Frequently Asked Questions
CLS offers a basic level of security assurance to improve device cybersecurity hygiene by implementing basic safeguards and eradicating common mistakes and vulnerabilities.
CLS labelling does not preclude the device from being hacked given the dynamism of the cybersecurity threat landscape. However, manufacturers applying for CLS are required to have an open vulnerability report and management channel, and for them to update their software in a timely manner.
Users seeking higher security assurance for industrial use (e.g. enterprise, manufacturing, industrial, healthcare usage) are strongly recommended to consider devices certified under formal evaluation and certification schemes such as the Singapore Common Criteria Scheme.
The two schemes cater to a disparate range of products.
The Common Criteria is based on an international standard (ISO/IEC 15408) for the security evaluation of IT products and is commonly used to provide moderate to high-security assurance typically expected of enterprise IT products.
On the other hand, the Cybersecurity Labelling Scheme is a basic cybersecurity hygiene scheme for consumer smart devices. It takes reference from an international standard (ETSI EN 303 645) which provides a set of baseline security and data protection provisions that are applicable to consumer IoT products connected to network infrastructure (such as Internet or home network) and aims to provide basic security assurance.