{
  "node_id": "sg-imda-mtcs-multi-tier-cloud-security-standard-ss-584",
  "title": "Singapore IMDA Multi-Tier Cloud Security Standard (MTCS, SS 584:2020)",
  "domain": "Cloud & SaaS",
  "version": "1.0.0",
  "last_updated": "2026-06-08",
  "bluf": "The Multi-Tier Cloud Security Standard (MTCS, SS 584) is Singapore's national cloud security standard administered by the Infocomm Media Development Authority (IMDA) under the Singapore Standards Council. The current revision SS 584:2020 succeeds prior editions SS 584:2013 and SS 584:2015 and is the operative reference for the Singapore government Cloud-First procurement strategy, the Monetary Authority of Singapore (MAS) Technology Risk Management Guidelines, and most financial-institution cloud adoption decisions. MTCS classifies cloud service offerings into three security assurance tiers reflecting increasing rigour of controls and audit evidence: Level 1 (baseline information security for non-business-critical or low-impact workloads), Level 2 (heightened controls for business or regulatory sensitive workloads typical of mainstream enterprise consumption), and Level 3 (highest assurance with comprehensive control coverage typical of regulated industry, government, and large financial institution workloads). MTCS certification is issued by independent certification bodies accredited by the Singapore Accreditation Council (SAC) under the framework of ISO/IEC 17021 management systems certification accreditation. The MTCS framework is comprehensive across information security governance, infrastructure security, software and application security, data governance, business continuity, change management, identity and access management, supplier management, and cloud-specific resilience including multi-tenancy isolation, virtualisation security, and elastic capacity management. MTCS is mandatory or strongly preferred for Singapore Government Commercial Cloud (GCC) procurement decisions and underpins the MAS Outsourcing Guidelines third-party cloud provider assessment. MTCS-certified providers include AWS, Microsoft Azure, Google Cloud, Alibaba Cloud, Oracle Cloud Infrastructure, IBM Cloud, and several regional CSPs. The standard intersects ASEAN Cloud Computing Initiative discussions and serves as a frequently-referenced model for emerging-market national cloud assurance frameworks.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "iso-iec-42001-2023-ai-management-system",
    "iso-iec-23894-ai-risk-management-2023",
    "nist-sp-800-53-r5",
    "fips-203-ml-kem-standard",
    "us-cisa-secure-by-design-principles-2023"
  ],
  "primary_citations_count": 10
}