Framework National Cyber & Cloud Schemes
MTCS
The Multi-Tier Cloud Security standard, Singapore Standard SS 584, is a cloud security certification standard developed under the Information Technology Standards Committee with support from the Infocomm Media Development Authority (IMDA) and Enterprise Singapore. The current edition is SS 584:2020.
It defines three levels: Level 1 for non-business-critical data and systems, Level 2 for most business-critical workloads, and Level 3 for regulated organizations with specific requirements and higher-impact systems. The controls build on ISO/IEC 27001 and 27017 and add cloud-specific requirements on tenancy, data governance, and resilience that rise with each level.
Singapore government agencies require MTCS certification at the appropriate level for cloud services they procure, and the Monetary Authority of Singapore and other regulated sectors reference it.
Certification follows the management system pattern: a certification body accredited by the Singapore Accreditation Council audits the provider, issues a certificate stating the level and scope, and performs annual surveillance with recertification every three years.
In writing, a provider needs an ISO/IEC 27001-style management system, a control matrix against the SS 584 requirements for the target level, a self-disclosure form describing the service (a required, published part of the scheme), data governance and residency documentation, tenant isolation evidence, incident and continuity procedures, and audit records.
help
Who has to comply
Voluntary in law, but required for cloud service providers participating in Singapore government tenders (at the level specified in the tender) and expected by many regulated financial institutions and healthcare organizations in Singapore. Providers may certify individual services at different levels.
What the assessor asks to see
Scope and level applied for; self-disclosure form; information security policy and management system documentation; risk assessment; control matrix against SS 584 requirements at the target level; tenant isolation and multi-tenancy controls; data governance, classification, retention, and residency records; identity and access management; cryptography and key management; logging and monitoring; vulnerability and change management; incident response and notification; business continuity and disaster recovery tests; supplier management; internal audit and management review; prior audit reports.
Levels
Level 1 covers basic security for non-business-critical data; Level 2 adds controls for business-critical workloads and is the common target for enterprise SaaS; Level 3 adds the strongest controls for regulated organizations and high-impact systems, including stricter data governance and resilience requirements.
Assessors
Who assesses MTCS
Certification bodies accredited by the Singapore Accreditation Council for the MTCS certification scheme (for example BSI, SOCOTEC Certification Singapore, and TÜV SÜD are among bodies offering it; verify current accreditation on the SAC site). Accredited by Singapore Accreditation Council (SAC), part of Enterprise Singapore.
Public register of assessors: https://www.imda.gov.sg/how-we-can-help/data-protection-and-cloud-security/multi-tier-cloud-security-standard
No firm has claimed a MTCS assessor listing yet. Claim yours →
Consultants
Who helps with MTCS
Singapore-based information security consultancies and the regional arms of global firms provide gap assessments and readiness; certification bodies offer pre-assessments separately. Readiness typically takes three to nine months for a provider that already holds ISO/IEC 27001.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a MTCS consultant listing yet. Claim yours →
Software
Tools for MTCS
Tools that name this framework in their own material.
No firm has claimed a MTCS tool listing yet. Claim yours →
Related reading
- Multi-Tier Cloud Security (MTCS) standard for SingaporeExplains the three tiers, what each is intended for, and the ISO 27001 prerequisite that Level 3 certification carries.Microsoft
- MTCS Tier 3 certificationShows what a Tier 3 certificate covers in practice and how the scope and surveillance audits are handled.Amazon Web Services
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for MTCS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with MTCS
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.