unlock-keyholeCEM Guide for Vendors

This page features information about the type of CEM that ICM vendors will need in order to pass their Annual Review.

πŸ” What is the Cyber Essentials Mark (CEM)?

The Cyber Essentials Mark (CEM) is a cybersecurity certification developed by the Cyber Security Agency of Singapore (CSA) to recognise organisations that have implemented fundamental "cyber hygiene" practices to protect themselves and their customers from common cyber-attacks.

As part of the Annual Review, moving forward ICM vendors will be required to attain the Cyber Essentials Mark. Please note, IMDA may suspend or terminate the appointment contract if the Pre Approved Vendor fails to meet any of the Annual Review Criteria's.

πŸ“‹ Types of CEM Required


🏭 CEM for ICT Vendor

Required for: Vendors with their own product or have ability to modify product source code to form your own product

Examples: Odoo, E-commerce platforms, product principals


πŸ›’ Standard CEM

Required for: Vendors that resell third-party products and do not modify source code of products, as well as vendors providing 100% professional services

Examples: Xero resellers, QuickBooks resellers, HRMS resellers, Digital Marketing services, HRSS Services


πŸ’° Certification Details

Detail
Information

πŸ’΅ Cost

$500 to $2,000 (could be higher depending on organisation size, system complexity, and certification body pricing)

⏰ Validity

Two years, requires revalidation upon expiry

🏒 Certification Bodies

Find CSA-appointed certification bodies herearrow-up-right


πŸ“‹ Which CEM Should You Get?

🏷️ Certification Type

πŸ‘₯ Who Should Get This

πŸ“ Description

πŸ”§ Coverage

πŸ›‘οΈ CEM

Non-Product Principals

β€’ Resellers

β€’ Service providers β€’ Professional services

Updated version of CEM covering comprehensive cybersecurity areas (Must have Classical Cybersecurity scope)

β€’ Classical Cybersecurity βœ…

β€’ Operational Technology (OT) Security

β€’ AI Security

🏭 CEM for ICT Vendor

Product Principals

β€’ Own product developers

β€’ Source code modifiers

β€’ Product creators

Enhanced version of CEM with added requirements specifically for ICT Solution Vendors

β€’ All CEM coverage β€’ Additional ICT vendor requirements

β€’ Enhanced security controls


πŸ“… CEM Requirements by Appointment Contract Period

For 1st April 2026 and 1st July 2026 Annual Review, CEM is not required. For all other AR, please refer to the table below:

πŸ“‹ Appointment Contract Start Date

🎯 CEM Requirement

1 May 2023 to 30 June 2024 (and passed recent annual review)

CEM not mandatory for next AR in 2026,

CEM mandatory for AR in 2027

1 July 2024 to 21 October 2025

CEM not mandatory for first AR

CEM mandatory for second AR onwards

After 22 October 2025

CEM mandatory for next AR in 2026

Last updated