HomeFrameworksNational Cyber & Cloud SchemesMTCS

Framework  National Cyber & Cloud Schemes

MTCS

The Multi-Tier Cloud Security standard, Singapore Standard SS 584, is a cloud security certification standard developed under the Information Technology Standards Committee with support from the Infocomm Media Development Authority (IMDA) and Enterprise Singapore. The current edition is SS 584:2020.

It defines three levels: Level 1 for non-business-critical data and systems, Level 2 for most business-critical workloads, and Level 3 for regulated organizations with specific requirements and higher-impact systems. The controls build on ISO/IEC 27001 and 27017 and add cloud-specific requirements on tenancy, data governance, and resilience that rise with each level.

Singapore government agencies require MTCS certification at the appropriate level for cloud services they procure, and the Monetary Authority of Singapore and other regulated sectors reference it.

Certification follows the management system pattern: a certification body accredited by the Singapore Accreditation Council audits the provider, issues a certificate stating the level and scope, and performs annual surveillance with recertification every three years.

In writing, a provider needs an ISO/IEC 27001-style management system, a control matrix against the SS 584 requirements for the target level, a self-disclosure form describing the service (a required, published part of the scheme), data governance and residency documentation, tenant isolation evidence, incident and continuity procedures, and audit records.

AI-compiled
Share
Sponsored
MTCS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with MTCS
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary in law, but required for cloud service providers participating in Singapore government tenders (at the level specified in the tender) and expected by many regulated financial institutions and healthcare organizations in Singapore. Providers may certify individual services at different levels.

What the assessor asks to see

Scope and level applied for; self-disclosure form; information security policy and management system documentation; risk assessment; control matrix against SS 584 requirements at the target level; tenant isolation and multi-tenancy controls; data governance, classification, retention, and residency records; identity and access management; cryptography and key management; logging and monitoring; vulnerability and change management; incident response and notification; business continuity and disaster recovery tests; supplier management; internal audit and management review; prior audit reports.

Levels

Level 1 covers basic security for non-business-critical data; Level 2 adds controls for business-critical workloads and is the common target for enterprise SaaS; Level 3 adds the strongest controls for regulated organizations and high-impact systems, including stricter data governance and resilience requirements.

Assessors

Who assesses MTCS

Certification bodies accredited by the Singapore Accreditation Council for the MTCS certification scheme (for example BSI, SOCOTEC Certification Singapore, and TÜV SÜD are among bodies offering it; verify current accreditation on the SAC site). Accredited by Singapore Accreditation Council (SAC), part of Enterprise Singapore.

Public register of assessors: https://www.imda.gov.sg/how-we-can-help/data-protection-and-cloud-security/multi-tier-cloud-security-standard

No firm has claimed a MTCS assessor listing yet. Claim yours →

Consultants

Who helps with MTCS

Singapore-based information security consultancies and the regional arms of global firms provide gap assessments and readiness; certification bodies offer pre-assessments separately. Readiness typically takes three to nine months for a provider that already holds ISO/IEC 27001.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a MTCS consultant listing yet. Claim yours →

Software

Tools for MTCS

Tools that name this framework in their own material.

No firm has claimed a MTCS tool listing yet. Claim yours →

Related reading

  1. Multi-Tier Cloud Security (MTCS) standard for SingaporeExplains the three tiers, what each is intended for, and the ISO 27001 prerequisite that Level 3 certification carries.Microsoft
  2. MTCS Tier 3 certificationShows what a Tier 3 certificate covers in practice and how the scope and surveillance audits are handled.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for MTCS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with MTCS

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.