Singapore CISOaaS VAPT Provider,
Secure Your Business with Up To 70% Grant Funding
A CSA-Supported Initiative to Uplift the Cybersecurity Posture of Singapore SMEs
VAPT for IMDA PSG Vendor Pre-Approval, DPTM, Cyber Trust Mark & Compliance Audits.
Fulfill your mandatory security audit or software pre-approval requirements with CREST-certified manual testing—fully supported under local SME funding.
CISOaaS (VAPT) Service
Who Qualifies?
- Registered & Operating in Singapore with a "live" status in ACRA
- Group Annual Sales not more than S$100M OR Group Employment Size not more than 200 employees
- Has Not previously applied or obtained any grants for similar project
Funding Levels
Funding is tiered based on number of End-points the Company has. The grant covers up to 70% of the costs, subject to a cap per endpoint tier. You only pay the remaining balance after grant.
*End-points include Company’s Laptops, desktops, servers, mobile devices, network equipments, Cloud instances etc
NCSS Members receive up to 80% co-funding
under Tech-and-Go! Scheme
*Now known as Transformation Sustainability Scheme
CREST Certified CISO as-a-Service
Vulnerability Assessment and Penetration Testing (VAPT)
CSRO Licence No: CS/PTS/C-202606-336

Vulnerability Assessment (VA)
Process of identifying and evaluating potential security weaknesses, enabling organisations to prioritise and remediate risks effectively.
- Network VA
- Web Application VA
- Mobile Application VA

Penetration Testing (PT)
Simulates real-world attacks to identify exploitable vulnerabilities, enabling organisations to strengthen their security.
- Network PT
- Web Application PT
- Mobile Application PT
How to Apply
Pre-Engagement
Submit Application
Await Notification
CSA will review the application and notify us of the outcome. We will then update you accordingly.
Begin Service
*You can apply for funding first and schedule the testing later when it fits your timeline
FAQ's
You only need to pay the net amount after grant.
You don’t have to fund the full 100% upfront or deal with the hassle of managing grant claims with CSA afterwards. Perennial handles the entire claim process directly with CSA.
All we need from you is to complete a short Cybersecurity Health Plan and submit a feedback form once the VAPT is completed to facilitate the final claim disbursement with CSA.
Your authorized company representative simply logs into the SMEs Go Digital portal via Corppass to submit the official declaration form (takes about 10–15 minutes, with no supporting documents required).
Based on your VAPT requirements and endpoint tier, Perennial will provide you with the exact application link
The CISOaaS scheme is a distinct CSA initiative designed to establish baseline cyber hygiene for local SMEs. As long as you are not claiming duplicate funding for the exact same scope of work under another grant, your business remains eligible.
The grant covers Vulnerability Assessment and Penetration Testing for:
Network VAPT
Web Applications VAPT
Mobile Applications VAPT
API and Wireless VAPT are not in the scope of the grant.
Grant approval typically takes 1 to 2 weeks from submission, and VAPT cannot commence until formal approval is received.
However, testing dates can be scheduled flexibly to align with your timeline. We strongly recommend submitting your grant application early to secure approval in advance and avoid last-minute scheduling bottlenecks.
If your application is not approved, you can choose not to proceed, or proceed without grant.
Performing a VAPT is a core technical requirement when applying for the Data Protection Trustmark (DPTM) certification or submitting your solution for PSG pre-approval vendor. The findings and remediation reports provided by Perennial serve as direct audit evidence required during assessment.
Our reports include a dedicated Attestation Section (with POCs, not just stating the test cases) detailing the areas that were tested and verified as secure. This provides auditors and stakeholders with a complete, auditable record of both identified vulnerabilities and confirmed security controls.

