|

CLS Level 2: Singapore Tightens Residential Router Cybersecurity Rules by 2027

A Discovery That Changed the Conversation

During the Ministry of Digital Development and Information’s Committee of Supply Debates 2026, the Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) announced plans to raise mandatory cybersecurity requirements for residential routers. The routers will move from Cybersecurity Labelling Scheme (CLS) Level 1 to CLS Level 2 by the end of 2027.

A specific finding drove the decision. In 2025, Singapore took part in a global operation that uncovered more than 2,700 local devices, including routers, that had been infected and folded into a large-scale network of compromised devices spanning multiple countries.

That network of hijacked devices had the potential to be weaponised for distributed denial of service (DDoS) attacks. For regulators, the discovery made clear that current protections were no longer keeping pace with how attackers actually operate.

What CLS Level 2 Actually Requires

The CLS has been around since 2020. It gives consumers a simple way to judge the cybersecurity posture of Internet of Things (IoT) devices through a tiered labelling system. As of mid-February 2026, 870 products had already earned a CLS label.

Right now, every residential router sold in Singapore only needs to clear CLS Level 1, which covers:

  • Unique default passwords (no shared or predictable factory-set passwords across units)
  • An active vulnerability management process
  • Ongoing software updates to patch known issues

Those measures matter, but CSA and IMDA were candid that Level 1 was designed for fundamental risks. It was never meant to withstand the more sophisticated techniques attackers use today, particularly around weak encryption, poor authentication, and insecure data storage.

CLS Level 2 closes those specific gaps. Manufacturers will need to build in:

  • Secure communications. Traffic to and from the router must run on TLS 1.2 or higher with approved cipher suites, following NIST guidance on acceptable encryption strength. Encryption methods also need to be replaceable, so a router can be upgraded to stronger algorithms later without a full hardware redesign. Risky default behaviors have to be switched off out of the box too, including telemetry that quietly reports network activity back to the manufacturer and IPv6 tunnelling protocols like Teredo, 6to4, or ISATAP, which can otherwise be used to create hidden communication channels.
  • Secure storage of sensitive data. Device identifiers, keys, and other sensitive information need to be stored in a way that resists extraction, rather than sitting in plain, easily readable form on the device.
  • Robust authentication mechanisms. Access to the router’s management interface can no longer be left open without authentication. Accounts must lock after a set number of failed login attempts, and a secure fallback path has to be available if the primary login method fails. Passwords face stricter rules too, with a minimum length requirement and complexity criteria, and credential fields must be masked on screen and not copyable. Firmware updates are covered as well: patches cannot ship with hardcoded credentials and must be delivered over a secured connection.

Taken together, these requirements are meant to make it significantly harder for a router to be quietly compromised. That closes off one common path attackers use to launch attacks on the rest of a home network or beyond.

Why Home Routers Became a National Priority

Routers occupy a unique position in any home network. Every connected device, from smart TVs to baby monitors, passes through them. That makes a router an unusually attractive target.

Once compromised, it can serve two purposes for an attacker. It can act as a doorway into every other device on the same network. Or it can become a recruit in a much larger network of hijacked devices used against unrelated targets entirely.

This dual risk is precisely why CSA and IMDA are treating routers as a priority category rather than folding them into a broader, slower-moving update. It also signals how regulators are thinking about IoT security more generally. Devices that sit at the edge of a network, quietly relaying everyone else’s traffic, are being held to a higher standard precisely because a single point of failure there creates risk for an entire household.

The Road to End-2027 Enforcement

CSA and IMDA have set an end-2027 target for the new requirements to take full effect. This gives manufacturers a multi-year runway to redesign products, update firmware architectures, and prepare for testing against the higher bar.

The timeline also gives certification bodies and test labs time to build out the technical capacity needed to assess Level 2 criteria at scale.

The shift reflects a broader pattern regulators across the region are following. Consumer IoT security is being treated not as a one-time checklist, but as a baseline that gets revisited as the threat landscape evolves. Expect manufacturers selling into Singapore to start factoring CLS Level 2 into product roadmaps well ahead of the 2027 deadline, particularly given how testing and certification lead times typically compress toward the end of any transition window.

Key Takeaways

The jump from CLS Level 1 to Level 2 is a substantive one. Manufacturers relying on password hygiene and update cadence alone will need to re-architect around secure communications, encrypted storage, and stronger authentication well before the 2027 deadline.

Source

Other posts you may find interesting...