Main Question:** Does your solution come with these dashboards and reports that are downloadable and exportable?

**Dashboard and Reports Requirements:** a. Dashboard with an overview of all job posts and application status b. Analytics or reports for candidate application tracking and recruitment performance analysis (e.g., Application to Vacancies Ratio (AVR), Job Offer Rate, etc)

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Skills Proficiency Levels Specification

**Main Question:** Does your solution specify the Skills Proficiency levels in accordance with the SkillsFuture Framework?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Integrated Interview Scheduling and Calendar View

**Main Question:** Does your solution allow viewing of calendars of hiring managers and to generate meeting links on meeting platforms (e.g. Zoom, MS Teams, Google Meet) within the system, for seamless scheduling of interviews?

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - AI Powered Recruitment and Talent Matching

**Main Question:** Does your solution have AI Features related to Recruitment and Talent Matching?

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Powered Recruitment and Talent Matching - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your Recruitment/Talent Matching AI features. Examples are:

**AI Features Examples:** a. Smart recommendation of candidates based on set requirements b. Candidate CV summarisation c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Next: Q16]

***

### Q14 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Automated Order Management

Enables seamless customer order capturing and fulfillment via various mobile messaging platforms by automatically capturing and converting natural language text and/or voice orders directly into digital sales orders and automatically keeping customers updated on their orders.

### Q1 🔴 Mandatory - Order Capturing and Fulfillment via Mobile Messaging Platforms (Text Message)

**Main Question:** Can your solution capture free-form, unstructured text message customer orders automatically via any mobile messaging platforms (e.g. Whatsapp, Text Messaging (SMS), Telegram, etc.), convert them into structured order records with the relevant customer details, and facilitate the processing of the order?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Order Capturing and Fulfillment via Structured Documents

**Main Question:** Can your solution capture structured customer orders (e.g. PDF or XLS purchase orders with fixed information fields, etc.), convert them into structured order records with the relevant customer details, and facilitate the processing of the order?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Order Capturing via Voice Messages

**Main Question:** Can your solution capture free-form, unstructured voice message customer orders automatically via any mobile messaging platforms (e.g. Whatsapp, Text Messaging (SMS), Telegram, etc.), convert them into structured order records with the relevant customer details, and facilitate the processing of the order?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - Language(s) Supported

**Main Question:** Other than English, does your solution support any other language(s)?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

### Q5 🔴 Mandatory Follow-up - Language(s) Supported - Elaboration

*This question appears only if you answered "Yes" to Q4*

**Main Question:** What other language(s) does your solution support?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🔴 Mandatory - Centralised Order Management

**Main Question:** Does your solution centralise all customer conversations and allow for ease of reference between the point-of-order (e.g.text chat, voice chat, etc.) and the customer order created in the system?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Inventory and Pricing Configuration

**Main Question:** Does your solution allow for the creation and maintenance of a database of SKUs, with differentiated pricing and Units of Measure (UOM) allowed for different level/tiering of customers?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Customer Analytics

**Main Question:** Does your solution allow for the classification of customers, analyse their purchase patterns and provide relevant recommendations and/or notifications?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Receipt and/or Delivery Note Generation

**Main Question:** Can your solution generate a receipt note and/or delivery note generation, for any customer order?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Software Integration

**Main Question:** Can your solution integrate with other relevant solutions (e.g. Inventory, Sales, Finance, etc.), to ensure a seamless information flow?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Technical Requirements:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

**Scope Requirements:** (e.g., Users can export data from the digital solution into CSV format for integration with third-party analytics tools or convert records into XLSX for detailed reporting, documentation, or compliance purposes)

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

### Q15 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

&#x20;**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

### Q17 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Customer Relationship Management (CRM)

Capture customer and prospect information, identify sales leads, generate sales funnel and manage marketing campaigns. This solution must cater to the sales needs of the entire business operations. Solution must be usable by a wide segment of SMEs, and not specific to SMEs in a specific industry/sector.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Customer Relationship Management

**Main Question:** Does your solution allow the company to perform the following functions?

**Core CRM Functionality Requirements:** a. Manage customer information and contact details b. Track customer interactions and communication history c. Manage sales pipeline and opportunities d. Create and manage customer accounts and profiles e. Generate quotes and proposals f. Track sales activities and follow-ups g. Manage customer support tickets and service requests

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Lead Management and Sales Pipeline

**Main Question:** Does your solution provide comprehensive lead management and sales pipeline functionality?

**Lead Management Requirements:** a. Capture and qualify leads from multiple sources b. Lead scoring and prioritization c. Lead assignment and distribution d. Track lead conversion rates e. Sales pipeline visualization with customizable stages f. Opportunity management with probability tracking g. Sales forecasting capabilities

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

**CRM-Specific Dashboard Requirements:** a. Sales performance metrics and KPIs b. Customer acquisition and retention analytics c. Lead conversion tracking d. Revenue and sales forecasting reports e. Customer interaction history and communication logs

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Marketing Automation Integration

**Main Question:** Does your solution include marketing automation capabilities or integrate with marketing platforms?

**Marketing Integration Features:** a. Email marketing campaigns b. Lead nurturing workflows c. Marketing campaign tracking d. Customer segmentation e. Integration with popular marketing platforms (e.g., Mailchimp, HubSpot, etc.)

🟡 Answer: ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Third-Party Integrations

**Main Question:** Does your solution integrate with commonly used business applications and platforms?

**Integration Capabilities:** a. Email platforms (Outlook, Gmail, etc.) b. Calendar applications c. Accounting software (QuickBooks, Xero, etc.) d. E-commerce platforms e. Social media platforms f. Communication tools (Slack, Microsoft Teams, etc.)

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

### Q8 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Features Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Predictive analytics for sales forecasting d. Intelligent lead scoring and customer insights e. Automated customer service responses f. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q13] ○ No \[Next: Q15]

***

### Q13 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Assessment Finished]

\--

### Q14 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# E-loyalty & Marketing Automation

Manage their customers through membership and loyalty program. Companies may set up campaigns or event-based marketing, and promotions. The e-loyalty CRM solution offers loyalty rewards, discounts, and other special incentives designed to reward customer's repeat business.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - E-loyalty and Marketing Automation

**Main Question:** Does your solution allow the company to perform the following functions?

**Core E-loyalty and Marketing Automation Requirements:** a. Create and manage customer loyalty programs with points, rewards, and tier systems b. Automate marketing campaigns across multiple channels (email, SMS, social media, etc.) c. Customer segmentation and targeting based on behavior, demographics, and purchase history d. Personalized marketing content and recommendations e. Track customer engagement and campaign performance f. Manage customer communications and notifications g. Integration with e-commerce platforms and POS systems h. Customer journey mapping and automation workflows

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Loyalty Program Management

**Main Question:** Does your solution provide comprehensive loyalty program management capabilities?

**Loyalty Program Requirements:** a. Points accumulation and redemption system b. Tier-based loyalty programs with different benefit levels c. Reward catalog management with various reward types d. Automated point expiry and balance management e. Member enrollment and profile management f. Loyalty program analytics and reporting g. Integration with payment systems for seamless transactions

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Marketing Campaign Automation

**Main Question:** Does your solution enable automated marketing campaign creation and execution?

**Marketing Automation Requirements:** a. Drag-and-drop campaign builder with visual workflow design b. Trigger-based campaigns (welcome series, abandoned cart, birthday, etc.) c. Multi-channel campaign orchestration (email, SMS, push notifications, social media) d. A/B testing capabilities for campaign optimization e. Automated lead nurturing and customer lifecycle campaigns f. Real-time campaign performance monitoring and analytics g. Template library for various campaign types

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Dashboards and Reports

**Main Question:** Does your solution come with dashboards and analytics for loyalty program and marketing campaign performance?

**Dashboard and Analytics Requirements:** a. Customer engagement and retention metrics b. Loyalty program performance analytics (enrollment rates, redemption rates, etc.) c. Marketing campaign ROI and conversion tracking d. Customer lifetime value and segmentation analysis e. Real-time campaign performance dashboards

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Omnichannel Customer Experience

**Main Question:** Does your solution provide omnichannel customer experience capabilities?

**Omnichannel Features:** a. Unified customer profiles across all touchpoints b. Consistent messaging and branding across channels c. Cross-channel campaign coordination d. Mobile app integration for loyalty programs e. Social media integration and management f. In-store and online experience synchronization

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Third-Party Integrations

**Main Question:** Does your solution integrate with commonly used business platforms and tools?

**Integration Capabilities:** a. E-commerce platforms (Shopify, WooCommerce, Magento, etc.) b. Point-of-Sale (POS) systems c. Customer Relationship Management (CRM) systems d. Email service providers e. Social media platforms f. Analytics tools (Google Analytics, etc.) g. Payment gateways and processors

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Features Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Predictive customer behavior analytics and churn prevention d. Intelligent customer segmentation and targeting e. Automated content personalization and product recommendations f. Optimal send time prediction for marketing campaigns g. Dynamic pricing and reward optimization h. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Next: Q16]

***

### Q14 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# E-Commerce - Online Shop (B2C)

Provide businesses with secure online storefronts to sell products and services directly to consumers. The system includes secure payment processing, inventory management, and user-friendly interfaces for product listings, enabling businesses to establish and manage their digital retail presence.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - E-commerce Online Shop

**Main Question:** Does your solution allow the company to perform the following functions?

**Core E-commerce Requirements:** a. Create and manage online product catalogs with categories, descriptions, images, and pricing b. Shopping cart functionality with add, remove, and modify capabilities c. Secure checkout process with multiple payment options d. Order management system (order tracking, status updates, fulfillment) e. Customer account creation and management f. Inventory management and stock tracking g. Product search and filtering capabilities h. Mobile-responsive design for optimal mobile shopping experience

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Payment Gateway Integration

**Main Question:** Does your solution integrate with secure payment gateways and support multiple payment methods?

**Payment Integration Requirements:** a. Integration with major payment gateways (PayPal, Stripe, local payment processors) b. Support for multiple payment methods (credit/debit cards, digital wallets, bank transfers) c. Secure payment processing with SSL encryption d. PCI DSS compliance for payment security e. Support for local payment methods (PayNow, GrabPay, etc.) f. Automated payment confirmation and receipt generation g. Refund and partial refund processing capabilities

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Order and Inventory Management

**Main Question:** Does your solution provide comprehensive order and inventory management capabilities?

**Order and Inventory Management Requirements:** a. Real-time inventory tracking and stock level monitoring b. Automated low stock alerts and notifications c. Order processing workflow (pending, confirmed, shipped, delivered) d. Order history and tracking for customers and administrators e. Bulk product import/export capabilities f. Product variant management (size, color, etc.) g. Supplier and vendor management integration h. Automated order confirmation emails and notifications

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Dashboards and Reports

**Main Question:** Does your solution come with e-commerce analytics dashboards and reporting capabilities?

**Dashboard and Analytics Requirements:** a. Sales performance metrics and revenue tracking b. Product performance analytics (best sellers, slow movers) c. Customer behavior analytics and purchase patterns d. Inventory turnover and stock level reports e. Order fulfillment and shipping analytics

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Marketing and SEO Features

**Main Question:** Does your solution include built-in marketing and SEO optimization features?

**Marketing and SEO Features:** a. Search Engine Optimization (SEO) tools and meta tag management b. Discount codes and promotional campaign management c. Email marketing integration and automated campaigns d. Social media integration and sharing capabilities e. Product reviews and ratings system f. Cross-selling and upselling recommendations g. Abandoned cart recovery features

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Multi-channel Integration

**Main Question:** Does your solution support multi-channel selling and marketplace integration?

**Multi-channel Capabilities:** a. Integration with popular marketplaces (Shopee, Lazada, Amazon, etc.) b. Social commerce integration (Facebook Shop, Instagram Shopping) c. Point-of-Sale (POS) system integration for omnichannel experience d. Centralized inventory management across all channels e. Unified order management from multiple sales channels f. Cross-channel analytics and reporting

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Shipping and Logistics Integration

**Main Question:** Does your solution integrate with shipping carriers and logistics providers?

**Shipping and Logistics Features:** a. Integration with major shipping carriers (SingPost, DHL, FedEx, etc.) b. Real-time shipping rate calculation c. Automated shipping label generation d. Package tracking integration e. Multiple shipping options for customers f. Local delivery and pickup options g. International shipping capabilities with customs documentation

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Features Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Intelligent product recommendations and personalization d. Dynamic pricing optimization based on market conditions e. Automated inventory forecasting and demand prediction f. AI-powered chatbots for customer service g. Image recognition for product categorization and tagging h. Fraud detection and prevention systems i. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Next: Q17]

***

### Q15 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Certification Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Inventory Management and Sales Management System

Integrate product tracking, pricing, and transaction processing. The system manages inventory through RFID/barcode scanning, handles sales documentation, enables price group creation, and generates business reports, while seamlessly connecting with POS systems.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Inventory Management**

Main Question: Does your solution come with an Inventory Management Module which enables the company to perform the following functions?

Functional Requirements: a. Set up and edit inventory product details for different item groups (e.g. dimensions, models, etc) b. Set up and edit various store areas for reference to inventory location (e.g. zones, aisles, etc) c. Create inventory journal logs to track movement of inventory items (e.g. date, quantity, cost, reserves, movement, location, staff log, etc) d. Create item price and discount groups e. Support barcode labelling f. Set up and edit warehouse details (e.g. branches, etc)

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Supplier Group Management (Inventory)**

Main Question: Does your solution come with a Supplier Group Module which allows the company to perform the following functions?

Functional Requirements: a. Set up and edit terms of payment b. Set up and edit vendor groups c. Set up and edit modes of payment d. Set up and edit prices and discounts for different vendor groups e. Set up and edit supplier contracts (e.g. payment details, quantity, etc)

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Delivery Management**

Main Question: Does your solution come with a Delivery Module that enables the company to perform the following functions?

Functional Requirements: a. Set up and edit delivery details (e.g. date, customer, mode of transport, shipping and receiving point, duration of journey, etc) b. Set up and edit terms of delivery c. Set up and edit carrier details d. Track goods receipt and issues

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Payment Management**

Main Question: Does your solution come with a Payment Module that enables the company to set up and edit purchase orders (e.g. items, quantity, etc)?

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Dashboards and Reports (Inventory)**

Main Question: Does your Inventory Management solution come with a Dashboard and Reports Module that enables the company to perform the following functions?

Functional Requirements: a. Track overall inventory levels in warehouse(s) b. Track delivery status by products and customers (e.g. outstanding shipments, etc) c. Generate inventory turns by finished goods, raw materials, WIP parts or product, etc. d. Generate inventory aging by days, storage location, and product type e. Generate inventory valuation by product, storage location f. Generate projected excess inventory g. Generate projected shortages by product h. Generate revenue at risk due to shortages i. Generate inventory incoming versus outgoing (by product, date, and overall)

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features Requirements: The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🔴 Mandatory - Inventory Forecasting**

Main Question: Does your solution come with a Forecasting Module which enables company to setup and edit forecast models (e.g. based on inventory levels, trends, and base demands, etc)?

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🔴 Mandatory - Inventory Level Alerts**

Main Question: Does your solution automatically trigger reminder alerts when inventory levels reach a pre-set low level?

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🔴 Mandatory - Units of Measurement Customisation**

Main Question: Does your solution allow customisation of different units of measurements (e.g. litres, weight, pallets, pieces, cartons, etc)?

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🟡 Preferred - Barcode/RFID/QR Code Scanning Integration**

Main Question: Does your solution allow for real-time stock-taking of inventory and assets via integration with with Barcode/RFID/QR Code Scanning hardware (e.g. installed with RFID reader, tags, tunnel gantry, etc)?

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🔴 Mandatory - Customer Groups Management**

Main Question: Does your solution come with a Customer Groups Module that enables the company to perform the following functions?

Functional Requirements: a. Set up and edit customer groups b. Set up and edit terms & modes of payment c. Set up and edit prices and discounts for different customer groups d. Set up and edit vendor contracts (e.g. payment details, quantity, etc)

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🔴 Mandatory - Invoice and Quotation Management**

Main Question: Does your solution come with an Invoice and Quotation Module which the enables the company to configure invoice and quotation details?

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13 🔴 Mandatory - InvoiceNow-Ready Solution Provider Accreditation**

Main Question: Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

Compliance Requirements: \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

Reference Information: Note: For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🔴 Mandatory - Sales and Delivery Management**

Main Question: Does your solution come with a Sales and Delivery Module that enables the company to perform the following functions?

Functional Requirements: a. Set up and edit sales form (e.g. sales origin, delivery details, customer details, item list, account manager, payment details, etc) b. Setup and edit delivery order form based on delivery module details c. Set up and edit customer payment

🔴 Answer: ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🔴 Mandatory - Dashboards and Reports (Sales)**

Main Question: Does your Sales Management solution come with a Dashboards and Reports Module that enables the company to perform the following functions?

Functional Requirements: a. Monitor sales transactions and forecasts b. Set up and edit sales contracts with customers based on prices and discounts of different customer groups c. Set up and edit sales returns function (e.g. warehouse, location, customer, product details, remarks, etc) d. Generate customer reports by sales e. Generate sales cycle analytics f. Conduct sales tracking (e.g. to analyse sales pipeline, by product category, etc)

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features Requirements: The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

**Q16 🔴 Mandatory - Inventory and Sales Integration**

Main Question: Are the Inventory Management function and the Sales Management function tightly integrated? (e.g. Delivery Module (Inventory) should be linked to Customer Group (Sales).)

🔴 Answer: ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

**Q17 🟡 Preferred - AI Powered Inventory Management**

Main Question: Does your solution come with AI Powered Inventory Management features?

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Next: Q19]

\--

**Q18 🔴 Mandatory Follow-up - AI Powered Inventory Management- Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Describe your AI Powered Inventory Management features. Examples are:

Feature Examples: a. Ability to perform demand prediction for inventory management b. Ability to automate routine sales tasks (e.g. update forecasts and determine call lists) c. Ability to automate customer responses, data capture activities, and follow-ups d. Ability to analyse and predict potential conversion of pipelines e. Others, please specify

Submission Requirements: Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q19 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 Answer: ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

**Q21 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q20*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Submission Requirements: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

\--

**Q22 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q21*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Requirements: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: Note: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Submission Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q23 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q24] ○ No \[Next: Q26]

\--

**Q24 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q23*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Information: Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

**Q25 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q24*

Main Question: Please specify the following information:

Required Information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Submission Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q26 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q23*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Information: Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q27] ○ No \[Assessment Finished]

\--

**Q27 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q26*

Main Question: Please specify the following information:

Required Information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Submission Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

***

###

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Accounting Management + Sales Management System

Streamline financial operations by integrating accounting processes and sales activities. The system manages general ledger, journal entries, tax calculations, cash flow tracking, and generates comprehensive financial reports alongside sales documentation and purchase orders.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Accounting Management

**Main Question:** Does your solution come with an Accounting Module which enables the company to perform the following functions?

**Functional Requirements:** a. Set up general ledger b. Create journal entries c. Allow reconciliations (e.g. to bank statements) d. Calculate sales tax e. Calculate cash flow f. Generate accounts receivable summary g. Generate accounts payable summary

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Customer Groups Management

**Main Question:** Does your solution come with Customer Groups Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit customer groups b. Set up and edit terms of payment c. Set up and edit modes of payment d. Set up and edit prices and discounts for different customer groups e. Set up and edit customer contracts (e.g. payment details, quantity, etc)

Note: This is applicable for both Accounting and Sales management systems.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Supplier Groups Management (Accounting)

**Main Question:** Does your solution come with a Supplier Groups Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit terms of payment b. Set up and edit supplier groups c. Set up and edit modes of payment d. Set up and edit prices and discounts for different supplier groups

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Dashboards and Reports (Accounting)

**Main Question:** Does your Accounting Management solution come with a Dashboards and Reports Module that enables the company to perform the following functions?

**Functional Requirements:** a. Apply filters to analyse customer groups b. Review outstanding/ageing payables c. Review outstanding/ageing receivables d. Create statement of accounts e. Create balance sheet f. Review overall budget g. Review monthly expenses and revenue h. Present an overview of company's health (e.g. operating profit, cash ratio, net cash flow from operating activities, current ratio, gross margin, return on capital, return on sale, gearing ratio, interest cover, and interest coverage ratio, etc.)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Dashboard Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Budgeting Management

**Main Question:** Does your solution come with a Budgeting Module that enables the company to create line item budgets?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Delivery Management

**Main Question:** Does your solution come with a Delivery Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit delivery details (e.g. date, customer, mode of transport, shipping and receiving point, duration of journey, etc) b. Set up and edit terms of delivery c. Set up and edit carrier details d. Track goods receipt and issues

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Invoice and Quotation Management

**Main Question:** Does your solution come with an Invoice and Quotation Module which the enables the company to configure invoice and quotation details?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - InvoiceNow-Ready Solution Provider Accreditation

**Main Question:** Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

**Compliance Requirements:** \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

Note: For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - RFID Integration

**Main Question:** Does your solution allow for real-time stock-taking of inventory and assets via integration with RFID hardware (e.g. installed with RFID reader, tags, tunnel gantry, etc)?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🔴 Mandatory - Sales and Delivery Management

**Main Question:** Does your solution come with a Sales and Delivery Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit sales form (e.g. sales origin, delivery details, customer details, item list, account manager, payment details, etc) b. Setup and edit delivery order form based on delivery module details c. Set up and edit customer payment

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Dashboards and Reports (Sales)

**Main Question:** Does your Sales Management solution come with a Dashboards and Reports Module that enables the company to perform the following functions?

**Functional Requirements:** a. Monitor sales transactions and forecasts b. Set up and edit sales contracts with customers based on prices and discounts of different customer groups c. Set up and edit sales returns function (e.g. warehouse, location, customer, product details, remarks, etc) d. Generate customer reports by sales e. Generate sales cycle analytics f. Conduct sales tracking (e.g. to analyse sales pipeline, by product category, etc)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Dashboard Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Accounting and Sales Integration

**Main Question:** Are the Sales Management function and Accounting Management function tightly integrated?

**Integration Examples:** (e.g. Sales/delivery orders (Sales) should be linked to customer groups (Accounting) and Sales management (Sales) should be linked to Accounts module (Accounting) )

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - AI Powered Sales Automation

**Main Question:** Does your solution come with AI Powered Sales Automation features?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

### Q15 🔴 Mandatory Follow-up - AI Powered Sales Automation - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Describe your Sales-Related AI features. Examples are:

**Feature Examples:** a. Ability to automate routine sales tasks (e.g. update forecasts and determine call lists) b. Ability to automate customer responses, data capture activities, and follow-ups c. Ability to analyse and predict potential conversion of pipelines d. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

### Q18 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

\--

### Q19 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

### Q21 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

### Q23 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

### Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Accounting Management + Inventory Management + Sales Management System

Provide comprehensive business control by integrating accounting, inventory and sales operations in a unified platform. The system combines financial management, inventory tracking with RFID/barcode capabilities, and sales processing, while offering detailed reporting and POS integration

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Accounting Management

**Main Question:** Does your solution come with an Accounting Module which enables the company to perform the following functions?

**Functional Requirements:** a. Set up general ledger b. Create journal entries c. Allow reconciliations (e.g. to bank statements) d. Calculate sales tax e. Calculate cash flow f. Generate accounts receivable summary g. Generate accounts payable summary

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Customer Groups Management

**Main Question:** Does your solution come with Customer Groups Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit customer groups b. Set up and edit terms of payment c. Set up and edit modes of payment d. Set up and edit prices and discounts for different customer groups e. Set up and edit customer contracts (e.g. payment details, quantity, etc)

Note: This is applicable for both Accounting and Sales management systems.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Supplier Groups Management (Accounting)

**Main Question:** Does your solution come with a Supplier Groups Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit terms of payment b. Set up and edit supplier groups c. Set up and edit modes of payment d. Set up and edit prices and discounts for different supplier groups

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Dashboards and Reports (Accounting)

**Main Question:** Does your Accounting Management solution come with a Dashboards and Reports Module that enables the company to perform the following functions?

**Functional Requirements:** a. Apply filters to analyse customer groups b. Review outstanding/ageing payables c. Review outstanding/ageing receivables d. Create statement of accounts e. Create balance sheet f. Review overall budget g. Review monthly expenses and revenue h. Present an overview of company's health (e.g. operating profit, cash ratio, net cash flow from operating activities, current ratio, gross margin, return on capital, return on sale, gearing ratio, interest cover, and interest coverage ratio, etc.)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Dashboard Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Budgeting Management

**Main Question:** Does your solution come with a Budgeting Module that enables the company to create line item budgets?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Inventory Management

**Main Question:** Does your solution come with an Inventory Management Module which enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit inventory product details for different item groups (e.g. dimensions, models, etc) b. Set up and edit various store areas for reference to inventory location (e.g. zones, aisles, etc) c. Create inventory journal logs to track movement of inventory items (e.g. date, quantity, cost, reserves, movement, location, staff log, etc) d. Create item price and discount groups e. Support barcode labelling f. Set up and edit warehouse details (e.g. branches, etc)

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Supplier Group Management (Inventory)

**Main Question:** Does your solution come with a Supplier Group Module which allows the company to perform the following functions?

**Functional Requirements:** a. Set up and edit terms of payment b. Set up and edit vendor groups c. Set up and edit modes of payment d. Set up and edit prices and discounts for different vendor groups e. Set up and edit supplier contracts (e.g. payment details, quantity, etc)

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Delivery Management

**Main Question:** Does your solution come with a Delivery Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit delivery details (e.g. date, customer, mode of transport, shipping and receiving point, duration of journey, etc) b. Set up and edit terms of delivery c. Set up and edit carrier details d. Track goods receipt and issues

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Payment Management

**Main Question:** Does your solution come with a Payment Module that enables the company to set up and edit purchase orders (e.g. items, quantity, etc)?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Dashboards and Reports (Inventory)

**Main Question:** Does your Inventory Management solution come with a Dashboard and Reports Module that enables the company to perform the following functions?

**Functional Requirements:** a. Track overall inventory levels in warehouse(s) b. Track delivery status by products and customers (e.g. outstanding shipments, etc) c. Generate inventory turns by finished goods, raw materials, WIP parts or product, etc. d. Generate inventory aging by days, storage location, and product type e. Generate inventory valuation by product, storage location f. Generate projected excess inventory g. Generate projected shortages by product h. Generate revenue at risk due to shortages i. Generate inventory incoming versus outgoing (by product, date, and overall)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Dashboard Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Inventory Forecasting

**Main Question:** Does your solution come with a Forecasting Module that enables company to setup and edit forecast models (e.g. based on inventory levels, trends, and base demands, etc)?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Invoice and Quotation Management

**Main Question:** Does your solution come with an Invoice and Quotation Module that enables the company to configure invoice and quotation details?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Inventory Level Alerts

**Main Question:** Does your solution automatically trigger reminder alerts when inventory levels reach a pre-set low level?

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Units of Measurement Customisation

**Main Question:** Does your solution allow customisation of different units of measurements (e.g. litres, weight, pallets, pieces, cartons, etc)?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - RFID Integration

**Main Question:** Does your solution allow for real-time stock-taking of inventory and assets via integration with RFID hardware (e.g. installed with RFID reader, tags, tunnel gantry, etc)?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q17]

***

### Q17 🔴 Mandatory - InvoiceNow-Ready Solution Provider Accreditation

**Main Question:** Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

**Compliance Requirements:** \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

Note: For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Sales and Delivery Management

**Main Question:** Does your solution come with a Sales and Delivery Module that enables the company to perform the following functions?

**Functional Requirements:** a. Set up and edit sales form (e.g. sales origin, delivery details, customer details, item list, account manager, payment details, etc) b. Setup and edit delivery order form based on delivery module details c. Set up and edit customer payment

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Dashboards and Reports (Sales)

**Main Question:** Does your Sales Management solution come with a Dashboards and Reports Module that enables the company to perform the following functions?

**Functional Requirements:** a. Monitor sales transactions and forecasts b. Set up and edit sales contracts with customers based on prices and discounts of different customer groups c. Set up and edit sales returns function (e.g. warehouse, location, customer, product details, remarks, etc) d. Generate customer reports by sales e. Generate sales cycle analytics f. Conduct sales tracking (e.g. to analyse sales pipeline, by product category, etc)

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Dashboard Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Accounting, Inventory, and Sales Integration

**Main Question:** Are the Accounting Management function, Inventory Management function and Sales Management function tightly integrated? E.g. Inventory and Accounting vendor groups are the same, Forecasting (Inventory) data should be linked to Financial reports (Accounting), Inventory Management (Inventory) should be linked to Sales/Delivery order (Sales)

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

***

### Q21 🟡 Preferred - AI Powered Inventory Management

**Main Question:** Does your solution come with AI Powered Inventory Management features?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q23]

\--

### Q22 🔴 Mandatory Follow-up - AI Powered Inventory Management - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Describe your AI Powered Inventory Management features. Examples are:

**Feature Examples:** a. Ability to perform demand prediction for inventory management b. Ability to automate routine sales tasks (e.g. update forecasts and determine call lists) c. Ability to automate customer responses, data capture activities, and follow-ups d. Ability to analyse and predict potential conversion of pipelines e. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q23 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q24] ○ No \[⚠️ Cannot Proceed]

***

### Q24 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Next: Q27]

\--

### Q25 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q26] ○ No \[⚠️ Cannot Proceed]

\--

### Q26 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q25*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q27] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q27 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q28] ○ No \[Next: Q30]

\--

### Q28 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q27*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q29] ○ No \[Assessment Finished]

\--

### Q29 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q28*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

### Q30 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q27*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q31] ○ No \[Assessment Finished]

\--

### Q31 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q30*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Fleet Management System

Combine telematics and GPS technology to monitor vehicle locations and performance in real-time. The system provides comprehensive fleet visibility, tracking vehicle conditions, optimising routes, and enabling data-driven fleet maintenance and operational decisions.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Fleet Management and Tracking

**Main Question:** Does your solution include telematics and GPS tracking technology which provides the company a complete overview of its fleet's real-time location and operating condition?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Customised Fleet Journey Management

**Main Question:** Does your solution allow the company to tailor the fleet journey and manage cost control?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Route Planning and Optimisation

**Main Question:** Does your solution automate route planning and optimisation based on data collected?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Data Analytics and Insights for Vehicles

**Main Question:** Does your solution provide data gathering and analysis on the following:

**Requirements:** a. Mileage and fuel consumption\
b. Vehicle maintenance and servicing tasks

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Common Data Standard TR128

**Main Question:** Does your solution comply with the Common Data Standard for the shipping container logistics ecosystem as defined in TR 128?

**Compliance Requirements:** To comply, you will need to have obtained a Letter of Conformance from an approved auditor. For detailed information about the certification process and requirements, please refer to the Guide for TR128. \[<https://www.enterprisesg.gov.sg/-/media/08032FA745C941FFB30BF9F4139BF5F3.ashx>]

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making\
b. Recognise text, images to shorten time taken for manual inputs of forms\
c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Note:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

### Q15 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors\
ii. The cybersecurity certification the organisation has met\
iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

### Q17 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met\
ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Fleet Safety Management System

Enhance vehicle safety through advanced monitoring technologies. The system incorporates driver status monitoring, blind spot detection, and/or driver assistance features to prevent accidents, improve driver behaviour, and ensure safer fleet operations

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Fleet Safety Management

**Main Question:** Does your solution provide at least one of the following features?

**Safety Features:** a. Driver Status Monitoring System (DSMS) to detect and alert the driver of fatigue events (e.g. closing of eyes) and distractions (e.g. making phone calls) b. Advanced Driver Assistance System (ADAS) to alert the driver of potential collisions (e.g. forward collision warning, lane departure warning, and pedestrian or cyclist collision warning, etc) c. Blind Spot Detection System to improve situational awareness and alert the driver of pedestrian, cyclist or motorcyclist, or worker in the vehicle's blind spot

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Driver Behaviour Monitoring

**Main Question:** Does your solution allow driver behaviour monitoring to uncover poor driving habit (e.g. harsh braking and acceleration, harsh cornering, tailgating and speeding, etc)?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - Vehicle Cabin Monitoring

**Main Question:** Can your solution provide Indoor Analogue Camera to capture the activity in vehicle cabin?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Fleet Security Features

**Main Question:** Does your solution provide fleet security features (e.g. remote locking)?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):**

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

### Q8 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q13]

\--

### Q11 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

### Q14 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q13*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Digital Marketing Packages

Combine various vendor-provided marketing services including Search Engine Optimisation (SEO), Search Engine Marketing (SEM), and Social Media Marketing to enhance brand visibility, drive website traffic, and boost revenue generation through targeted digital campaigns.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Digital Marketing Evaluation Report

**Main Question:** Do you provide a comprehensive Digital Marketing Evaluation Report named \[Evaluation Report.pdf]? The document MUST include the following sections with the section headers:

**Required Sections:** 2. Digital Marketing Packages Requirement

3. Digital Marketing Needs Analysis
4. Digital Marketing Strategy Development
5. Digital Marketing Campaigns
6. Digital Assets Creation
7. Review and Recommendation

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q2 🔴 Mandatory - Digital Marketing Packages Requirement

**Main Question:** Does your evaluation report contain a section called "Digital Marketing Packages Requirement" that follow the structure below?

**Package Requirements:** Each campaign must specify: a. Scope of work

* Each Digital Marketing campaign must be listed as an individual line item in the pricing package b. Target KPIs (Each package MUST consist of at least 1 Revenue Centric KPI in the form of ROAS or leads increase target) c. Digital assets with specific quantities (e.g., "6 social media posts, 4 blog articles, 2 infographics")
* Vendors are not allowed to use "up to" X digital assets
* Vendors may use specific deliverables (i.e. 6 blog posts) or range (i.e. 5-7 blog posts) d. Review and recommendations e. Handover checklist documentation

**Exclusions:** Note: The following items should be excluded from the package and vendors should not advertise or market any non-supportable items for free. \[1] Advertising cost e.g. ppc, ad buy on online or offline platforms, buying likes, influencer fees, including management fee of ad buy\* \[2] Outbound marketing costs e.g. outsourced telemarketing services, email subscriptions, purchase of marketing database \[3] Third-party website hosting, maintenance, SSL costs \[4] Purchase of hardware e.g. for livestreaming \[5] Third-party training courses

\*Advertising is part of the package, but its related costs are not supportable by the grant and shall be borne by SME

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Digital Marketing Needs Analysis

**Main Question:** Does your evaluation report contain a section called "Digital Marketing Needs Analysis" that follow the structure below?

**Evaluation Criteria:** Sample Portfolio showing your assessment methods of SMEs:

1. Business needs (e.g. questionnaires covering budget, goals, competitors, SWOT, gap analysis, etc.)
2. Digital presence (e.g. website audit, social media analysis)
3. Digital assets (e.g. brand guides, images, post, etc.)

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Digital Marketing Strategy Development

**Main Question:** Does your evaluation report contain a section called "Digital Marketing Strategy Development" that follow the structure below?

**Strategy Requirements:**&#x20;

a. Does your packages involve methodology or plan for the development of the digital marketing strategy?&#x20;

b. Does your proposed solution support the development and implementation of a comprehensive digital marketing strategy? (Key components of the strategy should include: Objectives, KPIs, Target Audience, Budget, Creation of digital assets, client engagement plan \[project activity with timeline] )

c. Do you have a structured conflict resolution framework in place to manage disputes and enhance client satisfaction?

**Key Components:** Key components of the strategy should include: Objectives, KPIs, Target Audience, Budget, Creation of digital assets, client engagement plan \[project activity with timeline].

**Evaluation Criteria:**

1. Methodology or plan (Eg: communication plan with SME, tools that identifies what is needed for the campaign)
2. Sample portfolio with service-specific tables (one each for SEO, social media, etc.) showing all above components given in (b).
3. Conflict resolution Framework: i. Escalation process and contact details (where customer is aware of the contact number, designation, name of the management personnel for issues escalation) ii. Revision limits iii. Refund policy

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Digital Marketing Campaigns

**Main Question:** Does your evaluation report contain a section called "Digital Marketing Campaigns" that follow the structure below?

**Campaign Requirements:** a. Do you execute at least 2 digital marketing campaigns? Example:

* Social Media Advertising (SMA) (e.g. Facebook, Instagram, TikTok Ads)
* Search Engine Optimisation (SEO), Content Marketing, Influencer Marketing, E-mail Marketing, Search Engine Marketing (SEM), Social Media Marketing (SMM)
* In-platform campaigns, Ad campaigns, Livestream b. Do you set measurable KPIs targets for campaigns? (e.g. ROAS, leads, engagement, CTR etc ) c. Do you use analytics tools to track and optimise campaigns? (e.g. Google Analytics, Facebook Analytics)

**Evaluation Criteria:** Submit campaign report for all the services with supporting examples from past portfolios, each including:

1. Campaign Details with timeline, list out digital assets created for the campaign
2. Campaign outcome-based on objectives and KPIs
3. Variable proof of campaign: Provide campaign proof showing screenshots, live links, campaign period and ad spent invoice, plus analytics reports with performance data from platforms like Facebook, Google Analytics etc. showing unique company identifier

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Digital Assets Creation

**Main Question:** Does your evaluation report contain a section called "Digital Assets Creation" that follow the structure below?

**Asset Requirements:** a. Does your package include creation of necessary digital assets? Examples of digital assets include banners, content posts, photographs and videos.

**Evaluation Criteria:**

1. Submit evidence of implemented digital assets (in form of screenshots, URL etc) you created for each of the campaign types offered in the "Digital Marketing Packages Requirement" section

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Review and Recommendation

**Main Question:** Does your evaluation report contain a section called "Review and Recommendation" that follow the structure below?

**Review Requirements:** a. Do you review campaign performance and use data analysis to provide improvement recommendations for SME's online presence or sales? b. Do you provide complete handover of digital assets, strategy documents, and ad accounts to SMEs upon project completion?

**Evaluation Criteria:**

1. Review and recommendation for all the campaigns based on analysis of campaign data.
2. Handover checklist with details of reports, passwords, accounts, digital assets etc with proper sign off between two parties.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Leads Management

**Main Question:** Does your package include: a. Development of processes to improve SME's conversion of leads generated from their online channels b. Recommendations and training on best practices in leads management

Note: Third-party training cannot be packaged into Annex 3 packages.

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - Leads Management - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Please elaborate on the processes for improving SMEs' conversion of generated leads, as well as the recommendations and training on best practices in lead management that your package provides.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🟡 Preferred - SME Segmentation

**Main Question:** Does your package solution cater to a specific SME segment and meet their specific needs? Examples of SME segmentation include: by industry, size, needs, B2B/B2C, digital maturity etc.

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - SME Segmentation - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Please elaborate on how your package solution cater to and meet the needs of the particular SME segment (e.g. by industry, size, B2B/B2C, digital maturity, etc.)

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

### Q13 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

### Q15 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Preparation for Digital Marketing Submission

Learn how to prepare a submission for digital marketing package


# Document Management and Mobile Access System

Enable secure cloud-based file storage and synchronisation across devices. The system provides document access control, search functionality, version tracking, and automated backups while ensuring secure mobile access to business files.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Can your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Document Management

**Main Question:** Does your solution enable the company to perform the following functions?

**Core Functions:** a. Synchronise digital documents across multiple sites b. Scan, capture, and digitise documents from multiple sources (i.e. paper files, emails and attachments, and external applications like CRM or ERP) c. Create user permissions and authorisation to restrict data access to selected personnel on a document-by-document basis d. Ability to search by text in document, file name, file format, indexing number, user, etc e. Provide audit trail to track the changes made to a document (including name of user, modification types (deletion, renaming, editing), timestamps, etc) f. Provide local data backup for disaster recovery g. Provide version control for retrieval (with minimum 5 versions or minimum 30 days of recovery period) h. Allow document collaboration and file-sharing

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - AI Powered Document Management

**Main Question:** Does your solution come with AI features for Document Management, such as:

**AI Features:** a. Automate document classification and processing b. Data extraction and document clustering c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q4 🟡 Preferred - Optical Character Recognition Content Search

**Main Question:** Does your solution come with Optical Character Recognition (OCR) functionalities?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

### Q5 🔴 Mandatory Follow-up - OCR Content Search - Elaboration

*This question appears only if you answered "Yes" to Q4*

**Main Question:** Please elaborate on the OCR functionalities such as:

**OCR Capabilities:** a. OCR content search within the document b. OCR content search in the search function c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🟡 Preferred - Document Regulatory Compliance

**Main Question:** Is your solution compliant to security and policy regulations regarding documents and records?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

\--

### Q7 🔴 Mandatory Follow-up - Document Regulatory Compliance - Elaboration

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Please briefly elaborate on the security measures implemented to ensure the security and confidentiality of the document stored in your solution.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

### Q14 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q13*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Multichannel E-commerce Software (MES)

Centralise management of multiple online sales channels through a single interface. The system synchronises inventory, orders, and listings across various marketplaces and webstores in real-time, while providing analytics dashboard for comprehensive sales performance monitoring.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Multi-channel Integration

**Main Question:** Can the solution integrate to multiple channels (minimally 2 channels), such as marketplaces (e.g. Amazon, Shopee, Lazada, etc.) and webstores (brand.com), and allow for management in a single dashboard , including inventory management and order processing?

Please specify the number and names of e-commerce platforms that the solution has already been integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Real-time Tracking

**Main Question:** Does the solution allow real-time or near real-time management of sales, orders, and inventory through a single interface?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Product Listing Management

**Main Question:** Can the solution allow for the creation and modification of product listings (e.g. product details, product description, product variations, product images, etc) across channels, and enable the uploading of multiple product listings at once while adhering to each channel's specific requirements?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Data Fetch

**Main Question:** Can the solution fetch data such as product listings, order details, and delivery status from the enterprise's accounts on their existing e-commerce channels, as well as pass data from the solution to the integrated e-commerce channels?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Inventory Management and Synchronisation

**Main Question:** Can the solution set up inventory product details (e.g. weight, size, variations, etc.), upload multiple inventory products, track inventory levels across various channels, and synchronise them as sales are made?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Dashboards and Reports (MES)

**Main Question:** Can the solution track sales and performance across multiple channels on a single dashboard, and generate reports on key performance metrics and insights (e.g. sales, transactions, order volumes, etc.)?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Marketing and Campaign Management

**Main Question:** Can the solution create and execute campaigns and digital marketing activities for the e-commerce channels?

**Campaign Types:** a. Onsite marketing campaigns (promotions, gift with purchase, flash sale on marketplaces) and/or b. Offsite marketing campaigns (paid media ads, search ads)

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Analytics and Insights

**Main Question:** Can the solution provide recommendations, and forecasts based on sales performance or inventory status?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Logistics Integration

**Main Question:** Can the solution integrate with third-party logistics software or database to provide real-time or near real-time data on order delivery status?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Fulfilment Document Generation

**Main Question:** Can the solution generate invoices, shipping labels, picking lists, and other fulfilment-related documents?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Financial Reconciliation

**Main Question:** Can the solution reconcile, consolidate, and classify all transactions including the sales, payments, and expenses (e.g. platform fees, marketing costs, logistics costs, etc.)?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q18 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

\--

### Q19 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q21 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q18*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Chatbots for Customer Engagement

Automate customer interactions through AI-powered digital assistants. The system handles customer enquiries, provides personalised recommendations, collects feedback, and manages lead generation, enabling 24/7 customer engagement while streamlining sales conversions and service improvement.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Gen AI

**Main Question:** Does your solution utilise GenAI functionality to power the Chatbot?

**GenAI Definition:** GenAI chatbots use a technology called Generative Pre-Trained Transformer (GPT) based on a Large Language Model. Compared to previous generation chatbots, GenAI chatbots have better natural language processing (NLP), providing more accurate responses and engage in context-aware conversations with the customers. Additionally, these chatbots can learn from user interactions and improve their responses over time, resulting in a more personalised and effective user experience.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Risk Mitigation Briefing

**Main Question:** Does the vendor commit to conducting a briefing (online or in-person) for each potential client before client purchases the solution, to ensure that each client is aware of the risks associated with using the Gen AI solution for its business, and the best practices to mitigate these risks?

**Requirements:** \[1] Vendors must adequately brief SME participants on these associated risks to ensure responsible Gen AI solution usage. Vendors will also be required to secure SMEs' acknowledgement of the associated risks before provisioning the solution. \[2] Vendors may also consider providing documentation or further information about their models' training data to their clients.

**Submission Requirements:** Please submit the following documents: a. Briefing materials (e.g. slides, pre-recorded video, etc.) that will be used to brief each client on the risks of using the Gen AI solution (e.g. accuracy, bias, reliability, toxicity, IP infringement, privacy, etc.) and risk mitigation measures (e.g. setting escalation criteria, out-of-bounds markers, etc.) b. Template of the customer quotation or contract where each client's acknowledgement of this briefing will be secured

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Setup and Data Pipeline

**Main Question:** Does your solution enable the company to perform the following functions during setup?

**Setup Functions:** a. Upload company-specific knowledge base in varied formats (e.g. FAQ flowcharts, customer service manuals, brand information or guide, etc.) to contextualise generated responses b. Set escalation criteria to automatically escalate certain type(s) of customer enquiries to human agents c. Allow business owners to define the conversation boundaries to restrict the chatbot responses to information available on the business website

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - AI Chatbot Knowledge Ingestion

**Main Question:** Can your solution ingest at least TWO of the following data sources to build the chatbot's knowledge base?

**Data Sources:** a. Direct website crawl (with website URL as input) b. Direct database integration (via SQL, API, etc) Examples of database integration may include: i. CRM (Customer data such as transaction history, communication history, loyalty programme, etc) ii. Sales or E-Commerce platform (Sales data such as SKUs, available stock, prices, campaign, promotion, etc) iii. Any other integrations to optimise and enhance customer engagement c. Structured files, such as FAQ with Question-and-Answer pairing, Product and Services offerings, etc d. Unstructured files, such as PDF or Word Document

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Customer Communication Platform Integration

**Main Question:** Can your solution be deployed on at least ONE of the following digital platforms or channels for customer engagement?

**Digital Platforms:** a. Company website b. Messaging apps (e.g. WhatsApp, Facebook Messenger, Telegram, etc) c. Email d. Social media (e.g. Instagram, TikTok, etc) e. Customer Relationship Management (CRM) system f. Audio calls or call center

**Note:** Vendor must provide implementation services to ensure that the solution is successfully integrated with the company's selected digital platform(s).

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Frontend and/or Backend Customer Engagement Capabilities

**Main Question:** Can your solution fulfill EITHER Frontend Customer Engagement Capabilities OR Backend Customer Engagement Capabilities?

Please indicate "Yes" for both question number 7 and 8 if your solution can fulfill BOTH requirements.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Frontend Customer Engagement Capabilities

**Main Question:** Can your solution provide a customer-facing chatbot that demonstrates at least TWO of the following capabilities?

**Frontend Capabilities:** a. Leads Management: to automatically collect information on and follow up on leads, facilitating tracking and conversion. b. Sales Assistant: to guide customers through the sales process, answering informational enquires and providing recommendations

For chatbots taking the role of sales assistant in an e-commerce environment, the two following features must be demonstrated: i. Assist the customer to complete an end-to-end sales via the chatbot conversation ii. Provide product upselling and cross-selling recommendation during the sales checkout process

c. Post-Sales Customer Support: to perform post-sales support, providing customers with information (e.g. order status, product or service support, escalation, etc) d. Scheduling and Reservation: to assist customers in making bookings based on resource (e.g. personnel, facility) availability, customer's past preferences, etc.

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Backend Customer Engagement Capabilities

**Main Question:** Can your solution provide an internal-facing chatbot that demonstrates at least THREE of the following capabilities?

**Backend Capabilities:** a. Suggestions or Improvements for Customer Engagement Agents: Generate real-time suggestions to improve responses or automatically translate messages b. Automated Reminders for Follow-Ups: Provide timely reminders to agents to provide follow-up actions for all instances of customer engagement c. Centralised Platform for Multi-Channel Customer Engagement: Provide a centralised platform for agents to manage customer conversations across multiple channels (e.g. Website, Social Media, Messaging Apps etc.) d. Real-Time Interventions: Enable managers to intervene conversations and take actions where necessary e. Creation of Customer Profiles: Identify customer characteristics and build comprehensive customer profiles based on conversations with customers

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Post-deployment Self-learning and Training Capabilities

**Main Question:** Can your solution self-learn to improve the accuracy and/or relevance of chatbot responses generated over time?

**Self-learning Examples:** a. Use reinforcement learning or feedback loops based on positive and negative customer interactions b. Learn from instances when a human agent takes over to answer customer enquiries c. Enable manual "supervised" training or customisation of chatbot responses and conversation flows d. Automatically retrain the chatbot based on business updates to their website or information

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Automatic Source Citations

**Main Question:** Can your solution automatically cite sources or references as part of its factual responses (e.g. to reduce hallucination risk when answering factual enquiries)?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Multi-Language Support

**Main Question:** Can your solution support conversations with customers in more than ONE language, other than English (e.g. Simplified/Traditional Mandarin, Bahasa Melayu, Tamil, etc.)?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Audio-based Conversation Support

**Main Question:** Can your solution support conversations with customers over voice chat?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🔴 Mandatory - Dashboards and Reports (Chatbots)

**Main Question:** Can your solution track customer leads and conversation histories on a single dashboard, and generate reports on key performance metrics and customer insights?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - Project Moonshot Evaluation

**Main Question:** Has your solution undergone evaluation by Project Moonshot?

**Project Moonshot Information:** Project Moonshot is a LLM Evaluation Toolkit, designed to integrate benchmarking, red teaming and testing baselines. It helps developers, compliance teams, and AI system owners manage LLM deployment risks by providing a seamless way to evaluate their applications' performance, both pre- and post-deployment. More information on Project Moonshot is provided at <https://aiverifyfoundation.sg/project-moonshot/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

### Q15 🔴 Mandatory Follow-up - Project Moonshot Evaluation - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please provide the report generated by Project Moonshot upon completion of the evaluation, where vendors are required to test their Gen AI system with the benchmarks stated below, which are available on Project Moonshot:

**Required Benchmarks:** i. MLCommons AI Safety Benchmark - Hate ii. Bias Benchmark for QA (BBQ) iii. UCI Adult Dataset

Complete the Moonshot testing form: <https://form.gov.sg/6699c08bfc8b1217e4d6662e>

Click "Yes" to proceed after you have uploaded the report and completed the form.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

### Q18 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

### Q21 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q23 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

### Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Marketing and Sales Content Generation

Leverage AI to create customised marketing materials by automating creation of social media posts, advertisements, emails, and images, while providing campaign ideation support and market insights to enhance marketing effectiveness and sales strategies.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Gen AI

**Main Question:** Does your solution utilise GenAI functionality to understand the company's marketing and/or sales requirements and generate new and relevant content (text, images, videos, audio, reports, etc.) based on the context?

**Requirements:** \[1] The solution platform and interface should be tailored specifically to support the company in achieving marketing- and sales-focused outcomes (i.e. should not be a general-purpose, non-specialised tool for content generation). \[2] Solutions which generate templated marketing or sales content and which are unable to adapt its outputs based on the company's inputs and prompts do not qualify for this solution category.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Risk Mitigation Briefing

**Main Question:** Does the vendor commit to conducting a briefing (online or in-person) for each potential client before client purchases the solution, to ensure that each client is aware of the risks associated with using the Gen AI solution for its business, and the best practices to mitigate these risks?

**Requirements:** \[1] Vendors must adequately brief SME participants on these associated risks to ensure responsible Gen AI solution usage. Vendors will also be required to secure SMEs' acknowledgement of the associated risks before provisioning the solution. \[2] Vendors may also consider providing documentation or further information about their models' training data to their clients.

**Submission Requirements:** Please submit the following documents: a. Briefing materials (e.g. slides, pre-recorded video, etc.) that will be used to brief each client on the risks of using the Gen AI solution (e.g. accuracy, bias, reliability, toxicity, IP infringement, privacy, etc.) and risk mitigation measures (e.g. setting escalation criteria, out-of-bounds markers, etc.) b. Template of the customer quotation or contract where each client's acknowledgement of this briefing will be secured

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Knowledge Base Upload

**Main Question:** Does your solution enable the company to upload company-specific knowledge base, brand voice and image, and requirements in varied formats (e.g. brand guide, sample marketing/sales materials, marketing brief, etc) to contextualise generated outputs?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Marketing Asset Generation

**Main Question:** Does your solution enable the company to perform at least ONE of the following functions?:

**Functions:** a. Sales and Marketing Asset Generation: Create sales and marketing assets tailored for the different audience groups b. Market Research: Define market research parameters and organise the generated insights and reports on a single dashboard

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Direct Integration Connection

**Main Question:** Can your solution be connected to at least TWO of the digital platforms/channels/tools to streamline data collection and/or publishing of generated content?

**Digital Platforms:** a. Social media platforms (e.g. Facebook, Instagram, LinkedIn) b. Content management systems (e.g. Wordpress, Wix) c. E-commerce platforms (e.g. Shopify, Shopee) d. Messaging apps (e.g. WhatsApp, Telegram) e. Email (e.g. Outlook) f. Search engines (e.g. Google) g. Customer Relationship Management (CRM) system h. Marketing Campaign Tools

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Content Generation Capabilities

**Main Question:** Does your solution demonstrate at least THREE of the following capabilities?

**Content Generation Capabilities:** a. Generate short-form or long-form copywriting (text) and optimise writing b. Generate visual or audio content (images, animations, videos, music, etc) c. Customise and personalise marketing collaterals or sales outreach (e.g. emails) based on customers profile and requirements d. Convert marketing and sales content from one format to another (e.g. blog post to video, image to product description, etc) e. Facilitate development and/or evaluation of new marketing & sales campaign concepts, content ideas, or product innovations f. Improve effectiveness of marketing or sales content generated (e.g. SEO research and optimisation, A/B Testing, etc) g. Perform market research on consumer audiences or competitors and track market trends in real-time h. Generate actionable insights in the form of dashboards or research reports to enhance marketing or sales campaigns

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Self-learning and Training Capabilities

**Main Question:** Can your solution be trained to improve the quality and relevance of the content generated?

**Training Examples:** a. Use reinforcement learning based on automated performance tracking and analytics of the published marketing or sales content b. Learn from instances when a human agent manually edits the generated content or refines the original prompt and layers on additional instructions to improve the generated content c. Enable manual "supervised" training based on user ratings of the generated content

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Analytics and Reporting

**Main Question:** Can your solution track the performance of the published marketing or sales content (e.g. user interactions with social media content, sales conversion rates, etc.) on a single dashboard, and generate reports on key performance metrics, customer insights, or market insights?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Multi-Language Support

**Main Question:** Can your solution support content generation or market research in more than ONE language, other than English (e.g. Simplified/Traditional Mandarin, Bahasa Melayu, Tamil, etc)?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Safeguards against IP infringement

**Main Question:** Does your solution include in-built safeguards against IP infringement (e.g. Plagiarism Checker)?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Project Moonshot Evaluation

**Main Question:** Has your solution undergone evaluation by Project Moonshot?

**Project Moonshot Information:** Project Moonshot is a LLM Evaluation Toolkit, designed to integrate benchmarking, red teaming and testing baselines. It helps developers, compliance teams, and AI system owners manage LLM deployment risks by providing a seamless way to evaluate their applications' performance, both pre- and post-deployment. More information on Project Moonshot is provided at <https://aiverifyfoundation.sg/project-moonshot/>

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - Project Moonshot Evaluation - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Please provide the report generated by Project Moonshot upon completion of the evaluation, where vendors are required to test their Gen AI system with the benchmarks stated below, which are available on Project Moonshot:

**Required Benchmarks:** i. MLCommons AI Safety Benchmark - Hate ii. Bias Benchmark for QA (BBQ) iii. UCI Adult Dataset

Complete the Moonshot testing form: <https://form.gov.sg/6699c08bfc8b1217e4d6662e>

Click "Yes" to proceed after you have uploaded the report and completed the form.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

### Q15 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

### Q18 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

### Q19 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q20 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q17*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Carbon Management Solution

Track and measure an organisation's greenhouse gas emissions from direct and indirect business activities by calculating carbon footprint using recognised emissions factors, enabling businesses to monitor, report, and manage their environmental impact effectively.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1** 🔴 **Mandatory** - Cloud-Based Solution

**Main Question:** Is your solution cloud-based, offering secure, scalable, and accessible services from anywhere with an internet connection?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2** 🔴 **Mandatory** - Organisation-level Scope 1 and 2 and/ or Product/ service-Level Carbon Emissions Calculation

**Main Question:** Does your solution calculate Scope 1 and 2 carbon emissions at the organisation level and/or calculate carbon emissions at the product/service level, in accordance with the GHG Protocol, ISO 14064-1, ISO 14040, 14044, 14067, PAS 2050, or other sector-specific methodologies?

**Examples:** a. Scope 1: direct emissions from owned or controlled sources (e.g. company facilities, company vehicles). b. Scope 2: indirect emissions from the generation of purchased energy (e.g. purchased electricity, steam, heating and cooling) consumed by the reporting company). c. Cradle-to-grave product/ service-level carbon emissions: includes all emissions associated with the full life cycle, from raw material extraction or service inputs to end-of-life treatment, covering both upstream and downstream supply chains. d. Cradle-to-gate product/ service-level carbon emissions: includes all emissions from raw material extraction or service inputs up to the point the product leaves the factory gate or service delivery - i.e. before distribution, use, or disposal.

**Submission Requirements:** Please indicate the level at which your solution calculates carbon emissions: a. Organisation level b. Product/service level c. Both organisation and product/service levels

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q3** 🟡 **Preferred** - Organisation-level Scope 3 Emissions Calculation

**Main Question:** Does your solution calculate Scope 3 at the organisation level, in accordance with the GHG protocol and/or ISO 14064-1?

**Examples:** a. Indirect emissions from upstream activities i. Purchase of goods and services ii. Capital goods iii. Fuel and energy related activities iv. Transportation and distribution v. Waste generated in operations vi. Business travel vii. Employee commuting viii. Leased assets

b. Indirect emissions from downstream activities i. Transportation and distribution ii. Processing of sold products iii. Use of sold products iv. End-of-life treatment of sold products v. Leased assets vi. Franchises vii. Investments

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

**Q4** 🔴 **Mandatory** - Emission Factors for Carbon Footprint Calculation

**Main Question:** Does your solution calculate carbon emissions for the company's activities and products based on locally developed emissions factors such as SEFR, EMA and internationally recognised emission factors such as IPCC, IEA, EPA, or UK DEFRA, or sector-specific emission factors (e.g. Ecoinvent, GaBi)?

**Examples:** a. Suggest the appropriate emission factor to use based on the company's sector, country of operation, or product/service. b. Allow the company will be able to overwrite the solution's emission factor suggestion and select the relevant emissions factor to use. c. Accommodate the addition of emissions factors that may be developed in future.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5** 🔴 **Mandatory** - Guidance and Support Provision

**Main Question:** Does your solution provide guidance and support on setting up and navigating the system?

**Example:** Company gets guidance on the necessary data to input and where to input data into the system.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6** 🟡 **Preferred** - Optimisation and Decarbonisation Roadmap

**Main Question:** Does your solution incorporate target-setting and recommend decarbonisation pathways and solutions?

**Examples:** a. Get advice and recommendations on emissions reduction b. Enable target setting and tracking to allow monitoring of emissions performance over time c. Recommend and prioritise suitable abatement solutions and is able to estimate emissions savings through various solution adoption

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

**Q7** 🔴 **Mandatory** - Emissions Report Generation

**Main Question:** Does your solution translate accounting data into an emissions report, including emissions summary and emissions hotspots?

**Example:** Company uses the solution to generate an emissions report including year-on-year comparisons (if available) of its emissions profile and hotspots.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8** 🟡 **Preferred** - Public Reporting and Disclosures on International Platforms

**Main Question:** Does your solution facilitate the generation of a sustainability report in line with frameworks such as ISSB, GRI, SASB, or TCFD and disclosure on international platforms such as CDP or SBTi?

**Example:** Company is able to use the solution to compile data required for public reporting and disclosures on international platforms.

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9** 🟡 **Preferred** - Emissions Data Verification

**Main Question:** Does your solution suport verification/ assurance of emissions data?

**Examples:**

1. Company can obtain verified emissions reports that align with national or international regulatory requirements (e.g. CBAM).
2. Company can obtain verified emissions reports to meet buyer/ financial institution requests.

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10** 🟡 **Preferred** - Benchmarking

**Main Question:** Does the solution compare the company's sustainability performance against industry benchmarks and identify areas for improvement?

**Examples:** a. Company is able to understand its relative emissions performance against industry peers. b. Suggest potential areas for improvement according to industry best practices.

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11** 🟡 **Preferred** - Supply Chain Emissions Management

**Main Question:** Does your solution track and manage supply chain emissions?

**Example:** The solution provides access to company's supply chain to directly provide data and view selected dashboards.

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

**Q12** 🔴 **Mandatory** - Data Collection

**Main Question:** Does your solution support multiple data collection methods beyond manual data entry, such as CSV imports, data from sensors, auto-population from invoices, and other sources, to enable the management and analysis of data related to carbon emissions?

**Examples:** a. Manual data entry: Enable manual data entry via user-friendly interface. b. Data from sensors: Automatically collects real-time electricity usage data from sensors installed. c. Invoice processing: Integrate with company's accounting software to automatically extract relevant data from utility bills and fuel invoices. d. Integration with ERP: Connect with company's Enterprise Resource Planning (ERP) system to collect data. e. Third-party data APIs: Connect to external APIs to collect relevant data for auto-population into the system.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13** 🔴 **Mandatory** - Emissions Dashboards

**Main Question:** Does your solution include a dashboard that allows for visualising data, including overall emissions profile and breakdown by scope?

**Examples:** a. Overview: Company owners use a high-level dashboard showing total emissions across all scopes. Interactive charts allow them to drill down into specific regions or business units with a single click. b. Emissions breakdown: Sustainability teams use stacked bar charts and treemaps to visualise the breakdown (reflect percentage split) of emissions by source and by scope.

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14** 🔴 **Mandatory** - User-Friendly Interface

**Main Question:** Does your solution provide an intuitive and role-based interface, allow users to save and retrieve data from their last login session, and easily translate data (e.g. dashboards and reports) into printable, exportable and user-friendly formats?

**Examples:** a. Intuitive navigation: A manager based overseas, with minimal training, easily navigates the system to input data. The experienced sustainability director in Singapore efficiently drills down through multiple layers of data using consistent, logical menu structures. b. Role-based dashboards: When logging in, each user sees a dashboard relevant to their role and responsibilities. c. Saving and exporting data: User can easily save and retrieve data from last log in session and data (e.g. emissions dashboards and reports) can be easily translated into printable, exportable and user-friendly formats.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15** 🟡 **Preferred** - AI Features

**Main Question:** Does your solution incorporate artificial intelligence capabilities to enhance carbon accounting processes, such as data collection through proxies, predictive analytics, anomaly detection, automated data categorisation or natural language processing?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

**Q16** 🔴 **Mandatory Follow-up** - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are: a. Data collection through proxies: Fill data gaps using suitable proxies and indicate relevant source information b. Predictive analytics: Forecast future emissions based on historical data and planned activities c. Anomaly detection: Automatically flag unusual spikes in emissions data for further investigation d. Automate data categorisation: Categorise and allocate emissions data to the correct scopes and categories e. Natural language processing: Extract relevant emissions data from unstructured text in invoices or reports

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17** 🔴 **Mandatory** - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

**Q18** 🟡 **Preferred** - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

\--

**Q19** 🔴 **Mandatory Follow-up** - Personal Data Protection

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

\--

**Q20** 🔴 **Mandatory Follow-up** - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

**Q21** 🟡 **Preferred** - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

\--

**Q22** 🟡 **Preferred** - CEM for Product Principal

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

**Q23** 🔴 **Mandatory Follow-up** - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

**Q24** 🟡 **Preferred** - CEM for Resellers

*This question appears only if you answered "No" to Q21*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

**Q25** 🔴 **Mandatory Follow-up** - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Field service management

Optimise mobile workforce operations by coordinating technician scheduling, work order tracking, and customer communications. The system streamlines maintenance and repair services, enabling efficient dispatch, real-time job status updates, and service delivery management.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Work Order Management and Scheduling

**Main Question:** Does your solution enable users to manage work order and technicians with the following features?:

**Work Order Management Requirements:**

* Create, assign, and track work orders from initiation to completion, including details such as customer information, job location, required skills and equipment, priority level, etc
* Schedule technicians based on their profile such as skill level, availability, or proximity to the job

**Example:** A manager assigns a technician to a high-priority job based on proximity and skill set.

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred - Work Order Automation using IoT

**Main Question:** Does your solution support integration with IoT sensors to trigger work orders and enable dynamic maintenance scheduling?

**Example:** An IoT sensor detects a malfunction in equipment and automatically generates a work order for repair.

🟡 Answer: ○ Yes \[Next: Q3] ○ No \[Next: Q3]

***

### Q3 🔴 Mandatory - Technician Mobile App

**Main Question:** Does your solution provide a mobile app that can be installed on technicians' mobile devices to access the following functions?:

**Mobile App Requirements:**

* Receive push notifications and view work orders
* Update job status with digital record such as text, e-signature, images and videos
* Allow data entry during offline mode and automatically sync data to cloud once online

**Example:** A technician updates job status with photos and e-signature while offline, which syncs once back online.

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Client and Contract Management

**Main Question:** Does your solution centralise customer data and site information, and manage contracts with the following features?:

**Contract Management Features:**

* Track contract expiry for proactive renewal management with automated reminders
* Manage site hierarchy that enables creation of detailed structures (e.g. buildings, levels, rooms) for technicians to locate assets during service calls

**Example:** A site manager receives automated reminders for contract renewals.

🟡 Answer: ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - HR System Payroll Automation

**Main Question:** Does your solution support integration with third-party HR systems to facilitate payrolls?

**Example:** Payroll data is automatically updated from the HR system.

🟡 Answer: ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Integration with Inventory Management System

**Main Question:** Does your solution support integration with third-party inventory management systems to keep track and update stock for on-site jobs?

**Example:** Inventory levels are updated in real-time after job completion.

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Asset Management

**Main Question:** Does your solution enable users to maintain a comprehensive asset register to capture equipment attributes, installation sites, lifecycle data and attached documents (such as technical manuals, drawings, photos)?

**Example:** An asset manager accesses lifecycle data and technical manuals for maintenance planning.

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Dashboards and Reports (FSM)

**Main Question:** Does your solution provide Dashboard and Reporting capabilities which can perform the following functions?:

**Dashboard and Reporting Requirements:**

* Show overall real-time monitoring of job status, technician availability and current locations, scheduling status, attendance and overtime report
* Generate attendance, jobsite (hours spent, type of job done) reports

**Example:** A manager reviews real-time job status and technician availability on a dashboard.

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - GenAI Automated Summaries

**Main Question:** Does your solution enable users to generate work order summaries using Generative AI that can:

**GenAI Summary Features:**

* Transform rough notes taken by technicians into well-organised summaries
* Write summaries that are concise and easy to understand

**Example:** A technician's rough notes are transformed into a clear and concise report.

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Capabilities:**

* Generate output, identify items, or provide recommendations based on training models to improve decision-making
* Recognise text, images to shorten time taken for manual inputs of forms
* Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

### Q14 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

\--

### Q15 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Requirements:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q16 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:**

* The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

### Q19 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q16*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:**

* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# AI Accounting Automation

Enables companies to automate key accounting processes such as data extraction, data entry, categorisation, and reconciliation. The solution integrates with popular accounting systems to ensure seamless data flow, and features self-learning capabilities that allow it to improve over time based on user input.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Integration with Accounting Management Systems

**Main Question:** Can your solution facilitate seamless data flow by integrating with various accounting systems to minimise manual data entry?

**Example:** The solution can connect with accounting systems, allowing automatic synchronisation of financial data and reducing the need for manual input.

**Submission Requirements:** Provide a list of accounting systems that can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q2 🔴 Mandatory - Model Accuracy

**Main Question:** Can your solution maintain a high level of accuracy in accounting automation tasks to minimise manual intervention?

**Example:** The solution achieves an accuracy rate of over 95% in invoice processing, determined by cross-referencing processed outputs with manually verified data.

**Submission Requirements:** Please state the expected accuracy level of your solution and how it is determined.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Automated Data Extraction

**Main Question:** Can your solution automatically extract data and relevant information from a wide range of document types, including images, text-based files, or unstructured formats, without relying on predefined templates or requiring additional setup?

**Example:** The solution extracts relevant information from receipts and invoices in various formats, automatically identifying key data points like dates, amounts, and vendor names.

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Automated Data Entry

**Main Question:** Can your solution automatically enter extracted data into an accounting system while including error-checking mechanisms to ensure data integrity and accuracy when exporting data into the accounting system?

**Example:** Extracted data from invoices is automatically populated into the accounting system, with built-in checks to validate data accuracy before final entry.

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Reconciliation

**Main Question:** Can your solution automate the reconciliation of data extracted from various financial documents and flag any discrepancies found during the reconciliation process for prompt review and resolution?

**Example:** The solution compares bank statements with internal records, highlighting mismatches for quick resolution, thus streamlining the reconciliation process.

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Automated Categorisation

**Main Question:** Can your solution automatically classify various types of financial documents based on their content, and over time learn from user-defined preferences to improve categorisation accuracy without relying on pre-defined categories?

**Example:** Financial documents like invoices and receipts are categorised based on content, with the system adapting to user-defined categories to enhance sorting precision.

🔴 Answer: ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Post-deployment Self-learning and Training

**Main Question:** Can your solution allow users to give feedback or make manual corrections to its outputs, and then automatically learn from these user inputs to improve future accuracy and performance, without needing constant manual updates or vendor intervention?

**Example:** When a user corrects a miscategorised transaction, the system updates its logic and applies similar changes to future entries automatically.

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Multi-language Support

**Main Question:** Can your solution detect and process information in multiple languages other than English, enhancing accessibility for diverse users?

**Example:** The solution processes invoices in languages such as Mandarin, Bahasa Melayu, and Tamil, allowing users to work in their preferred language.

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - Multi-language Support - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Provide a list of all languages that can be supported.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q14]

\--

### Q12 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

\--

### Q13 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Requirements:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

### Q15 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

### Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please specify the following information:

**Required Information:**

* The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

### Q17 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q14*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:**

* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Cross Border E-Commerce Packages

Provide third-party services to set up a presence on overseas online B2B or B2C marketplaces, handle the end-to-end e-commerce operations such as order management and customer service, and provide business advisory to the SMEs.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

***

**Q1 🔴 Mandatory - SME Cross-Border e-Commerce Readiness Analysis**

**Main Question:** Does your service include a robust methodology for the assessment of SME's current state of products competitiveness or product portfolio, digital presence and capabilities, and readiness for cross-border e-commerce in consultation with the SME?

Use Case Example: For a Singapore F\&B brand that wishes to expand overseas, the service assesses the SME's readiness for overseas expansion by analysing product portfolio and market fit.

Submission Requirements:

* Upload documentation to showcase the methodology or plan for business advisory and current state assessment applied to the 5HCs submitted. Do note that the documents submitted are to be vendors' benchmark for quality and track record.
* Actual analyses and strategies to be submitted in the final project report as a chapter under "SME's cross-border e-commerce analysis" with the following: Assessment of SME's products competitiveness or product portfolio analysis; Assessment of SME's current digital presence and capabilities; Assessment of SME's readiness for cross-border e-commerce

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

**Upload Supporting Document Required:** \[File Upload]

***

**Q2 🔴 Mandatory - Target Market Analysis**

**Main Question:** Does your service provide a comprehensive overview of the target market(s) that includes: a. Assessments/reasons for the selection of the target market(s) and platform recommendation(s) b. Local e-commerce landscape c. Local consumer behaviour and preferences d. Competitor landscape analysis e. Guidance on compliance with local regulation and marketplace policies f. Assessment of SME's business needs and challenges in the target market(s)

Use Case Example: For a Singapore skincare brand that wishes to enter Thailand, the service provides detailed analysis of Thai FDA requirements for cosmetics, popular beauty marketplaces before recommending platform(s).

Submission Requirements:

* Upload documentation to showcase the methodology or plan for business advisory and current state assessment applied to the 5HCs submitted. Do note that the documents submitted are to be vendors' benchmark for quality and track record.
* Actual analyses and strategies to be submitted in the final project report as a chapter under "Market Analysis" with the above components a) to f).

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Cross-border E-commerce Strategy Development**

**Main Question:** Does your service facilitate the development of a marketplace entry strategy that will help the SME generate sales from their e-store?

Key Strategy Components: a. Objectives b. Target Key Performance Indicators c. Proposed e-commerce platforms d. Proposed e-store/product positioning e. Pricing strategy f. Logistics and fulfilment approach g. Target audience, customer acquisition and marketing plans h. Digital assets to be created i. Budget breakdown j. Implementation timeline with key milestones

Submission Requirements:

* Upload documentation to showcase the methodology or plan for business advisory and current state assessment applied to the 5HCs submitted. Do note that the documents submitted are to be vendors' benchmark for quality and track record.
* Actual analyses and strategies to be submitted in the final project report as a chapter under "Cross-border E-commerce Strategy" with the above components a) to j).

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Establish Overseas Marketplace Presence**

**Main Question:** Does your service identify and establish a presence on at least one overseas marketplace and ensure that all services are tailored to the specific requirements and best practices of the chosen marketplace(s)?

Use Case Example: eStore creation on marketplaces such as Amazon, eBay, or Alibaba, etc.

Additional Requirements: List all the marketplaces that you can help an SME to onboard to.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q5 🔴 Mandatory - Onboarding and Set-up Services**

**Main Question:** Does your service deliver end-to-end onboarding and set-up including: a. Marketplace account creation and verification b. Initial product listing creation and content localisation c. e-Store design and marketing material creation d. Payment gateway setup e. Logistics partner integration

Use Case Example: The service comes with a complete setup of a e-store including product listings, shipping integration, and payment setup that is in the language of the target market, optimised for the selected platform and complies with the marketplace policies and guidelines.

Important Notes:

* This solution is targeted at SMEs with domestic e-commerce presence and intend to market their products/services in overseas marketplaces.
* Service delivered to be submitted in the final project report as a chapter under "E-commerce set-up and management" with the following: Document proof of e-commerce set-up and presence within the overseas marketplace: This should include (1) screenshot of the e-store with live product listings, (2) screenshot of utilisation and management of digital marketing tools, (3) e-store live url and (4) screenshot of customer service management (e.g. customer chats, enquiry management). Document proof of digital assets creation (e.g. campaigns collateral, product listings, e-store banners).

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Channel Management**

**Main Question:** Does your service provide ongoing operational support that complies with marketplace-required service levels including: a. Manage daily orders (e.g., Monitor incoming orders and inform the SME promptly) b. Manage digital assets (e.g. Regularly update and refresh digital content) c. Manage product postings (e.g., Monitor and adjust product listings based on performance analytics) d. Monitor inventory levels (e.g., Manage stock allocation during campaigns) e. Manage customer services (e.g., Respond to inquiries and informs the SME of returns and refunds requests)

Important Notes:

* Management of local e-commerce stores will not be supported.
* Review of channel management support to be submitted in the final project report as a chapter under "Review and recommendations" with the following: Performance review: This should include screenshots of sales performance/report from the Seller Centre (or equivalent) of each e-commerce channel; Recommendations; Signed declaration the relevant accounts (e.g. e-commerce platform accounts), digital assets and strategy documents were handed over.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - Marketing Campaign Management**

**Main Question:** Can your service help businesses create and execute targeted marketing campaigns with segmentation, scheduling, and message creation templates?

Use Case Example: The service implements and manages promotional campaigns, SEO, and PPC advertising. Users can use templates or customise campaign messages for regular customers.

Important Note: Message charges (via SMS, social media, instant messaging platform (e.g. WhatsApp), etc.) will not be supported under the grant.

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

**Q8 🔴 Mandatory - Dashboards and Reports**

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Technical Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation. The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🔴 Mandatory - System Integration & Connectivity**

**Main Question:** Can your solution seamlessly integrate with external systems using open APIs to support functionalities such as deliveries, order processing, and data synchronisation?

Use Case Example: The e-store integrates with the SME's inventory management system, ensuring that the inventory level is synced across different channels.

Additional Requirements: List the available integrations.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q10 🔴 Mandatory - Cloud and Multi-Device Accessibility**

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

**Q11 🟡 Preferred - Automated Product Translation and Localisation**

**Main Question:** Can the system use AI to automatically translate and localise product content for different markets?

Use Case Example: The solution automatically translates product descriptions from English to Thai, Bahasa Indonesia, and Vietnamese while maintaining appropriate cultural context and marketplace-specific terminology

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

**Q12 🟡 Preferred - Marketing Content Generation**

**Main Question:** Can your solution leverage Generative AI to customise and generate customer-bound messages for marketing campaigns?

Use Case Example: The system can automatically generate and/or recommend content for marketing campaigns, ensuring personalised and engaging communication

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

***

**Q13 🟡 Preferred - Price Optimisation**

**Main Question:** Can the system provide pricing recommendations within marketplace limitations to suggest optimal pricing strategies across different marketplaces?

Use Case Example: The system analyses past sales performance and price points during marketplace campaigns to recommend pricing strategies that comply with platform rules.

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

**Q14 🟡 Preferred - Growth Recommendations**

**Main Question:** Can your solution track and analyse data to provide strategic insights into the risks and the opportunities in real-time?

Use Case Example: Identifying products with high engagement but low conversion to improve on product offering or analysing commonly purchased item combinations to optimise marketing strategies.

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

**Q15 🟡 Preferred - AI Features**

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

**Q16 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17 🔴 Mandatory - Business Data Extraction**

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

**Q18 🟡 Preferred - Personal Data Collection**

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

***

**Q19 🔴 Mandatory - Personal Data Protection**

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020). To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications. If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

**Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

***

**Q22 🟡 Preferred - CEM for Product Principal**

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Important Note: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory. For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

**Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Additional Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

**Q24 🟡 Preferred - CEM for Resellers**

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Important Note: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory. For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

**Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Additional Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Gen-AI Digital Training System

Digitize staff training processes using Generative AI to convert company SOPs, guidelines, and procedures into automated training content, addressing the time-consuming nature of in-person training especially in high-turnover sectors. This ensures consistent, standardized training delivery across all locations while reducing manual effort during HR onboarding.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

***

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Trainer Module**

Main Question: Does your solution provide the ability to rapidly create and customise interactive training content? (e.g., drag-and-drop builders, quiz tools, media embedding)?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Administration/Management Module**

Main Question: Does your solution provide essential administrative features for user management, course assignments, content distribution and progress tracking?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Learner Module**

Main Question: Does your solution provide a platform that allows learners to easily access, navigate, and complete training content?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Learners Tracking**

Main Question: Does your solution facilitate comprehensive assessment and/or certificate of completion processes to validate learning outcomes?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Mobile Access**

Main Question: Does your solution enable learning on-the-go with mobile access?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🔴 Mandatory - GenAI Content Transformation**

Main Question: Does your solution convert internal documents like SOPs and branding guidelines into engaging learning content using Generative AI? (e.g., Generative AI converts guidelines into interactive modules)

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🔴 Mandatory - Dashboards and Reports**

Main Question: Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

**Q10 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q10*

Main Question: Describe your AI feature and its benefits. Examples are:

Examples and Requirements: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q11 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🟡 Preferred - Personal Data Collection (if applicable)**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

**Q13 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q13*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Information: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Note: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

**Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

**Q16 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q16*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Additional Information: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

**Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Please specify the following information:

Requirements: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors i. The cybersecurity certification the organisation has met ii. The scope of the certification

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

\--

**Q18 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q16*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Additional Information: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

**Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q19*

Main Question: Please specify the following information:

Requirements: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Advanced Manufacturing

Advanced Manufacturing solutions provide digital tools to enhance production efficiency and quality control.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Production Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/czWnVUYHg3jWdZit5gZp">/pages/czWnVUYHg3jWdZit5gZp</a></td><td>Facilitate project management and resource planning, including the planning and coordination of the materials and equipment usage; track and display real-time work completion status, based on data collected from shopfloor.</td></tr><tr><td><a href="/pages/REcUToA7lE5Bee3louRh">/pages/REcUToA7lE5Bee3louRh</a></td><td>Provide real-time visibility on the performance and status of machines to enable scheduling of maintenance.</td></tr><tr><td><a href="/pages/yqgVbaHWDH3sSuVYt52j">/pages/yqgVbaHWDH3sSuVYt52j</a></td><td>Allow defining quality checks and collection of quality data; trigger alarms when out-of-specifications and highlight issues; record causes and actions when problem arises, contributes to data analytics.</td></tr></tbody></table>

**Design & Engineering**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/3zlq8eJSsUgguH9eBFw5">/pages/3zlq8eJSsUgguH9eBFw5</a></td><td>Integrate design and manufacturing processes through unified software. The system converts CAD models into machine toolpaths, enabling direct translation of digital designs into manufacturing instructions for efficient and precise production of physical parts.</td></tr><tr><td><a href="/pages/klrQ7ocRvUGnTHt50igh">/pages/klrQ7ocRvUGnTHt50igh</a></td><td>Optimise milling and turning operations through advanced computational modelling and sensor technology. The system analyses tool performance, monitors machining processes, and enhances surface quality using real-time diagnostics and 3D metrology for improved manufacturing precision.</td></tr><tr><td><a href="/pages/m6YMAbUbFJQIrgNTxUl8">/pages/m6YMAbUbFJQIrgNTxUl8</a></td><td>Provide source of information on the sequence of processes, and the technical drawing of components and materials, and this solution includes information on tools, equipment, manpower and instructions used in each process; manage revision to product design, and allow manufacturing process changes and configuration.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Real-time Production Scheduling and Job Tracking

Facilitate project management and resource planning, including the planning and coordination of the materials and equipment usage; track and display real-time work completion status, based on data collected from shopfloor.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Work Order Management**

Main Question: Does your solution create and dispatch daily work orders that include information such as execution sequence, work instructions, resources, etc?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Work Order Viewing**

Main Question: Does your solution allow operators to view daily work orders and detailed information of each task?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Shopfloor Work Completion Status Tracking**

Main Question: Does your solution track and display real-time work completion status for each operation, based on data collected on the shopfloor (e.g. barcode scanners, manual key in)?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Production Equipment Monitoring and Alerts**

Main Question: Does your solution provide updates or notification alerts in the event when production equipment slows down or breaks down, affecting the entire production?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Work Order Scheduling**

Main Question: Does your solution allow the planning and coordination of change in work order sequences, postponing or incorporating urgent tasks due to unplanned issues?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution integrate with third-party systems (e.g. ERP) for purposes such as retrieval of work orders and record of completed operations?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

**Q8 🔴 Mandatory - Dashboards and Reports**

Main Question: Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

**Q10 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q9*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q11 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q15]

\--

**Q13 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q12*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Form Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

\--

**Q14 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q13*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Reseller Note: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

\--

**Q16 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q15*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

**Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q16*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q18 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q15*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

**Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q18*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Equipment Monitoring and Manufacturing Data collection

Provide real-time visibility on the performance and status of machines to enable scheduling of maintenance.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Real-time Equipment Status Monitoring**

Main Question: Does your solution monitor equipment status and downtime reason in real time via operator manual key in or automatic link with the equipment?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Equipment Data Management**

Main Question: Does your solution maintain the details and status of each equipment?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Notification Alerts**

Main Question: Does your solution generate notification alerts (e.g., via email or SMS) when equipment is down or shows signs of disruption?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Insights Dashboards and Reports**

Main Question: Does your solution generate dashboards and report on insights such as e.g. overall equipment effectiveness, cycle time per part, number of parts per operator, number of scrapped parts, setup time per part?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Real-time Shopfloor Insights**

Main Question: Does your solution display real-time insights on a user-friendly interface via the facility shopfloor monitor or mobile devices?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution integrate with third-party systems (e.g. ERP, CAD/CAM/PDM, MES and BI systems)?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

**Q7 🔴 Mandatory Follow-up - System Integration and Connectivity - Elaboration**

*This question appears only if you answered "Yes" to Q6*

Main Question: List the systems and/or softwares that your solution can integrate with.

Confirmation: Click "Yes" to proceed after you are done listing the systems and/or softwares

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q8 🟡 Preferred - Equipment Maintenance Scheduling**

Main Question: Does your solution allow users to schedule equipment maintenance on an ad-hoc basis or automatically based on pre-defined requirements (e.g. work hours)?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - Equipment Repair Management**

Main Question: Does your solution allow users to report an equipment breakdown or problem and dispatch non-scheduled repairs?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🟡 Preferred - Maintenance Staff Management**

Main Question: Does your solution enable users to manage the scope and staff in charge of maintenance for the equipment?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

**Q13 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q12*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q14 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

\--

**Q16 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q15*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Form Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

\--

**Q17 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q16*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Reseller Note: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q18 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

\--

**Q19 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q18*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

**Q20 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q19*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q21 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q18*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

**Q22 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q21*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Manufacturing Quality Management

Allow defining quality checks and collection of quality data; trigger alarms when out-of-specifications and highlight issues; record causes and actions when problem arises, contributes to data analytics.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Quality Check Configuration**

Main Question: Does your solution allow users to define quality checks required (e.g. attributes to record, frequencies, and sample sizes)?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Quality Data Collection**

Main Question: Does your solution allow the collection of quality data either through manual keying of information on screen by the operator or automatically through an interfaced connection with measurement equipment?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Alert System**

Main Question: Does your solution trigger alarms when measurements are out of specification and highlight quality issues to operators/inspectors for follow-ups?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Problem Resolution Recording**

Main Question: Does your solution allow users to record causes and actions when problems arise?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Data Analytics**

Main Question: Does your solution perform statistical analysis, detect trends and deviations for users to conclude about significant influences caused by equipment, batch, operator, temperature, etc?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Dashboard and Report Features**

Main Question: Does your solution provide dashboard and reporting capabilities on recorded quality checks and statistical analysis?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution integrate with third-party systems (e.g. ERP)?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

**Q10 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q9*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q11 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q15]

\--

**Q13 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q12*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Form Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

\--

**Q14 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q13*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Reseller Note: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

\--

**Q16 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q15*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

**Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q16*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q18 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q15*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

**Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q18*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Product and Manufacturing Process Configuration

Provide source of information on the sequence of processes, and the technical drawing of components and materials, and this solution includes information on tools, equipment, manpower and instructions used in each process; manage revision to product design, and allow manufacturing process changes and configuration.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Manufacturing Process Documentation**

Main Question: Does your solution provide a source of information on the sequence of processes involved to manufacture or assemble a product (e.g. technical drawing, Bill of Material (BOM), materials required and manufacturing process such as tools, equipment, instructions used to build the product?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Technical Drawing Management**

Main Question: Does your solution provide technical drawings of components and materials used in each process?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Process Management**

Main Question: Does your solution provide information on tools, equipment, manpower and instructions that may be used in each process?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Product Design Revision Management**

Main Question: Does your solution manage revisions to product design and update relevant manufacturing process changes that are impacted by the product design change?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution integrate with third-party systems e.g. CAD software?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

**Q7 🔴 Mandatory - Dashboards and Reports**

Main Question: Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

**Q9 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q8*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q10 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

**Q11 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q14]

\--

**Q12 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q11*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Form Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

\--

**Q13 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q12*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Reseller Note: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q14 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q17]

\--

**Q15 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q14*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

\--

**Q16 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q15*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q17 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q14*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

**Q18 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Machining Dynamics for Milling/Turning

Optimise milling and turning operations through advanced computational modelling and sensor technology. The system analyses tool performance, monitors machining processes, and enhances surface quality using real-time diagnostics and 3D metrology for improved manufacturing precision.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Machining Information Generation**

Main Question: Does your solution scientifically create information such as machining parameters, cutting depth, spindle speed, and feed rates for increased productivity and quality in milling/turning?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Stability Lobes Generation**

Main Question: Does your solution allow for users to generate stability lobes where Engineers can estimate their vibration resistant machining configuration with consideration of productivity and stability?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Machining Library Creation and Maintenance**

Main Question: Does your solution provide interfaces to allow users to build up their libraries for machines, material, tooling information, and improved parameters?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

**Q6 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q5*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q7 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q11]

\--

**Q9 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q8*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Assessment Finished]

\--

**Q10 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q9*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q11 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q8*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Assessment Finished]

\--

**Q12 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q11*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Computer-aided design & Computer-aided manufacturing (CAD/CAM)

Integrate design and manufacturing processes through unified software. The system converts CAD models into machine toolpaths, enabling direct translation of digital designs into manufacturing instructions for efficient and precise production of physical parts.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - CAD Design Capabilities**

Main Question: Does your solution provide Computer-aided design (CAD) capabilities to create, modify, analyse, or optimise a design?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - CAM Manufacturing Capabilities**

Main Question: Does your solution provide Computer-aided manufacturing (CAM) capabilities to control machine tools and related ones in the manufacturing of work pieces?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - File Format Support**

Main Question: Does your solution support common file formats for CAD/CAM such as DWG, DXF, STEP, IGES, STL, etc.?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution integrate with third-party systems (e.g. ERP, PLM, or other manufacturing systems)?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

**Q6 🔴 Mandatory - Dashboards and Reports**

Main Question: Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

**Q8 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q7*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q9 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🟡 Preferred - Personal Data Collection**

Main Question: Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q13]

\--

**Q11 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q10*

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Form Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

\--

**Q12 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)**

*This question appears only if you answered "Yes" to Q11*

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Reseller Note: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

**Q14 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q13*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

**Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q14*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

\--

**Q16 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q13*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Reference Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

**Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q16*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Upload Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Cybersecurity

These are essential security solutions to protect SMEs' digital assets and data. Solutions include basic endpoint protection through anti-virus and malware defence, network security via firewalls, data backup systems, and integrated security suites that combine multiple protective features in a single platform.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/pNxb0IqRMP8sU1yYTYFq">/pages/pNxb0IqRMP8sU1yYTYFq</a></td><td>Create and maintain copies of data to ensure its availability in the event of data loss, corruption or system failures. The solutions play a critical role in data protection, disaster recovery and business continuity by enabling the restoration of critical information and resources. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.</td></tr><tr><td><a href="/pages/8TQjBDhg2eGyTPiuZt8h">/pages/8TQjBDhg2eGyTPiuZt8h</a></td><td>Monitor and control incoming and outgoing network traffic based on predetermined security rules. Such solutions may be host-based, or network-based, and serve as a gatekeeper between trusted internal networks and untrusted external networks, effectively managing and filtering network communications to prevent unauthorized access and protect against cyber threats. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.</td></tr><tr><td><a href="/pages/JDjH7DwMBGTOD94p7oS7">/pages/JDjH7DwMBGTOD94p7oS7</a></td><td>Virus/Malware Protection solutions are designed to safeguard computer systems, networks, and devices from malicious software threats such as viruses, worms, Trojans, ransomware, spyware, and other forms of malware. These solutions play a critical role in maintaining the security and integrity of digital assets, preventing unauthorized access, data breaches and system disruptions. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.</td></tr><tr><td><a href="/pages/c94FC2XHc79TOBgx9muG">/pages/c94FC2XHc79TOBgx9muG</a></td><td>Integrated package of cybersecurity solutions including anti-malware, firewall and backup solutions to support organisations in addressing a subset of the requirements in CSA Cyber Essentials mark</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Secure/Protect - Virus/ Malware Protection

Virus/Malware Protection solutions are designed to safeguard computer systems, networks, and devices from malicious software threats such as viruses, worms, Trojans, ransomware, spyware, and other forms of malware. These solutions play a critical role in maintaining the security and integrity of digital assets, preventing unauthorized access, data breaches and system disruptions. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Endpoint Attack Detection

**Main Question:** Does your solution support the detection of attacks in endpoints on the organisation's environment?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Automated Virus and Malware Scanning

**Main Question:** Does your solution enable virus and malware scans to detect possible cyberattacks, where scans can be configured to be automated and remain active to provide constant protection?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Automated Security Updates

**Main Question:** Does your solution enable auto-updates or support configuration to updates of signature files or equivalent (e.g. non-signature based machine learning solutions) to detect new malware?

**Update Requirements:** Updates should occur at least once daily.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Automated File Scanning

**Main Question:** Does your solution support the ability to automatically scan the files upon access?

**Scope Requirements:** This includes files and attachments downloaded from the Internet through the web browser or email, and external sources such as from portable USB drives.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Cybersecurity Product Certification

**Main Question:** Has your solution undergone cybersecurity product certification?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - Cybersecurity Product Certification - Elaboration

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Please list all relevant cybersecurity certifications (e.g. Common Criteria (CC) or similar).

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q7 🔴 Mandatory - Professional Services Provision

**Main Question:** Does your company provide the following professional services:

**Service Requirements:** a. Installation and configuration\
b. Documentation of key deployment information of the solution\
c. Briefing for solution handover to customer

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users monitor, track and report cyber threats across networks and systems through data visualisation.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making\
b. Recognise text, images to shorten time taken for manual inputs of forms\
c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q14]

\--

### Q12 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Assessment Finished]

\--

### Q13 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors\
ii. The cybersecurity certification the organisation has met\
iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q14 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met\
ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Secure/Protect - Firewall

Monitor and control incoming and outgoing network traffic based on predetermined security rules. Such solutions may be host-based, or network-based, and serve as a gatekeeper between trusted internal networks and untrusted external networks, effectively managing and filtering network communications to prevent unauthorized access and protect against cyber threats. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Firewall Protection with Configuration

**Main Question:** Does your firewall solution support the protection of network, systems, and endpoints such as laptops, desktops, servers, and virtual environments, providing protection with configuration to analyse and accept only authorised network traffic into the organisation's network?

**Firewall Type Requirements:** Please indicate if the firewall solution is a: a. Host-based firewall\
b. Network perimeter firewall

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q2 🟡 Preferred - Cybersecurity Product Certification

**Main Question:** Has your solution undergone cybersecurity product certification?

🟡 **Answer:** ○ Yes \[Next: Q3] ○ No \[Next: Q4]

\--

### Q3 🔴 Mandatory Follow-up - Cybersecurity Product Certification - Elaboration

*This question appears only if you answered "Yes" to Q2*

**Main Question:** Please list all relevant cybersecurity certifications (e.g. Common Criteria (CC) or similar).

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q4 🔴 Mandatory - Professional Services Provision

**Main Question:** Does your company provide the following professional services:

**Service Requirements:** a. Installation and configuration\
b. Documentation of key deployment information of the solution\
c. Briefing for solution handover to customer

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users monitor, track and report cyber threats across networks and systems through data visualisation.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

### Q7 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making\
b. Recognise text, images to shorten time taken for manual inputs of forms\
c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q8 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q11]

\--

### Q9 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Assessment Finished]

\--

### Q10 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors\
ii. The cybersecurity certification the organisation has met\
iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q11 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Assessment Finished]

\--

### Q12 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met\
ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Backup

Create and maintain copies of data to ensure its availability in the event of data loss, corruption or system failures. The solutions play a critical role in data protection, disaster recovery and business continuity by enabling the restoration of critical information and resources. Such solutions help organisations to meet a subset of the requirements in the "Secure/Protect" category of CSA Cyber Essentials.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Business Data Backup

**Main Question:** Does your solution enable the organisation to back up essential business information (e.g. financial data, business transactions) from organisation's systems and keep them separate and isolated from the operating environment?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Backup Frequency Configuration

**Main Question:** Does your solution enable the organisation to configure the frequency of backups to align to its business requirements?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Backup Protection

**Main Question:** Does your solution support the protection of backups from unauthorised access and restrict access to authorised personnel only?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Cybersecurity Product Certification

**Main Question:** Has your solution undergone cybersecurity product certification?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

### Q5 🔴 Mandatory Follow-up - Cybersecurity Product Certification - Elaboration

*This question appears only if you answered "Yes" to Q4*

**Main Question:** Please list all relevant cybersecurity certifications (e.g. Common Criteria (CC) or similar).

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🔴 Mandatory - Professional Services Provision

**Main Question:** Does your company provide the following professional services:

**Service Requirements:** a. Installation and configuration\
b. Documentation of key deployment information of the solution\
c. Briefing for solution handover to customer

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users monitor, track and report cyber threats across networks and systems through data visualisation.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making\
b. Recognise text, images to shorten time taken for manual inputs of forms\
c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q13]

\--

### Q11 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Assessment Finished]

\--

### Q12 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors\
ii. The cybersecurity certification the organisation has met\
iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q13 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Assessment Finished]

\--

### Q14 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met\
ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Integrated anti-malware, firewall and backup

Integrated package of cybersecurity solutions including anti-malware, firewall and backup solutions to support organisations in addressing a subset of the requirements in CSA Cyber Essentials mark.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Integrated Security Suite

**Main Question:** Does your solution include virus/malware protection, firewall, and backup capabilities as part of an integrated suite from a single vendor, to provide seamless delivery to the customer?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred - Cybersecurity Product Certification

**Main Question:** Has your solution undergone cybersecurity product certification?

🟡 **Answer:** ○ Yes \[Next: Q3] ○ No \[Next: Q4]

\--

### Q3 🔴 Mandatory Follow-up - Cybersecurity Product Certification - Elaboration

*This question appears only if you answered "Yes" to Q2*

**Main Question:** Please list all relevant cybersecurity certifications (e.g. Common Criteria (CC) or similar).

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q4 🔴 Mandatory - Virus/Malware Protection -Endpoint Attack Detection

**Main Question:** Does your solution support the detection of attacks in endpoints on the organisation's environment?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Virus/Malware Protection -Automated Virus and Malware Scanning

**Main Question:** Does your solution enable virus and malware scans to detect possible cyberattacks, where scans can be configured to be automated and remain active to provide constant protection?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Virus/Malware Protection -Automated Security Updates

**Main Question:** Does your solution enable auto-updates or support configuration to updates of signature files or equivalent (e.g. non-signature based machine learning solutions) to detect new malware? Updates should occur at least once daily.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Virus/Malware Protection -Automated File Scanning

**Main Question:** Does your solution support the ability to automatically scan the files upon access?

**Scope Requirements:** This includes files and attachments downloaded from the Internet through the web browser or email, and external sources such as from portable USB drives.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Firewall - Firewall Protection with Configuration

**Main Question:** Does your firewall solution support the protection of network, systems, and endpoints such as laptops, desktops, servers, and virtual environments, providing protection with configuration to analyse and accept only authorised network traffic into the organisation's network?

**Firewall Type Requirements:** Please indicate if the firewall solution is a: a. Host-based firewall\
b. Network perimeter firewall

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🔴 Mandatory - Back up - Business Data Backup

**Main Question:** Does your solution enable the organisation to back up essential business information (e.g. financial data, business transactions) from organisation's systems and keep them separate and isolated from the operating environment?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Back up - Backup Frequency Configuration

**Main Question:** Does your solution enable the organisation to configure the frequency of backups to align to its business requirements?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Back up - Backup Protection

**Main Question:** Does your solution support the protection of backups from unauthorised access and restrict access to authorised personnel only?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🟡 Preferred - IT Asset Management

**Main Question:** Does your solution maintain an up-to-date inventory of all hardware (including mobile devices, IoT devices, and other equipment) and software assets (including cloud subscriptions, services, and cloud-deployed software/operating systems) in the user organisation with all of the following features?

**Asset Management Requirements:** a. Identify and flag unauthorised assets or those reaching End-of-Support for replacement action\
b. Support organisational authorisation processes for onboarding new hardware and software\
c. Record authorisation dates in the asset inventory following dispensation approval\
d. Identify and facilitate removal of assets without proper approval dates

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🟡 Preferred - Data Asset Management

**Main Question:** Does your solution enable the organisation to identify, manage and maintain an up-to-date inventory of all business-critical data, minimally capturing the following fields:

**Data Management Requirements:** a. Description\
b. Data classification and/or sensitivity\
c. Location\
d. Retention period

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🟡 Preferred - Data Loss Prevention

**Main Question:** Does your solution provide protection from employees leaking confidential and/or sensitive data outside of the organisation?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

### Q15 🔴 Mandatory - Professional Services Provision

**Main Question:** Does your company provide the following professional services:

**Service Requirements:** a. Installation and configuration\
b. Documentation of key deployment information of the solution\
c. Briefing for solution handover to customer

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users monitor, track and report cyber threats across networks and systems through data visualisation.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q19]

\--

### Q18 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making\
b. Recognise text, images to shorten time taken for manual inputs of forms\
c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

\--

### Q20 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors\
ii. The cybersecurity certification the organisation has met\
iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Requirements:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Submission Requirements:** i. The cybersecurity certification the organisation has met\
ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Built Environment

Built Environment solutions provide digital tools to enhance construction and building management through design visualisation, project management, safety monitoring, and facility operations. These solutions integrate modern technologies to improve workflow efficiency and project outcomes across the construction lifecycle.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Design & Planning**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/gWS9pytSZWhxx1OsXQuf">/pages/gWS9pytSZWhxx1OsXQuf</a></td><td>Enable creation of detailed digital building models from concept to completion by supporting CORENET X submissions, facilitate immersive design validation, and perform simulations to analyse building performance. Features include virtual walkthroughs and environmental impact assessments</td></tr><tr><td><a href="/pages/bT8LOBoDxBHKgabgwdHh">/pages/bT8LOBoDxBHKgabgwdHh</a></td><td>Coordinated Regulatory Approvals and Rule-Based Model Checker<br>Automate building code compliance verification through intelligent BIM model checking. The system performs automated quality assessments and regulatory compliance checks, streamlining the approval process and ensuring designs meet building code requirements before submission.</td></tr><tr><td><a href="/pages/F5Lza1mVyF2cW3PlMwEB">/pages/F5Lza1mVyF2cW3PlMwEB</a></td><td>Quantity Surveying and Valuation<br>Leverage digital building models to automate quantity takeoffs and cost estimations throughout construction phases by proving accurate measurements and cost calculations, enabling efficient project budgeting and financial planning.</td></tr></tbody></table>

**Project Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/FlacWikXUaLR4df127GL">/pages/FlacWikXUaLR4df127GL</a></td><td>Streamline payment processes by automating work verification against contract milestones and ensuring accurate tracking of deliverables, facilitates timely payment approvals, and maintains healthy project cash flow through digital documentation and verification workflows.</td></tr><tr><td><a href="/pages/3OK8wfaMHCdrqzyJQy36">/pages/3OK8wfaMHCdrqzyJQy36</a></td><td><br>Leverage analytics and machine learning to enhance construction project management. The system provides real-time dashboards monitoring cost, time, safety, quality, and productivity metrics, enabling data-driven decisions based on stakeholder-contributed information.</td></tr><tr><td><a href="/pages/Mf1RGoUrmj9Zba37Divm">/pages/Mf1RGoUrmj9Zba37Divm</a></td><td><br>Provide a comprehensive project management ecosystem which integrates communication, carbon emissions tracking, approvals workflow, engineering collaboration, performance monitoring, defect management, safety compliance, and data sharing across stakeholders throughout the building lifecycle.</td></tr></tbody></table>

**Safety & Inspection**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/BQTExANCDAYc0bCBGjNw">/pages/BQTExANCDAYc0bCBGjNw</a></td><td>Streamline construction oversight through digital solutions that enable electronic documentation of site inspections and follow-up tracking, complemented by advanced 3D imaging technology for precise verification of building works.</td></tr><tr><td><a href="/pages/MFxbGxtgysGcleIJ5SQg">/pages/MFxbGxtgysGcleIJ5SQg</a></td><td>Digitise the permit application and approval process for construction activities and streamlines safety documentation, automates workflow approvals, and maintains digital records of work permits, ensuring compliance and efficient site safety management.</td></tr><tr><td></td><td></td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# 3D Modeling, Immersive Visualisation & Analysis

Enable creation of detailed digital building models from concept to completion by supporting CORENET X submissions, facilitate immersive design validation, and perform simulations to analyse building performance. Features include virtual walkthroughs and environmental impact assessments.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Visualisation, Analysis, or Authoring Compliance**

Main Question: Does your solution comply to at least one of the following: a. Visualiation b. Analysis c. Authoring

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🟡 Preferred - Visualisation Capabilities**

Main Question: Does your solution provide visualisation capabilities?

🟡 Answer: ○ Yes \[Next: Q3] ○ No \[Next: Q6]

***

**Q3 🔴 Mandatory - Visualisation - Architectural Visualisation**

Main Question: Does your solution allow BIM models to be rendered to create cinematic-quality images and videos for architectural visualisation purpose?

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Visualisation - BIM Model Rendering**

Main Question: Does your solution render BIM models which are created from commonly used modelling and GIS software (such as Revit, CityEngine, ArchiCAD and Sketchup)?

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🟡 Preferred - Visualisation - BIM Model Visualisation**

Main Question: Does your solution enable users to visualise models using advanced visualisation techniques (such as VR, AR, MR and photogrammetry)?

🟡 Answer: ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

**Q6 🟡 Preferred - Analysis Capabilities**

Main Question: Does your solution provide analysis capabilities?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q11]

***

**Q7 🔴 Mandatory - Analysis - BIM Model Validation**

Main Question: Does your solution provide analysis, modelling, and simulation tools to help businesses design and validate their BIM models in areas such as computational fluid mechanics, structural analysis, etc.?

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🟡 Preferred - Analysis - BIM Standards Compliance**

Main Question: Does your solution support open standards such as IFC, BCF, COBie, CityGML, etc.?

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - Analysis - API Integration**

Main Question: Does your solution provide APIs for sharing information with external platforms and solutions?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🟡 Preferred - Analysis - Buildability and Constructability Computation**

Main Question: Does your solution allow users to compute scores such as buildability and constructability?

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🟡 Preferred - Authoring Capabilities**

Main Question: Does your solution provide authoring capabilities?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q17]

***

**Q12 🔴 Mandatory - Authoring - Multi-Disciplinary BIM Model Creation**

Main Question: Does your solution allow creation of BIM Models for different disciplines (including Architectural, Structural, MEP design, etc)?

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13 🔴 Mandatory - Authoring - CORENET X and IFC-SG Compliance**

Main Question: Does your solution support CORENET X IFC-SG modelling and information requirements as shown in the CORENET X Code of Practice and IFC-SG Resource Kit, and is listed on the CORENET X website (<https://go.gov.sg/cx>) as a software that has associated IFC-SG configuration template files?

Note: IFC-SG is an extension of the international open-BIM format (Industry Foundation Classes, IFC), which is platform-neutral and vendor-neutral. Under CORENET X, regulatory submissions are required to be prepared and submitted in IFC-SG format. More info on the CORENET X Code of Practice and IFC-SG Resource Kit can also be found on the CORENET X website.

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🔴 Mandatory - Authoring - CORENET X Training and User Support**

Main Question: Does your solution provide training to equip users with the necessary skillsets required to submit regulatory submissions under CORENET X? Note: Refer to following link for latest list of ongoing CORENET X industry training courses: <https://go.gov.sg/cx>

🔴 Answer: ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🟡 Preferred - Authoring - Open BIM Standards Compliance**

Main Question: Does your solution support open standards such as BCF, COBie, CityGML, etc.?

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Next: Q16]

***

**Q16 🟡 Preferred - Authoring - API Integration**

Main Question: Does your solution provide APIs for sharing information with external platforms and solutions?

🟡 Answer: ○ Yes \[Next: Q17] ○ No \[Next: Q17]

***

**Q17 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Next: Q19]

\--

**Q18 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q19 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q21] ○ No \[Next: Q23]

***

**Q21 🟡 Preferred - CEM for Product Principal**

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

***

**Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q21*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q23 🟡 Preferred - CEM for Resellers**

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

**Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q23*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Digital Contract Management - Digital Payment

Streamline payment processes by automating work verification against contract milestones and ensuring accurate tracking of deliverables, facilitates timely payment approvals, and maintains healthy project cash flow through digital documentation and verification workflows.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Access Control Configuration**

Main Question: Does your solution allow configuration of access controls for sensitive project information across different project stakeholders?

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Multi-Level Approval Workflow**

Main Question: Does your solution allow configuration of multi-level approval workflows and setting approval limits?

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Dashboards and Reports (DCM)**

Main Question: Does your solution allow customising of dashboards and reports to monitor key performance indicators minimally in the following areas: a. Spending Analytics, such as actual spending versus budgeted spending b. Supplier Quality and Performance, such as delivery reliability, historical comparison c. Internal Operations, such as time savings, breakdown of time spent in each step of process from purchase request creation, purchase order, invoice and payment processing

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - BE Payment Management**

Main Question: Does your solution handle progress claims, work verification, and payment settlement processes?

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - System Setup and User Training**

Main Question: Does your service cover system setup and users' training? Please provide details on how you will deliver these services.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q7 🟡 Preferred - Invoice Generation or Processing**

Main Question: Does your solution generate or process invoices?

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

**Q8 🔴 Mandatory Follow-up - InvoiceNow-Ready Solution Provider Accreditation**

*This question appears only if you answered "Yes" to Q7*

Main Question: Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

\[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

Note: For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🟡 Preferred - Procurement Management**

Main Question: Does your solution facilitate procurement functions such as request for quotations from more than one supplier to allow comparison, shortlisting, routing for approval, and conversion of purchase request to purchase order?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🟡 Preferred - Invoice Generation or Processing**

Main Question: Does your solution generate or process invoices?

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

**Q11 🟡 Preferred - Bank Payment Integration**

*This question appears only if you answered "Yes" to Q10*

Main Question: Does your solution integrate with financial institutions or banks' systems to facilitate direct bank payment and payment status update?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

**Q12 🟡 Preferred - Invoice Financing Integration**

Main Question: Does your solution integrate with financial institutions or banks' systems to enable automated financing services for invoice financing, supporting the following roles: a. Suppliers - solution allows suppliers to submit financing requests, upload supporting documents to sell their invoices to financial institutions for early payment, and track status of financing requests b. Financial Institutions - solution allows users to access financing requests and supporting documents to process the requests within the system

🟡 Answer: ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

**Q13 🟡 Preferred - Supply Chain Financing Integration**

Main Question: Does your solution integrate with financial institutions or banks' systems to enable automated financing services for supply chain financing, supporting the following roles: a. Buyers - solution allows buyers to submit financing requests, upload supporting documents to extend payment terms b. Suppliers - solution allows suppliers to submit financing requests, upload supporting documents to sell their invoices to financial institutions for early paymen,t and track status of financing requests c. Financial Institutions - solution allows users to access financing requests and supporting documents to process the requests within the system

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

**Q14 🟡 Preferred - Financing Services Integration**

Main Question: Can your solution integrate with financial institutions or banks' systems to enable automated financing services other than invoice financing and supply chain financing?

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

**Q15 🔴 Mandatory Follow-up - Financing Services Integration - Elaboration**

*This question appears only if you answered "Yes" to Q14*

Main Question: Please describe the additional integrations.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q16 🟡 Preferred - Automated Payment Reconciliation**

Main Question: Does your solution have an automated reconciliation feature to handle matching of purchase order, goods receipt and invoice, and dispute management to handle payment discrepancies?

🟡 Answer: ○ Yes \[Next: Q17] ○ No \[Next: Q17]

***

**Q17 🟡 Preferred - System Integration and Connectivity**

Main Question: Does your solution provide APIs that enable integration with external platforms using Common Data Environment (CDE) standards to facilitate data exchange?

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Next: Q18]

***

**Q18 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q19] ○ No \[Next: Q20]

\--

**Q19 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q18*

Main Question: Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q20 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

***

**Q21 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

***

**Q22 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Note: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

**Q23 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q24] ○ No \[Next: Q26]

***

**Q24 🟡 Preferred - CEM for Product Principal**

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

***

**Q25 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q24*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q26 🟡 Preferred - CEM for Resellers**

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q27] ○ No \[Assessment Finished]

\--

**Q27 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q26*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Quantity Surveying and Valuation

Leverage digital building models to automate quantity takeoffs and cost estimations throughout construction phases by proving accurate measurements and cost calculations, enabling efficient project budgeting and financial planning.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - BIM Take-off Automation

**Main Question:** Does your solution allow users to automate take-off based on Building Information Modelling (BIM) to quantify and estimate the construction quantities or cost for a project?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred - BIM Standards Compliance

**Main Question:** Does your solution support open standards such as IFC, BCF, COBie, CityGML, etc.?

🟡 **Answer:** ○ Yes \[Next: Q3] ○ No \[Next: Q3]

***

### Q3 🟡 Preferred - Integration with Project Management Systems

**Main Question:** Does your solution support integration with Project Management Systems to synchronise cost management activities related to project scheduling, resource allocation, and task management?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

### Q5 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q4*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q10]

***

### Q8 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Assessment Finished]

\--

### Q9 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload] **Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Assessment Finished]

\--

### Q11 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Smart Inspection and Management

Monitor workplace safety through digital record capture, data analysis, and/or provision of digital wearables such as smart helmets, wrist devices etc. for remote tracking of worker's health and safety.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🟡 Preferred - Cloud and Multi-Device Accessibility**

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🟡 **Answer:** ○ Yes \[Next: Q2] ○ No \[Next: Q2]

***

**Q2 🔴 Mandatory - Worksite Inspection Capabilities**

**Main Question:** Does your solution have the following capabilities for worksite inspection:

Worksite Inspection Requirements: a. Capturing digital records (such as videos, images, etc) for remote inspection and monitoring b. Process and analyse captured records for additional insights c. Allow users to export captured records (based on open standards) to external storage or platforms for archiving purpose

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🟡 Preferred - Provision of Digital Wearables**

**Main Question:** Does your solution provide digital wearables (e.g. wrist devices, smart helmets etc)?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q5]

\--

**Q4 🔴 Mandatory Follow-up - Digital Wearables Capabilities - Elaboration**

*This question appears only if you answered "Yes" to Q3*

**Main Question:** Describe the features of your digital wearable solution, examples are:

Digital Wearable Features: a. Allow users to collect, store, transmit, and/or receive data b. Support collection and analysis of worker's vital signs which can be easily configured according to the worker's need c. Monitor worker safety conditions (e.g. fatigue levels, location tracking, fall detection etc) and provide real-time alerts to identify hazards and predict workers' safety d. Provide APIs for sharing information with existing worksite inspection platforms e. Others, please specify

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q5 🟡 Preferred - Hardware IoT Standards Support**

**Main Question:** If your solution is bundled with additional hardware, do they support prevailing IoT standards?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

**Q6 🔴 Mandatory - Dashboards and Reports**

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Technical Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation. The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - AI Features**

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

**Q8 🔴 Mandatory - AI Features - Elaboration**

**Main Question:** Describe your AI feature and its benefits. Examples are:

AI Feature Examples: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q9 🔴 Mandatory - Business Data Extraction**

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🟡 Preferred - Personal Data Collection**

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q13]

***

**Q11 🔴 Mandatory - Personal Data Protection**

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020). To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications. If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

**Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

**Q14 🟡 Preferred - CEM for Product Principal**

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Important Note: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory. For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

**Q15 🔴 Mandatory - CEM for Product Principal - Elaboration**

**Main Question:** Please specify the following information:

Certification Requirements: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Additional Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

**Q16 🟡 Preferred - CEM for Resellers**

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Important Note: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory. For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q17]

***

**Q17 🔴 Mandatory - CEM for Resellers - Elaboration**

**Main Question:** Please specify the following information:

Certification Requirements: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Additional Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Confirmation Requirement: Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Smart Inspection and Management - e-Permit-to-work (e-PTW)

Digitise the permit application and approval process for construction activities and streamlines safety documentation, automates workflow approvals, and maintains digital records of work permits, ensuring compliance and efficient site safety management.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - e-PTW Mobile Submission and Approval

**Main Question:** Does your solution allow users to submit and approve permit-to-work applications online using mobile devices?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Audits Trails and Report Generation

**Main Question:** Does your solution provide audit trails and generate reports on the permit-to-work applications?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - System Integration and Data Archival

**Main Question:** Does your solution provide APIs for sharing information with external platforms or solutions, and allow users to migrate or archive their data?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q7 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q11]

\--

### Q9 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Note: \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q14]

***

### Q12 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Assessment Finished]

\--

### Q13 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Coordinated Regulatory Approvals and Rule-Based Model Checker

Automate building code compliance verification through intelligent BIM model checking. The system performs automated quality assessments and regulatory compliance checks, streamlining the approval process and ensuring designs meet building code requirements before submission.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - BIM Compliance Checker

**Main Question:** Does your solution allow users to check BIM model quality or compliance with Building Codes?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred - BIM Standards Compliance

**Main Question:** Does your solution support open standards such as IFC, BCF, COBie, CityGML, etc.?

🟡 **Answer:** ○ Yes \[Next: Q3] ○ No \[Next: Q3]

***

### Q3 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q5]

\--

### Q4 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q3*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q5 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q9]

***

### Q7 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Assessment Finished]

\--

### Q8 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Assessment Finished]

\--

### Q10 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Data and AI-driven Decision Support System

Leverage analytics and machine learning to enhance construction project management. The system provides real-time dashboards monitoring cost, time, safety, quality, and productivity metrics, enabling data-driven decisions based on stakeholder-contributed information.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Data Analytics

**Main Question:** Does your solution provide data visualisation and/or data analytic features including data collection, cleaning, transformation, sense making and descriptive statistics?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Requirements:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - BE Data Import and Export

**Main Question:** Is your solution able to import/export multiple sources of the built environment sector data from/to external platforms/solutions digitally using standard protocols for sharing/migrating/archival purposes?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - System Setup and User Training

**Main Question:** Does your service cover system setup and users' training?

**Submission Requirements:** Please provide details on how you will deliver these services.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q6 🟡 Preferred - Building Environment Data Standards Compliance

**Main Question:** Is your solution able to comply with the built environment sector datasets and data exchange protocol when one such standard is being set up in near future?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Advanced Data Analytics

**Main Question:** Does your solution provide advanced data analytic features such as diagnostic, predictive, and prescriptive analysis?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

***

### Q14 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Built Environment Digital Platform

Provide a comprehensive project management ecosystem which integrates communication, carbon emissions tracking, approvals workflow, engineering collaboration, performance monitoring, defect management, safety compliance, and data sharing across stakeholders throughout the building lifecycle.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Project Data Storage and Access

**Main Question:** Does your solution enable users to store, share, and access project data (e.g. BIM, site data and project management data) throughout the design, fabrication, construction, and asset management stages?

**Example:** A structural engineer uploads revised foundation plans, which are shared to and accessed by the construction manager for on-site implementation.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - BIM Model Federation

**Main Question:** Does your solution provide for federation of BIM models from different disciplines (e.g. architectural, structural, mechanical, electrical, and plumbing (MEP) and construction) to visualise them concurrently for collaboration and coordination purposes?

**Example:** An architect overlays their design with the structural engineer's model to ensure aesthetic elements align with load-bearing components.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - BIM Version Control

**Main Question:** Does your solution manage different versions of a BIM model to be shared across project stakeholders?

**Example:** The platform maintains version history of BIM models, allowing architects to share the latest design updates with contractors while enabling access to previous versions for reference.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Site Activity Monitoring

**Main Question:** Does your solution enable users to coordinate and monitor the various site activities, such as manpower utilisation, resources (e.g. construction materials, etc), defects, safety non-compliance, inspection, progress and etc.?

**Example:** A project manager reviews the day's site activity schedule on the platform, identifies areas with resource shortages, and reassigns manpower and materials to ensure smooth operations.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Digital Data Submission

**Main Question:** Does your solution allow digital submission of data to and from other platforms for review, approval, and record using a certain API that complies with BCA's latest Site Management Data Standards?

**Example:** The platform allows submission of manpower usage and productivity data to BCA monthly through the Electronic Productivity Submission System (EPSS).

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Issue Tracking

**Main Question:** Does your solution enable users to raise issues (e.g. design or construction matters), track statuses, and provide responses?

**Example:** A site supervisor logs a structural design concern through the platform, assigns it to the design team, and monitors resolution progress until a response is provided and the issue is closed.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Multi-device Access

**Main Question:** Does your solution connect users across all stages of the project on multiple devices (e.g. PC and mobile)?

**Example:** A site engineer updates defect statuses on-site using a mobile app, while the project manager reviews the overall project timeline and task progress on a desktop dashboard.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - BE Dashboards and Reports

**Main Question:** Does your solution allow data to be aggregated and analysed across various project phases and presented on dashboards within the platform, which can be configured and exported if needed?

**Example:** The platform provides real-time insights on progress of project completion status, generate consolidated view into a dashboards, and allows stakeholders to export progress insights.

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Requirements:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - IoT Interoperability

**Main Question:** Is your solution interoperable with IoT devices (e.g. sensors and cameras) by different OEMs?

**Example:** The platform seamlessly integrates with temperature sensors and site cameras, enabling automated data collection and real-time monitoring of site conditions.

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Automated Alerts

**Main Question:** Does your solution provide auto-triggers and alert notifications for authorised users?

**Example:** The platform automatically notifies relevant users of pending approvals or unresolved safety issues, and updates relevant stakeholders once the issue is resolved.

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Singapore-Based Cloud Hosting

**Main Question:** Does your solution support cloud deployment with the database hosted in data centres located in Singapore?

**Example:** The platform is deployed on a cloud infrastructure compliant with local regulations, with all data securely hosted in Singapore-based data centres to ensure data sovereignty.

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Digital Forms and Workflow Creation

**Main Question:** Does your solution allow users to create digital forms and workflows to enable data entry and routing?

**Example:** The user can create customised Site Safety Inspection forms with predefined checklists, allowing safety officers to conduct and record inspections. The workflow automatically routes completed inspections to project managers for review.

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

**Example:** The project manager reviews project status on his desktop in office and on his mobile device while on site.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Project Management

**Main Question:** Does your solution help project manager with planning, coordinating, and job scheduling?

**Example:** The project manager assigns tasks to team members, setting priorities and deadlines, and outlining all the scheduled and planned resources.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Project Monitoring

**Main Question:** Does your solution provide real-time monitoring of jobs/projects from end to end with the ability to pull real-time reports and check job/project status for both internal and external parties?

**Example:** The platform provides a real-time dashboard for the main contractor to monitor work progress, while the project manager can generate reports on project status such as concrete poured, or man-hours worked, to share the data with internal and external stakeholders.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Portfolio-wide Visibility

**Main Question:** Does your solution provide portfolio-wide visibility to present information on resource availability and budget performance for multiple projects at once?

**Example:** The platform allows the firm to oversee multiple projects simultaneously, if workers complete their work on one project earlier than expected, the resource manager can reallocate these workers to another project. The platform also provides overall budget performance for budget reallocation.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🔴 Mandatory - Advanced Collaboration Functionality

**Main Question:** Does your solution provide advanced collaboration functionality that not only allows team members to connect, but lets them link their social interactions to project tasks and action items (e.g. file sharing, shared calendars and contact lists)?

**Example:** The design team, contractors, and client representatives, share and update BIM models, link discussions to specific design elements, assign action items directly from shared project timelines, and schedule site visits based on shared calendars.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Document Management

**Main Question:** Does your solution allow team members to view and edit their project documents in real time, eliminating the need for multiple conflicting versions of critical materials?

**Example:** Architects and engineers collaboratively edit site plans and specifications in real-time, with version control ensuring team members are working with the latest information.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Centralised Project Information

**Main Question:** Does your solution allow for project information to be accessible in one place, including but not limited to planned and completed tasks, past and upcoming calendar events, customer data, project resources, expenses and bills send to clients?

**Example:** Project managers can access site progress checklists, site coordination meetings, stock level of materials, and payment records in one place.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Budgeting Management

**Main Question:** Does your solution enable the company to do timely and efficient project budgeting, including budget reports, budget dashboard?

**Example:** The budget dashboard shows actual vs. planned expenditure across all work packages.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

***

### Q21 🔴 Mandatory - User Account and Scheduling Management

**Main Question:** Does your solution enable the company to perform the following functions:

**Required Functions:** a. Set up admin and end user accounts for all project members b. Set up and edit business units for different team member profiles c. Allow scheduling interface to be customisable by administrator d. Allow integration with any existing project scheduling and management system

**Example:** The admin sets up user accounts for different team members, customising access levels based on roles. The platform integrates to existing scheduling software used by different subcontractors.

🔴 **Answer:** ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

***

### Q22 🟡 Preferred - User Access and Reminder Management

**Main Question:** Does your solution enable the company to perform the following functions:

**Functions:** a. Grant access to all employee for mobile-based, web-based, and cloud-based usage b. Push notifications to employees automatically of own work shift c. Prompt and remind users of scheduling updates

**Example:** Employee receives automatic notifications about new assignments, schedule changes, or urgent repair requests, and checks these updates on their mobile device or desktop.

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Next: Q23]

***

### Q23 🟡 Preferred - Worker Hours Monitoring

**Main Question:** Is the solution capable to track or monitor the number of hours per day a worker has worked consecutively to abide to MOM rules and/or to ensure that a worker is not overworked?

**Example:** The platform alerts site supervisors when a worker is approaching MOM's maximum allowed hours.

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Next: Q24]

***

### Q24 🟡 Preferred - ERP Integration

**Main Question:** Can your solution integrate with other ERP solutions (for instance Accounting & Sales Management, Inventory Management, Project Management, Workforce Management, and/or Fleet Management etc.) or does your solution provide Open APIs that allow third-party solutions to integrate with your solution?

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Next: Q26]

\--

### Q25 🔴 Mandatory Follow-up - ERP Integration - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Briefly describe the APIs available.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q26] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q26 🟡 Preferred - Automated Clash Detection

**Main Question:** Does your solution automatically identify potential clashes or conflicts between design disciplines within the uploaded models?

**Example:** The platform detects interference where an HVAC duct intersects a structural beam in a 3D model.

🟡 **Answer:** ○ Yes \[Next: Q27] ○ No \[Next: Q27]

***

### Q27 🟡 Preferred - Automated Schedule Risk Analysis

**Main Question:** Does the platform analyse project schedules to predict potential risks or delays or costs overun?

**Example:** Alerts the project team if material delivery delays could impact the installation timeline for precast panels.

🟡 **Answer:** ○ Yes \[Next: Q28] ○ No \[Next: Q28]

***

### Q28 🟡 Preferred - Automated Resolution Recommendation

**Main Question:** Does the platform suggest possible resolutions to address detected clashes, ways to optimise scheduling, or ways to mitigate identified cost risks?

**Example:** Highlights that a crane is overbooked for overlapping tasks and proposes rescheduling one task to a different time slot.

🟡 **Answer:** ○ Yes \[Next: Q29] ○ No \[Next: Q29]

***

### Q29 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q30] ○ No \[Next: Q31]

\--

### Q30 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q29*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q31] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q31 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q32] ○ No \[⚠️ Cannot Proceed]

***

### Q32 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q33] ○ No \[Next: Q35]

\--

### Q33 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q32*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q34] ○ No \[⚠️ Cannot Proceed]

***

### Q34 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q35] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q35 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q36] ○ No \[Next: Q38]

***

### Q36 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q37] ○ No \[Assessment Finished]

\--

### Q37 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q36*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q38 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q39] ○ No \[Assessment Finished]

\--

### Q39 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q38*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Early Childhood

Early Childhood solutions provide digital tools to enhance pre-school operations and child development monitoring.

**Centre Administration**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/0DhS3go1mHk5a65XMBLz">/pages/0DhS3go1mHk5a65XMBLz</a></td><td>Provide the maintenance of pre-school centre operation (e.g. Health &#x26; Safety Management, Staff/Student/Asset Management systems) and Finance management (e.g. e-Payment, Invoicing)</td></tr><tr><td><a href="/pages/O9dEZvZLnypJMDB0XBAM">/pages/O9dEZvZLnypJMDB0XBAM</a></td><td>Allow creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.</td></tr><tr><td><a href="/pages/dq7Cn73GQJYTkrIBF3ER">/pages/dq7Cn73GQJYTkrIBF3ER</a></td><td>Provide the maintenance of pre-school centre operation (e.g. Health &#x26; Safety Management, Staff/Student/Asset Management systems) and Finance management (e.g. e-Payment, Invoicing) and allows creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.</td></tr><tr><td><a href="/pages/7p83REr7ZVviTIDqawKa">/pages/7p83REr7ZVviTIDqawKa</a></td><td>The solution streamlines real-time vacancy tracking, waitlist management, and enrolment allocation while generating capacity reports and<br>threshold alerts.</td></tr></tbody></table>

**Analytics & Insights**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/5AINj2DvqVimUEQ0ijah">/pages/5AINj2DvqVimUEQ0ijah</a></td><td>Help preschool operators analyse daily operational data. The system provides insights into parent preferences, predicts student dropout rates, and enables family profiling, supporting data-driven decisions for improved business management.</td></tr><tr><td><a href="/pages/HOaeY6zW7o68j2EYPl3w">/pages/HOaeY6zW7o68j2EYPl3w</a></td><td>Transform educational data into intuitive dashboards for tracking children's progress by enabling educators to monitor developmental milestones against benchmarks, evaluate teaching effectiveness, and efficiently assess individual learning outcomes through visual analytics.</td></tr><tr><td><a href="/pages/uU9kmUbvxucp4IBb9Juw">/pages/uU9kmUbvxucp4IBb9Juw</a></td><td>Combine operational and developmental data analysis by using AI to optimise centre management and service quality while monitoring children's progress, providing data-driven recommendations for both business operations and individualised child development needs.</td></tr></tbody></table>

**Professional Development**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/UeDxHRiX7JB9MIpvU4cP">/pages/UeDxHRiX7JB9MIpvU4cP</a></td><td>Attract potential teachers to join the industry by leveraging digital platforms that are integrated with ECDA's systems.</td></tr><tr><td><a href="/pages/vfxaZiXwbvFmjjcrGiTM">/pages/vfxaZiXwbvFmjjcrGiTM</a></td><td>Provide personalised professional development for early childhood educators and intervention specialists. The system delivers customised training content and mentoring support, enabling continuous professional growth and skill enhancement for teaching staff.</td></tr></tbody></table>

**Safety & Security**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/0VTqqr49uLNdtW1nWKEr">/pages/0VTqqr49uLNdtW1nWKEr</a></td><td>Equip surveillance systems with video analytics, centre leaders can receive alerts on potential risks or hazards, such as children who are left on their own without adult supervision in classrooms and intrusion. Preschool operators may also leverage data collected to identify areas for improvement in centre operations for enhanced safety and security measures.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Pre-School Management System

Multi-functional system that streamlines preschool operations and administration (e.g. Finance Management, Staff and Child Records Keeping, Waitlist and Vacancy Matters).

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory — Finance Management

**Main Question:** Does your solution contain a Finance module that provides, but is not limited to, the following functions:

* a. Configuration of school fee type, fee period and discounts (if any) and management and/or tracking of government grants and subsidies per eligible child (approved period, subsidy received etc.)
* b. Payment processing with invoice and receipt generation
* c. Support bulk sending of electronic invoices, receipts, and payment due notifications with both scheduled and on-demand reminder capabilities.
* d. Tracking of different payment modes (cash, cheque, e-payment : NETS, VISA, FAST etc.) and bank reconciliation
* e. Generation of basic reports e.g. ageing report

🔴 **Answer:** ○ Yes \[Next: Q2]     ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred — Finance Management - Preferred Features

**Main Question:** Does your solution provide deposit collection and refund management functionalities?

🟡 **Answer:** ○ Yes \[Next: Q3]     ○ No \[Next: Q3]

***

### Q3 🔴 Mandatory — Staff Records Management

**Main Question:** Does your solution contain a Staff Records module that provides, but is not limited to, the following functions:

* a. Staff personnel particulars, attendance and health record management
* b. Class allocation for staff

🔴 **Answer:** ○ Yes \[Next: Q4]     ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred — Staff Records Management - Preferred Features

**Main Question:** Does your solution contain a Staff Records module that provides, but is not limited to, the following preferred functions:

* a. Employment Profile Management
* b. Benefits and Claims Management
* c. Performance Appraisal Management
* d. Staff Communication and e-Surveys
* e. Daily Staff Deployment Planning Management with Staff-Child Ratio evaluation
* f. Relief Staff Deployment Management
* g. Payroll and Leave Management

🟡 **Answer:** ○ Yes \[Next: Q5]     ○ No \[Next: Q5]

***

### Q5 🔴 Mandatory — Child Records Management

**Main Question:** Does your solution contain a Child Records module that provides, but is not limited to, the following functions:

* a. Child personal record management (include health information, allergies, growth chart management, medical certificate, medical condition, medicine, personal particulars and parent and/or guardian details)
* b. Infant Care routine care records management (e.g. infant poop, feed, sleep pattern etc.) where applicable
* c. Class allocation and group deployment

🔴 **Answer:** ○ Yes \[Next: Q6]     ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred — Child Records Management - Preferred Features

**Main Question:** Does your solution contain a Child Records module that provides, but is not limited to, the following preferred functions:

* a. Child development roadmap and progress report
* b. Child incident report and submission management
* c. Integration with additional learning support programme data from third parties of ECDA

🟡 **Answer:** ○ Yes \[Next: Q7]     ○ No \[Next: Q7]

***

### Q7 🔴 Mandatory — Child Attendance Management

**Main Question:** Does your solution contain a Child Attendance module that provides, but is not limited to, the following functions:

* a. Manual and automated check-in and check-out (e.g. via digital QR codes and/or in-app sign in or out by teachers and/or facial recognition etc.)
* b. Alerts and notifications sent to parents (when child is signed in or out, alerts for non-pickups, absences)
* c. Child Attendance Profiles (contains monthly attendance details such as no. of days present and/or no. of days absent and/or no. of days expected to be present) and complete audit trails (date, timestamp and user who created or modified the attendance record to be displayed within the module's interface)

🔴 **Answer:** ○ Yes \[Next: Q8]     ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory — School Operations Management

**Main Question:** Does your solution contain a School Operations Module that provides, but not limited to, the following functions:

* a. Web enquiry form (allow parents to enquire about programme and indicate interest)
* b. Visitor Management (e.g. sign-in and/or sign-out time and their temperature)

🔴 **Answer:** ○ Yes \[Next: Q9]     ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred — School Operations Management - Preferred Features

**Main Question:** Does your solution contain a School Operations Module that provides, but not limited to, the following preferred functions:

* a. Bus transport attendance and temperature tracking
* b. Maintenance planning and monitoring (e.g. cleaning, pest control, fixtures, etc.)
* c. Curriculum development framework repository

🟡 **Answer:** ○ Yes \[Next: Q10]     ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory — Parent Communication Management

**Main Question:** Does your solution allow the preschool to manage content meant for parents such as the following:

* a. Publicity and general announcement (such as upcoming events and programmes) via SMS, Email or parent-centre app.
* b. School media repository, child portfolio and highlights
* c. Parents' Handbook, Terms of Reference and agreements e.g. PDPA consent, medication administration

🔴 **Answer:** ○ Yes \[Next: Q11]     ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred — Parent Communication Management - Preferred Features

**Main Question:** Does your solution allow the preschool to manage content meant for parents by offering the following preferred functions:

* a. Incident notification
* b. Feedback and E-survey (school can create their own survey questionnaire and collate survey results)
* c. Real-time chat function
* d. Case management and reports
* e. Parent Education Resources and Programmes
* f. Parents Self-Service Portal (allow parents to log in to update personal particulars and information about their child)

🟡 **Answer:** ○ Yes \[Next: Q12]     ○ No \[Next: Q12]

***

### Q12 🔴 Mandatory — Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q13]     ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred — Fire Drill Management

**Main Question:** Does your solution contain a Fire Drill Management module to manage fire escape route plan, fire drill exercises, review of fire extinguisher expiry dates, schedule of fire drill exercises, schedule of fire alarm testing, maintenance schedule of fire equipment etc.?

🟡 **Answer:** ○ Yes \[Next: Q14]     ○ No \[Next: Q14]

***

### Q14 🟡 Preferred — HFMD Monitoring

**Main Question:** Does your solution provide a Hand Foot Mouth Disease (HFMD) Monitoring and Reporting module that allows the school to track incidents and generate reports for submission to Ministry of Health and ECDA?

🟡 **Answer:** ○ Yes \[Next: Q15]     ○ No \[Next: Q15]

***

### Q15 🟡 Preferred — Pre-Visit Licence Evaluation Preparation

**Main Question:** Does your solution allow the school to prepare the Pre-Visit licence Evaluation form?

🟡 **Answer:** ○ Yes \[Next: Q16]     ○ No \[Next: Q16]

***

### Q16 🟡 Preferred — SPARK Report Submission

**Main Question:** Does your solution allow the school to prepare and submit SPARK Standards Self Evaluation and Report to ECDA?

🟡 **Answer:** ○ Yes \[Next: Q17]     ○ No \[Next: Q17]

***

### Q17 🔴 Mandatory — Vacancy and Waitlist Management

**Main Question:** Does your solution contain a Vacancy and Waitlist module that provides, but not limited to, the following functions:

* a. Update vacancies in real-time by service/programme type, auto-calculate vacancies based on enrolments and withdrawals and set capacity limits through integration with staff records to maintain compliant staff-child ratios
* b. Display confirmed incoming or outgoing children for each service and/or programme.
* c. Waitlist management of enrolment interests from different channels e.g. internal transfers, walk-ins, social media lead, web portal leads, etc
* d. Track and monitor the sequence of applicants and allocate available vacancies based on predefined rules or priority order
* e. Generate monthly vacancy statuses for each service level showing at least seven months (current and six following months) of data with the labels 'Available', 'Limited' and 'Full' in a format compatible with ECDA's Content Management System.

  **Note:** "Limited" is defined as less than or equals to 5% of available capacity
* f. Send out real-time alerts or display visual indicators triggered by pre-defined conditions (e.g. when certain level of capacity or limit is reached).

🔴 **Answer:** ○ Yes \[Next: Q18]     ○ No \[⚠️ Cannot Proceed]

***

### Q18 🟡 Preferred — Multi-Tenancy Vacancy and Waitlist Management

**Main Question:** Does your solution support multi-tenancy with consolidated view and management of vacancy and waitlist data across multiple centres?

🟡 **Answer:** ○ Yes \[Next: Q19]     ○ No \[Next: Q19]

***

### Q19 🔴 Mandatory — Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features:

* **Option 1:** Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* **Option 2:** At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q20]     ○ No \[⚠️ Cannot Proceed]

***

### Q20 🟡 Preferred — AI Powered Education Management

**Main Question:** Does your solution have any AI features?

🟡 **Answer:** ○ Yes \[Next: Q21]     ○ No \[Next: Q22]

\--

### Q21 🔴 Mandatory Follow-up — AI Powered Education Management - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Describe your AI features. Examples are:

* a. Use of Chatbot to assist with parent's queries
* b. Ability to generate draft paragraphs of children's portfolio based on image analysis
* c. Ability to provide recommendation on food menu planning based on health condition of child
* d. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q22]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box — Describe your AI features]

***

### Q22 🔴 Mandatory — Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q23]     ○ No \[⚠️ Cannot Proceed]

***

### Q23 🔴 Mandatory — Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q24]     ○ No \[⚠️ Cannot Proceed]

***

### Q24 🔴 Mandatory — Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q25]     ○ No \[⚠️ Cannot Proceed]

***

### Q25 🟡 Preferred — Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q26]     ○ No \[Next: Q28]

***

### Q26 🟡 Preferred — CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q27]     ○ No \[Assessment Finished]

\--

### Q27 🔴 Mandatory Follow-up — CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q26*

**Main Question:** Please specify the following information:

* i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* ii. The cybersecurity certification the organisation has met
* iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Field — Specify certification details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q28 🟡 Preferred — CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q29]     ○ No \[Assessment Finished]

\--

### Q29 🔴 Mandatory Follow-up — CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q28*

**Main Question:** Please specify the following information:

* i. The cybersecurity certification the organisation has met
* ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Field — Specify certification details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# e-Forms for Pre-school

Allow creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - e-Form Management

**Main Question:** Does your solution allow for the creation and update of the following forms:

**Form Requirements:** a. Child care enrolment and subsidy application i. Submit basic enrolment details (applicable for all children) applying for Child Care Subsidies ii. Apply for Start-Up Grant (SUG) and/or Child Care Financial Assistance (CCFA) (applicable for Singapore Citizen children only) ii. Update change in applicant (for existing enrolled Singapore Citizen children)

b. Subsidy update and Special Approval application (Existing enrolment) i. Update child and/or applicant/spouse's details (for existing enrolled Singapore Citizen children) ii. Apply or Renewal of Special Approval, Start-Up Grant (SUG) iii. Apply for financial assistance for child care (CCFA) for children who are already enrolled in the centre (applicable for Singapore Citizen children only)

c. Withdrawal from child care centre or subsidy scheme i. Withdraw child from child care centre ii. Withdraw from subsidy scheme

d. Provide basic enrolment submission details (applicable for all children) b. Support Kindergarten Fee Assistance Scheme (KiFAS)

Note: KiFAS is only applicable for Anchor Operators (AOPs) and Ministry of Education (MOE) Kindergarten only.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - File Upload Feature

**Main Question:** Does your solution support the uploading of documents (File size up to 8 MB) from parents to facilitate the enrolment of the child?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Annex Management

**Main Question:** Does your solution allow for the creation and update of Annexes for collection of additional information (e.g. allergies, grandparents' contacts, etc.)?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - System Integration and Connectivity

**Main Question:** Does your solution provide APIs for sharing and/or retrieving of information with external platforms or solutions?

**Example Integrations:** e.g. able to link to MyInfo to autofill personal detail, able to link to ECDA system, etc.

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - System Integration and Connectivity - Elaboration

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Briefly describe the APIs available.

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Third-Party Integration

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

### Q8 🔴 Mandatory Follow-up - Third-Party Integration - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa

Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - AI Powered Education Management

**Main Question:** Does your solution have any AI features?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - AI Powered Education Management - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Describe your AI features. Examples are:

**Example Features:** a. Recognise text, images to shorten time taken for manual inputs of forms

b. Others, please specify

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

***

### Q16 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

***

### Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors

ii. The cybersecurity certification the organisation has met

iii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q18 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

***

### Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met

ii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

<br>

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Pre-School Management System + e-Forms for Pre-school

Provide the maintenance of pre-school centre operation (e.g. Health & Safety Management, Staff/Student/Asset Management systems) and Finance management (e.g. e-Payment, Invoicing) and allows creation and update of forms to facilitate preschool enrolment, withdrawal and subsidy application for use by parents, operators and ECDA.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory — Finance Management

**Main Question:** Does your solution contain a Finance module that provides, but is not limited to, the following functions:

* a. Configuration of school fee type, fee period and discounts (if any) and management and/or tracking of government grants and subsidies per eligible child (approved period, subsidy received etc.)
* b. Payment processing with invoice and receipt generation
* c. Support bulk sending of electronic invoices, receipts, and payment due notifications with both scheduled and on-demand reminder capabilities.
* d. Tracking of different payment modes (cash, cheque, e-payment : NETS, VISA, FAST etc.) and bank reconciliation
* e. Generation of basic reports e.g. ageing report

🔴 **Answer:** ○ Yes \[Next: Q2]     ○ No \[⚠️ Cannot Proceed]

***

### Q2 🟡 Preferred — Finance Management - Preferred Features

**Main Question:** Does your solution provide deposit collection and refund management functionalities?

🟡 **Answer:** ○ Yes \[Next: Q3]     ○ No \[Next: Q3]

***

### Q3 🔴 Mandatory — Staff Records Management

**Main Question:** Does your solution contain a Staff Records module that provides, but is not limited to, the following functions:

* a. Staff personnel particulars, attendance and health record management
* b. Class allocation for staff

🔴 **Answer:** ○ Yes \[Next: Q4]     ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred — Staff Records Management - Preferred Features

**Main Question:** Does your solution contain a Staff Records module that provides, but is not limited to, the following preferred functions:

* a. Employment Profile Management
* b. Benefits and Claims Management
* c. Performance Appraisal Management
* d. Staff Communication and e-Surveys
* e. Daily Staff Deployment Planning Management with Staff-Child Ratio evaluation
* f. Relief Staff Deployment Management
* g. Payroll and Leave Management

🟡 **Answer:** ○ Yes \[Next: Q5]     ○ No \[Next: Q5]

***

### Q5 🔴 Mandatory — Child Records Management

**Main Question:** Does your solution contain a Child Records module that provides, but is not limited to, the following functions:

* a. Child personal record management (include health information, allergies, growth chart management, medical certificate, medical condition, medicine, personal particulars and parent and/or guardian details)
* b. Infant Care routine care records management (e.g. infant poop, feed, sleep pattern etc.) where applicable
* c. Class allocation and group deployment

🔴 **Answer:** ○ Yes \[Next: Q6]     ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred — Child Records Management - Preferred Features

**Main Question:** Does your solution contain a Child Records module that provides, but is not limited to, the following preferred functions:

* a. Child development roadmap and progress report
* b. Child incident report and submission management
* c. Integration with additional learning support programme data from third parties of ECDA

🟡 **Answer:** ○ Yes \[Next: Q7]     ○ No \[Next: Q7]

***

### Q7 🔴 Mandatory — Child Attendance Management

**Main Question:** Does your solution contain a Child Attendance module that provides, but is not limited to, the following functions:

* a. Manual and automated check-in and check-out (e.g. via digital QR codes and/or in-app sign in or out by teachers and/or facial recognition etc.)
* b. Alerts and notifications sent to parents (when child is signed in or out, alerts for non-pickups, absences)
* c. Child Attendance Profiles (contains monthly attendance details such as no. of days present and/or no. of days absent and/or no. of days expected to be present) and complete audit trails (date, timestamp and user who created or modified the attendance record to be displayed within the module's interface)

🔴 **Answer:** ○ Yes \[Next: Q8]     ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory — School Operations Management

**Main Question:** Does your solution contain a School Operations Module that provides, but not limited to, the following functions:

* a. Web enquiry form (allow parents to enquire about programme and indicate interest)
* b. Visitor Management (e.g. sign-in and/or sign-out time and their temperature)

🔴 **Answer:** ○ Yes \[Next: Q9]     ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred — School Operations Management - Preferred Features

**Main Question:** Does your solution contain a School Operations Module that provides, but not limited to, the following preferred functions:

* a. Bus transport attendance and temperature tracking
* b. Maintenance planning and monitoring (e.g. cleaning, pest control, fixtures, etc.)
* c. Curriculum development framework repository

🟡 **Answer:** ○ Yes \[Next: Q10]     ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory — Parent Communication Management

**Main Question:** Does your solution allow the preschool to manage content meant for parents such as the following:

* a. Publicity and general announcement (such as upcoming events and programmes) via SMS, Email or parent-centre app.
* b. School media repository, child portfolio and highlights
* c. Parents' Handbook, Terms of Reference and agreements e.g. PDPA consent, medication administration

🔴 **Answer:** ○ Yes \[Next: Q11]     ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred — Parent Communication Management - Preferred Features

**Main Question:** Does your solution allow the preschool to manage content meant for parents by offering the following preferred functions:

* a. Incident notification
* b. Feedback and E-survey (school can create their own survey questionnaire and collate survey results)
* c. Real-time chat function
* d. Case management and reports
* e. Parent Education Resources and Programmes
* f. Parents Self-Service Portal (allow parents to log in to update personal particulars and information about their child)

🟡 **Answer:** ○ Yes \[Next: Q12]     ○ No \[Next: Q12]

***

### Q12 🔴 Mandatory — Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q13]     ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred — Fire Drill Management

**Main Question:** Does your solution contain a Fire Drill Management module to manage fire escape route plans, fire drill exercises, review of fire extinguisher expiry dates, schedule of fire drill exercises, schedule of fire alarm testing, maintenance schedule of fire equipment etc.?

🟡 **Answer:** ○ Yes \[Next: Q14]     ○ No \[Next: Q14]

***

### Q14 🟡 Preferred — HFMD Monitoring

**Main Question:** Does your solution provide a Hand Foot Mouth Disease (HFMD) Monitoring and Reporting module that allows the school to track incidents and generate reports for submission to Ministry of Health and ECDA?

🟡 **Answer:** ○ Yes \[Next: Q15]     ○ No \[Next: Q15]

***

### Q15 🟡 Preferred — Pre-Visit Licence Evaluation Preparation

**Main Question:** Does your solution allow the school to prepare the Pre-Visit licence Evaluation form?

🟡 **Answer:** ○ Yes \[Next: Q16]     ○ No \[Next: Q16]

***

### Q16 🟡 Preferred — SPARK Report Submission

**Main Question:** Does your solution allow the school to prepare and submit SPARK Standards Self Evaluation and Report to ECDA?

🟡 **Answer:** ○ Yes \[Next: Q17]     ○ No \[Next: Q17]

***

### Q17 🔴 Mandatory — e-Form Management

**Main Question:** Does your solution allow for the creation and update of the following forms:

**a. Child care enrolment and subsidy application**

* i. Submit basic enrolment details (applicable for all children) applying for Child Care Subsidies
* ii. Apply for Start-Up Grant (SUG) and/or Child Care Financial Assistance (CCFA) (applicable for Singapore Citizen children only)
* iii. Update change in applicant (for existing enrolled Singapore Citizen children)

**b. Subsidy update and Special Approval application (Existing enrolment)**

* i. Update child and/or applicant/spouse's details (for existing enrolled Singapore Citizen children)
* ii. Apply or Renewal of Special Approval, Start-Up Grant (SUG)
* iii. Apply for financial assistance for child care (CCFA) for children who are already enrolled in the centre (applicable for Singapore Citizen children only)

**c. Withdrawal from child care centre or subsidy scheme**

* i. Withdraw child from child care centre
* ii. Withdraw from subsidy scheme

**d. Provide basic enrolment submission details (applicable for all children)**

* Support Kindergarten Fee Assistance Scheme (KiFAS)

  **Note:** KiFAS is only applicable for Anchor Operators (AOPs) and Ministry of Education (MOE) Kindergarten only.

🔴 **Answer:** ○ Yes \[Next: Q18]     ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory — File Upload Feature

**Main Question:** Does your solution support the uploading of documents (File size up to 8 MB) from parents to facilitate the enrolment of the child?

🔴 **Answer:** ○ Yes \[Next: Q19]     ○ No \[⚠️ Cannot Proceed]

***

### Q19 🟡 Preferred — Annex Management

**Main Question:** Does your solution allow for the creation and update of Annexes for collection of additional information (e.g. allergies, grandparents' contacts, etc.)?

🟡 **Answer:** ○ Yes \[Next: Q20]     ○ No \[Next: Q20]

***

### Q20 🔴 Mandatory — Vacancy and Waitlist Management

**Main Question:** Does your solution contain a Vacancy and Waitlist module that provides, but not limited to, the following functions:

* a. Update vacancies in real-time by service/programme type, auto-calculate vacancies based on enrolments and withdrawals and set capacity limits through integration with staff records to maintain compliant staff-child ratios
* b. Display confirmed incoming or outgoing children for each service and/or programme.
* c. Waitlist management of enrolment interests from different channels e.g. internal transfers, walk-ins, social media lead, web portal leads, etc
* d. Track and monitor the sequence of applicants and allocate available vacancies based on predefined rules or priority order
* e. Generate monthly vacancy statuses for each service level showing at least seven months (current and six following months) of data with the labels 'Available', 'Limited' and 'Full' in a format compatible with ECDA's Content Management System.

  **Note:** "Limited" is defined as less than or equal to 5% of available capacity
* f. Send out real-time alerts or display visual indicators triggered by pre-defined conditions (e.g. when certain level of capacity or limit is reached).

🔴 **Answer:** ○ Yes \[Next: Q21]     ○ No \[⚠️ Cannot Proceed]

***

### Q21 🟡 Preferred — Multi-Tenancy Vacancy and Waitlist Management

**Main Question:** Does your solution support multi-tenancy with consolidated view and management of vacancy and waitlist data across multiple centres?

🟡 **Answer:** ○ Yes \[Next: Q22]     ○ No \[Next: Q22]

***

### Q22 🔴 Mandatory — Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

The dashboard must include at least one of the following interactive features:

* **Option 1:** Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* **Option 2:** At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q23]     ○ No \[⚠️ Cannot Proceed]

***

### Q23 🟡 Preferred — AI Powered Education Management

**Main Question:** Does your solution have any AI features?

🟡 **Answer:** ○ Yes \[Next: Q24]     ○ No \[Next: Q25]

\--

### Q24 🔴 Mandatory Follow-up — AI Powered Education Management - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Describe your AI features. Examples are:

* a. Use of Chatbot to assist with parent's queries
* b. Ability to generate draft paragraphs of children's portfolio based on image analysis
* c. Ability to provide recommendation on food menu planning based on health condition of child
* d. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q25]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box — Describe your AI features]

***

### Q25 🔴 Mandatory — Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q26]     ○ No \[⚠️ Cannot Proceed]

***

### Q26 🔴 Mandatory — Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q27]     ○ No \[⚠️ Cannot Proceed]

***

### Q27 🔴 Mandatory — Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q28]     ○ No \[⚠️ Cannot Proceed]

***

### Q28 🟡 Preferred — Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q29]     ○ No \[Next: Q31]

***

### Q29 🟡 Preferred — CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q30]     ○ No \[Assessment Finished]

\--

### Q30 🔴 Mandatory Follow-up — CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q29*

**Main Question:** Please specify the following information:

* i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* ii. The cybersecurity certification the organisation has met
* iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Field — Specify certification details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q31 🟡 Preferred — CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q32]     ○ No \[Assessment Finished]

\--

### Q32 🔴 Mandatory Follow-up — CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q31*

**Main Question:** Please specify the following information:

* i. The cybersecurity certification the organisation has met
* ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished]     ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Field — Specify certification details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Data Mining & Analytics (Centre Operations)

Help preschool operators analyse daily operational data. The system provides insights into parent preferences, predicts student dropout rates, and enables family profiling, supporting data-driven decisions for improved business management.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Parent Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** a. Parent Management (Help centres better understand parents' preferences for communication, enrolment, payment, online Home-Based Learning (HBL) content development, etc.)

**Examples:** i. Ability to prospect parent communication content, mode, frequency, etc based on their historical preference, viewing habits, responses made. ii. Use AI (if applicable) to forecast dropout rates to prepare the centre for replacement intake iii. Ability to profile parents and grandparents based on income, residence type, etc.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Staff Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** b. Staff Management (Identify behaviour and trends associated with staff with a focus on educators, centre leaders as the workforce, staff retention, smarter deployment, delegation of workload, etc.)

**Examples:** i. Ability to perform Staff Profiling to increase retention and better identify traits of prospective applicants (based on data points like distance from home to workplace, employment history, age, past employers, expected salaries, etc).

**Secondary data points can include:**

* Track staffs' duration in service
* Monitor performance charts over the course of service
* Generate Recommendation/Forecast by AI (if applicable) on possible secondary duties which tap on staff's strength, passion areas based on the above
* Assess Workload (i.e. special assignments and projects)

ii. Automated data for industry benchmarking if specific operators want to share selected information

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - Health and Safety Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** c. Health and Safety Management (Enhance centre health and safety management capabilities (e.g. infectious disease seasonal patterns, cleaning and disinfection planning/scheduling, visitor management etc based on data like MC rates, infection occurrences, attendance and temperature records, areas and objects with high touchpoints, etc))

**Examples:** i. Ability to provide reminders and checklists for self-checks on health and safety indicators ii. Ability to provide centralised interface to communicate centre's health and safety matters iii. Ability to provide data-mine pertinent indicators (if applicable) to co-relate on health areas (e.g. MC, infection occurrence, MOH data, health and safety servicing activities)

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Finance Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** d) Finance Management (Enhance financial planning e.g. budgetary and reinvestment of productivity gains based on data like past purchase patterns for bulk services, groceries, ancillary expenses on staff uniforms, stationery, manpower savings, etc.)

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Data Preparation

**Main Question:** Does your solution have the capability to:

**Technical Requirements:** a. Import, clean and prepare data for analysis? b. Aggregate data from multiple sources (at least two and have the ability to include third-party data sources) of different functions (e.g. CRM - parents, HR, Finance, Preschool centre operations) if applicable

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Predictive Analytics Capabilities

**Main Question:** Does your solution have the capability to predict data such as marketing responses, business trends, secure data mining, or geospatial analysis?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - System Integration and Connectivity

**Main Question:** Does your solution provide connectors or prebuilt integration tools to integrate with other enterprise applications?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - Dashboards and Reports Formatting

**Main Question:** Does your solution allow the user to present the analytics and reports in different formats (e.g. graphs, tabular formats, etc.) for key business areas including but not limited to child matters, HR, centre information and parent information?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - Machine Learning Capabilities

**Main Question:** Does your solution incorporate machine learning capabilities?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Technical Support Services

**Main Question:** Does your solution include offering support services to support preschools on the above requirements such as technical support, etc?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Integration with Existing Systems

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

### Q13 🔴 Mandatory Follow-up - Integration with Existing Systems - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🟡 Preferred - AI Powered Analytics Platform

**Main Question:** Does your solution have any analytics-related AI features?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

### Q15 🔴 Mandatory Follow-up - AI Powered Analytics Platform - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Describe your analytics-related AI features. Examples are:

**Examples:** a. Provide forecasting analytics (e.g. decision trees, segmentation, regression) b. Derive consolidated insights that are actionable to improve centre operations (e.g. improved staff retention, better communication with parents, maximising productivity gains, optimising learning outcomes, reducing wastage, etc.) c. Obtain predictive insights on areas like health and safety management, optimise manpower deployment to improve churn rate and forecast staff turnover and employee performance as described in requirement 3 d. Predict trends such as marketing responses, business directions, secure data mining, or geospatial analysis incorporating public data points e. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

***

### Q20 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Data Mining & Analytics (Child Development)

Transform educational data into intuitive dashboards for tracking children's progress by enabling educators to monitor developmental milestones against benchmarks, evaluate teaching effectiveness, and efficiently assess individual learning outcomes through visual analytics.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Child Development

**Main Question:** Does your solution provide data mining and analytics capabilities for the following domains of child development through the use of evaluation checklists, including:

**Development Domains:** a. Language and Literacy (EL and MTL) - Ability to listen and read for information and enjoyment, speak to convey meaning and communicate, etc. b. Numeracy - Recognise and use simple relationships and patterns, use numbers in daily experiences, etc. c. Discovery of the World - Show an interest in the world, finding out why things happened and how things work, etc. d. Aesthetics and Creative expression - Enjoy and express ideas and feelings through art, music and movement, etc. e. Health, Safety and Motor skills Development - Develop gross and fine motor skills, space, effort and relationship awareness, etc. f. Values, Learning Dispositions, Social and Emotional Development - Understand emotions and communicating emotions, sense of self and ability to self regulate, building positive relationships which are the basis for development and learning, etc. g. Physical health / growth - Measure height, weight, etc.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Child Development Analytics

**Main Question:** Does your solution allow operators to aggregate data from every child across all domains in each class to track the average development progress?

**Additional Capability:** a. If applicable, does it track and monitor a class' progress in specific areas against the National Health Booklet benchmarks?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Customisable Assessment

**Main Question:** Does your solution allow operators to incorporate new checklists items or data points and make amendments to existing ones which are specific to children's demographics or the operator's pedagogy or specific programmes?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Documentation Categorisation

**Main Question:** Does your solution recognise the categorisation of documentation such as photos of children at least in the domains mentioned-above?

**Additional Capability:** a. If applicable, allow customisation of categories on preschool's request.

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Student Goal Setting

**Main Question:** Does your solution allow user to provide inputs and set goals for each child?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - User Role Management

**Main Question:** Does your solution include various user roles (e.g. Educator, Centre leader, Principal, Learning Support Educator etc) with varying levels of access to data and analysis of dashboards (i.e. different levels of transparency and visibility of information when photos, assessment, inputs, and recommendations are posted)?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Profile Creation and Personalisation

**Main Question:** Does your solution create individual profiles for each child and allow personalised approach for every child's development?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Smart Assessment Analysis

**Main Question:** Does your solution pick up common keywords based on the assessment made and provide initial recommendations based on it?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory - Dashboards and Reports Formatting

**Main Question:** Does your solution allow the user to present the analytics and reports of each evaluation checklist or domain in different formats (e.g. graphs, tabular format, etc.)?

**Additional Capabilities:** a. Does your solution allow the export of selected graphs, tables, or charts to be shared with parents? b. Does your solution analyse the individual child's progress against the class' performance to identify areas for additional attention and assistance?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Data Preparation

**Main Question:** Does your solution have the capability to import, clean, and prepare data for data analysis?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🟡 Preferred - System Integration and Connectivity

**Main Question:** Does your solution provide connector,prebuilt interface, or integration tools to integrate with other enterprise applications?

**Technical Requirements:** The interface protocol shall be using secured FTP (SFTP) setup via batch file transfer or web services/ application programming interface (API). For near real-time and real-time interfaces between systems, web services/API shall be used as the mode of interface.

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🟡 Preferred - IT Support Services

**Main Question:** Does your solution include offering support services to support preschools on the above requirements such as technical support, etc?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🟡 Preferred - Integration with Existing Systems

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

### Q15 🔴 Mandatory Follow-up - Integration with Existing Systems - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q18]

\--

### Q17 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q18 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

***

### Q22 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q24 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

### Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Data Mining & Analytics (Centre Operations and Child Development)

Combine operational and developmental data analysis by using AI to optimise centre management and service quality while monitoring children's progress, providing data-driven recommendations for both business operations and individualised child development needs.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Parent Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** a. Parent Management (Help centres better understand parents' preferences for communication, enrolment, payment, online Home-Based Learning (HBL) content development, etc.)

**Examples:** i. Ability to prospect parent communication content, mode, frequency, etc based on their historical preference, viewing habits, responses made. ii. Use AI (if applicable) to forecast dropout rates to prepare the centre for replacement intake iii. Ability to profile parents and grandparents based on income, residence type, etc.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Staff Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** b. Staff Management (Identify behaviour and trends associated with staff with a focus on educators, centre leaders as the workforce, staff retention, smarter deployment, delegation of workload, etc.)

**Examples:** i. Ability to perform Staff Profiling to increase retention and better identify traits of prospective applicants (based on data points like distance from home to workplace, employment history, age, past employers, expected salaries, etc).

**Secondary data points can include:**

* Track staffs' duration in service
* Monitor performance charts over the course of service
* Generate Recommendation/Forecast by AI (if applicable) on possible secondary duties which tap on staff's strength, passion areas based on the above
* Assess Workload (i.e. special assignments and projects)

ii. Automated data for industry benchmarking if specific operators want to share selected information

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - Health and Safety Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** c. Health and Safety Management (Enhance centre health and safety management capabilities (e.g. infectious disease seasonal patterns, cleaning and disinfection planning/scheduling, visitor management etc based on data like MC rates, infection occurrences, attendance and temperature records, areas and objects with high touchpoints, etc))

**Examples:** i. Ability to provide reminders and checklists for self-checks on health and safety indicators ii. Ability to provide centralised interface to communicate centre's health and safety matters iii. Ability to provide data-mine pertinent indicators (if applicable) to co-relate on health areas (e.g. MC, infection occurrence, MOH data, health and safety servicing activities)

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Finance Management Insights

**Main Question:** Does your solution provide data mining and analytics capabilities for preschool centre operations, including:

**Scope Requirements:** d) Finance Management (Enhance financial planning e.g. budgetary and reinvestment of productivity gains based on data like past purchase patterns for bulk services, groceries, ancillary expenses on staff uniforms, stationery, manpower savings, etc.)

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Data Preparation

**Main Question:** Does your solution have the capability to:

**Technical Requirements:** a. Import, clean and prepare data for analysis? b. Aggregate data from multiple sources (at least two and have the ability to include third-party data sources) of different functions (e.g. CRM - parents, HR, Finance, Preschool centre operations) if applicable

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - AI Powered Analytics

**Main Question:** Does your solution have any Analytics-Related AI features?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

### Q8 🔴 Mandatory Follow-up - AI Powered Analytics - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** Describe your Analytics-Related AI features. Examples are:

**Examples:** a. Provide forecasting analytics (e.g. decision trees, segmentation, regression) b. Derive consolidated insights that are actionable to improve centre operations (e.g. improved staff retention, better communication with parents, maximising productivity gains, optimising learning outcomes, reducing wastage, etc.) c. Obtain predictive insights on areas like health and safety management, optimise manpower deployment to improve churn rate and forecast staff turnover and employee performance as described in requirement 3 d. Predict trends such as marketing responses, business directions, secure data mining, or geospatial analysis incorporating public data points e. Generate output, identify items, or provide recommendations based on training models to improve decision-making f. Recognise text, images to shorten time taken for manual inputs of forms g. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🟡 Preferred - Machine Learning Capabilities

**Main Question:** Does your solution incorporate with machine learning capabilities?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory - Child Development

**Main Question:** Does your solution provide data mining and analytics capabilities for the following domains of child development through the use of evaluation checklists, including:

**Development Domains:** a. Language and Literacy (EL and MTL) - Ability to listen and read for information and enjoyment, speak to convey meaning and communicate, etc. b. Numeracy - Recognise and use simple relationships and patterns, use numbers in daily experiences, etc. c. Discovery of the World - Show an interest in the world, finding out why things happened and how things work, etc. d. Aesthetics and Creative expression - Enjoy and express ideas and feelings through art, music and movement, etc. e. Health, Safety and Motor skills Development - Develop gross and fine motor skills, space, effort and relationship awareness, etc. f. Values, Learning Dispositions, Social and Emotional Development - Understand emotions and communicating emotions, sense of self and ability to self regulate, building positive relationships which are the basis for development and learning, etc. g. Physical health / growth - Measure height, weight, etc.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Child Development Analytics

**Main Question:** Does your solution allow operators to aggregate data from every child across all domains in each class to track the average development progress?

**Additional Capability:** a. If applicable, does it track and monitor a class' progress in specific areas against the National Health Booklet benchmarks?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Customisable Assessment

**Main Question:** Does your solution allow operators to incorporate new checklists items or data points and make amendments to existing ones which are specific to children's demographics or the operator's pedagogy or specific programmes?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - Documentation Categorisation

**Main Question:** Does your solution recognise the categorisation of documentation such as photos of children at least in the domains mentioned-above?

**Additional Capability:** a. If applicable, allow customisation of categories on preschool's request.

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🟡 Preferred - Student Goal Setting

**Main Question:** Does your solution allow user to provide inputs and set goals for each child?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

### Q15 🟡 Preferred - User Role Management

**Main Question:** Does your solution include various user roles (e.g. Educator, Centre leader, Principal, Learning Support Educator etc) with varying levels of access to data and analysis of dashboards (i.e. different levels of transparency and visibility of information when photos, assessment, inputs, and recommendations are posted)?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q16]

***

### Q16 🟡 Preferred - Profile Creation and Personalisation

**Main Question:** Does your solution create individual profiles for each child and allow personalised approach for every child's development?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q17]

***

### Q17 🟡 Preferred - Smart Assessment Analysis

**Main Question:** Does your solution pick up common keywords based on the assessment made and provide initial recommendations based on it?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q18]

***

### Q18 🔴 Mandatory - Dashboards and Reports Formatting

**Main Question:** Does your solution allow the user to present the analytics and reports of each evaluation checklist or domain in different formats (e.g. graphs, tabular format, etc.)?

**Additional Capabilities:** a. Does your solution allow the export of selected graphs, tables, or charts to be shared with parents? b. Does your solution analyse the individual child's progress against the class' performance to identify areas for additional attention and assistance?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🟡 Preferred - System Integration and Connectivity

**Main Question:** Does your solution provide connector,prebuilt interface, or integration tools to integrate with other enterprise applications?

**Technical Requirements:** The interface protocol shall be using secured FTP (SFTP) setup via batch file transfer or web services/ application programming interface (API). For near real-time and real-time interfaces between systems, web services/API shall be used as the mode of interface.

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q20]

***

### Q20 🟡 Preferred - Professional Services

**Main Question:** Does your solution include offering support services to support preschools on the above requirements such as technical support, etc?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q21]

***

### Q21 🟡 Preferred - Third-Party Integration

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems ?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q23]

\--

### Q22 🔴 Mandatory Follow-up - Third-Party Integration - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q23 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q24] ○ No \[⚠️ Cannot Proceed]

***

### Q24 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q25] ○ No \[⚠️ Cannot Proceed]

***

### Q25 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q26] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q26 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q27] ○ No \[Next: Q29]

***

### Q27 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q28] ○ No \[Assessment Finished]

\--

### Q28 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q27*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q29 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q30] ○ No \[Assessment Finished]

\--

### Q30 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q29*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Talent Attraction Platform

Attract potential teachers to join the industry by leveraging digital platforms that are integrated with ECDA's systems.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Outreach, Attract and Recruit Staff Including ECEs (Early Childhood Educators)

**Main Question:** Does your solution:

**Core Functionality Requirements:** a. Allow operators to advertise the careers/openings available with a short write-up and update the listing as and when required b. Allow potential applicants to upload their CVs and other documents e.g. certifications c. Provide surveys for potential applicants to use to assess their suitability for an EC career (i.e. job fit and organisation fit) and for operators to evaluate these applicants' suitability d. Embed Candidate Relationship Management (CRM) to allow two-way conversations between operators and applicants e. Notify operators each time a job application is sent in automatically (Notification settings should preferably be configurable for operators to edit frequency and recipients of the notifications) f. Obtain applicant's consent for the submission of personal particulars to the operator

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Application Tracking

**Main Question:** Does your solution allow operators to update the status of each application received, and perform the following:

**Application Management Features:** a. Track and inform operators from the point when each application is received till the point when evaluation of the application is complete i.e. applicant is hired or rejected b. Remind operators to process and update each application or status at various intervals (e.g. 30 days after application is received and/or 30 days since application has been last updated from applied to processing or processing to approved/rejected)? c. (If required by the operator) Send automated email replies based on pre-defined templates to update applicants of the status of their application e.g. processing, rejected, accepted, etc.

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🟡 Preferred - Employee Database Management

**Main Question:** Does your solution manage operators' part-time and relief staff database in accordance to the operator's data management policies, such as:

**Database Management Capabilities:** a. Store a list of applicants who have applied for positions prior b. Store a list of part-time and relief staff which includes their names, contact number, certifications, availability and their work history at the various centres (if an operator has more than 1 centre) c. (If applicable) Allow the lists mentioned in (a) and (b) to be accessed by a customisable list of users/ centres of the same operator d. Allow part time staff and applicants to amend their particulars at their own time e. Allow part time staff and applicants to select the dates they are able to work with the system matching these ECEs to centres with vacancies and notify operators of such matches

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Job Applications and Onboarding

**Main Question:** Does your solution:

**Advanced Application Features:** a. Have a video conference function for operators to interview shortlisted applicants b. Come with AI capabilities e.g. matching of applicant to available openings based on certification / years of experience submitted c. Include a personalised module for selected applicants to submit necessary documents for onboarding purposes (e.g. certificates, testimonials, etc.) d. Allow virtual tours of the centre for orientation purposes

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Job Application Status Tracker

**Main Question:** Does your solution allow potential applicants to track the status (e.g. Applied, Processing, Approved, Rejected, etc.) of their applications at any point of time and subscribe or unsubscribe to operator's job mail subscription, such as:

**Applicant Self-Service Features:** a. Send an auto message that the application is received after an applicant has applied for a role b. Allow potential applicants to subscribe and unsubscribe to receive alerts on job openings on a regular basis

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🔴 Mandatory - Dashboards and Reports Retrieval

**Main Question:** Does your solution allow users to retrieve data analytics or reports in formats such as graphs and tables? e.g. the number of ECEs applying for positions in a particular months, the number of viewers clicking on listings, etc.

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Professional Services

**Main Question:** Does your solution include support services to support preschools on the above requirements such as technical support etc.?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Third-Party Integration

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems ?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - Third-Party Integration - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q16 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

***

### Q17 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Learning Platform for CPD and Mentoring

Provide personalised professional development for early childhood educators and intervention specialists. The system delivers customised training content and mentoring support, enabling continuous professional growth and skill enhancement for teaching staff.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Platform Administration and Management

**Main Question:** Does your solution perfom the following functions:

**Core Administrative Functions:** a. User accounts management including the creation, cessation, access, roles and maintenance of accounts (trainer, administrator, learner) b. Learners management (training records/ progress): attendance, assessment, learners' profiles (i.e. Infant Educator, Early Years Educator, Preschool Educator, Inclusion Coordinator, Early Intervention and Learning Support tracks), users' learning needs analyses based on their job roles and Technical Skills Competencies c. Dashboards and reports with analytics that provide insights including learners' progress/ activity, courses popularity etc. d. Automated workflows management e.g. reminders and notifications for learners and trainers on upcoming training courses e. Content management tool to update the course catalogue and showcase quantitative (e.g. star rating to reflect total average feedback on courses, Likert scale ratings for individual questions) and qualitative feedback from previous participants or trainees f. Administration of feedback and surveys from the learners and ability to collate and analyse the feedback/survey results

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Multi-tenancy Offer

**Main Question:** Does your solution offer multi-tenancy for easy administration for HQ centres?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Trainers' Module - Mandatory

**Main Question:** Does your solution offer the following features:

**Essential Trainer Features:** a. Provide a course-authoring tool that supports the creation of lessons from scratch and/or sync with external content including the upload and usage of multiple file formats including PowerPoint, PDF, MP4, MOV, YouTube links, Google docs/sheets, Word etc. b. Create and assign learning paths/ workflows for different learners' profiles with courses and plans customised for each profile c. Engage learners on a collective/ 1-to-1 basis before, during, or after training/course e.g. survey d. Assess and track learners' progress in building their Technical Skills and Competencies e. Send out notifications for activities that require attention e.g. announcements, assignment submission

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Trainers' Module - Preferred

**Main Question:** Does your solution offer one or more of the following features:

**Additional Trainer Features:** a. Ability to record courses and/or conduct live courses b. Integrated tools to facilitate training, such as polls, forums, real-time collaboration board c. Integrated tools to assess/grade assignments or observation records and provide comments

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - Trainers' Module - Elaboration

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Briefly describe the features that are included in your solution.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q7 🔴 Mandatory - Learners' Module

**Main Question:** Does your solution offer the following features:

**Essential Learner Features:** a. Provide a platform for learners to login for self-directed learning b. Allow learners to do a self-assessment and conduct a learning needs analysis with the centre leader referencing the Technical Skills and Competencies tied to their roles c. Provide profile view, schedule and progress chart / plan based on the relevant Technical Skills and Competencies to map training/development and update the plan based on training attended. When applicable, include data sync to One\@ECDA for Continuing Professional Development (CPD) hours tracking d. Communicate, collaborate and share resources with other fellow learners and trainers? e. Submit comments/assignments, access files/ materials, retrieve performance certificates or grades e.g. remarks for observation records f. Browse course catalogue, search/ sort available courses/ training based on feedback ratings and sign up for courses/ training g. Recommend courses/ learning content based on learning needs and if applicable, allow for users to flag out courses to be notified when there are available classes for registration h. Provide feedback (quantitative/ qualitative) for attended courses, viewable by other users

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - System Integration and Connectivity

**Main Question:** Does your solution provide connectors or prebuilt integration tools to integrate with other enterprise applications?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Learning Standards Compliance

**Main Question:** Does your solution support learning content software standards such as AICC, SCORM, TinCan 1.0?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - Third-Party Integration

**Main Question:** Is your solution currently integrated with the pre-schools' existing IT systems ?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - Third-Party Integration - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Content Storage

**Main Question:** Does your solution incorporate storage for the uploaded materials (e.g. teaching PowerPoint files, assignments)?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Technical Support Services

**Main Question:** Does your solution include offering support services to support preschools on the above requirements such as technical support, etc?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - White-Labelling

**Main Question:** Does your solution allow white-labelling ?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

### Q15 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q18]

\--

### Q17 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q18 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

***

### Q22 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q24 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

### Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Video Analytics for Preschool Safety

Equip surveillance systems with video analytics, centre leaders can receive alerts on potential risks or hazards, such as children who are left on their own without adult supervision in classrooms and intrusion. Preschool operators may also leverage data collected to identify areas for improvement in centre operations for enhanced safety and security measures.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Video Management**

**Main Question:** Can your solution provide video management capabilities, such as:

**Core Requirements:**

* Enable on-site monitoring through IP-enabled video cameras
* Enable clients to manage and store video footage from cameras, handle large amounts of data, provide real-time monitoring, and allow for easy retrieval and analysis of footage
* Support Secure Sockets Layer (SSL) or other encrypted communication layers between the video cameras and the video camera gateway
* Provide editing functions for video footage, such as the extraction of video clips from a specific time frame, removal of audio, export of clips and other similar functions
* Allow for zooming in on video footage during playback or review
* Enable video search using filters e.g. time, location, event type and facial recognition (to track individuals across multiple video sources for easy extraction of relevant clips)
* Enable organisation and management of video clips through bookmarking and folder-based categorisation

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Real-time Video Analytics**

**Main Question:** Can your solution provide the following real-time video analytics capabilities:

**Analytics Requirements:**

* Intrusion/threat/loitering detection - allow for the definition of zones that require greater surveillance and trigger automated alerts when intrusion, threat, or loitering is detected
* Face indexing and/or facial recognition, trigger alerts when blacklisted individuals enter the area or when children are left unsupervised in the absence of adults
* Instant notification when camera feeds are not sent through

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Machine Learning**

**Main Question:** Does your solution support model retraining based on user feedback?

**Submission Requirements:** Describe the processes and the typical timeframe for a retained model to be deployed and take effect.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q4 🟡 Preferred - Other Features (Video Management)**

**Main Question:** Can your solution provide other video management capabilities, such as:

**Additional Capabilities:**

* Masking of faces feature with selective masking of faces in footage that needs to be shared with third parties, to protect the identities and privacy of staff, children, and visitors
* Allow for natural language searches using prompts/keywords such as "adult hitting a child" to facilitate incident investigation
* Others, please specify

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

**Q5 🔴 Mandatory Follow-up - Other Features (Video Management) - Elaboration**

*This question appears only if you answered "Yes" to Q4*

**Main Question:** Describe your other video management capabilities:

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q6 🟡 Preferred - Other Features (Video Analytics)**

**Main Question:** Can your solution provide other video analytics capabilities?

**Analytics Capabilities:**

* Provide an anti-tampering module that ensures cameras, and sensors are functioning optimally by triggering alerts if views are blocked or cameras are out of focus, to ensure consistent surveillance
* Send out real-time alerts triggered by pre-defined video events, such as falls, rough handling of children, or liquid spillage
* Provide reports with machine learning/analytics capabilities, such as safety breaches, threat detection, and traffic flow insights, in various formats (such as graphs and tables)
* Detect emotional / body-language cues that indicate distress and triggering alerts
* Others, please specify

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

**Q7 🔴 Mandatory Follow-up - Other Features (Video Analytics) - Elaboration**

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Describe your other video analytics capabilities.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q8 🟡 Preferred - CCTV Cameras**

**Main Question:** Does your solution provide high-quality cameras that capture clear and detailed video footage, such as CCTV cameras with a minimum resolution of 1080P, footage in colour, and a minimum of 30 frames per second?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - Video Storage**

**Main Question:** Does your solution include a video storage component?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

**Q10 🔴 Mandatory Follow-up - Video Storage - Elaboration**

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Describe the specifications of the storage solution, including retention limits (min. of 30 days), total capacity, whether it is on-premise, cloud-based etc.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q11 🔴 Mandatory - Professional Services**

**Main Question:** Do you provide support services to assist preschools, such as technical support and hardware installation?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🟡 Preferred - System Integration and Connectivity**

**Main Question:** Can your solution be integrated with the pre-schools' existing IT systems or any other management systems?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

**Q13 🔴 Mandatory Follow-up - System Integration and Connectivity - Elaboration**

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Please provide a brief description of the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q14 🔴 Mandatory - Dashboards and Reports**

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🟡 Preferred - AI Features**

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

**Q16 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Capabilities:**

* Generate output, identify items to help in incident investigation
* Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17 🔴 Mandatory - Business Data Extraction**

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

**Q18 🔴 Mandatory - Personal Data Protection**

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

**Q19 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Notes:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

**Q21 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

**Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:**

* The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors
* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q23 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

**Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Required Information:**

* The cybersecurity certification the organisation has met
* The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Vacancy and Waitlist Management

The solution streamlines real-time vacancy tracking, waitlist management, and enrolment allocation while generating capacity reports and\
threshold alerts.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Vacancy and Waitlist Management**

Main Question: Does your solution contain a Vacancy and Waitlist module that provides, but not limited to, the following functions:

**Core Requirements:** a. Update vacancies in real-time by service/programme type, auto-calculate vacancies based on enrolments and withdrawals and set capacity limits through integration with staff records to maintain compliant staff-child ratios

b. Display confirmed incoming or outgoing children for each service and/or programme.

c. Waitlist management of enrolment interests from different channels e.g. internal transfers, walk-ins, social media lead, web portal leads, etc

d. Track and monitor the sequence of applicants and allocates available vacancies based on predefined rules or priority order

e. Generate monthly vacancy statuses for each service level showing at least seven months (current and six following months) of data with the labels 'Available', 'Limited' and 'Full' in a format compatible with ECDA's Content Management System.

Note: "Limited" is defined as less than or equals to 5% of available capacity

f. Sends out real-time alerts or display visual indicators triggered by pre-defined conditions (e.g. when certain level of capacity or limit is reached).

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🟡 Preferred - Multi-Tenancy Vacancy and Waitlist Management**

Main Question: Does your solution support multi-tenancy with consolidated view and management of vacancy and waitlist data across multiple centres?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

**Q4 🟡 Preferred - Third-Party Integration**

Main Question: Is your solution currently integrated with the pre-schools' existing IT systems?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q6]

\--

**Q5 🔴 Mandatory Follow-up - Third-Party Integration - Elaboration**

*This question appears only if you answered "Yes" to Q4*

Main Question: Briefly describe the integrations currently available with the pre-schools' IT systems.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q6 🔴 Mandatory - Dashboards and Reports**

Main Question: Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa

Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - AI Powered Education Management**

Main Question: Does your solution have any AI features?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

**Q8 🔴 Mandatory Follow-up - AI Powered Education Management - Elaboration**

*This question appears only if you answered "Yes" to Q7*

Main Question: Describe your AI features. Examples are:

**AI Feature Examples:** a. Use of Chatbot to assist with parent's queries

b. Ability to generate draft paragraphs of children's portfolio based on image analysis

c. Ability to provide recommendation on food menu planning based on health condition of child

d. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q9 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

**Q11 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

**Q12 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q15]

\--

**Q13 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q12*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Assessment Finished]

***

**Q14 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q13*

Main Question: Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors

ii. The cybersecurity certification the organisation has met

iii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

**Q15 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q12*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Important Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Assessment Finished]

***

**Q16 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q15*

Main Question: Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met

ii. The scope of the certification

**Submission Requirements:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Estate Agency

Estate Agency solutions provide digital tools to streamline property transaction processes and regulatory compliance.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/uS1iwSzgRzDUddcPuN8e">/pages/uS1iwSzgRzDUddcPuN8e</a></td><td>Helps estate agents and real estate salespersons to manage property transaction-related documents and submit transaction records to the Council for Estate Agencies (CEA) efficiently.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Document Management for Estate Agents

Help estate agents and real estate salespersons to manage and generate property transaction-related documents efficiently.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

<table><thead><tr><th width="59">S/No.</th><th width="718">Requirements</th></tr></thead><tbody><tr><td>1.01🔴</td><td>Can your solution allow for cloud based, mobile based and/or web-based usage?</td></tr><tr><td>1.02🔴</td><td>Does your solution support the central storage and retention of the property transaction-related documents listed in Para 7(1) of the Code of Practice for Estate Agents under the Second Schedule of the Estate Agents (Estate Agency Work) Regulations 2010 (COPEA) in digital format?</td></tr><tr><td>1.03🔴</td><td>Does your solution support the retention of the property transaction-related documents in electronic format for at least five years, in accordance with Para 7(1) of the COPEA?</td></tr><tr><td>1.04</td><td>Does your solution support estate agents and salespersons in digitally filling out the following contract templates published at the webpage  &#x3C;www.cea.gov.sg/professionals/agreements_and_checklists>: (a) the eight prescribed Estate Agency Agreements (also set out in the Third Schedule of the Estate Agents (Estate Agency Work) Regulations 2010), (b) the Tenancy Agreement (for HDB flat rental transactions), (c) the Tenancy Agreement (for private residential property transactions), (d) the Option to Purchase (for private residential property transactions), and (e) the Agreement for the Sale and Purchase of Private Residential Property (for private residential property transactions)?</td></tr><tr><td>1.05</td><td>Does your solution support estate agents in digitally filling out the Option to Purchase and Sale and Purchase Agreement in the sale of units in uncompleted private residential properties, as prescribed under the Housing Developer Rules (Rev Ed 2008)?</td></tr><tr><td>1.06</td><td>Does your solution support the auto-population of fields in the property transaction-related documents (e.g. using data from MyInfo, or porting over from other documents/CRM systems)?</td></tr><tr><td>1.07</td><td>Does your solution support the electronic signing of the eight prescribed Estate Agency Agreements?</td></tr><tr><td>1.08</td><td>Does your solution manage commission receipts and payouts?</td></tr><tr><td>1.09</td><td>Does your solution track whether the estate agent or salesperson had obtained the vendor client's written consent for them to advertise the property before the advertisement is posted?</td></tr><tr><td>1.10</td><td>Does your solution monitor ongoing changes to regulatory requirements, and address those changes? </td></tr><tr><td>1.11</td><td>If your solution comes with the following<br>- Collect Personal Identifiable Information and/or<br>- Sensitive Personal Information (SPI)<br><br>Has your company engaged a qualified 3rd party to conduct a security vulnerability assessment of your solution in the last 12 months? If you are a reseller of the solution, please verify with your product principal that they have conducted a security vulnerability assessment of their solution by a qualified 3rd party in the last 12 months. If Yes, please indicate the name of the 3rd party assessor and date of the assessment test in the comment field, and also submit the assessment test report as supporting document.<br><br>Note:<br>[1] Qualified 3rd party include assessors appointed under IMDA GoSecure Programme; Cybersecurity companies accredited under Accreditation@SGD Programme; and CREST-Certified companies or companies with equivalent certifications</td></tr></tbody></table>

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Transaction Records Submission for Estate Agents

Help estate agents and real estate salespersons to manage and submit transaction records to the Council for Estate Agencies (CEA) efficiently.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

<table><thead><tr><th width="59">S/No.</th><th width="718">Requirements</th><th width="88">Type</th></tr></thead><tbody><tr><td>2.01🔴</td><td>Can your solution allow for cloud based, mobile based and/or web-based usage?</td><td>Mandatory</td></tr><tr><td>2.02🔴</td><td>Does your solution support estate agents in digitally submitting their salespersons’ property transactions, completed by clients of the estate agent, to CEA in accordance with CEA's requirements (e.g. monthly submission using CEA’s template, covering residential property transactions)?</td><td>Mandatory</td></tr><tr><td>2.03</td><td>Does your solution monitor ongoing changes to regulatory requirements, and address those changes? </td><td>Preferred</td></tr><tr><td>2.04</td><td>If your solution comes with the following<br>- Collect Personal Identifiable Information and/or<br>- Sensitive Personal Information (SPI)<br><br>Has your company engaged a qualified 3rd party to conduct a security vulnerability assessment of your solution in the last 12 months? If you are a reseller of the solution, please verify with your product principal that they have conducted a security vulnerability assessment of their solution by a qualified 3rd party in the last 12 months. If Yes, please indicate the name of the 3rd party assessor and date of the assessment test in the comment field, and also submit the assessment test report as supporting document.<br><br>Note:<br>[1] Qualified 3rd party include assessors appointed under IMDA GoSecure Programme; Cybersecurity companies accredited under Accreditation@SGD Programme; and CREST-Certified companies or companies with equivalent certifications</td><td>Preferred</td></tr></tbody></table>

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Due Diligence Checks for Salespersons

Offer due diligence checks tools for estate agents and real estate salespersons to screen prospective clients.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

<table><thead><tr><th width="59">S/No.</th><th width="718">Requirements</th></tr></thead><tbody><tr><td>3.01🔴</td><td>Can your solution allow for cloud based, mobile based and/or web-based usage?</td></tr><tr><td>3.02🔴</td><td>Does your solution support estate agents and salespersons in conducting the Customer Due Diligence (CDD) measures to prevent money laundering or terrorism financing activities in accordance with the Estate Agents (Prevention of Money Laundering and Financing of Terrorism) Regulations 2021 [EA(PMLFT) Regs]?<br><br>Such measures include supporting estate agents and salespersons in completing the Real Estate Salesperson’s Checklists (Annex D &#x26; E) and Customer’s Particulars Forms (Annex D1 &#x26; E1) of the Guide on EA(PMLFT) Regs, available at:</td></tr><tr><td>3.03🔴</td><td>Does your solution support the retention and keeping of electronic copies of the documents listed at Annex G of the Guide on EA(PMLFT) Regs for at least five years after the business relationship has ended or after the date of transaction?</td></tr><tr><td>3.04🔴</td><td>Does your solution support estate agents and salespersons in conducting the following due diligence checks for residential property transactions by tapping on the applicable APIs:<br><br>For Residential Rental Property Transactions:<br>3.04.1 Eligibility conditions for HDB flats via HDB's APIs on eligibility to rent out flat/bedrooms and non-citizen quota for renting out of HDB flats;<br>3.04.2 Property usage restrictions for private properties via URA's API on approved residential use;<br>3.04.3 Property ownership details via SLA's API on property ownership information; and<br>3.04.4 Validity of work permit of foreign tenants via MOM's API on work pass validity checks.<br><br>For Residential Sale and Resale Property Transactions:<br>3.04.5 Eligibility conditions for HDB flats via HDB's APIs on Ethnic Integration Policy quota, Singapore Permanent Resident quota and Minimum Occupation Period for HDB resale flats;<br>3.04.6 Property ownership details via SLA's API on property ownership information; and</td></tr><tr><td>3.05</td><td>For Residential Rental Property Transactions:<br>Validity of work permit of foreign tenants via MOM's API on work pass validity checks.</td></tr><tr><td>3.06🔴</td><td>Does your solution support estate agents and salespersons in calculating stamp duty payable via IRAS' stamp duty-related APIs?</td></tr><tr><td>3.07</td><td>Does your solution monitor ongoing changes to regulatory requirements, and address those changes? </td></tr><tr><td>3.08</td><td>If your solution comes with the following<br>- Collect Personal Identifiable Information and/or<br>- Sensitive Personal Information (SPI)<br><br>Has your company engaged a qualified 3rd party to conduct a security vulnerability assessment of your solution in the last 12 months? If you are a reseller of the solution, please verify with your product principal that they have conducted a security vulnerability assessment of their solution by a qualified 3rd party in the last 12 months. If Yes, please indicate the name of the 3rd party assessor and date of the assessment test in the comment field, and also submit the assessment test report as supporting document.<br><br>Note:<br>[1] Qualified 3rd party include assessors appointed under IMDA GoSecure Programme; Cybersecurity companies accredited under Accreditation@SGD Programme; and CREST-Certified companies or companies with equivalent certifications</td></tr></tbody></table>

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Document Management & Transaction Records Submission for Estate Agents

Helps estate agents and real estate salespersons to manage property transaction-related documents and submit transaction records to the Council for Estate Agencies (CEA) efficiently.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

**🔴 Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Document Management**

**Main Question:** Does your solution support the central storage and retention of the property transaction-related documents listed in Para 7(1) of the Code of Practice for Estate Agents under the Second Schedule of the Estate Agents (Estate Agency Work) Regulations 2010 (COPEA) in digital format?

**🔴 Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Document Retention**

**Main Question:** Does your solution support the retention of the property transaction-related documents in electronic format for at least five years, in accordance with Para 7(1) of the COPEA?

**🔴 Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🟡 Preferred - Digital Filing of Contracts**

**Main Question:** Does your solution support estate agents and salespersons in digitally filling out the following contract templates published at the webpage <[www.cea.gov.sg/professionals/agreements\_and\_checklists](http://www.cea.gov.sg/professionals/agreements_and_checklists)>: (a) the eight prescribed Estate Agency Agreements (also set out in the Third Schedule of the Estate Agents (Estate Agency Work) Regulations 2010), (b) the Tenancy Agreement (for HDB flat rental transactions), (c) the Tenancy Agreement (for private residential property transactions), (d) the Option to Purchase (for private residential property transactions), and (e) the Agreement for the Sale and Purchase of Private Residential Property (for private residential property transactions)?

**🟡 Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

**Q5 🟡 Preferred - Digital Filing of Purchase Documents**

**Main Question:** Does your solution support estate agents in digitally filling out the Option to Purchase and Sale and Purchase Agreement in the sale of units in uncompleted private residential properties, as prescribed under the Housing Developer Rules (Rev Ed 2008)?

**🟡 Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

**Q6 🟡 Preferred - Fields Auto-Population**

**Main Question:** Does your solution support the auto-population of fields in the property transaction-related documents (e.g. using data from MyInfo, or porting over from other documents/CRM systems)?

**🟡 Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

**Q7 🟡 Preferred - Electronic Signing**

**Main Question:** Does your solution support the electronic signing of the eight prescribed Estate Agency Agreements?

**🟡 Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

**Q8 🟡 Preferred - Commission Receipt and Payouts Management**

**Main Question:** Does your solution manage commission receipts and payouts?

**🟡 Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - Client Consent Tracking**

**Main Question:** Does your solution track whether the estate agent or salesperson had obtained the vendor client's written consent for them to advertise the property before the advertisement is posted?

**🟡 Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🟡 Preferred - Regulatory Compliance Monitoring**

**Main Question:** Does your solution monitor ongoing changes to regulatory requirements, and address those changes?

**🟡 Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🔴 Mandatory - Transaction Records Submission**

**Main Question:** Does your solution support estate agents in digitally submitting their salespersons' property transactions, completed by clients of the estate agent, to CEA in accordance with CEA's requirements (e.g. monthly submission using CEA's template, covering residential property transactions)?

**🔴 Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🔴 Mandatory - Dashboards and Reports**

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Technical Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

**🔴 Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13 🟡 Preferred - AI Features**

**Main Question:** Does your solution incorporate AI in your core features and functions?

**🟡 Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

**Q14 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

**🔴 Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q15 🔴 Mandatory - Business Data Extraction**

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

**🔴 Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

**Q16 🟡 Preferred - Personal Data Collection**

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

**🟡 Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

**Q17 🔴 Mandatory Follow-up - Personal Data Protection**

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

**🔴 Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

**Q18 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

**🔴 Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

**Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

**🟡 Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

\--

**Q20 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

**🟡 Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

**Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

**🔴 Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q22 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q19*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

**🟡 Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

**Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

**🔴 Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Food Services

Food Services solutions provide digital tools to integrate front and back-of-house operations.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/refDzZl78L5tZIKtzqxH">/pages/refDzZl78L5tZIKtzqxH</a></td><td>Integrate front and back-of-house operations for F&#x26;B businesses by unifying point-of-sale, kitchen management, inventory, and supplier management functions, enabling seamless coordination across the entire F&#x26;B value chain.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Connected Business Suite

Integrate front and back-of-house operations for F\&B businesses by unifying point-of-sale, kitchen management, inventory, and supplier management functions across the entire F\&B Value Chain.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Digital Ordering and Payment

**Main Question:** Does your solution allow customers to:

**Customer Capabilities:** a. View the food menu to place orders b. Self-order for dine-in and/or takeaway c. Make secured e-payment\* (credit card, PayNow, or equivalent) directly via the app or website d. Receive e-receipts

**Payment Requirements:** \*Customers are encouraged to make e-payment via the app/ website during bill settlement.

**Exclusions:** All hardware, POS software, kitchen management modules, kitchen display solutions, e-commerce sites/ integration to e-commerce sites, e-waiter, e-menu, automated reservation, and queue management are not supported.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Food Menu Management

**Main Question:** Does your solution include a food menu module that allows F\&B operators to manage food menus?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Promotion and Upselling Management

**Main Question:** Does your solution include a promotion and upselling module that allows F\&B operators to:

**Required Capabilities:** a. Create promotions, and b. Upsell food items through recommendation based on promotions available, related food items or aggregated order trends?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Customer Management Management

**Main Question:** Does your solution allow F\&B operators to collect and assess customer data such as customer profile, purchase history, reward or loyalty points etc?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Business Dashboards and Analytics

**Main Question:** Can your solution consolidate customer and sales data from all sales channels and provide dashboards, reporting and/or insights capabilities?

**Business Analytics Requirements:** A business analytics module that analyses data collected from the digital ordering and payment and customer management modules, inventory and procurement sales, and provides F\&B operators with insights on consumption behaviour etc. to support activities such as upselling, menu planning, human resource scheduling, and cost control.

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Inventory Management and Alerts

**Main Question:** Does your solution come with an inventory management function that allows for real-time updates of inventory level when orders are fulfilled or when the inventory is stocked up? The solution must be able to automatically trigger reminders or alerts when the inventory has reached a pre-set low level.

**Package Requirements:** You are required to provide a package in Annex with all the features listed in questions 7,8,9 and 11. For the other 4 packages, you may provide a combination of the modules indicated in questions 7,8,9 and 11.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Integration to Accounting Management Solution

**Main Question:** Does your solution integrate with at least one third-party cloud accounting management solution such as but not limited to Xero, Quickbook Online, Financio?

**Integration Requirements:** Only off the shelf integration to a third-party cloud accounting management solution will be supported. The development of new accounting solutions will not be supported.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Integration to Food Delivery Platform

**Main Question:** Does your solution integrate with food delivery platforms such as Grabfood, Deliveroo and Food Panda?

**Integration Requirements:** Only off the shelf integration to a food delivery platform will be supported. New development is not supported.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - Integration to Human Resource Management System (HRMS)

**Main Question:** Does your solution integrate with a third-party Human Resource Management System (HRMS) solution?

**Integration Requirements:** Only off the shelf integration to a third-party HRMS solution will be supported. New development is not supported.

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🔴 Mandatory - Module Integration

**Main Question:** Are all modules and features in your solution (i.e. digital ordering and payment, customer management module, business analytics and inventory management and/or accounting, food delivery platform, HR) tightly integrated to each other?

**Integration Requirements:** The cost of integrating solutions provided by the same vendor will not be supported.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Training and Technical Support

**Main Question:** Does your solution

**Required Support Features:** a. include technical training to admin users and all staff who will be using the system b. allow admin users to perform basic technical recovery and reboot c. include support such as self-help tool for troubleshooting, and offer continuous system enhancements and/or modifications during contract period

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q18 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

***

### Q19 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q21 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Legal

Legal solutions provide digital tools to enhance law practice management and legal services delivery.

Read [Legal FAQ](https://go.gov.sg/palegalfaq) to understand Productivity Solutions Grant for the Legal Sector.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Practice and Document Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/YjQYCq6WCg7DpssySYFB">/pages/YjQYCq6WCg7DpssySYFB</a></td><td>Integrate and automate various administrative, operational, client-related tasks, including billing, accounting, invoicing, time tracking and client contacts.</td></tr><tr><td><a href="/pages/W9Ob3JZYcqLlKh9fPOx8">/pages/W9Ob3JZYcqLlKh9fPOx8</a></td><td>Store, organise, and manage legal documents of various formats that can be accessed and shared securely with intended parties. Features include version control and audit trail.</td></tr><tr><td><a href="/pages/ylvD0WHyAhZ7JBGT0fzy">/pages/ylvD0WHyAhZ7JBGT0fzy</a></td><td>Consolidate all documents and matter correspondences, including documents, emails, and notes, across different communication channels from both internal and external sources, into a single channel for correspondence.</td></tr></tbody></table>

**Legal Research and Analysis**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/Ss6EX9FqFvCdbdu8PajT">/pages/Ss6EX9FqFvCdbdu8PajT</a></td><td>Scan and analyse large volumes of electronic data, such as emails, documents, databases and more, to identify information relevant to a case or contract via intelligent search functions.</td></tr><tr><td><a href="/pages/5Mol6As60vi1s2VRtxpw">/pages/5Mol6As60vi1s2VRtxpw</a></td><td>Enable law practices to manage, search, and review large volumes of electronic documents with advanced search and analytics features (e.g. concept searching, email threading, and anomaly discovery).</td></tr><tr><td><a href="/pages/zxErWmcwP5AKrNCV7wKl">/pages/zxErWmcwP5AKrNCV7wKl</a></td><td>Streamline the process of creating complex documents by using pre-existing templates and clauses, to auto-generate documents such as contracts, agreements, legal forms, proposals, and reports.</td></tr><tr><td><a href="/pages/EGjEEZqle5sY7HjGUdCE">/pages/EGjEEZqle5sY7HjGUdCE</a></td><td>Provide law practices with access to legal research materials, precedents, legal opinions, journals, legislation, and other legal materials that they may harness.</td></tr></tbody></table>

**Compliance and Risk Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/eLt9OAnyVz7PDUAk9HiF">/pages/eLt9OAnyVz7PDUAk9HiF</a></td><td>Concentrate evidence and court documents into a single hub, create an audit trail that tracks and records changes in court documents.</td></tr><tr><td><a href="/pages/E3zXuAnl7nm48NLsFv3Z">/pages/E3zXuAnl7nm48NLsFv3Z</a></td><td>Automate the compliance processes, perform ongoing due diligence, and enable law practices to comply with regulations related to KYC (Know Your Customer) /AML (Anti-Money Laundering) / CFT (Combating the Financing of Terrorism).</td></tr></tbody></table>

**Legal Support Tools**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/Tl81hfkCvnnmlXFQwAZ4">/pages/Tl81hfkCvnnmlXFQwAZ4</a></td><td>Provide basic legal information, compile information on the client’s queries, and automate conversations with clients using natural language. This tool facilitates the collection of client data, arrangement of client appointments, and generate emails using information captured in conversations.</td></tr><tr><td><a href="/pages/1WvDV424iCNPkjlfBlQh">/pages/1WvDV424iCNPkjlfBlQh</a></td><td>Transcribe speeches that include legal terms and lexicons which allow for creation of accurate timely records and references. May include sentiment analysis features to classify sentiments of the transcribed speeches</td></tr><tr><td><a href="/pages/jIw79uIY40fLFdwzVwXk">/pages/jIw79uIY40fLFdwzVwXk</a></td><td>Enable law practices to translate legal documents and other materials easily</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Practice Management System (PMS)

Integrate and automate various administrative, operational, client-related tasks, including billing, accounting, invoicing, time tracking and client contacts.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Customer Relationship Management**

Main Question: Does your solution come with Customer Relationship Management functions to help the firm manage its interactions with current and potential customers, such as customer contact, opportunity management, and sales and marketing activities?

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Financial Management and Accounting Functions**

Main Question: Does your solution come with Financial Management and Accounting functions to help the firm manage its budget, billing and invoicing?

Additional Requirements: The solution automatically generate billing and invoices based on billable hours, and manage payments, overdue invoices and receivables.

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Case Management and Task Tracking**

Main Question: Does your solution come with Project Management functions to help the firm estimate project costs, monitor work in progress, and monitor staff performance?

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🟡 Preferred - Calendar Management**

Main Question: Does your solution include calendar functions with scheduling, reminders, and notifications pertaining to case management?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

**Q6 🔴 Mandatory - Conflict of Interest and Compliance Checking**

Main Question: Does your solution check for conflicts of interest and compliance with local statutory requirements?

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🟡 Preferred - Time and Expenses Tracking**

Main Question: Does your solution track the time and expenses spent to enable itemised billing for each case?

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q8 🔴 Mandatory - Dashboards and Reports (PMS)**

Main Question: Does your solution provide customised dashboards and reporting capabilities to track the firm's operations, staff projects and client status?

Technical Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Dashboard Requirements: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🔴 Mandatory - Module Integration**

Main Question: Are the modules above tightly integrated such that information can be pulled from all modules to the dashboard?

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🟡 Preferred - System Integration**

Main Question: Does your solution support integration with systems and software such as email, Know Your Customer (KYC) / Anti-Money Laundering (AML) functions, audit tools, document management systems, accounting software, and HR software?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q12]

\--

**Q11 🔴 Mandatory Follow-up - System Integration - Elaboration**

*This question appears only if you answered "Yes" to Q11*

Main Question: List the systems and software that your solution can be integrated with.

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q12 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

**Q13 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q13*

Main Question: Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

🔴 Answer: ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q14 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Compliance Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

**Q16 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Information: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

🔴 Answer: ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q19] ○ No \[Next: Q21]

***

**Q18 🟡 Preferred - CEM for Product Principal**

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

**Q19 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q19*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q20 🟡 Preferred - CEM for Resellers**

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

**Q21 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q21*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Document Management System (DMS)

Store, organise, and manage legal documents of various formats that can be accessed and shared securely with intended parties. Features include version control and audit trail.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Document Management**

Main Question: Does your solution have matter-centric functions which allow users to create matters and automatically organise and save any documents, emails and notes to folders in the workspaces?

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Document Categorisation and Tagging**

Main Question: Does your solution allow document categorisation and tagging which allows users to distinguish between motions, orders, pleadings, complaints and contracts etc.?

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🟡 Preferred - Automatic Document Recognition**

Main Question: Does your solution automatically recognise the type of document that is uploaded to it (e.g. affidavit, pleading and contract, etc)?

🟡 Answer: ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

**Q5 🔴 Mandatory - Version Control**

Main Question: Does your solution allow users to see each iteration of a document, and view, restore, or compare previous versions of every document?

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🟡 Preferred - Data Extraction via OCR**

Main Question: Does your solution use Optical Character Recognition (OCR) to identify and extract text from documents?

🟡 Answer: ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

**Q7 🟡 Preferred - Search Capabilities**

Main Question: Does your solution have index and search functions for files in different formats (e.g. audio, text, image, etc.)?

🟡 Answer: ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

**Q8 🟡 Preferred - e-Signing**

Main Question: Does your solution provide or integrate an e-signing solution to facilitate instant approval processes?

🟡 Answer: ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🔴 Mandatory - Email Management**

Main Question: Does your solution have email management functions which allow emails to be stored, indexed and managed? Is your solution integrated with email tools e.g. Microsoft Outlook and Gmail?

🔴 Answer: ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

**Q10 🟡 Preferred - User Authentication**

Main Question: Does your solution provide user authentication when access to a file or folder is shared through a link in the email invitation?

🟡 Answer: ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🔴 Mandatory - Document Security**

Main Question: Does your solution enable users to set access rights (e.g. read, write, delete, etc.) for a folder or a document by user roles?

🔴 Answer: ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

**Q12 🔴 Mandatory - Secure Workspace Sharing**

Main Question: Does your solution allow users to securely share workspaces with colleagues, consultants, and clients?

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13 🔴 Mandatory - Audit Trail**

Main Question: Does your solution provide an audit trail to track document access history with username, dates and time stamps?

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🟡 Preferred - Practice Management System Integration**

Main Question: Is your solution integrated with at least one Practice Management System?

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

**Q15 🟡 Preferred - System Integration**

Main Question: Does your solution support integration with other software, such as Document Review and Document Assembly software?

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

**Q16 🔴 Mandatory Follow-up - System Integration - Elaboration**

*This question appears only if you answered "Yes" to Q15*

Main Question: List the software that your solution can be integrated with.

🔴 Answer: ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Next: Q19]

\--

**Q18 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

🔴 Answer: ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q19 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Compliance Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

***

**Q21 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Information: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

🔴 Answer: ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q22 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q23] ○ No \[Next: Q25]

***

**Q23 🟡 Preferred - CEM for Product Principal**

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

**Q24 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q23*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q25 🟡 Preferred - CEM for Resellers**

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q26] ○ No \[Assessment Finished]

\--

**Q26 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q25*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Matters Management and Collaboration Tool

Consolidate all documents and matter correspondences, including documents, emails, and notes, across different communication channels from both internal and external sources, into a single channel for correspondence.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility**

Main Question: Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 Answer: ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Matter-Centric Workspace**

Main Question: Does your solution have matter-centric functions which allow users to create matters and automatically organise and save any documents, emails and notes to folders in the workspaces?

🔴 Answer: ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Task Management and Assignment**

Main Question: Does your solution allow users to create, assign, and track tasks within each matter?

🔴 Answer: ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🟡 Preferred - Calendar Integration**

Main Question: Does your solution include calendar functions with scheduling, reminders, and notifications pertaining to matter management?

🟡 Answer: ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

**Q5 🔴 Mandatory - Real-time Collaboration**

Main Question: Does your solution enable real-time collaboration features such as document co-editing, commenting, and version control?

🔴 Answer: ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Communication Tools**

Main Question: Does your solution provide integrated communication tools such as messaging, discussion threads, or chat functions within each matter workspace?

🔴 Answer: ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🔴 Mandatory - Access Control and Permissions**

Main Question: Does your solution enable users to set granular access rights and permissions for different team members within each matter?

🔴 Answer: ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🔴 Mandatory - Client Portal Access**

Main Question: Does your solution provide secure client portal access where clients can view matter progress, documents, and communicate with the legal team?

🔴 Answer: ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

**Q9 🟡 Preferred - External Collaboration**

Main Question: Does your solution allow secure collaboration with external parties such as opposing counsel, experts, or consultants?

🟡 Answer: ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🔴 Mandatory - Progress Tracking and Reporting**

Main Question: Does your solution provide matter progress tracking with status updates, milestone tracking, and reporting capabilities?

🔴 Answer: ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

**Q11 🟡 Preferred - Time Tracking Integration**

Main Question: Does your solution integrate time tracking functionality for billable hours within the collaboration workspace?

🟡 Answer: ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

**Q12 🔴 Mandatory - Notification System**

Main Question: Does your solution provide automated notifications and alerts for task deadlines, matter updates, and team communications?

🔴 Answer: ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

**Q13 🔴 Mandatory - Audit Trail and Activity Log**

Main Question: Does your solution maintain comprehensive audit trails and activity logs for all matter-related activities, document changes, and user interactions?

🔴 Answer: ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🟡 Preferred - Mobile Collaboration**

Main Question: Does your solution provide full collaboration functionality through mobile applications for iOS and Android devices?

🟡 Answer: ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

**Q15 🟡 Preferred - Integration with Legal Software**

Main Question: Does your solution integrate with other legal software such as Practice Management Systems, Document Management Systems, or Legal Research tools?

🟡 Answer: ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

**Q16 🔴 Mandatory Follow-up - Integration with Legal Software - Elaboration**

*This question appears only if you answered "Yes" to Q15*

Main Question: List the legal software and systems that your solution can be integrated with.

🔴 Answer: ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q17 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 Answer: ○ Yes \[Next: Q18] ○ No \[Next: Q19]

\--

**Q18 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q17*

Main Question: Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

🔴 Answer: ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q19 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 Answer: ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Compliance Requirement: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 Answer: ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

***

**Q21 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Information: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-Party Definition: Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

🔴 Answer: ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q22 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 Answer: ○ Yes \[Next: Q23] ○ No \[Next: Q25]

***

**Q23 🟡 Preferred - CEM for Product Principal**

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

**Q24 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q23*

Main Question: Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

**Q25 🟡 Preferred - CEM for Resellers**

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Requirements: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 Answer: ○ Yes \[Next: Q26] ○ No \[Assessment Finished]

\--

**Q26 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q25*

Main Question: Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

🔴 Answer: ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Online Legal Research System

Provide law practices with access to legal research materials, precedents, legal opinions, journals, legislation, and other legal materials that they may harness.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Comprehensive Legal Database Access

**Main Question:** Does the solution provide access to a wide range of legal databases containing legal research materials, precedents, legal opinions, journals, legislation, and other relevant legal materials?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Research Materials Search

**Main Question:** Is your solution able to search research materials (e.g. cases, precedents, law reports, etc.) across multiple countries within a single search?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Search Results Filtering

**Main Question:** Is your solution able to filter search results by content type, jurisdiction, and legal topic to narrow results more quickly and identify the most relevant documents?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Case Understanding and Related Content Discovery

**Main Question:** Does your solution have features (e.g. case status icons, location of report, appellate history, related cases cited with judicial treatment, legislation cited, Journal articles and commentary citing) which allow users to get a clear understanding of a particular case quickly, such as being able to discover related cases, and trace case lineages?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Current and Updated Content

**Main Question:** Does your solution automatically update to include the latest cases and changes in legislation?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Alert Options

**Main Question:** Does your software have alert options to manage your updates?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Dashboards and Analytics

**Main Question:** Does the system provide dashboards, reporting, and analytics capabilities to track and analyse user interactions, search patterns, document access, and other relevant metrics, enabling insights for system optimisation and user behaviour understanding?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Annotation and Collaboration Tools

**Main Question:** Does the solution provide tools for users to annotate, tag, and collaborate on legal research materials, enabling efficient teamwork and knowledge sharing within the law practice?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Customisation and Personalisation

**Main Question:** Does the solution allow users to access their search history, customise their research experience, save preferences, and personalise their access to legal materials based on their specific areas of practice and interest?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - System Integration - Legal Specific

**Main Question:** Does your solution support integration with other systems such as legal practice management systems, case management tools, document management systems, or any news sites that a firm subscribes to?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - System Integration - Legal Specific - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** List the external systems and solutions that your solution is integrated with.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

\--

### Q18 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Note:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

\--

### Q20 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q19*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Document Assembly Software

Streamline the process of creating complex documents by using pre-existing templates and clauses, to auto-generate documents such as contracts, agreements, legal forms, proposals, and reports.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Template Management

**Main Question:** Does your solution provide a template management system to create, store and organise dynamic templates and clauses for document assembly?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Automatic Document Generation

**Main Question:** Can your solution generate customised documents such as contracts, agreements, legal forms, proposals, and reports by automatically filling in selected dynamic templates with user inputs?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Client-Facing Portal

**Main Question:** Does your solution have a client-facing portal to collect client information to fill in templates?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🔴 Mandatory - Document Transformation

**Main Question:** Can your solution transform frequently used documents or forms into dynamic templates that will allow document authors to generate a customised document?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Customisable Templates

**Main Question:** Does your solution allow users to customise templates with branding and styling?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - System Integration - Legal Specific

**Main Question:** Does your solution support integration with other systems such as legal practice management systems, case management tools, document management systems, e-signature tools, word processing software (e.g. Microsoft Word), or email?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q9]

\--

### Q8 🔴 Mandatory Follow-up - System Integration - Legal Specific - Elaboration

*This question appears only if you answered "Yes" to Q7*

**Main Question:** List the external systems and solutions that your solution is integrated with.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q9 🟡 Preferred - Regulatory Compliance Application

**Main Question:** Can your solution apply internal compliance and external regulations to ensure that all documents generated automatically conform to the firm's governance procedures?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory - Conditional Logic Defining

**Main Question:** Does your solution allow users to define conditional logic within templates to manage the inclusion or exclusion of sections, paragraphs, or individual elements based on specific criteria?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - Collaboration Functionality

**Main Question:** Does your solution facilitate collaboration among users involved in the document assembly process, allowing for review, edits, comments, and approvals?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Version Control and Audit Trail

**Main Question:** Does your solution maintain version control and provide an audit trail for all template and document assembly activities to track changes and ensure accountability?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🔴 Mandatory - Export and Delivery Options

**Main Question:** Does your solution offer options for exporting assembled documents in different formats (e.g. PDF, Word, or HTML), as well as support delivery methods like email or direct printing?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - Low or No-Code Solution

**Main Question:** Is your solution low-code or no-code?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q15]

***

### Q15 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q18]

\--

### Q17 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q18 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

\--

### Q20 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

\--

### Q21 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Note:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Next: Q25]

\--

### Q23 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

### Q24 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q25 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q22*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q26] ○ No \[Assessment Finished]

\--

### Q26 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q25*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Document Review Software

Enable law practices to manage, search, and review large volumes of electronic documents with advanced search and analytics features (e.g. concept searching, email threading, and anomaly discovery).

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Document Ingestion

**Main Question:** Does your solution support the importing of documents from diverse sources including local storage, cloud storage services (e.g. Google Drive, Dropbox), email attachments, and document management systems?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Advanced Search

**Main Question:** Can your solution effectively manage, search, and review large volumes of electronic documents, incorporating advanced search and analytics features (e.g. concept searching, email threading, and anomaly discovery), to meet the specific needs of law practices?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Anomaly Detection

**Main Question:** Does your solution have anomaly detection functions which allow users to find both structural and linguistic anomalies between any clause or document type?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Legal Reference Validation

**Main Question:** Can your solution quickly review defined terms, references, and citations to ensure validity, accuracy, consistency, and clarity?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Document Error Detection

**Main Question:** Can your solution locate and correct mistakes in the document (e.g. inconsistent numbering, phrases, and case-specific information)?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Multi-Language Support

**Main Question:** Does your solution provide multilingual support for users to effectively manage, search, and review documents in various languages?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Data Visualisation

**Main Question:** Does your solution allow users to review the entire document and view proofreading issues in a consolidated dashboard?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Collaboration

**Main Question:** Does your solution facilitate simultaneous collaboration with legal teams across areas of practice, offices and jurisdictions, by allowing efficient document review, annotation, and tagging?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🔴 Mandatory - Workflow Management

**Main Question:** Can your solution facilitate the definition and management of document review workflows, encompassing tasks such as assigning reviewers, establishing deadlines, monitoring review statuses and providing alerts to relevant stakeholders?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Version Control and Audit Trail

**Main Question:** Does your solution maintain version control and provide an audit trail for all document review activities to track changes and ensure accountability?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🟡 Preferred - System Integration - Legal Specific

**Main Question:** Does your solution support integration with other systems such as legal practice management systems, case management tools, and Microsoft Word?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

### Q13 🔴 Mandatory Follow-up - System Integration - Legal Specific - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** List the external systems and solutions that your solution is integrated with.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

\--

### Q19 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Mandatory Action:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

\--

### Q20 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Note:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

\--

### Q22 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q24 🟡 Preferred - CEM for Resellers

*This question appears only if you answered "No" to Q21*

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Reference Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

### Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

**Document Submission:** Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Confirmation Requirement:** Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]\
**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# eDiscovery Tool

Scan and analyse large volumes of electronic data, such as emails, documents, databases and more, to identify information relevant to a case or contract via intelligent search functions.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Data Ingestion

**Main Question:** Can your solution support the ingestion and processing of a wide range of electronic data types and file formats commonly used in business and legal contexts?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Data Import

**Main Question:** Can your solution import data directly from commonly used third-party platforms (e.g. OneDrive, Microsoft Teams)?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Search Index and Interface

**Main Question:** Does your solution possess full search capabilities (e.g. concept search, facet search, fuzzy search, Boolean search, etc.) which enables users to do keyword searches across large quantities of documents, attachments, metadata, document IDs and codes at one time, such that users can remove duplicates and identify relevant documents?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Collaboration and Review

**Main Question:** Does your solution facilitate collaboration among legal teams and reviewers, by allowing annotation, tagging, and categorisation of documents for review?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Audit Trail

**Main Question:** Does your solution maintain an audit trail and provide a clear chain of custody for all processed data?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Text Transcription

**Main Question:** Can your solution create text transcripts of audio or video files, allowing those files to be searched with text-based queries?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Optical Character Recognition Search

**Main Question:** Can your solution perform Optical Character Recognition (OCR) such that images are searchable?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - Email Threading

**Main Question:** Does your solution have an email review function which allows each email to be grouped with its attachments and with other emails in the "chain" to which the email belongs, as well as quickly identify spam?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Predictive Coding or Technology Assisted Review

**Main Question:** Can your solution perform "Technology Assisted Review" which will analyse the content of the documents and rank or group them based on how relevant they are to the case for users to locate them faster?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Data Visualisation

**Main Question:** Does your solution include integrated analytics functions such that users can apply data visualisations and analysis to find key facts and fact patterns more quickly?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - Intuitive User Interface

**Main Question:** Does your solution have an intuitive user interface which allows users to analyse the scope of the case and develop their case strategy effectively?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🔴 Mandatory - Case Report Customisation

**Main Question:** Can your solution design and customise case reports?

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Version Control and Audit Trail

**Main Question:** Does your solution maintain version control and provide an audit trail for all activities to track changes and ensure accountability?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Legal Hold Management

**Main Question:** Does your solution allow legal hold management to impose legal holds on pertinent data to prevent alteration or deletion during ongoing eDiscovery processes, and to oversee the lifecycle of legal holds?

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🟡 Preferred - Case Management

**Main Question:** Can your solution organise and manage eDiscovery projects (e.g. case creation, task assignment to team members and deadline tracking)?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q18]

***

### Q18 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with other systems (e.g. document management, document review systems, or case management tools)?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q19]

***

### Q19 🔴 Mandatory - Export and Delivery Options

**Main Question:** Does your solution offer options for exporting assembled documents in different formats (e.g. PDF, Word, HTML), as well as support delivery methods like email or direct printing?

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q22]

\--

### Q21 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q22 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

***

### Q23 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q24] ○ No \[⚠️ Cannot Proceed]

***

### Q24 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q25] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q25 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q26] ○ No \[Next: Q28]

***

### Q26 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q27] ○ No \[Assessment Finished]

\--

### Q27 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q26*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q28 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q29] ○ No \[Assessment Finished]

\--

### Q29 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q28*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Legal Chatbot

Provide basic legal information, compile information on the client’s queries, and automate conversations with clients using natural language. This tool facilitates the collection of client data, arrangement of client appointments, and generate emails using information captured in conversations.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Appointment Scheduling

**Main Question:** Is your solution able to interact directly with clients to provide the relevant information by asking the right questions, processing enquiries, booking appointments, generating simple documents and emails and providing simple guides to users to address their problems?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with third-party systems such as messaging apps (e.g. WhatsApp, Telegram, Facebook Messenger), emails, calendars, or case management systems to access and update case information, schedules, appointments, and deadlines?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Knowledge Base Access

**Main Question:** Does your solution have access to a wide range of legal information bases, including statutes, judgments, and publicly available legal information?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Multi-Language Support

**Main Question:** Does your solution provide multilingual support to cater to clients and legal professionals who speak different languages?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Usage Metrics Tracking

**Main Question:** Does your solution track usage metrics such as the number of interactions, types of queries, and peak usage times to understand user engagement?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - User Satisfaction Gathering

**Main Question:** Does your solution gather feedback and conduct sentiment analysis to assess user satisfaction and identify areas for improvement?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Performance Evaluation

**Main Question:** Does your solution analyse the accuracy and effectiveness of its responses to continuously enhance its legal knowledge base and NLP capabilities?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Trend Analysis

**Main Question:** Does your solution identify trends in legal queries and topics to anticipate and address emerging legal issues?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Legal Query Routing

**Main Question:** Is your solution able to direct complex queries from clients to human lawyers?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Low or No-Code Solution

**Main Question:** Is your solution no-code or low-code?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

***

### Q20 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Risk Assessment Solution (KYC/AML)

Automate the compliance processes, perform ongoing due diligence, and enable law practices to comply with regulations related to KYC (Know Your Customer) /AML (Anti-Money Laundering) / CFT (Combating the Financing of Terrorism).

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Risk Assessment Functionalities (KYC or AML)

**Main Question:** Does your solution check against the following lists: a. Persons or entities convicted of being involved in criminal activities such as fraud, money laundering, trafficking, terrorism or supporting terrorism, corruption and/or organised crimes locally and overseas? b. Interpol red notice c. Targeted financial sanction lists, including UNSCR lists, Russia d. TSOFA Schedule A e. Politically Exposed Persons (PEPs) and their immediate family members? e.g. a politician or immediate family members of the politician in a particular country f. blacklisted persons or entities within jurisdictions which are subject to sanctions or trade embargoes issued by the UN, OFAC or other similar institutions, MHA Sanction List

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Risk Assessment against Journalistic Documents

**Main Question:** Does your solution run checks against the following, including but not limited to: a. Panama Papers, Russia Laundromat, Pandora Papers b. Adverse news in local and overseas media

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Multi-User Login Access

**Main Question:** Does your solution allow multiple login access (for entities with many users)?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Blacklist Monitoring

**Main Question:** Does your solution perform ongoing monitoring or update the database with new blacklisted persons or entities?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Access Control Management

**Main Question:** Does your solution provide access control features?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Risk Assessment Audit Trail

**Main Question:** Does your solution provide an audit trail to track modifications to the risk assessment with usernames, dates, and time stamps?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Alert and Reporting

**Main Question:** Does your solution provide alerts and reporting features?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - File Exporting

**Main Question:** Does your solution allow screening records and risk assessments to be stored and exported in a PDF format?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with external systems, such as document management systems?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - System Integration - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** List the systems that your solution can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🟡 Preferred - Ongoing Monitoring Alerts

**Main Question:** Does your solution provide alerts on changes to past searches, i.e. ongoing monitoring.

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🟡 Preferred - Search Credit Usage

**Main Question:** Does your solution expend credits for every name search or unique name searches only?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q21]

\--

### Q19 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

***

### Q22 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q24 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

### Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Evidence Management Platform

Concentrate evidence and court documents into a single hub, create an audit trail that tracks and records changes in court documents.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Document Annotation

**Main Question:** Does your solution allow users to annotate, highlight, comment on, and tag documents?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🟡 Preferred - Evidence Collation

**Main Question:** Does your solution automatically collate evidence into bundles, sequence and paginate bundles, remove duplicated evidence, and update bundles when new documents are added?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q4]

***

### Q4 🔴 Mandatory - Audit Trail

**Main Question:** Does your solution provide an audit trail to track all actions and changes taken on evidence items with usernames, dates, and time stamps?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Document Hyperlinking

**Main Question:** Does your solution allow users to add hyperlinks to relevant paragraphs or documents?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Document Search

**Main Question:** Does your solution allow users to search for documents based on their text, tag, notes, key persons or events, affidavit, or bundle?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Search Filtering

**Main Question:** Does your solution allow users to narrow down their search results using filters or search parameters?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Collaborative Features

**Main Question:** Does your solution allow documents to be shared with and edited by multiple users concurrently?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🔴 Mandatory - Electronic Evidence Presentation

**Main Question:** Does your solution allow electronic presentation of evidence during in-person and virtual hearings?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with external systems, such as document management systems?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - System Integration - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** List the systems that your solution can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

***

### Q20 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Speech Transcription for Legal Matters

Transcribe speeches that include legal terms and lexicons which allow for creation of accurate timely records and references. May include sentiment analysis features to classify sentiments of the transcribed speeches.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Audio and Video Transcription

**Main Question:** Does your solution transcribe audio, video, phone calls, web calls, or live recordings?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Legal Transcription Model Training

**Main Question:** Does your solution have and allow for updates to the transcription model with specific legal terms and lexicons and train the model to apply these rules to subsequent transcriptions automatically?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Timestamp Inclusion

**Main Question:** Does your solution include timestamps in the transcripts?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Keyword Search

**Main Question:** Does your solution allow the user to search for keywords within transcripts?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Transcript Editing

**Main Question:** Does your solution allow the user to edit, highlight, redact or comment on sections of the transcript?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Speech Analysis

**Main Question:** Does your solution analyse speech sentiment, call duration, or distribution of talking time?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - File Exporting

**Main Question:** Does your solution allow transcripts to be exported in various formats such as PDF or Word?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with external systems, such as document management systems?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - System Integration - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** List the systems that your solution can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

### Q13 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q14 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q17 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

***

### Q18 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

### Q19 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q20 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Translation Software

Enable law practices to translate legal documents and other materials easily.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Multi-Format File Support

**Main Question:** Does your solution support files in various formats such as PDF, Word, or Excel, and retain the formatting in the original file?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Multi-Language Reading

**Main Question:** Does your solution read text in English and other languages?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Multi-Language Translation

**Main Question:** Does your solution translate text into English and other languages?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Translation Management

**Main Question:** Does your solution allow users to edit, download, and share translated documents?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Change Tracking

**Main Question:** Does your solution track changes to the translation?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Legal Terminology Library Creation

**Main Question:** Does your solution allow users to create a customisable library of legal terminology and train the model to apply these rules to subsequent translations automatically?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - System Integration

**Main Question:** Does your solution support integration with external systems, such as document management systems?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - System Integration - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** List the systems that your solution can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Describe your AI feature and its benefits. Examples are:

a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Additional Information:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q16 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

***

### Q17 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Note:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Logistics

Logistics solutions provide digital tools to optimise supply chain and distribution operations.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Trade Services**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/kcoT7LO73LF4YOwwcgXP">/pages/kcoT7LO73LF4YOwwcgXP</a></td><td>Connect the trade and logistics communities for trade-related applications.</td></tr></tbody></table>

**Warehouse Operations**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/DzCnYvWDO6zQfmvHiaRs">/pages/DzCnYvWDO6zQfmvHiaRs</a></td><td>Control and track the transfer and storage of materials in a warehouse. The system supports processes needed in the shipping and receiving of goods.</td></tr><tr><td><a href="/pages/UuVOcIQ54iuOg11P4fxL">/pages/UuVOcIQ54iuOg11P4fxL</a></td><td>Control and administer the movement of inventory, with real time data.</td></tr><tr><td><a href="/pages/b9MKqJlC7fhbnYV8P6XG">/pages/b9MKqJlC7fhbnYV8P6XG</a></td><td>use digital sensors to monitor environmental conditions in warehouses by tracking and transmiting real-time temperature and humidity data, ensuring proper storage conditions and maintaining cold chain integrity for sensitive goods.</td></tr></tbody></table>

**Transport Operations**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/hG7hL7wAuhvD2XKQXNuw">/pages/hG7hL7wAuhvD2XKQXNuw</a></td><td>Enable real-time visibility of the whereabouts of vehicles.</td></tr><tr><td><a href="/pages/xDT38ayyH7ckB8vNfFx8">/pages/xDT38ayyH7ckB8vNfFx8</a></td><td>Digitalise information flow in freight forwarding operations that can encompass import and export shipments over air, sea and land.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Networked Trade Platform Value Added Services

Connect the trade and logistics communities for trade-related applications.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - NTP VAS Listing

**Main Question:** Is your solution listed on the Networked Trade Platform (NTP) Value-added-Services (VAS) catalogue?

**Important Notes:** \[1] Solution cannot be pre-approved unless it is listed on the NTP VAS Catalogue. Please contact the NTP Helpdesk at (65) 6263 1061 to find out how your solution can be listed on the NTP VAS Catalogue. \[2] Only NTP VAS offering Cloud-Based Digital Solution will be supported for pre-approval. Professional and Business Services, such as Financing and Insurance, Market Intelligence/Insight are not currently supported.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - NTPS VAS Categories

**Main Question:** Does your solution fall into at least ONE of the following NTP VAS categories:

**NTP VAS Categories:** a. Arrange Shipment b. Declaring Customs c. Financing Trade d. International Connectivity e. Market Insights f. Permit Preparation g. Reports and Payment h. Sourcing Customer i. Tracking Shipment j. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🟡 Preferred - AI Analytics

**Main Question:** Does your solution come with features that use Analytics?

🟡 **Answer:** ○ Yes \[Next: Q4] ○ No \[Next: Q5]

\--

### Q4 🔴 Mandatory Follow-up - AI Analytics - Elaboration

*This question appears only if you answered "Yes" to Q3*

**Main Question:** Describe your AI Analytics feature(s) and its benefits. Examples follow:

**AI Analytics Examples:** a. Ability to perform demand prediction for inventory management b. Ability to predict customer behaviour and identify potential sales lead c. Ability to automate routine sales tasks (update forecasts and determine call lists) d. Ability to automate customer responses, data capture activities and follow-ups e. Ability to analyse and predict potential conversion of pipelines f. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q5 🟡 Preferred - Invoice Generation or Processing

**Main Question:** Does your solution generate or process invoices?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - InvoiceNow-Ready Solution Provider Accreditation

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

**Requirements:** \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

**Additional Information:** For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q7 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q13 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

***

### Q14 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Assessment Finished]

\--

### Q15 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details] **Date of Issue Required:** \[Date Field] **Upload Supporting Document Required:** \[File Upload]

***

### Q16 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Inventory Management

Control and administer the movement of inventory, with real time data.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Inventory Management (Logistics)

**Main Question:** Does your solution come with an inventory management module tailored to logistics businesses that contain at least 3 of the following functions:

**Required Functions:** a. Set up and edit product details of different item groups (e.g. description) b. Set up and edit various storage areas for reference to inventory location (e.g. racks) c. Provide real-time information of stock quantity through weight sensor or any other equivalent technology. d. Create inventory journal logs to track movement of inventory items (e.g. date, quantity, movement, location) e. Support RFID tag encoding and/or barcode labelling for product tracking and querying of product information

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - RFID Inventory Tracking

**Main Question:** Does your solution allow real time stock taking of inventory and/or assets via integration with RFID hardware, e.g. installed with RFID reader, tags, tunnel gate, or weight based inventory tracking solution?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - RFID Hardware

**Main Question:** Does your solution include RFID hardware such as readers, gantry tags or weight-based inventory monitoring sensor?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🔴 Mandatory - Inventory Alert

**Main Question:** Does your solution automatically trigger reminder alert when the inventory reached a low stock threshold?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Warehouse Management Integration

**Main Question:** Does your solution allow real time update of inventory via integration with warehouse management system, i.e. inventory updated when orders are fulfilled or when inventory is stocked up?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q8]

\--

### Q7 🔴 Mandatory Follow-up - Warehouse Management Integration - Elaboration

*This question appears only if you answered "Yes" to Q6*

**Main Question:** Please briefly describe how the integration is done.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q8 🟡 Preferred - NTP Integration

**Main Question:** Is your solution integrated with NTP? If not, you can contact: <Enquiry_NTP@customs.gov.sg> for further discussion on integration with NTP.

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

### Q14 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q16 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

***

### Q17 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Warehouse Management

Control and track the transfer and storage of materials in a warehouse. The system supports processes needed in the shipping and receiving of goods.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Warehouse Management

**Main Question:** Does your solution contain modules to support the key functions of the following inbound and outbound logistics operations in the warehouse?

**Inbound Operation:** i. Receiving of cargos ii. Putaway or Storage of cargos

**Outbound Operation:** i. Picking of orders ii. Packing of cargos iii. Loading of cargos according to the delivery locations iv. Dispatch of orders

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Inventory Management Integration

**Main Question:** Does your solution allow integration with Inventory Management Solution/Inventory Tracking Solution and/or comes with inventory modules to enable the following functions:

**Required Functions:** a. Asset tracking, with visibility of the Lot/Serial number b. Compatible with barcode or RFID technology to track inventory c. Stock Counting d. Stock Locator e. Stock Notification: Receive alerts and notifications when there is an Inventory under-stock or over-stock

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Warehouse Billing System

**Main Question:** Does your solution support warehouse billing and issuing of invoices based on activity, storage consumption, charge rates, and/or the customer's contract terms?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Invoice Generation or Processing

**Main Question:** Does your solution generate or process invoices?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - InvoiceNow-Ready Solution Provider Accreditation

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

**Requirements:** \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

**Additional Information:** For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - NTP Integration

**Main Question:** Is your solution integrated with NTP? If not, you can contact: <Enquiry_NTP@customs.gov.sg> for further discussion on integration with NTP

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q11 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

***

### Q12 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q15]

\--

### Q13 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q12*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

***

### Q16 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q18 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

### Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Active Cold Chain Management

Use digital sensors to monitor environmental conditions in warehouses by tracking and transmitting real-time temperature and humidity data, ensuring proper storage conditions and maintaining cold chain integrity for sensitive goods

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Real-time Tracking

**Main Question:** Can your solution provide real-time alerts or updates on the location and temperature of the tracked cargo at parcel level on Web desktop and Mobile App?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Multi-sensor Tracking

**Main Question:** Can your solution support tracking of at least 100 sensors simultaneously at any one point of time ?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Long-Lasting Battery

**Main Question:** Can the sensor or tracking devices used in your solution support long-lasting battery as a power source or backup power source?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Temperature Resistance

**Main Question:** Can the sensors and accessories in your solution operate in a temperature range between -20 ℃ to 60 ℃ ?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Multi-Sensors Support

**Main Question:** Can your solution support multiple types of sensors to track the condition of the cargos (i.e. shock, humidity or vibration), if required?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Data Transmission

**Main Question:** Can your solution support wireless transmission of sensor data to a device gateway or a secure Cloud-based system at a minimum of 10 seconds intervals using LTE network, bluetooth, or WiFi connection?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Delivery Report Generation

**Main Question:** Is your solution able to generate a report pertaining to the delivery with the following information:

**Required Report Information:** a. Graph to display temperature fluctuation; b. Identify temperature excursion; c. Delivery location; d. Other relevant information (i.e. date, driver detail)

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Sensor Analytics

**Main Question:** Can the solution provide analytics and track patterns using the collected sensor data?

**Analytics Examples:** e.g. predict where and when hotspots are likely to develop and how much coolant is needed for multimodal transport

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Transport and Warehouse Management Integration

**Main Question:** Can the solution integrate with transport management system or warehouse management system?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - NTP Integration

**Main Question:** Is your solution integrated with NTP? If not, you can contact: <Enquiry_NTP@customs.gov.sg> for further discussion on integration with NTP.

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

### Q16 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q19 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q22]

***

### Q20 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q22 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Transport Management

Enable real-time visibility of the whereabouts of vehicles.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - GPS Fleet Tracking

**Main Question:** Does your solution include telematics and GPS tracking technology which provides the company a complete overview of its fleet's real-time location and operating condition?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Customised Fleet Journey Management

**Main Question:** Does your solution allow companies to tailor the fleet journey, manage cost control, improve fleet utilisation, and improve productivity?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Electronic Proof of Delivery

**Main Question:** Does your solution provide for management of transport jobs?

**Examples include:** creation and posting of jobs, job transfer, job scheduling and assignment, job monitoring, etc.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Transport Job Management

**Main Question:** Does your solution provide electronic proof of delivery?

**Examples include:** capturing of signatures and photos

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Mobile App for Drivers/Dispatchers

**Main Question:** Does your solution provide drivers/dispatchers with mobile application for tracking and direct communication and coordination with the coordinator/controller?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Job History Tracking and Analytics Capabilities

**Main Question:** Does your solution track job history and provide insightful analytics?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Partner Collaboration

**Main Question:** Does your solution enable collaboration with partners and subcontractors?

**Examples include:** transfer of jobs to partners

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🟡 Preferred - Cross-border Shipment Tracking

**Main Question:** Does your solution allow cross-border tracking of shipment and real-time updates?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Route Planning and Optimisation

**Main Question:** Does your solution automate route planning and optimisation based on data collected?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Data Analytics and Insights for Vehicles

**Main Question:** Does your solution provide data gathering and analysis on the following:

**Requirements:** a. Mileage and fuel consumption b. Drivers' behaviour (e.g. dangerous driving, speeding) c. Vehicle maintenance and servicing tasks

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - NTP Integration

**Main Question:** Is your solution integrated with NTP? If not, you can contact: <Enquiry_NTP@customs.gov.sg> for further discussion on integration with NTP.

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🔴 Mandatory - Common Data Standard TR128

**Main Question:** Does your solution comply with the Common Data Standard for the shipping container logistics ecosystem as defined in TR 128?

**Compliance Requirements:** To comply, you will need to have obtained a Letter of Conformance from an approved auditor. For detailed information about the certification process and requirements, please refer to the Guide for TR128. \[<https://www.enterprisesg.gov.sg/-/media/08032FA745C941FFB30BF9F4139BF5F3.ashx>]

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]

***

### Q14 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features Required:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q20]

\--

### Q19 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

**Submission Requirements:** To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

***

### Q20 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**For Resellers:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q21 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Next: Q24]

***

### Q22 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Assessment Finished]

\--

### Q23 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q24 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Note:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Assessment Finished]

\--

### Q25 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Freight Management

Digitalise information flow in freight forwarding operations that can encompass import and export shipments over air, sea and land.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - User Role Management

**Main Question:** Does your solution enable the user to perform administration of user accounts and management of access rights or permissions for modules/functions/features in the solution?

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q3 🔴 Mandatory - Freight Operations Support

**Main Question:** Can your solution fulfill EITHER sea freight OR air freight operation?

Please indicate "Yes" for both question number 4 and 5 if your solution can fulfill BOTH requirements.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Sea Freight Management

**Main Question:** If your solution support the key processes in sea freight, does the solution cover at least 3 of the functions listed below:

**Sea Freight Functions:** a. Sea export operation b. Sea import operation c. Sea and air transhipment operation d. Cost computation for specific freight jobs (e.g. integrating carrier rates, port rates, any other relevant charges)

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Air Freight Management

**Main Question:** If your solution support the key processes in air freight, does the solution cover at least 3 of the functions listed below:

**Air Freight Functions:** a. Air export operation b. Air import operation c. Airway bill management d. Air and sea transhipment operation e. Generation of all other necessary documents required by the airlines, and the freight processes

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🔴 Mandatory - Shipment Tracking

**Main Question:** Does your solution provide users with the visibility of the shipment status (i.e. shipment location)?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🟡 Preferred - Automated Booking Document Generation

**Main Question:** Does your solution allow for automated generation of booking document with the respective airline/vessel operators?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Freight Platform Integration

**Main Question:** Is your solution integrated with other key e-platforms used for the air and/or sea freight?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q10]

\--

### Q9 🔴 Mandatory Follow-up - Freight Platform Integration - Elaboration

*This question appears only if you answered "Yes" to Q8*

**Main Question:** Please name these e-platforms and specify the extent of integration.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q10 🔴 Mandatory - Invoice and Quotation Management

**Main Question:** Does your solution provide either:

**Invoice/Quotation Options:** a. an Invoice/Quotation Module which enable the company to setup/edit invoice and quotation details b. integration with accounting management software to leverage on its capability to generate invoices

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - Invoice Generation or Processing

**Main Question:** Does your solution generate or process invoices?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - InvoiceNow-Ready Solution Provider Accreditation

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Is your solution listed on IMDA InvoiceNow-Ready Solution Provider (IRSP) Listing?

**Requirements:** \[1] If you are the Product Principal of the solution, you are required to be accredited as an IRSP by IMDA. \[2] If you are the reseller of the solution, your Solution Product Principal must declare to IMDA that you are an authorised reseller of their solution.

**Additional Information:** For more information on InvoiceNow, refer to: Becoming an InvoiceNow-Ready Solution Provider | E-invoicing | IMDA (<https://www.imda.gov.sg/how-we-can-help/nationwide-e-invoicing-framework/becoming-an-invoicenow-ready-solution-provider>)

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🟡 Preferred - Accounting Software Integration

**Main Question:** Can your solution be integrated with accounting management software to provide the following features:

**Integration Features:** a. General Ledger b. Sales Ledger c. Purchase Ledger d. Invoicing

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q15]

\--

### Q14 🔴 Mandatory Follow-up - Accounting Software Integration - Elaboration

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Please state the accounting management software that your solution can be integrated with.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🟡 Preferred - Transport and Warehouse Management Integration

**Main Question:** Can the solution be integrated with transport management system or warehouse management system?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - Transport and Warehouse Management Integration - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Please state the transport and warehouse management systems that can be integrated with your solution.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🟡 Preferred - NTP Integration

**Main Question:** Is your solution integrated with NTP? If not, you can contact: <Enquiry_NTP@customs.gov.sg> for further discussion on integration with NTP.

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q18]

***

### Q18 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q21]

\--

### Q20 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q21] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q21 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

***

### Q22 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q23] ○ No \[Next: Q25]

\--

### Q23 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q22*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q24] ○ No \[⚠️ Cannot Proceed]

***

### Q24 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q25] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q25 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q26] ○ No \[Next: Q28]

***

### Q26 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q27] ○ No \[Assessment Finished]

\--

### Q27 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q26*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q28 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q29] ○ No \[Assessment Finished]

\--

### Q29 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q28*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Personal Care Services

Personal Care Services solutions provide digital tools to streamline salon and spa operations.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/ears1J3MoHmwbqPhc5mi">/pages/ears1J3MoHmwbqPhc5mi</a></td><td>Streamline beauty and spa operations by integrating appointment scheduling, booking management, sales tracking, marketing campaigns, customer relationship management, and HR functions in one platform</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Salon Management System

Streamline beauty and spa operations by integrating appointment scheduling, booking management, sales tracking, marketing campaigns, customer relationship management, and HR functions in one platform

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Multi-outlet Management and Centralised Administration Capabilities

**Main Question:** Can your solution allow management of multiple outlets:

**Multi-outlet Requirements:** a. single login to any outlet to perform the functions b. Generate of consolidated reports for all outlets c. Push updates to all outlets or selected outlet (e.g. A new 90min message treatment service that cost $90 will be launched and this service is available for all outlets.)

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Dashboards and Reports (Salon)

**Main Question:** Does your solution generate analytics reports and/or dashboards to provide insights to the areas of:

**Analytics Areas:** a. appointment scheduling such as appointment fulfillment rate, missed appointments b. sales analysis such as top outlet sales performance, top employee performance, YoY Sales growth, Sales revenue by outlet, sales report by service / retail products c. CRM reports such as New Clients Per Month, New Client Retention, Repeat Client Retention, Frequency of Visit (FOV), Client loyalty points d. employee management such as employee productivity, commission report e. inventory management such as below minimum stock , stock movement , stock balance f. packages management such as balance packages value (deferred income)

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features (Must include at least one):** Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

Please state how many reports per area based on your available modules.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q4 🔴 Mandatory - Appointment Scheduling

**Main Question:** Does your solution offer these appointment scheduling features:

**Scheduling Features:** a. Provide calendar view for employees to manage all appointments b. Ability to configure slots by available employees capacity c. Provide integrated calendar and scheduling features for room, and equipment management d. Ability to configure and send automated reminders and custom messages to customers about appointments and notify them of any change

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Booking Management

**Main Question:** Does your solution include a Booking Management Module?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - Booking Management Features

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Does your solution offer these booking features:

**Booking Features:** a. Customer self-service online booking through secured login and viewing real-time availability via website, Facebook, or online booking apps b. Customer self-service cancellation or re-scheduling of appointments c. Facilities appointment booking based on package credits, balances, free trials, first time customer, or through making online payment via accepting full payment or deposit (optional) d. Display of Terms and Conditions during each purchase

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Customer Management

**Main Question:** Does your solution support customer management through collection and easy access to data including customer profile, preference, medical conditions, allergy, purchase history, treatment history etc.?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Real-time Data Synchronisation

**Main Question:** Is your solution able to synchronise the customer data collected from the Salon Management System in real time?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Customer Rewards or Loyalty Programme

**Main Question:** Does your solution include a Customer Rewards or Loyalty Programme Module?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q11]

\--

### Q10 🔴 Mandatory Follow-up - Customer Rewards or Loyalty Programme Features

*This question appears only if you answered "Yes" to Q9*

**Main Question:** Does your solution offer at least 2 features for Customer Rewards or Loyalty Programme, such as:

**Loyalty Programme Features:** a. Automatic recording of rewards points for purchases, visits, referrals, reviews, and etc b. Customer self-service viewing of rewards, balance, and history c. Redemption of rewards points for gifts, products, services, vouchers, and etc d. Pre-set functions to generate reminders for reward points expiry e. Configuration of approval workflow to manage manual reward points adjustment f. Ability to set tiered rewards programme (e.g. basic, silver, gold, platinum)

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - Package Management

**Main Question:** Does your solution include a Package Management Module?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - Package Management Features

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Does your solution offer these features for Package Management, such as:

**Package Management Features:** a. Package setup (package quantity, package price, promotion and discount, expiry time) b. Audit log for customer package adjustments c. Workflow approval for customer package adjustments

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Sales Management

**Main Question:** Does your solution allow for recording of receipts and payments?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Digital Payment Integration

**Main Question:** Does your solution offer and/or acknowledge receipt of cashless payment by consumers e.g. via wireless/mobile payment terminals or integrated digital payment gateway? Please name the various payment modes and integration payment partners.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q15 🔴 Mandatory - Third-Party POS Integration Capabilities

**Main Question:** Does your solution offer POS functions or allow integration with 3rd party POS solution?

Please indicate the POS Software and if this is developed in-house or if it's an integration to a 3rd party POS solution.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🔴 Mandatory - SMS or E-Marketing Management

**Main Question:** Does your solution come with these features which allow company to perform the following functions:

**Marketing Features:** a. Create marketing campaigns with email and SMS with ability to add text, headings, images and even call-to-action buttons that will link to booking, packages b. Select customer list (VIP, inactive customers, frequent customer) c. Generate reports to view campaign success (e.g. click through rate)

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🔴 Mandatory - Human Resource Management

**Main Question:** Can your solution manage a company's employee records in all key HR administrative areas below:

**HR Administrative Areas:** a. Personnel Management (i.e. Create employees records and details, Allow for employee self-service to maintain updates) b. Payroll and Commission Management (i.e. E-payroll, Commission reports, Payroll reports, MOM itemised payslip, Policy and statutory compliance)

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🟡 Preferred - IRAS Auto Inclusion Scheme (AIS) Compliance

**Main Question:** Is your solution listed on IRAS's List of Supporting Payroll Software Vendors for the Auto Inclusion Scheme (AIS) for employment income?

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Next: Q19]

***

### Q19 🟡 Preferred - Other Optional HR Modules

**Main Question:** Can your solution manage a company's employee records in other HR administrative areas below:

**Optional HR Areas:** a. Leave Management (i.e. Comprehensive Leave Management and settings, Leave policy configurations, leaves reports) b. Attendance Tracking (i.e. daily recording of employee attendance, attendance reports) c. Rostering (i.e. employee scheduling)

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Next: Q20]

***

### Q20 🟡 Preferred - Inventory Management

**Main Question:** Does your solution include an Inventory Management Module?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q24]

\--

### Q21 🔴 Mandatory Follow-up - Inventory Management Features

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Does your solution enable the following functions:

**Inventory Functions:** a. Set up and edit inventory product details for different item groups (e.g. dimensions, models) b. Create inventory journal logs to track movement of inventory items (e.g. date, quantity, cost, reserves, movements, location, staff log) c. Create item prices and discount groups d. Set up and edit warehouse details (e.g. branches) e. Grant access to all employees for mobile-based, web-based, and cloud-based usage

🔴 **Answer:** ○ Yes \[Next: Q22] ○ No \[⚠️ Cannot Proceed]

\--

### Q22 🔴 Mandatory Follow-up - Inventory Integration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Does your solution allow for real-time update of inventory via integration with existing Salon Management System solution?

i.e. inventory updated when orders are fulfilled, or inventory is stocked up

Please briefly describe how the integration is done in the comment section.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q23] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

\--

### Q23 🔴 Mandatory Follow-up - Inventory Alert

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Does your solution automatically trigger reminder alert when inventory level reached a pre-set low level?

🔴 **Answer:** ○ Yes \[Next: Q24] ○ No \[⚠️ Cannot Proceed]

***

### Q24 🟡 Preferred - Mobile App

**Main Question:** Does your solution include a mobile app solution that can be configured and linked to the Salon Management System?

**Note:** \[1] Mobile Development is not supportable. Any cost incurred for customisation has to be borne by SMEs.

🟡 **Answer:** ○ Yes \[Next: Q25] ○ No \[Next: Q26]

\--

### Q25 🔴 Mandatory Follow-up - Mobile App - Elaboration

*This question appears only if you answered "Yes" to Q24*

**Main Question:** Please state the module(s) that are available in the mobile app. e.g. Booking module

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q26] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q26 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q27] ○ No \[Next: Q28]

\--

### Q27 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q26*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q28] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q28 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q29] ○ No \[⚠️ Cannot Proceed]

***

### Q29 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q30] ○ No \[⚠️ Cannot Proceed]

***

### Q30 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

**Reseller Requirements:** If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Qualified Third-Party Definition:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q31] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q31 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q32] ○ No \[Next: Q34]

***

### Q32 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q33] ○ No \[Assessment Finished]

\--

### Q33 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q32*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q34 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Compliance Timeline:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

**Additional Information:** For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q35] ○ No \[Assessment Finished]

\--

### Q35 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q34*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Retail

Retail solutions provide digital tools to enhance retail business operations, store management and digital commerce.&#x20;

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Point of Sale**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/2ZyaLrcKxeJELuPSaXcy">/pages/2ZyaLrcKxeJELuPSaXcy</a></td><td>Enable mobile transaction processing through portable devices by connecting point-of-sale operations with backend CRM and inventory management, allowing staff to complete sales anywhere in-store while maintaining real-time synchronisation with business systems.</td></tr><tr><td><a href="/pages/SVlezMI2CYVMi5tFQVt3">/pages/SVlezMI2CYVMi5tFQVt3</a></td><td>Enable customers to independently scan and pay for purchases by streamlining the retail checkout process through automated scanning, payment processing, and security features, reducing queues and improving shopping convenience.</td></tr></tbody></table>

**Store Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/8zsWgMgkjrAzYFOJUznF">/pages/8zsWgMgkjrAzYFOJUznF</a></td><td>Automate price display through digital tags by enabling real-time updates of product pricing and information across store shelves, ensuring pricing accuracy and reducing manual labour while enabling dynamic price management.</td></tr><tr><td><a href="/pages/v3AWFEwYSkbb9QLPuA4n">/pages/v3AWFEwYSkbb9QLPuA4n</a></td><td>Use video technology and IoT sensors to gather retail intelligence by analysing customer behaviour, traffic patterns, and store performance metrics, providing actionable insights for optimising store layout, staffing, and merchandising decisions.</td></tr></tbody></table>

**Digital Commerce**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/WHhahAlVIK4gTSvl8nSh">/pages/WHhahAlVIK4gTSvl8nSh</a></td><td>Allows a retailer to deliver a seamless shopping experience across various customer touchpoints, and to have real-time product and inventory visibility, reducing stocking issues.</td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Integrated POS (with mobile features)

Enable mobile transaction processing through portable devices by connecting point-of-sale operations with backend CRM and inventory management, allowing staff to complete sales anywhere in-store while maintaining real-time synchronisation with business systems.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Sales Analytics

**Main Question:** Does your solution automate sales transactions, generate sales report, and provide insights on customer behaviour and product popularity?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Enhanced POS Features

**Main Question:** Does your solution offer at least one of the following modules that improve the company's business processes beyond the standard POS functions, such as the following:

**Enhanced POS Modules:** a. Commission Management b. Discount and Gift Card Management c. Customer Relationship Management System (CRM)\* or allow integration with third-Party CRM system

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🟡 Preferred - Return Management

**Main Question:** Does your solution include the Return Tracking feature?

🟡 **Answer:** ○ Yes \[Next: Q5] ○ No \[Next: Q5]

***

### Q5 🟡 Preferred - Other Features

**Main Question:** Does your solution include any other features not listed in this checklist?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q7]

\--

### Q6 🔴 Mandatory Follow-up - Other Features - Elaboration

*This question appears only if you answered "Yes" to Q5*

**Main Question:** Please elaborate on these other features.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q7 🔴 Mandatory - Digital Payment Acknowledgement

**Main Question:** Does your solution offer and/or acknowledge receipt of cashless payment by consumers e.g. via wireless/mobile payment terminals or integrated digital payment gateway?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🟡 Preferred - Omni-Channel Retail Support

**Main Question:** Does your solution support omni-channel retailing? i.e. allowing customers to purchase at multiple touchpoints such as online, in-store and on-the-go platform

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - POS System with Mobile Access

**Main Question:** Does your solution offer Mobile POS system to assist retail associates in performing their duties (i.e. performing sales transactions, checking inventory) via electronic devices (such as Tablet, Kiosk, Mobile Chatbot)?

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q11] ○ No \[⚠️ Cannot Proceed]

***

### Q11 🟡 Preferred - AI Features Integrated POS

**Main Question:** Does your solution offer any artificial intelligence features?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q13]

\--

### Q12 🔴 Mandatory Follow-up - AI Features Integrated POS - Elaboration

*This question appears only if you answered "Yes" to Q11*

**Main Question:** Describe your AI features. Some examples are as follows:

**AI Feature Examples:** a. Chatbots b. Automated identification of recurring activities c. Ability to discover niche customer segments d. Predictive insights on stocking and inventory management e. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q13 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🟡 Preferred - Customer Data Collection

**Main Question:** Does your solution include any of the following:

**Customer Data Features:** a. Customer Relationship Management (CRM) or b. Customer Loyalty Management, or c. Collect Personal Identifiable Information

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

### Q18 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

### Q19 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q20 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

### Q21 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Electronic Shelf Label (ESL)

Automate price display through digital tags by enabling real-time updates of product pricing and information across store shelves, ensuring pricing accuracy and reducing manual labour while enabling dynamic price management.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Operational Accessibility

**Main Question:** Is your solution cloud-based or accessible through a user-friendly interface, allowing authorised personnel to easily access and manage the electronic shelf labelling system from various devices and locations?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Scalability

**Main Question:** Is your solution scalable to accommodate at least 500 ESL tags or labels across different sections and departments within the store?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Integration with Existing Systems

**Main Question:** Is your solution capable of seamless integration and real-time updates with existing POS systems to ensure smooth operation and data synchronisation?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - System Reporting

**Main Question:** Does your system provide reporting tools to collect data and insights regarding the operational status and performance of ESL components, including tags or labels, transmitters, network connectivity, and the successful transmission of updates from systems to the ESL?

**Note:** Backend systems include the central management system, inventory databases, pricing databases, and any other systems.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🟡 Preferred - Multi-Language Support

**Main Question:** Can the ESL system display product information in multiple languages to cater to diverse customer base in international or multicultural settings?

🟡 **Answer:** ○ Yes \[Next: Q6] ○ No \[Next: Q6]

***

### Q6 🟡 Preferred - Customer Engagement Features

**Main Question:** Can the ESL system incorporate features such as QR codes for additional product details, customer reviews, or links to promotional videos?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Hardware features

**Main Question:** Are the ESL tags or labels built to be energy-efficient, minimising maintenance and operational costs?

**Note:** Most ESL tags and labels should have a minimum battery life of at least 5 years, subject to environmental and usage patterns.

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - Temperature and Environmental Considerations

**Main Question:** Can the ESL labels operate effectively in various environmental conditions, including temperature fluctuations, ensuring reliability in different store environments?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q16]

\--

### Q14 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q13*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

\--

### Q15 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Next: Q19]

\--

### Q17 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Assessment Finished]

\--

### Q18 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q19 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q20] ○ No \[Assessment Finished]

\--

### Q20 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q19*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Self Checkout Solution

Enable customers to independently scan and pay for purchases by streamlining the retail checkout process through automated scanning, payment processing, and security features, reducing queues and improving shopping convenience.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Operational Accessibility

**Main Question:** Is the solution cloud-based or accessible through a user-friendly interface, allowing authorised personnel for easy access and management of self-checkout solution?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Scalability

**Main Question:** Is the SCO solution scalable to accommodate the expansion of more self-checkout counters?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Product Recognition

**Main Question:** Is the SCO kiosk equipped with product recognition technology to identify items accurately, minimising errors during the checkout process?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Efficient Payment Processing and Integration

**Main Question:** Can the self-checkout solution be integrated with payment gateway(s) to support various payment methods? It is mandatory for the solution to be integrated with PayNow.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Integration with Existing Systems

**Main Question:** Is the solution capable of seamless integration with existing systems (e.g. POS, Inventory Management, CRM) to ensure smooth operation and data synchronisation?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🔴 Mandatory - Customer Assistance Options

**Main Question:** Are there easily accessible options for customers to seek assistance or resolve issues during the self-checkout process, such as a help button or on-screen support?

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

### Q7 🔴 Mandatory - Age Verification Capability

**Main Question:** Does the solution include age verification capability for selected products as determined by the retailer?

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

### Q8 🔴 Mandatory - Real-time Alerts for Staff

**Main Question:** Does the self-checkout solution provide real-time alerts to staff in case of system issues, allowing for immediate response and minimising disruptions?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Data Analytics for Customer Insights

**Main Question:** Does the self-checkout solution provide robust data analytics tools to gather insights into customer behaviour, preferences, and overall transaction patterns?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Security and Anti-Theft Compliance

**Main Question:** Are there security measures implemented to prevent theft or fraudulent activities during the self-checkout process?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Multi-Language Support

**Main Question:** Can the SCO solution display product information in multiple languages to cater to diverse customer base in international or multicultural settings?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Customer Accessibility Features

**Main Question:** Are there accessibility features in the self-checkout solution, such as voice guidance, to cater to customers with diverse needs?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🟡 Preferred - Receipt Options

**Main Question:** Does the solution offer flexibility in receipt options, such as digital receipts, to align with changing customer preferences and reduce paper waste?

🟡 **Answer:** ○ Yes \[Next: Q14] ○ No \[Next: Q14]

***

### Q14 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

### Q15 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q17]

\--

### Q16 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q15*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q17 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q18] ○ No \[⚠️ Cannot Proceed]

***

### Q18 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

***

### Q19 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

### Q21 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q23 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

### Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# In-Store Analytics

Use video technology and IoT sensors to gather retail intelligence by analysing customer behaviour, traffic patterns, and store performance metrics, providing actionable insights for optimising store layout, staffing, and merchandising decisions.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Operational Accessibility

**Main Question:** Is the solution cloud-based or accessible through a user-friendly interface, allowing authorised personnel to easily access and manage the ISA system from various devices and locations?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Scalability

**Main Question:** Is the ISA system scalable to accommodate an increase in number of IOT devices (e.g. Smart Cameras, Beacons, Proximity Sensors, RFID)?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Integration with Existing Systems

**Main Question:** Does the In-Store Analytics solution seamlessly integrate with the retailer's existing systems (e.g. point-of-sale (POS) systems, inventory management)?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Customer Behaviour Tracking

**Main Question:** Can the solution uncover and analyse customer traffic patterns within the store, aiding in the efficient layout design and product interaction or placement?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Customer Heatmap Insights

**Main Question:** Can the solution generate heat maps to visually represent customer hotspots within the store, aiding in strategic placement of promotions or popular products?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Customer Queue Insights

**Main Question:** Can the solution offer insights into queue lengths and waiting times, helping retailers optimise checkout processes and staff allocation?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Customer Emotion Insights

**Main Question:** Can the solution recognise customer emotion so as to provide insights?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🔴 Mandatory - Data Security and Privacy Measures

**Main Question:** Are there data security measures put in place to protect the data collected by In-Store Analytics, and does the solution ensure compliance with data and privacy regulations?

🔴 **Answer:** ○ Yes \[Next: Q9] ○ No \[⚠️ Cannot Proceed]

***

### Q9 🟡 Preferred - Conversion Rate Analysis

**Main Question:** Does the solution offer features to analyse conversion rates, helping retailers understand how many visitors make purchases and refining strategies to improve conversion?

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

### Q10 🟡 Preferred - Report Customisation

**Main Question:** Can retailers customise reports based on their specific needs and priorities, ensuring that the analytics provided align with customer's needs?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

### Q11 🟡 Preferred - Real-time Alerts and Notifications

**Main Question:** Can the system provide real-time alerts and notifications to store management or staff based on predefined thresholds or anomalies in customer behaviour?

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

### Q12 🟡 Preferred - Customer Segmentation Analysis

**Main Question:** Can the In-Store Analytics solution provide insights into customer segments, allowing for targeted strategies based on the preferences and behaviours of different customer groups?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q13]

***

### Q13 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features: Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q15] ○ No \[Next: Q16]

\--

### Q15 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q14*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q16 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

### Q17 🟡 Preferred - Personal Data Collection

**Main Question:** Does your digital solution collect, use, disclose, process or dispose personal data?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

### Q18 🔴 Mandatory Follow-up - Personal Data Protection

*This question appears only if you answered "Yes" to Q17*

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q19] ○ No \[⚠️ Cannot Proceed]

\--

### Q19 🔴 Mandatory Follow-up - Vulnerability Assessment/Penetration Testing (VA/PT)

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months? The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q20] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q20 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Next: Q23]

\--

### Q21 🟡 Preferred - CEM for Product Principal

*This question appears only if you answered "Yes" to Q20*

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q22] ○ No \[Assessment Finished]

\--

### Q22 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q21*

**Main Question:** Please specify the following information:

**Required Information:** i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q23 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q24] ○ No \[Assessment Finished]

\--

### Q24 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q23*

**Main Question:** Please specify the following information:

**Required Information:** i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]&#x20;

**Text Elaboration Required:** \[Text Box for Description/Details]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Omnichannel Retail Management (OCRM)

Allows a retailer to deliver a seamless shopping experience across various customer touchpoints, and to have real-time product and inventory visibility, reducing stocking issues.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

**Q1 🔴 Mandatory - Operational Accessibility**

Main Question: Is the solution cloud-based or accessible through a user-friendly interface, allowing authorised personnel to easily access and manage the OCRM solution from various devices and locations?

Example: Store managers access sales and inventory data from tablets and smartphones to make real-time decisions off-site.

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

**Q2 🔴 Mandatory - Physical Sales Transactions Support**

Main Question: Does the solution allow the processing of customer transactions in physical stores using cash and cashless methods?

Example: Staff uses POS or Mobile-POS for entering of product codes, calculating totals, accepting various modes of payment, processing payment securely and generating receipts.

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

**Q3 🔴 Mandatory - Multiple Touchpoints for Customer Engagement and Sales Transactions**

Main Question: Does the solution allow retailers to promote and sell products and services online over multiple touchpoints?

Example: The customer sees content, browses products, makes purchases, and completes transactions online on either an Online Store/Brand.com, Social media channels (e.g. Facebook, Instagram, Tik Tok), chat applications (e.g. WhatsApp, Telegram), or Marketplaces (e.g. Lazada, Shopee, Amazon).

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

**Q4 🔴 Mandatory - Seamless Customer Experience Across Touchpoints**

Main Question: Does the solution allow the delivery of a seamless experience across customer touchpoints, complementing the customer experience at its physical stores?

Note: Customer touchpoints include physical stores, online stores, social media & chat commerce channels, online market places, etc.

Example: The customer sees a promotion on any of the online touchpoints, purchases a product online, and choose between home delivery or in-store pickup for collection.

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

**Q5 🔴 Mandatory - Inventory Levels Management**

Main Question: Does the solution help retailers to manage their inventories to ensure efficient operations and meet customer demands across channels?

Example: The solution monitors, organises, and optimises inventory levels such that popular items are always in stock.

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

**Q6 🔴 Mandatory - Customer Loyalty and Retention - Relationship Management**

Main Question: Does the solution help retailers manage their relationships with customers and increase customer loyalty?

Example: The solution captures customer data and segment customers, delivering personalised marketing messages such as discounts on favourite menu items based on past purchase history.

🔴 **Answer:** ○ Yes \[Next: Q7] ○ No \[⚠️ Cannot Proceed]

***

**Q7 🔴 Mandatory - Dashboards and Reports (OCRM)**

Main Question: Can your solution provide dashboards and reporting capabilities to optimise business performance?

Dashboard Requirements: Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

Interactive Features Required: The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q8] ○ No \[⚠️ Cannot Proceed]

***

**Q8 🟡 Preferred - Supplier Relationship Management**

Main Question: Does the solution help retailers to transact with the supplier partners and streamline the ordering process, ensuring that new stock arrives on time?

Example: Store managers track delivery times and manage incoming consignment inventory.

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

**Q9 🟡 Preferred - GenAI-Powered Customer Responses**

Main Question: Does your solution offer natural language processing (NLP) capability for understanding user intent and sentiment, allowing for fast, accurate, and personalised support?

Example: An LLM Chatbot answers FAQs and urgent queries such as return policies, delivering relevant information instantly to improve customer satisfaction and drive sales.

🟡 **Answer:** ○ Yes \[Next: Q10] ○ No \[Next: Q10]

***

**Q10 🟡 Preferred - Personalised Product Recommendations**

Main Question: Can your solution recommend personalised product recommendations based on customer behaviour and purchase history?

Example: Customers are given personalised product recommendations and dynamic pricing offers based on their purchase history and browsing behaviour.

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q11]

***

**Q11 🟡 Preferred - Marketing and Customer Segmentation**

Main Question: Can your solution segment and create marketing campaigns to target different customer groups?

Example: The solution optimises marketing campaigns using AI-powered content personalisation to different segments of customers based on purchasing behaviour.

🟡 **Answer:** ○ Yes \[Next: Q12] ○ No \[Next: Q12]

***

**Q12 🟡 Preferred - AI Features**

Main Question: Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q13] ○ No \[Next: Q14]

\--

**Q13 🔴 Mandatory Follow-up - AI Features - Elaboration**

*This question appears only if you answered "Yes" to Q12*

Main Question: Describe your AI feature and its benefits. Examples are:

AI Feature Categories: a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

**Text Elaboration Required:** \[Text Box for Description/Details]

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

**Q14 🔴 Mandatory - Business Data Extraction**

Main Question: Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

***

**Q15 🔴 Mandatory - Personal Data Protection**

Main Question: Can your solution demonstrate compliance with the following Personal Data Protection requirements?

Compliance Requirements: Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

Submission Requirements: To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q16] ○ No \[⚠️ Cannot Proceed]

***

**Q16 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)**

Main Question: Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

Scope Requirements: The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

Submission Requirements: Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

Additional Requirements: If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

Qualified Third-party Definition: \[1] Qualified third-party refers to: CREST-certified companies \[<https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

🔴 **Answer:** ○ Yes \[Next: Q17] ○ No \[⚠️ Cannot Proceed]

***

**Q17 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)**

Main Question: Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q18] ○ No \[Next: Q20]

\--

**Q18 🟡 Preferred - CEM for Product Principal**

*This question appears only if you answered "Yes" to Q17*

Main Question: Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

**Q19 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration**

*This question appears only if you answered "Yes" to Q18*

Main Question: Please specify the following information:

Required Information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

***

**Q20 🟡 Preferred - CEM for Resellers**

*This question appears only if you answered "No" to Q17*

Main Question: Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

Compliance Timeline: Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Additional Information: Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q21] ○ No \[Assessment Finished]

\--

**Q21 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration**

*This question appears only if you answered "Yes" to Q20*

Main Question: Please specify the following information:

Required Information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Submission Requirements: Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

**Date of Issue Required:** \[Date Field]\
**Upload Supporting Document Required:** \[File Upload]\
**Text Elaboration Required:** \[Text Box for Description/Details]

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}


# Security

Security solutions provide digital tools to enhance security operations through automation and real-time monitoring.

Below is our comprehensive list of solution categories. Click on any category to view its detailed requirements:

**Operations Management**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/rwZR6Cql0vzQVoArKN5C">/pages/rwZR6Cql0vzQVoArKN5C</a></td><td>Integrate multiple security systems into one unified interface by connecting' visitor management, incident tracking, and video surveillance, enabling centralised monitoring, intelligent response coordination, and streamlined security operations management.</td></tr><tr><td><a href="/pages/F2P1QY6FAIFLUt9OGujI">/pages/F2P1QY6FAIFLUt9OGujI</a></td><td>Streamline patrol operations through real-time tracking and reporting and manage guard assignments, patrol routes, and incident documentation while enabling instant communication and digital reporting through mobile devices.</td></tr></tbody></table>

**Access Control**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/wuIBTBb6sV8bQyLStBzo">/pages/wuIBTBb6sV8bQyLStBzo</a></td><td>Control facility access through digital registration by processing visitors using optional features like biometrics, car plate recognition, and integrating access control features, ensuring secure entry management while streamlining the check-in process.</td></tr></tbody></table>

**Surveillance & Automation**

<table data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th></tr></thead><tbody><tr><td><a href="/pages/oKVNAqLDCULzJHL7Cu6A">/pages/oKVNAqLDCULzJHL7Cu6A</a></td><td>Combine IP cameras with intelligent monitoring capabilities. The system uses video analytics to automatically detect security incidents, enhance surveillance coverage, and provide real-time alerts for improved site security management.</td></tr><tr><td></td><td></td></tr></tbody></table>

{% hint style="warning" %}
If you are unable to find a suitable solution category or need help with onboarding, please contact us through this [form](https://go.gov.sg/pareginterest).
{% endhint %}


# Mobile-Enabled Patrol and Incident Management

Streamline patrol operations through real-time tracking and reporting and manage guard assignments, patrol routes, and incident documentation while enabling instant communication and digital reporting through mobile devices.

**Instructions**

* This page helps you prepare "*Solution Requirements*" section in Vendor Management Portal and you will see the exact questions and flow.
* 🔴 **Mandatory questions:** Must answer "Yes" to continue
* 🟡 **Preferred questions:** Can answer either way and continue
* Follow the question flow as indicated

### Q1 🔴 Mandatory - Mobile Accessibility

**Main Question:** Does your solution allow mobile access for attendance, patrol and incident management for security officers?

🔴 **Answer:** ○ Yes \[Next: Q2] ○ No \[⚠️ Cannot Proceed]

***

### Q2 🔴 Mandatory - Guard Tour Management

**Main Question:** Does your solution come with a guard tour management module to log the activities of the security officers performing their patrolling duty?

🔴 **Answer:** ○ Yes \[Next: Q3] ○ No \[⚠️ Cannot Proceed]

***

### Q3 🔴 Mandatory - Incident Management

**Main Question:** Does your solution come with an incident management module to allow a security officer to report and investigate incidents including documentation such as documents, photos, videos etc. on who, what, where and when for each incident; and allow these documentations to be submitted electronically for each incident?

🔴 **Answer:** ○ Yes \[Next: Q4] ○ No \[⚠️ Cannot Proceed]

***

### Q4 🔴 Mandatory - Time Attendance Tracking

**Main Question:** Does your solution come with an attendance management module to keep track of the security officer's attendance for the purpose of computing working hours and/or salaries?

🔴 **Answer:** ○ Yes \[Next: Q5] ○ No \[⚠️ Cannot Proceed]

***

### Q5 🔴 Mandatory - Cloud and Multi-Device Accessibility

**Main Question:** Does your solution allow for cloud-based, mobile-based, and/or web-based usage?

🔴 **Answer:** ○ Yes \[Next: Q6] ○ No \[⚠️ Cannot Proceed]

***

### Q6 🟡 Preferred - Centralised Command Centre

**Main Question:** Does your solution have the ability to allow supervision of multiple sites and teams (including location tracking) remotely through a centralised command centre?

🟡 **Answer:** ○ Yes \[Next: Q7] ○ No \[Next: Q7]

***

### Q7 🟡 Preferred - Patrolling Hardware Support

**Main Question:** Does your solution come with the option to provide the necessary hardware (e.g. wearable technology such as body worn camera, comms sets, GPS device, integrated IoT devices, etc.) to augment patrolling duties?

🟡 **Answer:** ○ Yes \[Next: Q8] ○ No \[Next: Q8]

***

### Q8 🟡 Preferred - System Integration and Connectivity

**Main Question:** Does your solution allow prebuilt integration tools or connector with other enterprise applications?

🟡 **Answer:** ○ Yes \[Next: Q9] ○ No \[Next: Q9]

***

### Q9 🔴 Mandatory - Dashboards and Reports

**Main Question:** Can your solution provide dashboards and reporting capabilities to track key metrics, user interactions, operational performance, or other relevant data insights across your digital solution?

**Dashboard Requirements:** Your digital solution should have one or more dashboards that provide an at-a-glance overview of key metrics/indicators with at least 4 charts/graphs to help users analyse data through data visualisation.

**Interactive Features:** The dashboard must include at least one of the following interactive features:

* Option 1: Interactive charts/graphs that allow users to interact with one chart and apply that interaction as a filter to other charts on the dashboard, and vice versa
* Option 2: At least three common filters/slicers applicable to ALL charts/graphs on the same dashboard

🔴 **Answer:** ○ Yes \[Next: Q10] ○ No \[⚠️ Cannot Proceed]

***

### Q10 🟡 Preferred - AI Features

**Main Question:** Does your solution incorporate AI in your core features and functions?

🟡 **Answer:** ○ Yes \[Next: Q11] ○ No \[Next: Q12]

\--

### Q11 🔴 Mandatory Follow-up - AI Features - Elaboration

*This question appears only if you answered "Yes" to Q10*

**Main Question:** Describe your AI feature and its benefits. Examples are:

**AI Feature Examples:** a. Generate output, identify items, or provide recommendations based on training models to improve decision-making b. Recognise text, images to shorten time taken for manual inputs of forms c. Others, please specify

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q12] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]

***

### Q12 🔴 Mandatory - Business Data Extraction

**Main Question:** Can your solution enable SMEs to efficiently extract business data in various discrete formats such as CSV, XLSX, XML, and TSV?

🔴 **Answer:** ○ Yes \[Next: Q13] ○ No \[⚠️ Cannot Proceed]

***

### Q13 🔴 Mandatory - Personal Data Protection

**Main Question:** Can your solution demonstrate compliance with the following Personal Data Protection requirements?

**Compliance Requirements:** Digital solutions that collect, use, disclose, process or dispose personal data should incorporate features that support the obligations under the Personal Data Protection Act (2020).

To comply with this requirement, you MUST complete the Personal Data Protection Requirements form at <https://go.gov.sg/pdp>.

🔴 **Answer:** ○ Yes \[Next: Q14] ○ No \[⚠️ Cannot Proceed]

***

### Q14 🔴 Mandatory - Vulnerability Assessment/Penetration Testing (VA/PT)

**Main Question:** Has your solution undergone a comprehensive security vulnerability assessment/penetration testing (VA/PT) conducted by a qualified third-party within the last 12 months?

**Scope Requirements:** The scope of the VA/PT must cover network security; application security; data protection measures and access control (if applicable); API security testing (if applicable); Cloud security configuration review (if applicable). Specifically, for web application security, the scope must cover minimally all OWASP Top 10 vulnerabilities.

**Submission Requirements:** Please submit the VA/PT report (dated maximum 1 year from the checklist submission date). The VA/PT Report must include Executive summary; Detailed findings and risk ratings; Remediation recommendations; Evidence of vulnerability fixes or mitigation plans; Testing methodology used; Scope of assessment; Assessor's qualifications and certifications.

If you are the reseller of the solution, please obtain the VA/PT report from your product principal. SOC 2 Type II report can be accepted if the detailed technical vulnerability assessment results are part of the SOC2 Type II scope.

**Note:** \[1] Qualified third-party refers to: CREST-certified companies \[ <https://www.crest-approved.org/members/>] or companies with security professional with relevant CREST certifications; Security professionals with recognised certifications such as: Offensive Security Certified Professional (OSCP); EC-Council Certified Penetration Testing Professional (CPENT); GIAC Penetration Tester (GPEN); or other equivalent industry-recognised certifications.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Next: Q15] ○ No \[⚠️ Cannot Proceed]

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q15 🟡 Preferred - Cybersecurity Compliance - Cyber Essentials Mark (CEM)

**Main Question:** Are you the Product Principal of the solution that you are submitting for pre-approval?

🟡 **Answer:** ○ Yes \[Next: Q16] ○ No \[Next: Q18]

***

### Q16 🟡 Preferred - CEM for Product Principal

**Main Question:** Has your organisation achieved CSA Cyber Essentials for ICT Vendor Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q17] ○ No \[Assessment Finished]

\--

### Q17 🔴 Mandatory Follow-up - CEM for Product Principal - Elaboration

*This question appears only if you answered "Yes" to Q16*

**Main Question:** Please specify the following information: i. The certificate demonstrating your organisation has attained Cyber Essentials for ICT Vendors ii. The cybersecurity certification the organisation has met iii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

***

### Q18 🟡 Preferred - CEM for Resellers

**Main Question:** Has your organisation achieved CSA Cyber Essentials Mark certification or equivalent recognised cybersecurity certifications (including but not limited to Cyber Trust Mark or ISO27001) that validate the implementation of appropriate security controls against common cyber threats in your organisation and the solution you are submitting for pre-approval?

**Additional Information:** Vendors are encouraged to comply at application and are required to meet this requirement by the Annual Review, where it will be assessed as mandatory.

Note: For more information on Cyber Essentials mark, please refer to <https://www.csa.gov.sg/cyber-essentials/>

🟡 **Answer:** ○ Yes \[Next: Q19] ○ No \[Assessment Finished]

\--

### Q19 🔴 Mandatory Follow-up - CEM for Resellers - Elaboration

*This question appears only if you answered "Yes" to Q18*

**Main Question:** Please specify the following information: i. The cybersecurity certification the organisation has met ii. The scope of the certification

Please also upload a copy of the Certification and indicate the Certification Issuance Date in the date field.

Click "Yes" to confirm you have completed the instructions.

🔴 **Answer:** ○ Yes \[Assessment Finished] ○ No \[⚠️ Cannot Proceed]

**Text Elaboration Required:** \[Text Box for Description/Details]&#x20;

**Date of Issue Required:** \[Date Field]&#x20;

**Upload Supporting Document Required:** \[File Upload]

{% hint style="info" %}
**Preparing for submission?**

Your submission should contain screenshots and write-ups that clearly demonstrate compliance with each mandatory requirement sub-point. [Contact us](https://form.gov.sg/68117f6fa667a54847523fd2) if you need help.&#x20;
{% endhint %}




---

[Next Page](/llms-full.txt/1)

