Singapore has had an official cybersecurity rating for smart devices since October 2020. It’s called the Cybersecurity Labelling Scheme, it prints one to four asterisks on the retail box, and I’d bet a plate of chicken rice you have never once used it to decide what to buy.
That’s mostly not your fault. The label is small, the asterisks are unexplained, and the categories it covers are so lopsided that for a typical HDB smart home it’s close to useless. But it’s about to get more teeth — the government announced in March 2026 that it’s raising the mandatory bar for residential routers — and there’s one thing buried in the scheme’s rules that is genuinely the most useful buying signal in Singapore smart home retail. Nobody talks about it.
Let’s go through what the label actually means, what it doesn’t cover, and whether it should change what you put in your flat.
Four asterisks, four very different promises
The scheme is run by the Cyber Security Agency of Singapore, through its Cybersecurity Certification Centre. Annoyingly, “CSA” in the smart home world also means the Connectivity Standards Alliance — the body behind Matter and Zigbee. They’re different organisations, and confusingly they’ve signed an agreement with each other. More on that later.
The label rates a device from Level 1 to Level 4, shown as one to four asterisks. The baseline comes from ETSI EN 303 645, the European standard for consumer IoT security, which sets out 13 high-level security provisions for internet-connected consumer devices.
Level 1 (✱) is the honour system. The manufacturer signs a declaration of conformity saying the device meets baseline requirements: a unique default password rather than admin/admin, no hardcoded credentials, and a documented process for shipping security updates. Nobody from a lab opens the box. Since April 2025 an approved testing laboratory has to review the application before submission, which puts a small speed bump in front of pure fiction, but it’s still fundamentally self-declared.
Level 2 (✱✱) adds secure product lifecycle requirements drawn from IMDA’s IoT cyber security guidelines — how the vendor handles vulnerability disclosure, how updates get signed and delivered, how sensitive data is stored and transmitted. Still a declaration of conformity, still no lab crawling over the firmware.
Level 3 (✱✱✱) is where an outsider finally looks. The product goes to a CLS-approved third-party lab for software binary analysis, hunting for known vulnerabilities and common weaknesses in the shipped firmware.
Level 4 (✱✱✱✱) is the real one. A full security evaluation against ETSI EN 303 645 by an approved lab, plus mandatory penetration testing. Someone is paid to break into your doorbell.
The gap between Level 1 and Level 4 is enormous, and the asterisks do a terrible job of communicating that. One asterisk means “the vendor filled in a form.” Four means “professionals attacked it and failed.” Those aren’t points on a scale so much as different universes.
You can see the fee schedule for yourself and draw conclusions: as of April 2025, a Level 1 application costs S$57. Level 4 costs S$2,347. Guess which one most manufacturers pick.
The coverage problem
Here’s where it gets awkward. Pull up the full CLS product list — it’s public and searchable — and look at what’s actually on it.
At the time of writing the registry holds 864 entries, active and archived combined. The March 2026 government announcement put the count at 870 products labelled as of mid-February 2026. Broken down by level, it’s roughly 662 at Level 1, 75 at Level 2, 8 at Level 3, and 119 at Level 4.
That Level 4 number looks encouraging until you see the category split:
- Wi-Fi routers: 392
- IP cameras: 241
- Smart appliances: 49
- Smart home hubs: 23
- Smart door locks: 1
One. A single smart door lock, in the country that has put a digital lock on what feels like every second HDB gate. Meanwhile routers and IP cameras account for roughly three-quarters of everything on the list.
The names you’ll recognise are networking and surveillance brands — D-Link, TP-Link, ASUS, Netgear, Nokia, Synology on the router and mesh side; Hikvision, i-Pro, Axis and D-Link filling out the camera list. There’s a Hisense TV sitting at Level 4. What you will largely not find is the stuff that actually populates a Singapore smart home: the bulbs, the curtain motors, the presence sensors, the wall switches, the retrofit lock modules.
This isn’t a conspiracy. It’s economics. Routers are labelled because they have to be. Almost everything else is voluntary, and a S$40 Matter bulb cannot absorb even a Level 1 certification cost across its margin, let alone the paperwork.
So if you were hoping to walk into a shop and comparison-shop smart home gear by asterisk count, that’s not a thing you can do yet. The label is currently a router-and-camera scheme wearing a smart home badge.
The one category where it’s compulsory
Routers are the exception, and they’re the exception for a good reason.
Since 2 May 2022, every Wi-Fi router sold for local use in Singapore has had to comply with IMDA’s TS RG-SEC technical specification and attain at least CLS Level 1. Registered routers carry two labels: the IMDA compliance mark and the CSA cybersecurity label. If you bought a router at retail in Singapore in the last four years, it has been through this.
On 2 March 2026, at the MDDI Committee of Supply debates, CSA and IMDA announced they’re raising that floor from Level 1 to Level 2 by the end of 2027. In practice that means residential routers will need to demonstrate secure communications, secure storage of sensitive data, and robust authentication mechanisms — not just a unique default password and a promise to patch.
The trigger was concrete. In February 2025, Singapore took part in a global operation against a botnet and CSA identified roughly 2,700 infected devices here — routers and baby monitors among them, with attackers creating unauthorised administrator accounts and installing tooling directly on the hardware. No critical information infrastructure was hit, and the campaign was opportunistic rather than aimed at Singapore. But 2,700 compromised boxes sitting in ordinary homes is exactly the argument for making the baseline higher.
If you’re due a router upgrade, this is the practical takeaway: a Level 2 router today is buying you the 2027 standard early. Level 1 is the floor, and the floor is being raised because it turned out not to be high enough.
Worth pairing with the network side of the problem too — a labelled router doesn’t help much if everything hangs off one flat network. We went through the trade-offs in IoT network segmentation for HDBs and condos, including why aggressive VLANs will happily break your Matter setup.
The genuinely useful bit nobody mentions
Here’s the part of the scheme I actually think should change your buying behaviour, and it isn’t the asterisks.
A CLS label is valid only for as long as the manufacturer supports the product with security updates, capped at a maximum of three years.
Read that again. The label is not a permanent certificate of quality. It’s a time-bound statement that the vendor has committed to patching this device, and it lapses when that commitment does. Which means the CLS registry doubles as something no product page in Singapore will give you: a public, dated record of vendor support commitments.
This is the single hardest thing to find out before you buy a smart device — how long will this thing keep getting firmware? It’s the difference between a S$300 hub that runs for eight years and one that becomes a paperweight when the vendor pivots. We’ve written about smart home gear with an expiry date and the ways Singapore buyers get caught by it; the CLS list is a partial antidote, at least for the categories it covers.
Check the registry before you buy a router or an IP camera. If a model’s label has been archived rather than renewed, that’s a vendor telling you something in public that its marketing page never will.
Your German, Korean and Japanese labels count here
The scheme isn’t a walled garden, which matters if you buy grey-import or overseas-market gear — a common enough move here when a device launches in Europe or Japan first.
CSA has signed mutual recognition arrangements so that foreign labels map onto CLS levels:
- Germany — the BSI IT Security Label is recognised as meeting CLS Level 2.
- South Korea — KISA’s Cybersecurity Certification (CIC) at Basic level and above is recognised as CLS Level 3, effective January 2025.
- Japan — a Memorandum of Cooperation covering CLS and Japan’s JC-STAR scheme entered into force on 1 June 2026.
- Finland — recognised at Level 3 and above, though Finland wound down its own labelling scheme in July 2025.
And in March 2024, CSA signed a mutual recognition arrangement with the Connectivity Standards Alliance covering its Product Security Verified Mark. That one is quietly significant for smart home buyers, because the Alliance is the Matter organisation, and its IoT Device Security Specification 1.0 was deliberately built by consolidating the US, Singapore and European baselines into one set of requirements. Signify (Philips Hue and WiZ), Google, Amazon, NXP, Schneider Electric and around 200 other members worked on it.
The practical implication: as the Product Security Verified Mark spreads across Matter devices, those devices get a recognised path into the Singapore scheme without a separate certification run. That’s the mechanism most likely to fix the coverage gap above — not manufacturers individually deciding to pay S$57 per SKU to Singapore.
Regulatory pressure elsewhere is pushing the same direction, and the timing is tight. From 11 September 2026 — days away as this publishes — the EU Cyber Resilience Act’s reporting obligations bite: any manufacturer that learns a vulnerability in its product is being actively exploited must notify ENISA and the relevant national CSIRT within 24 hours, with a fuller assessment at 72 hours and a final report within 14 days of a fix. Full CRA compliance, including CE marking and conformity assessment, follows on 11 December 2027.
Vendors that want to keep selling in Europe are building that disclosure machinery right now whether they like it or not. Once they have it, a CLS Level 2 declaration is a much smaller lift — which is the most plausible reason the Singapore list might finally fill out.
So should you buy on the label?
My honest read, category by category:
Routers and mesh systems — yes, use it. This is the one place the label is dense enough to compare across products, and it’s the device with the largest blast radius in your home. Aim for Level 2 or better, and treat it as buying the 2027 requirement two years early.
IP cameras — yes, and be picky. 241 labelled cameras is real coverage, and a camera is the device where a compromise is most personally invasive. If you’re weighing where footage lives and who can see it, the privacy considerations around cameras and household staff are worth reading alongside the security question.
Hubs — check, but don’t expect much. 23 entries isn’t enough to comparison-shop. If your preferred hub is on the list, good. If it isn’t, that’s not evidence of anything. Judge hubs on local control and ecosystem fit instead — our guide on choosing an Aqara hub walks through what actually differentiates them, and if you’d rather keep everything off the cloud entirely, Home Assistant hardware in the current RAM-price climate is the other route.
Locks — the label won’t help you. One entry. Buy on the fundamentals instead: mechanical quality, whether it fails safe, local unlock paths that survive an internet outage, and whether the vendor is still going to exist. How to choose a digital smart door lock in Singapore is a better framework than any asterisk count right now.
Bulbs, sensors, switches, curtain motors — ignore the label. It doesn’t exist for these categories in any meaningful volume. Prioritise devices that work locally over Matter or Zigbee rather than through a vendor cloud, because a device that never phones home has a dramatically smaller attack surface regardless of what’s printed on the box. If you’re still mapping out which protocol to standardise on, Matter smart homes and what works best today is a reasonable starting point.
The five-minute version
If you do nothing else after reading this:
- Check your router. If it’s older than four years, it may predate the mandatory label entirely. Replace it, and buy Level 2.
- Change the admin password. Level 1 guarantees a unique default password, not that you’ve moved off it. The 2,700 infected devices were largely a hygiene failure, not an exotic exploit.
- Turn on automatic firmware updates on every device that offers it, and go looking for the ones that don’t.
- Search the CLS registry before your next router or camera purchase. It takes thirty seconds and tells you something the product page won’t.
- Prefer local control for everything else. The best defence against a vendor’s cloud getting breached is a device that doesn’t need the cloud.
The Cybersecurity Labelling Scheme is not yet the shopping tool it was pitched as. For most of a Singapore smart home, it’s a blank. But it’s a real, public, dated register of who has committed to keeping your devices patched — and in a market where “smart” too often means “abandoned in eighteen months,” that’s worth thirty seconds of your time before you tap your card.



