
Cybersecurity Requirements M&E Vendors Must Meet for CII Projects
Mechanical & Electrical (M&E) vendors supporting Singapore Government projects increasingly operate at the intersection
In Singapore, SSAT (System Security Acceptance Test) and SSCT (System Security Compliance Test) are mandatory gatekeeper assessments for IT/OT vendors serving Government Agencies and Critical Information Infrastructure (CII). These independent audits validate cybersecurity compliance before any system is approved for deployment.
Key Assessment Charateristics
Environment: Typically applied to on-premise, restricted, or air-gapped networks.
Process: Documentation-heavy audits covering hardening, host configurations, vulnerability assessments (VA), and penetration testing.
Independent Oversight: Must be conducted by a certified third-party assessor.
For Mechanical & Electrical (M&E) vendors—particularly those handling CCTV or Building Management Systems (BMS)—the primary focus is network architecture. Because these systems bridge the gap between OT and IT, they are viewed as high-risk entry points. Consequently, stringent security controls in these areas are often the leading cause of delays in project commissioning.
In our experience supporting government contractors, we found that vendors are often caught off-guard by the cybersecurity requirements. Failing to factor these in early can turn a profitable project into a financial liability.
Common Reasons for the Oversight:
Information Gaps: Cybersecurity requirements are rarely in the main scope; they are often buried in Annexes or Appendixes. Main contractors sometimes overlook sending these specific cybersecurity Annexes to their M&E subcontractors.
The “Someone Else’s Job” Assumption: Many vendors assume the Main Contractor handles all compliance, only to realize their specific scope (CCTV, BMS, etc.) carries its own independent obligations.
Underestimation of Scope: Vendors may assume requirements are small enough to handle internally, only to discover later that the audit and documentation are far more demanding than expected.
Failing to cater for cybersecurity requirements risks:
g
From secure network design to CIS hardening, we help ensure your infrastructure is audit-ready and aligned with government cybersecurity requirements

With a strong track record in SG Gov projects, we understand agency expectations and proactively resolve issues before they become blockers

Singapore regulated entity, vetted and verified by CSA. Licensed since June 2022 - Licence No CS/PTS/C-2022-0123R

Our team is based locally and meets the stringent clearance requirements to handle restricted government project data and on-site assessments

With > 20 years of experience in network and infra, we provide expertise in network design, the phase you have to sign off before audit can begin

No account managers or middle-men. You speak directly with the expert
System Security Compliance Test (SSCT) and System Security Acceptance Test (SSAT) are audit processes required by Singapore Government agencies to verify that a vendor’s IT system (on premise) meets the respective Government agency’s cybersecurity requirements. This verification must be completed and documented before a system can connect to government networks.
SSCT/SSAT is required whenever a vendor delivers on-premise system within Government Network. This is especially true if the agency is DSTA or if the project is managed by DSTA. Without passing SSCT, vendor will not be allowed to connect to the network.
A standard System Security Compliance Test (SSCT) involves a three-stage process: Pre-test Planning (Network architecture, SCCT Plan submission), System Hardening (aligned with CIS or OEM guidelines), and Technical Verification (Host Configuration Review and VA). The process concludes with a formal report in the specific format required for project sign-off.
Because these audits typically require all non-compliance issues to be remediated, Perennial also provides expert assistance in drafting technical justifications for Waivers or Mitigations when full compliance is not feasible due to legacy or operational constraints.”
Yes. For Singapore Government projects overseen by agencies like GovTech or DSTA, the System Security Compliance Test (SSCT) must be conducted by an independent third-party cybersecurity firm. This ensures an unbiased, professional verification of your security controls. Without an independent third-party audit report, the system cannot meet the mandatory security clearance required for final project sign-off and the release of project payments.
To prevent project delays, vendors should integrate cybersecurity planning as early as the Presales/Tendering stage. Perennial Consultancy offers zero-cost presales consultation to help you assess the audit scope, design a compliant network architecture, and factor the necessary cybersecurity effort into your project bid.

Mechanical & Electrical (M&E) vendors supporting Singapore Government projects increasingly operate at the intersection

Let’s face it — system hardening isn’t glamorous.It’s not as exciting as catching a

When former U.S. President Donald Trump’s arrival at the United Nations was delayed by