Ref: CISOaaS · Cyber Security Agency of Singapore (CSA) · reviewed 05 Jul 2026
CISO-as-a-Service (Cybersecurity Health Plan)
CSA pays up to 70% of the cost of hiring an approved cybersecurity consultant who audits your business, writes a tailored cybersecurity health plan, and helps you fix the gaps. It is the standard route to getting Cyber Essentials certified without hiring your own security staff.
Not published; co-funding applies to consultancy engagement with CSA-appointed providers
Who qualifies
- ✓SMEs with little or no in-house cybersecurity expertise
- ✓Businesses wanting the Cyber Essentials or Cyber Trust mark
- ✓Companies handling customer data that need to show baseline cyber hygiene
- ✓Firms that have had a scare (phishing, ransomware attempt) and want a proper plan
What it pays for
- Cyber health check-up against CSA's Cyber Essentials / Cyber Trust marks
- A tailored cybersecurity health plan
- Help closing the cyber hygiene gaps identified
- Related services offered by providers (vulnerability assessment, incident response support)
How to apply
Rolling applications; engagement typically runs a few months through assessment and remediation
- 1Pick a CSA-onboarded CISOaaS provider from the list on the CSA page
- 2Register interest via the SMEs Go Digital platform or contact the provider directly
- 3Provider runs the cyber health check and agrees scope with you
- 4Sign up with the provider; the 70% co-funding is applied to the engagement
- 5Work through the health plan towards Cyber Essentials certification
Advisor's note
The 70% covers the consultant, not your new security tools; budget separately for the fixes the health plan will tell you to buy (some are PSG-supportable). Page verified live and updated 30 Jun 2026.
Planning a digitalisation or overseas-expansion project? Those usually run under EDG or MRA, which our team delivers end to end.
Common questions
How much does the CISOaaS cover?
Up to 70% co-funding, not published; co-funding applies to consultancy engagement with CSA-appointed providers. CSA pays up to 70% of the cost of hiring an approved cybersecurity consultant who audits your business, writes a tailored cybersecurity health plan, and helps you fix the gaps. It is the standard route to getting Cyber Essentials certified without hiring your own security staff.
Who is eligible for the CISOaaS?
SMEs with little or no in-house cybersecurity expertise Businesses wanting the Cyber Essentials or Cyber Trust mark Companies handling customer data that need to show baseline cyber hygiene Firms that have had a scare (phishing, ransomware attempt) and want a proper plan
What does the CISOaaS pay for?
Cyber health check-up against CSA's Cyber Essentials / Cyber Trust marks A tailored cybersecurity health plan Help closing the cyber hygiene gaps identified Related services offered by providers (vulnerability assessment, incident response support)
How do I apply for the CISOaaS?
1. Pick a CSA-onboarded CISOaaS provider from the list on the CSA page 2. Register interest via the SMEs Go Digital platform or contact the provider directly 3. Provider runs the cyber health check and agrees scope with you 4. Sign up with the provider; the 70% co-funding is applied to the engagement 5. Work through the health plan towards Cyber Essentials certification
How long does the CISOaaS take?
Rolling applications; engagement typically runs a few months through assessment and remediation
Find out what the CISOaaS will co-fund for you.
15 minutes on WhatsApp. We check your eligibility, the realistic support amount, and whether a different grant fits better. No fee, no obligation.
WhatsApp us nowOften claimed together
PSG · Enterprise Singapore (via GoBusiness)
Productivity Solutions Grant
Co-funds up to 50% of PRE-APPROVED software and equipment: ERP, accounting, HR, inventory, e-commerce, and sector-specific solutions. The fastest grant to claim because the solutions are pre-vetted.
ADS · IMDA
Advanced Digital Solutions
Co-funds up to 50% of advanced, integrated digital solutions (AI, robotics, integrated B2B platforms) that go beyond single-purpose PSG software.
GenAI for SMEs · IMDA (SMEs Go Digital)
GenAI for SMEs (GenAI Navigator + pre-approved GenAI solutions)
IMDA's current GenAI offering for SMEs: a free GenAI Navigator tool that matches you to the right solution, plus a catalogue of pre-approved GenAI solutions (chatbots, marketing content generation, office productivity, generative web design) with up to 50% grant support. This is what the earlier GenAI Sandbox trials have evolved into.
Go Digital Advisor · IMDA (SMEs Go Digital)
Go Digital Advisor & Digital Health Check (formerly CTO-as-a-Service)
Free self-serve advisory on the SMEs Go Digital portal: a 5-10 minute Digital Health Check scores how digitally ready you are for your sector, and the Go Digital Advisor matches your pain points to grant-supported solutions. It is the current form of what IMDA used to call CTO-as-a-Service.