# CEM Guide for Vendors

### 🔍 What is the Cyber Essentials Mark (CEM)?

\
The Cyber Essentials Mark (CEM) is a cybersecurity certification developed by the **Cyber Security Agency of Singapore (CSA)** to recognise organisations that have implemented fundamental "cyber hygiene" practices to protect themselves and their customers from common cyber-attacks.

*As part of the Annual Review, moving forward ICM vendors will be required to attain the Cyber Essentials Mark. Please note, IMDA may suspend or terminate the appointment contract if the Pre Approved Vendor fails to meet any of the Annual Review Criteria's.*

### 📋 Types of CEM Required

***

#### 🏭 **CEM for ICT Vendor**

**Required for:** Vendors with their own product or have ability to modify product source code to form your own product

**Examples:** Odoo, E-commerce platforms, product principals

***

#### 🛒 **Standard CEM**

**Required for:** Vendors that resell third-party products and do not modify source code of products, as well as vendors providing 100% professional services

**Examples:** Xero resellers, QuickBooks resellers, HRMS resellers, Digital Marketing services, HRSS Services

***

### 💰 Certification Details

| Detail                      | Information                                                                                                                                                                                               |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 💵 **Cost**                 | $500 to $2,000 (could be higher depending on organisation size, system complexity, and certification body pricing)                                                                                        |
| ⏰ **Validity**              | Two years, requires revalidation upon expiry                                                                                                                                                              |
| 🏢 **Certification Bodies** | Find CSA-appointed certification bodies [here](https://www.csa.gov.sg/our-programmes/support-for-enterprises/sg-cyber-safe-programme/cybersecurity-certification-for-organisations/how-to-get-certified/) |

***

### 📋 Which CEM Should You Get?

| 🏷️ **Certification Type** | 👥 **Who Should Get This**                                                                                                            | 📝 **Description**                                                                                             | 🔧 **Coverage**                                                                                        |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |
| **🛡️ CEM**                | <p><strong>Non-Product Principals</strong>  </p><p>• Resellers  </p><p>• Service providers  • Professional services</p>               | Updated version of CEM covering comprehensive cybersecurity areas  *(Must have Classical Cybersecurity scope)* | <p>• Classical Cybersecurity ✅ </p><p> • Operational Technology (OT) Security</p><p> • AI Security</p> |
| **🏭 CEM for ICT Vendor**  | <p><strong>Product Principals</strong> </p><p>• Own product developers </p><p> • Source code modifiers  </p><p>• Product creators</p> | Enhanced version of CEM with added requirements specifically for ICT Solution Vendors                          | <p>• All CEM coverage  • Additional ICT vendor requirements  </p><p>• Enhanced security controls</p>   |

***

### 📅 CEM Requirements by Appointment Contract Period

*For **1st April 2026 and 1st July 2026** Annual Review, CEM is not required. For all other AR, please refer to the table below:*

| 📋 **Appointment Contract Start Date**                             | 🎯 **CEM Requirement**                                                                                              |
| ------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------- |
| **1 May 2023 to 30 June 2024** *(and passed recent annual review)* | <p>CEM <strong>not mandatory</strong> for next AR in 2026, </p><p>CEM <strong>mandatory</strong> for AR in 2027</p> |
| **1 July 2024 to 21 October 2025**                                 | <p>CEM <strong>not mandatory</strong> for first AR </p><p>CEM <strong>mandatory</strong> for second AR onwards</p>  |
| **After 22 October 2025**                                          | CEM **mandatory** for next AR in 2026                                                                               |
