Singapore: Updates Security Rules for Home Gateways

Home / Country Update / Singapore: Updates Security Rules for Home Gateways

Singapore’s Info-communications Media Development Authority (IMDA) has released Issue 2 of its Technical Specification for Security Requirements for Residential Gateways (IMDA TS RG-SEC), dated June 2026. The update replaces Issue 1 from October 2020 and restructures the specification around the Cybersecurity Labelling Scheme (CLS) for IoT, following the uplift of the baseline home gateway requirement from CLS Level 1 to CLS Level 2. It sets minimum technical security requirements for the design and management of residential gateways, the devices that connect home IoT products to the internet access service provider’s network. Manufacturers seeking equipment registration in Singapore will need to align their gateway security controls with the revised clauses.

Singapore on map device regulatory update

Why IMDA Is Tightening Residential Gateway Security

Residential gateways sit at the center of the home network, linking routers, set-top boxes, cameras, and other connected devices to the wider internet. IMDA’s specification is designed to minimize vulnerabilities in these devices at the point of purchase and deployment, protecting both communication networks and the IoT devices behind them from threats originating online. Issue 2 is meant to be read alongside the CLS for IoT Publication No. 4A, and the requirements in TS RG-SEC apply in addition to, not in place of, the CLS Level 2 baseline provisions.

Minimum Password Strength and Authentication Controls

The updated specification requires that access to a residential gateway’s administrative login page and configuration settings accept only unique passwords of at least 10 characters, meeting at least two of four complexity rules covering uppercase letters, lowercase letters, digits, and special characters. Passwords cannot contain consecutive identical characters, and login IDs cannot match their associated password. On the authentication side, gateways must block unprotected access to the management webpage, lock accounts after a set number of failed login attempts, and provide a secure fallback authentication method when an account is locked.

Credentials Handling, Firmware Updates, and Data Protection

Issue 2 also introduces stricter credentials handling rules: password fields must block copy-paste, passwords must always be masked on screen, and remote management credentials, including those tied to Broadband Forum’s TR-069 protocol, cannot be displayed on the gateway’s management page. Devices must ship with data-collection features that send network statistics back to the manufacturer disabled by default, along with IPv6 tunnelling mechanisms such as Teredo, 6to4, and ISATAP, which can otherwise create hidden communication channels. Firmware patches must not contain hardcoded credentials and must be delivered over a secured connection, and encryption algorithms used for data protection must be replaceable so stronger algorithms can be adopted later without a full device redesign.

What Changed From Issue 1 and What Comes Next

Compared with the 2020 version, Issue 2 removes several clauses now covered directly by the CLS Level 2 baseline, revises the device setup, authentication, and credentials handling sections, and adds a standalone clause requiring compliance with CLS Level 2 requirements. The updated Annex A conformance checklist marks most password, authentication, and credentials provisions as mandatory, with device pre-loaded settings for telemetry and IPv6 tunnelling marked as conditional based on feature availability. Manufacturers and importers preparing residential gateways for the Singapore market should review their compliance documentation against the new Annex A checklist ahead of equipment registration.

For this article’s source information and any product certification guidance, please contact Global Validity. 

Quick Country Facts

Singapore

Certification Body: Infocomm Media Development Authority (IMDA)

Certification Type: Mandatory

License Validity: 60 Months

Application Language: English

Legal License Holder: Local Representative

In-Country Testing Requirement: Testing Not Required

The regulatory information above is based on radio type approval certification. Access additional certification requirements in over 200 countries and territories with Global Validity’s free proprietary product certification management software, Access Manager. Learn more about the platform here or fill our quick contact form! 

Global Validity is your partner for global certification success

Want to learn more about regulatory compliance and how we can help? Simply fill out the form below and we’ll be in touch!