Free · No email required · 3 minutes

Do you need CSA Cyber Essentials — and how ready are you?

Answer about 15 plain-English questions about your business and how you run your IT — a few more if you put Cloud, OT or AI Security in scope. You’ll see straight away whether certification is expected of you, how you score against the areas CSA actually assesses, what to fix first, and how much CSA funding you may qualify for. Nothing is sent anywhere — the result appears on this page.

Instant on-screen result Scored against all 9 CSA domains + pillars Funding estimate included
Step 1 of 3

About your organisation

This sets your scope and works out what CSA funding support you may be entitled to.

Where is your business incorporated? CSA funding support is limited to organisations incorporated in Singapore.
How many people work in your organisation?
Roughly how many endpoints do you have? Laptops, desktops, servers and mobile devices used for work. This band determines your funding amount.
Who looks after your IT today?
How digitalised is your business?
Which areas would you want in scope? Since the 2025 enhancement you only certify the pillars relevant to your business. Choose all that apply — Classical Cybersecurity applies to nearly everyone. Each extra pillar you choose adds a few more questions in step 3.
Not sure which of these apply to you? Here’s each one in plain English

Classical Cybersecurity is your everyday IT — laptops, phones, servers, your network, email and the people using them. This applies to every organisation, so it is always in scope.

Cloud Security covers anything your business runs on someone else’s servers instead of your own: Microsoft 365, Google Workspace, Azure, AWS, Xero, Dropbox and any other subscription software. Nearly every business has some.

OT Security covers operational technology — the computers and controllers that run physical equipment rather than information. If your business has machinery, a production line, refrigeration or cold rooms, a building management system, lifts, warehouse automation, or door access and CCTV systems, the controllers behind them are OT. It is assessed separately because when IT fails you lose data or time, but when OT fails something physical stops, or becomes unsafe — and OT often runs older software that cannot simply be patched or restarted, and is frequently reached remotely by the equipment vendor.
If you are a typical office business — an agency, a law firm, an accountancy, a consultancy, a software company — you almost certainly have no OT, and should leave this unticked.

AI Security covers any AI tool your team uses for work: ChatGPT, Claude, Microsoft Copilot, Gemini, and the AI features now built into software you already pay for. If anyone on your team pastes work into an AI tool, this applies to you — whether or not it was ever formally approved.

Your answers stay in your browser. Nothing is submitted and no email is required.

Good to know

About this self-assessment

Is this the official CSA assessment?

No — and it’s important to be clear about that. This is a free readiness indicator we built to help you understand where you stand before you commit to anything. The official Cyber Essentials assessment is a formal self-assessment certified by a CSA-appointed certification body, and it requires documented evidence for every requirement. Think of this page as the honest conversation before that process starts.

How accurate is the readiness score?

It’s a good directional indicator, based on your own answers about the nine core domains CSA assesses, plus the extra questions for any Cloud, OT or AI pillar you put in scope. A formal gap assessment goes considerably deeper, because an assessor works from evidence rather than self-reported answers — which is why businesses that score well here can still find gaps. Treat the score as a starting point, not a verdict.

What happens to my answers?

Nothing leaves your browser. The assessment is calculated entirely on your own device, we don’t ask for an email address, and no answers are stored or sent to us. If you want us to see your result, use the “Email me this result” link — that opens your own mail app with a summary you can review and send.

Why does “not sure” count against me?

Because certification runs on evidence. If you can’t confirm today whether MFA is enforced everywhere or whether a backup has ever been restore-tested, an assessor won’t be able to either. “Not sure” is treated as a gap until it’s verified and documented — and verifying it is usually quick.

How is the funding figure worked out?

From CSA’s published funding bands, using your endpoint count and the number of pillars you want in scope. Funding applies to the first successful Cyber Essentials certification per organisation, for SMEs and non-profits incorporated in Singapore, and is deducted directly from your certification fee. It runs until 6 February 2028. Figures are subject to CSA’s terms and eligibility — we confirm your exact entitlement before you commit to anything.

My score was low. Is that bad news?

Not really. A low score means the basics aren’t in place yet, which is a very ordinary starting point for a growing SME — and it’s the same work that cuts your day-to-day risk, certification aside. None of the assessed areas requires exotic technology. It requires someone to work through them in order, which is exactly what we do.

What is OT Security, and does my business have any?

OT stands for operational technology — the computers and controllers that run physical equipment, rather than the IT that handles information. Your IT is email, files, laptops and databases. Your OT is the controller inside a production line, a chiller or cold room, a lift, a conveyor, a CNC machine, or a building management, CCTV and door-access system.

In practice it applies to manufacturers, food and beverage producers, logistics and warehousing, marine and offshore, facilities managers and utilities. If you run a typical office business — an agency, a law firm, an accountancy, a consultancy, a software company — you have no OT, and you should leave that pillar unticked.

CSA assesses it separately for good reason. When IT fails you lose data or time; when OT fails, something physical stops or becomes unsafe. OT also tends to run older software that cannot simply be patched or rebooted while the line is running, and it is often reached remotely by the equipment vendor — a route into the business most owners have never thought about. It used to sit isolated from the internet, and increasingly it does not, which is why it became a pillar in 2025.

We’re bigger than an SME. Should we look at Cyber Trust?

Possibly. Cyber Trust is the risk-based mark for larger and more digitalised organisations, with broader requirements. If your answers suggest it, we’ll flag it in your result. Most organisations still start with Cyber Essentials, and there’s no harm in doing so — but we’ll tell you honestly which one fits.

Want the full picture first? Read our guide to CSA Cyber Essentials — what it is, the nine domains, funding and how certification works.

Rather just talk it through?

Skip the questionnaire and speak to someone who does this every week. We’ll tell you in one call whether you need the mark, what it takes, and what it costs after funding.