Singapore’s Digital Infrastructure Bill introduces licensing requirements

September 10, 2026 at 2:46 PM GMT+8

Singapore’s Digital Infrastructure Bill which was tabled in Parliament for First Reading recently, sets out two new licensing regimes to strengthen the security and resilience of major cloud services and data centers; and to ensure the environmental sustainability of data center operations.

To be administered by the Infocomm Media Development Authority (IMDA), the proposed law mandates licensing for: (i) major co-location and cloud DCs with a critical IT load of at least 10 megawatts (MW), and (ii) major Cloud Service Providers whose Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) services generate at least S$100 million (US$79 million) in average annual revenue from users in Singapore over the three preceding years.

The Bill covers a broad range of operational resilience risks – such as technical failures, power or cooling issues, fires and other physical or operational incidents, for which licensees will have to implement security risk management measures, business continuity and disaster recovery plans, as well as report specified incidents and disruptions to IMDA.

It complements the Cybersecurity Act, which sets out narrower cybersecurity requirements for major digital infrastructure. At the implementation stage, the requirements under both the Bill and the Cybersecurity Act will be streamlined.

The second set of licensing regime requires all operators of data centers, both new and existing, with a critical IT load of at least 3MW to be licensed. They will be required to meet facility-level energy-efficiency requirements, including Power Usage Effectiveness (PUE), and later, IT equipment and water efficiency, where necessary, following consultation with industry.

The Bill also provides a basis for strategic, economic, and green energy commitments made – in exchange for being awarded new DC capacity through exercises such as the Data Centre – Call for Application (DC-CFA) – to be enforced as license conditions. This ensures that material commitments made in securing scarce capacity are accountable.

When implementing the proposed law, MDDI (Ministry of Digital Development and Information) and IMDA will streamline licensing and reporting processes to minimise regulatory burden, as  well as provide sufficient transition time for existing DCs to meet the requirements.

“The Bill will give our businesses, organisations, and citizens assurance that the infrastructure they depend on is secure and resilient — and give businesses the clarity and predictability they need to invest in Singapore’s digital infrastructure for the long term. It will also ensure that our DC sector continues to grow in a sustainable manner and makes the best use of our scarce national resources,” the release states.

The Bill has been developed in collaboration with industry stakeholders, including major DC operators, Cloud Service Providers, industry associations and enterprise users. The Bill will be tabled for a Second Reading at the next available Parliament sitting.

Singapore which now has more than 1.6 gigawatts of data center (DC) capacity, has implemented several data center-related guidelines previously including Advisory Guidelines for Resilience and Security of Cloud Services and DCs, Green DC Roadmap, the refreshed BCA-IMDA Green Mark certification for DCs, and standards covering IT energy efficiency, liquid cooling and tropical data centers.