The original regulations reference ETSI EN 303 645 V2.1.1 for one deemed-compliance route, while the current law also preserves an ISO/IEC 29147 route for vulnerability disclosure and, since 4 December 2025, recognizes current JC-STAR STAR-1 and Singapore Cybersecurity Labelling Scheme labels in Schedules 2 and 2A. OPSS enforcement policy updates also matter because they show how the authority frames risk, proportionality, and escalating intervention.
These updates should be reflected in assurance and governance review, even if they do not automatically change the three statutory duties.