Singapore tables an MPA bill on port cybersecurity and autonomy

The Maritime and Port Authority of Singapore (Amendment) Bill, Bill No. 24/2026, was introduced for First Reading in Parliament on Tuesday, 6 October. MPA’s same-day media statement is the working primary. Singapore Statutes Online published the Bill the same date. Digital Ship’s 8 October write-through is the industry read of that package. Parliament is scheduled to debate the Bill at Second Reading in November 2026. The Act would come into operation on a date the Minister appoints by notification in the Gazette. It is not in force. It is not a rewrite of the Cybersecurity Act 2018, not a worldwide MASS code, and not a port-entry ban.

MPA said the 1996 Act has not kept pace with digitalisation, remote operations, autonomous vessels and more complex port activity. The Bill is written to let the Authority intervene to keep the Port of Singapore safe, reliable and efficient. For a DPA, a ship manager with a Singapore agency, or a terminal operator on MPA systems, the useful facts are the new Part 13B cybersecurity duties, the maritime-entity test, the extraterritorial reach, and the fact that incident clocks and technical standards are still to be prescribed. Do not brief Tuesday as a completed cyber standard.

What the Bill actually puts on MPA’s books

Section 7 of the MPA Act would gain a new function: to oversee and promote the cybersecurity of computers and computer systems in the maritime sector in Singapore and to regulate persons who own or operate them. A new Part 13B would sit in front of Part 14. “Computer system” is defined to include virtual systems and operational technology — industrial control systems, programmable logic controllers, SCADA and distributed control systems — not only office IT. “Operate” means effective control, including the right to change the system or to perform security configuration. Mere use is not operation.

MPA could designate a computer or computer system as Important Information Infrastructure if it is owned or operated by a maritime entity, or if it is a connected computer system that is directly or indirectly linked to MPA’s own systems, and if the Authority is satisfied that the system is necessary for the continuous delivery of an essential transport service and that its loss or compromise would substantially affect the availability of that service, the operation of the port or any part of it, or Singapore’s reputation as a provider of marine services. Systems already designated as critical information infrastructure, third-party-owned CII, or systems of temporary cybersecurity concern under the Cybersecurity Act 2018 are excluded. Designation is by written notice, not Gazette. The notified owner or operator has at least 14 days to make representations. Part 13B does not affect powers under the 2018 Act.

A maritime entity, for this Part, is a person in the business of providing an essential transport service in Singapore; the owner of a Singapore ship, or of any other vessel that is in or intending to enter Singapore’s territorial waters; or the owner or operator of a maritime device that is in or intending to enter those waters. Part 13B applies whether the computer or computer system is located, or a virtual system is hosted, in or outside Singapore. Notices and directions may be given to individuals and companies outside Singapore. Offences under the Part apply whether committed in or outside Singapore.

Once designated, a notified operator would have to report prescribed cybersecurity incidents — on the designated III, on interconnected systems the operator also runs, and on any other computer system the operator runs — in the form and manner published on mpa.gov.sg, within a prescribed period after becoming aware. That period is not in the Bill. Material changes to design, configuration, security or operation would have to be notified within 30 days. A change of ownership or operator would have to be notified at least 90 days in advance; a person who fails to give that notice remains the notified owner or operator for up to 90 days after they finally tell MPA. Audits of compliance would be required at least once every five years by an auditor approved or appointed by MPA. A cybersecurity risk assessment would be required at least once a year. Both reports would be due to MPA within 30 days. MPA could run cybersecurity exercises and direct participation. It could issue directions to deal with a threat, to meet technical standards, or to appoint an auditor, generally after a representation period unless it considers that impracticable. Standards of performance under a new Seventh Schedule would cover design and configuration, detection, records, disclosure to potentially affected parties, vulnerability testing, contingency and recovery plans, vendor cybersecurity services, staff competence, and board-level accountability. Those standards have no legislative effect, but a notified operator must comply unless MPA waives them. Appeals lie to the Minister; an appeal does not stay the decision unless the Minister so directs.

Most Part 13B offences are a fine of not more than $20,000, imprisonment of not more than six months, or both, with a further $2,000 a day for a continuing offence after conviction. Failure to report a material change, or to file an audit or assessment report on time, is the lower $5,000 band. Failure to take part in a directed exercise is a $20,000 fine with no imprisonment line in that section. Port regulations under section 41 could also require masters, owners and agents to supply information on computers used on or in relation to vessels arriving and departing, with the same $20,000 / six-month ceiling.

Licensing, wrecks, MASS, drones and AI sit beside the cyber Part

MPA’s statement is explicit that cybersecurity is one of five amendment blocks, not the whole Bill. A comprehensive licensing framework would set out how the Authority assesses licence applications for maritime services that support the port and would let MPA issue directions on efficiency, safety, reliability, environmental sustainability or quality of regulated services. Powers to deal with stranded or abandoned vessels, wrecks and other objects that affect navigation, the marine environment or port operations would be widened. Investigative powers to obtain and verify information, inspect, and deal with false or missing documents would be strengthened.

On emerging technology, MPA said the amendments would update definitions and provisions so the Authority has a legal basis to regulate the safe use of autonomous surface vessels, aerial drones and artificial intelligence in maritime operations. That is an enabling clause, not a published MASS code, not a drone operations manual, and not an AI-on-the-bridge circular. Operators who already run remotely operated craft, survey drones or decision-support tools in Singapore waters should treat November’s Second Reading as the moment those definitions will be debated, not as a reason to assume today’s operating model is already recast.

Operational implications

The designation test reaches beyond a Singapore-incorporated terminal company. An owner of a Singapore ship, an owner of a foreign-flag hull that intends to enter territorial waters, and an owner or operator of a maritime device heading for those waters can be a maritime entity. A system hosted outside Singapore can still be designated if it is necessary for an essential transport service or is connected to MPA. A cloud vendor or an overseas technical manager with effective control — the right to change the system or to configure security — can be an operator. A master who only uses the ECDIS is not, on the Bill’s wording, operating it.

Until regulations prescribe which incidents must be reported and in what period, no CIRCIA-style 72-hour clock exists under this Bill. What does exist on the face of the text is the architecture: designation by notice, annual assessments, five-year audits, 30-day material-change notices, 90-day ownership-change notices, directed exercises, and OT explicitly in scope. A company that waits for Gazette commencement before mapping which of its port-community, agency, ECDIS, cargo-control or drone-command systems could meet the essential-transport or port-operation test will be late. A company that treats a Cybersecurity Act 2018 CII designation as covering the new III duties will have misread the exclusion: CII is carved out of III, not a substitute for MPA’s sectoral directions on systems that are not CII.

Do not recast Tuesday as an in-force standard, a worldwide autonomy code, a bunkering-licence rewrite already in effect, or a Hormuz kinetic file. The confirmed facts are First Reading on 6 October, Bill 24/2026, Second Reading in November, and commencement only when the Minister appoints a date.

What Operators Should Note

  • Treat Bill 24/2026 as a First Reading text, not a live duty. Introduced 6 October. Second Reading scheduled for November 2026. Commencement by ministerial Gazette notification. National Maritime and port-community systems keep today’s Cybersecurity Act 2018 and MPA licence conditions until then. Do not rewrite an SMS cyber annex on the strength of a First Reading.
  • Map who is a maritime entity and who has effective control. Essential-transport providers in Singapore; owners of Singapore ships; owners of other vessels in or intending to enter territorial waters; owners or operators of maritime devices on the same geography. Operate means the right to change or to configure security, including from outside Singapore. Mere use is not operation. A connected system linked to MPA can be designated even if the owner is not a maritime entity.
  • Keep OT, cloud and virtual systems on the same sheet as office IT. Part 13B’s computer-system definition includes ICS, PLC, SCADA, DCS and virtual machines, hosted in or outside Singapore. An ECDIS, a cargo-control network, a drone ground station or a port-community node that is necessary for an essential transport service, or whose loss would hit port operations or Singapore’s marine-services reputation, is in the designation test. CII already designated under the 2018 Act is excluded from III, not exempt from the 2018 Act.
  • Build the duty list even while clocks remain “prescribed.” Prescribed incident types and reporting periods are not in the Bill. Annual risk assessments, five-year MPA-approved audits, 30-day material-change notices, 90-day ownership or operator-change notices, directed exercises and 89W directions are. Most offences sit at $20,000 / six months, with $2,000 a day continuing. Material-change and late-report failures are $5,000. Section 41 regulations can already be written to demand computer-system particulars from arriving and departing vessels.
  • Do not read the MASS, drone and AI clauses as an operations code. MPA asked for a legal basis to regulate safe use of autonomous surface vessels, aerial drones and artificial intelligence. That is enabling language. It is not a published remote-operations certificate, not an IMO MASS instrument, and not a reason to assume today’s survey-drone or decision-support model is already prohibited. Watch the November debate for the definitions.
  • Keep licensing, wreck-removal and information powers off the cyber-only brief. The Bill also consolidates maritime-service licensing and directions on safety, reliability, environmental sustainability, efficiency and quality; widens action on stranded or abandoned vessels, wrecks and objects; and strengthens inspection and false-document powers. A bunkering, agency or towage licensee should read those blocks, not only Part 13B. Do not merge this file with a US CIRCIA clock or with a Hormuz warning.

Regulas Shipping will keep lining Bill 24/2026’s Part 13B designation test and November Second Reading against the Cybersecurity Act 2018 so operators can treat Singapore’s MPA amendments as a live legislative file, not as an already-in-force cyber standard or a worldwide autonomy code.

Don’t miss future updates!

We don’t spam! Read our privacy policy for more info.

More From Author

US lists 22 tankers in an Iran shadow-fleet package

US ports press for a single CIRCIA report as CISA rule hits OIRA