Build trust.
Certify your readiness.

Choose your certification path with Infinite Cybersecurity. Consultancy is carried out by our appointed delivery partner, Evvo Labs Pte Ltd.

Illustrative portrait of a professional working on a laptop.
Expert guidance. A human approach.

The right certification
starts with your risk.

CSA offers two complementary marks. Choose according to your operating environment and risk profile, then build the evidence to support it.

Establish your foundation

Cyber Essentials Mark

Practical cyber hygiene for organisations building their security foundations, especially teams with limited in-house expertise.

  • Five core security categories
  • Guided self-assessment and independent review
  • Certification valid for two years
Explore Cyber EssentialsCSA scheme overview (opens in a new tab)

Match assurance to exposure

Cyber Trust Mark

A risk-based approach for organisations with more extensive digital operations and greater cybersecurity needs.

  • Five preparedness tiers matched to risk
  • Risk assessment and independent audit
  • Certification valid for three years, with annual surveillance audits
Explore Cyber TrustCSA scheme overview (opens in a new tab)

Certification scope, assessment and renewal arrangements are set by the relevant scheme. Cyber Essentials certification (opens in a new tab) Cyber Trust certification (opens in a new tab)

Make progress visible.

Infinite connects your business priorities to a clear engagement scope. Our appointed delivery partner, Evvo Labs, guides the controls, ownership and evidence needed for assessment.

A practical plan.
A clear owner.
Evidence that holds up.

Infinite coordinates the engagement with our appointed delivery partner, Evvo Labs. We agree the scope and responsibilities with your team and its technology partners.

01

Assess and select

Review business exposure, systems and stakeholder expectations. Identify the appropriate mark, scope and, for Cyber Trust, preparedness tier.

02

Close the gaps

Translate findings into prioritised actions. Guide policy, process and control improvements with clear ownership.

03

Prepare the evidence

Support assessment documentation, organise records and work through readiness questions before the independent review.

04

Keep it working

Agree a handover and review rhythm so your team can maintain controls and prepare for the next assessment.

Independent certification remains independent. Your CSA-appointed certification body assesses and decides certification. Our appointed delivery partner, Evvo Labs, supports your preparation; Infinite coordinates your engagement.

How certification works (opens in a new tab)
An updated view of security

Your technology
defines the scope.

The enhanced CSA schemes address cloud, AI and operational technology alongside classical cybersecurity. We help identify relevant systems, services and business boundaries before the assessment.

Explore the enhanced CSA scheme (opens in a new tab)
Business scopePeople · Processes · Evidence
Classical ITCloudAIOT

Map the environment. Agree the scope. Apply the relevant requirements.

Funding support

Expert guidance.
A more accessible start.

Up to70%

Co-funding for eligible SMEs using qualifying CISOaaS consultancy services.

Check CSA’s current programme (opens in a new tab)

Consultancy support

Eligible clients may obtain CSA co-funding through the CISOaaS programme. Eligibility, the selected package and prevailing programme terms determine the support available.

We help you clarify scope and identify the application route. Confirm approval requirements and your contribution before starting a funded engagement.

Certification-fee support is separate

CSA also publishes subsidies for Singapore-incorporated SMEs and non-profit organisations on their first successful certification. Apply through your selected certification body; the published support period runs to 6 February 2028.

Funding is conditional. Consultancy support and certification-fee support have different rules and must be checked separately.

View Cyber Trust certification support (opens in a new tab)

Make an informed start.

Clear roles, realistic expectations and official sources.

Who carries out the consultancy?

Our appointed delivery partner, Evvo Labs Pte Ltd, carries out Cyber Essentials Mark and Cyber Trust Mark consultancy. Evvo is listed in CSA’s CISOaaS provider directory for these services. Infinite Cybersecurity offers the engagement and remains your primary point of contact.

Who will manage my engagement?

Infinite Cybersecurity, a service of Infinite Value Ventures Pte Ltd, remains your primary point of contact. We help define your requirements, coordinate the engagement with Evvo Labs and translate findings into practical business priorities. Your proposal sets out the contracting entity, scope, deliverables and each party’s responsibilities.

Is Evvo Labs listed as a CISOaaS provider?

Our appointed delivery partner, Evvo Labs Pte Ltd, appears in CSA’s published CISOaaS directory for Cyber Essentials and Cyber Trust consultancy. You can verify the legal name in the relevant workbook sheets. CSA’s listing is not an endorsement or service guarantee.

Open CSA’s provider directory (XLSX) (opens in a new tab)
Can we receive a grant for consultancy?

Eligible SMEs may receive up to 70% co-funding for qualifying CISOaaS services. The selected package and current programme terms govern eligibility and the contribution required. CSA links applicants to the SMEs Go Digital platform.

Check eligibility and the application route (opens in a new tab)
Are certification-body fees included?

Do not assume they are. The consultancy proposal should identify what is included and what is separately payable. CSA’s certification-fee subsidies are a different form of support, applied for through the selected certification body.

Cyber Essentials fee support (opens in a new tab) Cyber Trust fee support (opens in a new tab)
How does Cyber Trust select the right tier?

The scheme uses a risk assessment to match the organisation’s profile to a preparedness tier: Supporter, Practitioner, Promoter, Performer or Advocate. The target should reflect your business risk and assurance needs.

Read CSA’s risk-based approach (opens in a new tab)
Does certification replace our other obligations?

Certification recognises security practices within its defined scope. Sector-specific, contractual and data-protection obligations may still require separate work. We discuss these dependencies when scoping the engagement.

Turn the requirements
into a workable plan.

Share your business context and assurance needs with Infinite. We’ll help you choose a path and coordinate the consultancy with our appointed delivery partner, Evvo Labs.

Discuss your requirements with Infinite

Go directly to the source.

Scheme information checked against CSA publications on . Requirements and funding terms may change.

CSA’s provider listing does not constitute endorsement of a provider or a guarantee of its services. Certification decisions are made by the appointed certification body.