Where we are with each framework. A framework is marked "Certified" only once the certificate or report has been issued.
PDPA (Singapore)
In effect
We handle personal data under the Personal Data Protection Act 2012. Our privacy policy is public.
- Pending
- Appointment of a named Data Protection Officer
CSA Cyber Essentials
In progress
Self-assessment against the Cyber Security Agency of Singapore's Cyber Essentials mark is under way.
- Pending before submission
- MFA enforced on all administrator accounts
- Staff security briefing
- Incident response tabletop exercise
- Endpoint protection confirmed on all staff devices
ISO/IEC 27001:2022
In progress
We are building our information security management system: scope, risk register, Statement of Applicability, policies and procedures.
- Pending
- Management review and formal approval of policies
- Three months of ISMS operation with records
- Stage 1 certification audit (target: early 2027)
IMDA InvoiceNow Solution Provider (IRSP)
Pending
Not yet accredited. Technical testing on the InvoiceNow network is complete and the application to IMDA is being finalised.
- Pending
- Submit application to IMDA
- IMDA assessment and live demonstration
SOC 2
Planned
On our roadmap after ISO/IEC 27001: Type I first, then Type II.
PDPC Data Protection Trustmark
Planned
Planned once our data protection programme and DPO are in place.
MUST software is built for the InvoiceNow (Peppol) network and IRAS requirements. An item marked "Pending" is not yet in place. It moves to "Certified" or "In effect" only once it has been granted.