Cyber Essentials.
A stronger start.

Build your cybersecurity foundations with Infinite Cybersecurity. Cyber Essentials Mark consultancy is carried out by our appointed delivery partner, Evvo Labs Pte Ltd.

Illustrative portrait of a professional working on a laptop.
Expert guidance. A human approach.

Good cyber hygiene.
Stronger business confidence.

Cyber Essentials is CSA’s baseline certification for organisations building their cybersecurity foundations, particularly those with limited in-house resources. It recognises practical safeguards against common cyber threats.

About the CSA Cyber Essentials Mark (opens in a new tab)
5 categories
A structured foundation for everyday cyber hygiene.
2-year validity
Certification follows independent assessment.
Your operating environment
Define the scope around your business, systems and technology use.

Five categories.
One practical foundation.

Our appointed delivery partner, Evvo Labs, translates the standard into work your team can own. Explore how its consultancy turns requirements into day-to-day practice.

A black notebook surrounded by soft green and lavender geometric forms.
Five categories. A connected foundation.
01AssetsKnow your people, systems and data.

Evvo helps organise hardware, software and data inventories, identify accountable owners, and plan relevant employee awareness activities.

02Secure/ProtectPut the right safeguards in place.

Evvo reviews access, protective software and configuration practices, then agrees a prioritised remediation plan with your IT team.

03UpdateMake patching a repeatable practice.

Evvo helps define responsibility for software updates, track unsupported systems, and assemble evidence that patching is managed.

04BackupMake recovery part of normal operations.

Evvo works with your team to document backup arrangements, access and recovery checks, and record gaps that need attention.

05RespondGive your team a clear response plan.

Evvo helps map incident contacts, escalation steps and recovery responsibilities, then walks through a realistic response scenario.

Category names follow CSA’s 2025 standard; the activities above describe consultancy delivered by our appointed partner, Evvo Labs. Read the official requirements (PDF) (opens in a new tab)

Built around the way
your business works.

Cloud services, AI tools and operational technology change the questions you need to ask. Infinite helps define the business requirements, and Evvo reviews your environment before we agree the engagement scope.

Classical IT

Devices, accounts, software and business data.

Cloud

Business applications, access and shared responsibilities.

Artificial intelligence

Approved tools, data handling and staff awareness.

Operational technology

Connected operational systems and their business context.

The enhanced scheme includes classical, cloud, AI and OT security. Applicable requirements depend on the certification scope. Check the current scheme and variants (opens in a new tab)

From the first review
to assessment readiness.

Infinite coordinates your engagement, while our appointed delivery partner, Evvo Labs, carries out the consultancy. We agree deliverables and responsibilities before work begins.

  1. 01

    Understand

    Review your environment, existing controls and certification goals.

    Your outputScope & gap assessment
  2. 02

    Improve

    Prioritise gaps and guide your team through control and policy improvements.

    Your outputPractical remediation plan
  3. 03

    Prepare

    Organise evidence, support self-assessment and resolve readiness questions.

    Your outputAssessment evidence pack
  4. 04

    Independent assessment

    Your selected CSA-appointed certification body assesses the application and decides certification.

    Separate engagementCertification decision

Our appointed delivery partner, Evvo Labs, provides consultancy. Infinite coordinates your engagement, and your certification body provides independent assessment. See CSA’s certification process (opens in a new tab)

Funding support

Expert guidance.
A more accessible start.

Up to70%

Co-funding for eligible SMEs using qualifying CISOaaS consultancy services.

Check CSA’s current programme (opens in a new tab)

Consultancy support

Eligible clients may obtain CSA co-funding through the CISOaaS programme. Eligibility, the selected package and prevailing programme terms determine the support available.

We help you clarify scope and identify the application route. Confirm approval requirements and your contribution before starting a funded engagement.

Certification-fee support is separate

CSA also publishes subsidies for Singapore-incorporated SMEs and non-profit organisations on their first successful certification. Apply through your selected certification body; the published support period runs to 6 February 2028.

Funding is conditional. Consultancy support and certification-fee support have different rules and must be checked separately.

View Cyber Essentials certification support (opens in a new tab)

Before you begin.

Answers to the questions that shape a useful first conversation.

Who carries out the consultancy?

Our appointed delivery partner, Evvo Labs Pte Ltd, carries out Cyber Essentials Mark and Cyber Trust Mark consultancy. Evvo is listed in CSA’s CISOaaS provider directory for these services. Infinite Cybersecurity offers the engagement and remains your primary point of contact.

Verify Evvo in the provider directory (XLSX) (opens in a new tab)
Who will manage my engagement?

Infinite Cybersecurity, a service of Infinite Value Ventures Pte Ltd, remains your primary point of contact. We help define your requirements, coordinate the engagement with Evvo Labs and translate findings into practical business priorities. Your proposal sets out the contracting entity, scope, deliverables and each party’s responsibilities.

How long does it take, and what will it cost?

The scope, number of endpoints, current gaps and speed of remediation determine the work involved. We scope the engagement before quoting. Your certification body sets its own assessment fees and schedule; these are separate from consultancy.

What should we prepare for a first discussion?

Bring an overview of your company, approximate device and user counts, key applications, cloud and AI usage, existing security measures and any customer deadline. We will use these to focus the readiness review.

Is certification or grant approval guaranteed?

No. Certification depends on meeting the scheme’s requirements and the independent assessment. Funding depends on eligibility, approved scope and current terms. We support preparation and explain the process without promising either outcome.

Does the standard cover healthcare or ICT vendors?

CSA publishes additional variants for ICT vendors, Health Information Act entities and Health Information Management System vendors. Tell us if these apply so the correct scheme and provider eligibility can be checked.

Review CSA’s scheme variants (opens in a new tab)
Should we choose Cyber Essentials or Cyber Trust?

Cyber Essentials builds a baseline. Cyber Trust uses a risk-based approach for organisations with more extensive digital operations. We help you assess fit against business exposure and stakeholder expectations.

Compare the two certification paths

Start with where
your business is today.

Tell Infinite about your systems, priorities and certification goals. We’ll define the next step and coordinate delivery with our appointed partner, Evvo Labs.

Discuss your requirements with Infinite

Go directly to the source.

Scheme information checked against CSA publications on . Requirements and funding terms may change.

CSA’s provider listing does not constitute endorsement of a provider or a guarantee of its services. Certification decisions are made by the appointed certification body.