Welcome to Perennial Consultancy

Singapore CISOaaS VAPT Provider,
Secure Your Business with Up To 70% Grant Funding

A CSA-Supported Initiative to Uplift the Cybersecurity Posture of Singapore SMEs

VAPT for IMDA PSG Vendor Pre-Approval, DPTM, Cyber Trust Mark &  Compliance Audits.

Fulfill your mandatory security audit or software pre-approval requirements with CREST-certified manual testing—fully supported under local SME funding. 

CISOaaS (VAPT) Service

CTM Promoter

Who Qualifies?

Funding Levels

Funding is tiered based on number of End-points the Company has. The grant covers up to 70% of the costs, subject to a cap per endpoint tier. You only pay the remaining balance after grant.

*End-points include Company’s Laptops, desktops, servers, mobile devices, network equipments, Cloud instances etc

NCSS Members receive up to 80% co-funding
under Tech-and-Go! Scheme

*Now known as Transformation Sustainability Scheme

CREST Certified CISO as-a-Service

Vulnerability Assessment and Penetration Testing (VAPT)
CSRO Licence No: CS/PTS/C-202606-336

Vulnerability Assessment (VA)

Process of identifying and evaluating potential security weaknesses, enabling organisations to prioritise and remediate risks effectively.
- Network VA
- Web Application VA
- Mobile Application VA

Penetration Testing (PT)

Simulates real-world attacks to identify exploitable vulnerabilities, enabling organisations to strengthen their security.
- Network PT
- Web Application PT
- Mobile Application PT

How to Apply

Pre-Engagement

Arrange a mandatory briefing with us to verify your eligibility and the right VAPT service before application.

Submit Application

Login with Corppass at IMDA's CTOaaS Portal, ensure the package stated is correct. Submit the Declaration Form.

Await Notification

CSA will review the application and notify us of the outcome. We will then update you accordingly.

Begin Service

Once notification is received, you are cleared to proceed. The VAPT service engagement officially begins*.

*You can apply for funding first and schedule the testing later when it fits your timeline

FAQ's

You only need to pay the net amount after grant.

You don’t have to fund the full 100% upfront or deal with the hassle of managing grant claims with CSA afterwards. Perennial handles the entire claim process directly with CSA.

All we need from you is to complete a short Cybersecurity Health Plan and submit a feedback form once the VAPT is completed to facilitate the final claim disbursement with CSA.

Your authorized company representative simply logs into the SMEs Go Digital portal via Corppass to submit the official declaration form (takes about 10–15 minutes, with no supporting documents required).

Based on your VAPT requirements and endpoint tier, Perennial will provide you with the exact application link

The CISOaaS scheme is a distinct CSA initiative designed to establish baseline cyber hygiene for local SMEs. As long as you are not claiming duplicate funding for the exact same scope of work under another grant, your business remains eligible.

The grant covers Vulnerability Assessment and Penetration Testing for:

  • Network VAPT

  • Web Applications VAPT

  • Mobile Applications VAPT

API and Wireless VAPT are not in the scope of the grant.

Grant approval typically takes 1 to 2 weeks from submission, and VAPT cannot commence until formal approval is received.

However, testing dates can be scheduled flexibly to align with your timeline. We strongly recommend submitting your grant application early to secure approval in advance and avoid last-minute scheduling bottlenecks.

If your application is not approved, you can choose not to proceed, or proceed without grant.

Performing a VAPT is a core technical requirement when applying for the Data Protection Trustmark (DPTM) certification or submitting your solution for PSG pre-approval vendor. The findings and remediation reports provided by Perennial serve as direct audit evidence required during assessment.

Our reports include a dedicated Attestation Section (with POCs, not just stating the test cases) detailing the areas that were tested and verified as secure. This provides auditors and stakeholders with a complete, auditable record of both identified vulnerabilities and confirmed security controls.

 

Let's Start the Conversation

You can also drop us an email at [email protected]