A late-night call from a panicked operations manager still resonates: servers overheating, alarms shrieking, and a decision about whether to throttle workloads or risk a cascading outage. That episode underlines a blunt reality — Singapore’s digital backbone is powerful, but fragile when growth is demanded without carefully timed upgrades. The proposed Digital Infrastructure Bill, now on the table, is a necessary step. The implementation must be pragmatic, predictable and patient.
Data centre operators have asked for breathing room to meet new energy-efficiency requirements. That request is not an excuse; it is a fact rooted in engineering timelines, procurement cycles and the complexity of retrofits. The consultation conducted from July 1 to 22 gathered 25 responses from operators, cloud providers and associations. Consensus emerged: the Bill is important. Support runs deep. The complication is not opposition — it is feasibility.
What the Bill requires — and why it matters
Two licensing regimes are being introduced: foundational digital infrastructure (FDI) and data centre (DC). Thresholds are clear. Facilities that require 10 megawatts of electrical power for essential computing equipment, and cloud providers with more than an average annual revenue of S$100 million in Singapore users over three years, fall into the FDI category. DC licensees are those using at least 3MW to power servers, storage and networking hardware.
Licensees will need to harden both physical and digital defences, maintain business continuity and disaster recovery plans, and report incidents to IMDA. Penalties for non-compliance are steep: up to S$1 million or up to 10% of annual Singapore turnover, whichever is higher. That is a clear signal that resilience and accountability are priorities. Make no mistake: expectations are high, and the consequences are real.
Energy efficiency and the PUE debate
Power usage effectiveness (PUE) will be a central measurement. A PUE closer to 1 denotes greater efficiency. Historical benchmarks in contract awards tell the story: selected contracts in July 2023 required a PUE of 1.3; proposals selected in August 2026 had a 1.25 requirement. The Bill has not locked a PUE target yet, and that is precisely why transition time matters.
Upgrading a 2011-built facility with a PUE above 1.3 is not a weekend job. It takes capital, planning and often staged infrastructure work that must avoid service disruption. “A transition period is necessary because it lets us assess sites properly and make upgrades in a structured, non-disruptive way,” one operator pointed out during consultation. That statement deserves more than lip service.
Operational friction: licensing, reporting and duplication
Practical obstacles were raised repeatedly. License application and renewal processes require streamlining. Audit cycles and reporting obligations must be proportionate and harmonised across agencies. There is genuine concern about overlapping requirements between the proposed Digital Infrastructure Act and the existing Cybersecurity Act. Multiple, near-identical reporting pathways do not improve security; they create administrative drag and risk delayed responses.
Respondents called for a single application form, consolidated documentation and aligned audits. Authorities have responded constructively, indicating exploration of process streamlining and inter-agency coordination with CSA. Where reporting is identical, a single submission to IMDA will suffice, with appropriate information-sharing behind the scenes. That is a sensible starting point. Execution must follow.
Security and resilience expectations
Advisory guidelines already require fire and flood mitigation measures, safeguards against supply chain attacks, and protections from malware and ransomware. Cloud providers must tighten privileged account controls and keep audit logs for detection and investigation. These measures are not optional extras; they are foundational. Yet, expecting instant compliance without calibrated timelines and targeted support would be unrealistic and, frankly, counterproductive.
Technology evolves. So must regulations. The Bill’s approach to finalise requirements from next year and update them as technology changes is correct. Still, the cadence of updates must be predictable. Frequent sudden shifts in standards will frustrate compliance and investment decisions.
Balancing scarce resources and scale
Singapore’s limited land, power and water resources demand disciplined growth. MDDI and IMDA have emphasised that scarce resources must be managed carefully so compute demand yields lasting value. That is not rhetoric — it requires policy that nudges operators toward efficiency while enabling necessary expansion.
Practical levers include phased compliance windows, incentives for retrofits and clear guidance on acceptable upgrade pathways. If two-thirds of the nation’s roughly 70 data centres will need both DC and FDI licences, the regulatory transition must be staged to avoid a bottleneck that harms service availability.
What needs to happen next — decisively
- Publish phased compliance timelines tied to objective milestones, not arbitrary calendar dates.
- Implement a single, unified application and reporting portal to reduce duplication across IMDA, MDDI and CSA.
- Introduce transitional incentives for energy-efficiency upgrades, especially for legacy facilities built before modern PUE expectations.
- Lock in a predictable schedule for updates to technical requirements, with industry consultation windows defined well in advance.
These are practical measures. They balance urgency with realism. They protect the services Singaporeans rely on — from digital banking and ride-hailing to e-commerce and AI-driven tools — while preserving finite national resources.
Nobody wants a regulatory framework that is either lax or blindly punitive. The path forward must be firm but fair. Provide clear rules, reasonable time to comply, and a streamlined mechanism to report and remediate incidents. Do that, and Singapore will continue to lead by showing that resilience, sustainability and growth can coexist — provided transitions are managed with discipline and a deep respect for operational realities.

