New Digital Infrastructure Bill To Strengthen The Foundations For Singapore's Digital Economy
8 September 2026
The Ministry of Digital Development and Information (MDDI) introduced the Digital Infrastructure Bill (the “Bill”) for First Reading in Parliament today. The Bill will establish two new licensing regimes to strengthen (a) the security and resilience of major cloud services and data centres (DCs), and (b) the environmental sustainability of DC operations in Singapore. In doing so, the Bill will strengthen the foundations on which Singapore's digital economy is being built, and provide regulatory clarity that supports long-term infrastructure investment in Singapore. (Refer to Annex A for an overview of Singapore’s approach to building digital infrastructure.)
The Bill has been developed in collaboration with industry stakeholders, including major DC operators, Cloud Service Providers (CSPs), industry associations and enterprise users of these digital infrastructure.
Key features of the Digital Infrastructure Bill
The Bill will establish two licensing regimes administered by the Infocomm Media Development Authority (IMDA).
Security and resilience of major DCs and CSPs. The Bill will establish a licensing regime for (i) major co-location and cloud DCs with a critical IT load of at least 10 megawatts (MW),[1] and (ii) major CSPs whose Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) services generate at least S$100 million in average annual revenue from users in Singapore over the three preceding years. These thresholds are calibrated to cover the DCs and CSPs whose disruption would have a significant impact on Singapore's economy and society. The Bill complements the Cybersecurity Act, which sets out cybersecurity requirements for major foundational digital infrastructure, by covering a broader range of operational resilience risks – such as technical failures, power or cooling issues, fires and other physical or operational incidents – that can also disrupt the delivery of digital services. To manage these risks, licensees will be required to implement security risk management measures, business continuity and disaster recovery plans, and report specified incidents and disruptions to IMDA.
Environmental sustainability of DC operations. All operators of DCs with a critical IT load of at least 3MW will be licensed. As a first step, DCs will be required to meet facility-level energy-efficiency requirements, including Power Usage Effectiveness (PUE) requirements. These requirements will apply to existing and new DCs. The framework will also allow further requirements, including for IT equipment and water efficiency, to be introduced where necessary and following consultation with industry.
The Bill also provides a basis for strategic, economic, and green energy commitments made – in exchange for being awarded new DC capacity through exercises such as the Data Centre – Call for Application (opens in new tab) (DC-CFA) – to be enforced as licence conditions. This ensures that material commitments made in securing scarce capacity are accountable and create broader value for Singapore, given that Singapore's DC capacity is supported by scarce national resources, including land and power.
Public consultation and industry engagement
MDDI and IMDA conducted a public consultation on the draft Bill from 1 to 22 July 2026 and received responses from 25 respondents. Respondents were supportive of the Bill’s policy objectives, and provided feedback on the practical implementation of the licensing regimes and regulatory requirements.[2] Feedback received has been taken into account in the finalised Bill. As we implement the Bill, MDDI and IMDA will:
Minimise regulatory burden by streamlining licensing and reporting processes and, where possible, recognise existing industry standards and certifications;
Provide sufficient transition time for existing DCs to meet regulatory requirements;
Streamline requirements under the Bill and the Cybersecurity Act; and
Continue engaging industry on the detailed requirements, transition arrangements and implementation of the regulatory framework.
Investing in Singapore’s digital future
Predictable and credible rules are part of Singapore's value proposition, especially for capital-intensive digital infrastructure investments with a multi-decade lifespan. The Bill will give our businesses, organisations, and citizens assurance that the infrastructure they depend on is secure and resilient — and give businesses the clarity and predictability they need to invest in Singapore's digital infrastructure for the long term. It will also ensure that our DC sector continues to grow in a sustainable manner and makes the best use of our scarce national resources. Altogether, the Bill will strengthen the foundations on which Singapore's digital economy, and our AI ambitions, will be built.
Second Reading of the Bill
The Bill will be tabled for a Second Reading at the next available Parliament sitting.
Annex A
Background on Singapore’s Approach to Building Digital Infrastructure
Singapore is a trusted regional hub for digital infrastructure, hosting submarine cables that connect Singapore and the region to the world, and more than 1.6 gigawatts of data centre (DC) capacity. These digital infrastructure are the foundation on which Singapore's digital economy, and our ambition to be a leading regional hub for Artificial Intelligence (AI), are being built. Building up our own capabilities allows Singapore to better manage cybersecurity and resilience risks, and ensure that the infrastructure underpinning key digital services that our economy and society depend on meet certain minimum standards. Cloud Services and DCs are becoming systemically important as they support a growing range of activities that businesses and consumers rely on daily, from digital banking and ride-hailing to e-commerce, digital identity and authentication. As dependence on digital infrastructure deepens, so does the impact of disruptions on businesses, public services, and individuals.
At the same time, demand for compute is rising rapidly, driven by the growing use of AI, autonomous systems and other data-intensive applications. Singapore needs to grow its compute and DC capacity to support our increasingly AI-driven economy. But as a resource-constrained city-state, we must do so in a disciplined manner as DCs are also intensive users of land, power and water. These scarce resources must be managed carefully as compute demand grows, so that we make the best use of the resources we have to build the infrastructure Singapore needs, while improving resource efficiency and ensuring that scarce resources generate lasting value.
The Government has been planning ahead for these challenges, and has worked with industry over several years to strengthen the security, resilience and sustainability of Singapore's digital infrastructure. For example, IMDA launched the Advisory Guidelines for Resilience and Security of Cloud Services and DCs (opens in new tab) to set out industry best practices for managing risks ranging from technical misconfigurations and physical hazards such as fires and cooling failures, to cyberattacks. We have also worked with industry to chart a sustainable growth pathway for the sector through initiatives such as the Green DC Roadmap (opens in new tab), the refreshed BCA-IMDA Green Mark certification for DCs (opens in new tab), and standards covering IT energy efficiency (opens in new tab), liquid cooling (opens in new tab) and tropical data centres (opens in new tab). These measures draw from industry practices, international developments, and lessons from past incidents, and were shaped in extensive consultation with industry stakeholders.
As the risks our digital infrastructure face become more complex,[3] and demand for compute grows against Singapore's resource constraints, a common statutory baseline is needed to ensure consistent outcomes across the sector, while allowing detailed requirements to evolve as technology, risks, and industry practices change. We are thus introducing a new Digital Infrastructure Bill, which builds on our earlier efforts, to establish clear and enforceable baseline requirements for digital infrastructure of systemic importance.
[1] This includes co-location DCs (which house third parties' IT equipment) and cloud DCs (which the operator uses to deliver cloud services to third parties). DCs used solely for the operator's own internal purposes are not covered.
[2] The closing note on the public consultation is available on MDDI's website at:
[3] In February 2023, a utility power surge tripped cooling systems at a data centre and caused a multi-hour cloud service outage that affected Government and other organisations in Singapore. In October 2023, a cooling system failure at a Singapore data centre disrupted online banking and payment services provided by major banks in Singapore over more than 12 hours, resulting in over 810,000 failed access attempts and 2.5 million failed payment and ATM transactions. In September 2024, a fire at a data centre affected cloud services relied upon by e-commerce and digital platforms.
