Our MTCS lead auditors specialize in evaluating cloud security measures against the Singapore Accreditation Council’s (SAC) SS 584:2020 (SS 584) standard for Multi-Tiered Cloud Computing Security (MTCS), designed to provide a structured, risk-based approach to aligning cloud operations with business, regulatory, and customer assurance requirements.
The SS 584 Standard for MTCS provides organizations with a structured framework designed to help systematically evaluate, strengthen, and demonstrate the security of their cloud environments. The certification framework is built around three progressive tiers ranging from baseline security suitable for low-impact data (Level 1) to stringent controls for highly confidential or regulated information (Level 3). MTCS requirements can be mapped to international standards such as ISO/IEC 27001, ensuring global relevance while addressing Singapore’s local compliance landscape, including the Personal Data Protection Act (PDPA) and sector-specific cybersecurity mandates. MTCS certification enhances transparency, builds customer trust, and ensures compliance with industry best practices and regulatory requirements. The standard serves as a critical benchmark for organizations seeking to adopt or provide secure, reliable, and compliant cloud services in Singapore and beyond.
To prepare for MTCS certification, organizations must first understand the SS 584 standard requirements and how the requirements apply to their cloud service. This begins with determining the scope of the MTCS, including the cloud computing service model being certified (IaaS, PaaS, SaaS or a combination) and impact level of data (from 1 – low to 3 – high); controls, policies, objectives, procedures and a Cloud Service Provider Disclosure can then be developed to guide in conformity to the standard.
A readiness assessment is a pre-certification review designed to evaluate how prepared an organization is to undergo the formal audit. Readiness reviews help identify gaps between what is currently designed and/or implemented and the requirements of the standard, so that they can be addressed prior to the beginning of the official certification process. Although not required for certification, a readiness assessment can be a valuable step in any compliance initiative—helping you identify and address areas of concern ahead of an audit, quickly demonstrate your commitment to high security standards, and proactively reassure customers as you work toward full certification.
This first stage is largely an evaluation of your designed MTCS against the requirements of the SS 584 standard. This stage is more high-level than the next since your auditor won’t dive into the effectiveness of all controls in practice (yet). The goal of the Stage 1 audit is to ensure you are ready to undergo the Stage 2 review. Your auditor will be looking for what is referred to as “areas of concern” i.e., lack of objective evidence to meet the SS 584 standard. If these areas of concern go unaddressed, they can or will likely materialize into formal nonconformities during the Stage 2.
In this stage, your auditor will also be looking for opportunities for improvement to help identify areas that can be enhanced. After you complete the Stage 1 process, you should address any areas of concern that your auditor notes in order to prepare for Stage 2. How this affects your overall timeline will be up to you, but you should expect to spend some time in between the initial certification stages to address areas of concern and demonstrate the effectiveness of the MTCS.
If your MTCS appears well-designed and accounts for all necessary requirements, then it’s time to watch it in action. During this phase, the auditor will evaluate your MTCS to determine if its active practices, activities, and controls are functioning effectively. Your MTCS will be assessed against the full requirements of the SS 584 standard.
Similar to the Stage 1, the auditor will be looking for nonconformities and opportunities for improvement based upon the SS 584 standard and your own defined requirements:
Note: Despite it not being necessary for the issuing of your certificate, your auditor will take the time to evaluate evidence of remediation for any noted minor nonconformities during the subsequent surveillance review (detailed below) to formally close them out.
Upon successful completion of the certification process (Stage 1 and Stage 2), an MTCS certificate of conformity is issued. The certificate is valid for a three-year period, with annual surveillance audits conducted to ensure continued compliance with the standard and the effectiveness of the MTCS. Surveillance audits require 1/3 of the time of the initial certification review. Surveillance audits can last anywhere between 2-5+ days (dependent on the number of personnel in-scope) and consist of documentation review and meetings with control owners, and other relevant personnel. Often, a sampling approach is taken during surveillance audits, as opposed to the initial certification audit which includes a full assessment of the MTCS controls.
Doug Kanney is a Managing Principal at Schellman. Doug leads the HITRUST, and HIPAA service lines and assists with methodology and service delivery across the SOC, PCI-DSS, and ISO service lines.