// singapore regulation, grants & skills · intermediate

Deploying IoT in Singapore: IMDA Registration, CLS Compliance and Wireless Connectivity (2026)

17 min read· Updated 27 August 2026 · By TechDirectory Editorial Team

Share with your friends:

Singapore is an unusually good place to put connected hardware to work: standalone 5G across the island, dense fibre and data centres, a nationwide LoRaWAN sensor network, and a government actively funding enterprises to adopt robots and AIoT — artificial intelligence combined with the Internet of Things. The bottleneck is rarely the technology. It is that a device shipping freely in the United States or the European Union can be unlawful to sell or deploy here until IMDA has registered the exact model for local sale and, for consumer-facing products, the Cyber Security Agency of Singapore has rated its security.

This guide maps both tracks, the five registration schemes and what each costs, the Singapore band plans that quietly break imported radios, the wireless options ranked by regulatory friction, and a ten-step route from product design to a live site. It is practical compliance education for buyers, integrators and manufacturers — not legal advice, and not a substitute for reading IMDA's and CSA's own pages before you file.

Quick factsWhat you need to know
Who registers the equipmentIMDA, under the Telecommunications Act and the Telecommunications (Dealers) Regulations
Who runs the security labelCSA, through the Cybersecurity Labelling Scheme for IoT — CLS(IoT)
Where you applyGoBusiness for equipment registration and CLS. Network and spectrum licences go through IMDA's IRIS portal instead
Who may applyAn equipment supplier or dealer holding a valid IMDA Telecommunication Dealer's Licence. Overseas manufacturers apply through a Singapore entity that holds one
Registration schemesFive application types: ESER, SER, GER, GER-CB and COFC
Registration validity5 years for ESER, SER, GER and GER-CB. COFC is lifetime. Renewal is $50
Typical IoT routingWi-Fi, Bluetooth and short-range sensors → ESER (free). IoT user equipment → SER ($100). IoT base stations, UWB and DSRC → GER ($350/$500)
CLS levelsFour, shown as one to four asterisks. Each level adds an assessment tier
CLS mandatory scopeWi-Fi routers and residential gateways only — minimum Level 1 since 2 May 2022, rising to Level 2 by end-2027
Sub-GHz LoRa band917–925 MHz under IMDA TS SRD (Sep 2023). Not the US 902–928 MHz plan
Licence-exempt 6 GHz Wi-FiLower band only: 5,945–6,425 MHz
Fees and timelinesPublished and revised periodically — confirm on IMDA, CSA and GoBusiness before you budget

Table of contents

Do I need IMDA registration, a CLS label, or both?

Direct answer: Deploying IoT in Singapore runs on two tracks. IMDA registers the equipment itself — one registration per model, valid five years, filed by a Singapore entity holding a Telecommunication Dealer's Licence. CSA's Cybersecurity Labelling Scheme rates the same device's security from one to four asterisks. IMDA registration is mandatory for most radios. CLS is mandatory only for Wi-Fi routers.

The tracks answer different questions. IMDA asks whether the device behaves properly on the airwaves and on public networks: frequency, output power, emissions, electrical safety, human RF exposure and — increasingly — whether it degrades a carrier or home network. CSA asks whether it resists the attacks that turn consumer hardware into botnets. A product can pass one and fail the other, and the two applications are filed separately even though both start at GoBusiness. A third track appears if you build your own radio network rather than buying capacity: private cellular and campus 5G need a network licence from IMDA through the IRIS portal, on top of registering the base stations as equipment.

Who regulates what: IMDA, CSA, the operators and you

IMDA — the Infocomm Media Development Authority — licenses dealers, registers equipment models, publishes the technical specifications equipment must meet, manages spectrum and licenses networks. If your product transmits, IMDA is unavoidable. The FBO licensing explainer covers the operator-side framework.

CSA runs CLS(IoT), a voluntary label with one compulsory corner. It does not decide whether your radio may transmit; it decides what security rating a consumer device may advertise. The two agencies converge on exactly one product class — Wi-Fi routers, where IMDA's technical specification and CSA's label are welded together.

The operators own the spectrum your cellular IoT device will actually use. Registration proves the model is legal; it does not guarantee the module supports the bands and features a given operator has switched on. Confirm band support and M2M profiles with the operator, not only with the module vendor. You, the deploying enterprise, own everything after installation: segmentation, credentials, firmware currency, logging, incident response and vendor exit. No label covers that, which is why SS 711:2025 and the IMDA IoT Cyber Security Guide exist.

Who this applies to: Anyone who imports, manufactures, hires, sells, offers for sale or holds for sale radio or telecommunication equipment for local use in Singapore — overseas manufacturers selling through a local distributor, integrators bundling sensors into a solution, and enterprises deploying their own radios on their own sites.
Who this does not apply to: Products with no radio and no telecommunication interface. Equipment handled purely for re-export under a Telecommunication Dealer's Individual Licence, a different pathway from local sale. Equipment IMDA exempts from registration, where a Confirmation of Conformity is voluntary. If your product sits near any of these lines, confirm the classification with IMDA in writing before you commit to a launch date.

IMDA equipment registration, scheme by scheme

The prerequisite: a Singapore entity with a Dealer's Licence

Applicants must be equipment suppliers or dealers holding a valid IMDA Telecommunication Dealer's Licence. This is the most common blocker for overseas manufacturers: there is no route to register a model as a foreign entity acting alone. You either incorporate in Singapore and hold the licence, or you appoint a local distributor, importer or authorised representative who does.

The Class Licence covers dealing in approved (registered) equipment and equipment listed in the First Schedule of the Telecommunications (Dealers) Regulations. The Individual Licence reaches further, including non-registered equipment handled solely for re-export — the right choice for regional distribution hubs, bonded stock and demo pools. Both go through GoBusiness and need a Singapore UEN. Our IMDA telecom equipment importing guide covers the licence, the TradeNet declaration and the customs side in detail.

Pick the accountable party early: The dealer licence holder, the registration record, the shipping invoice and the model on the label all have to describe the same device and the same entity. In a real supply chain the manufacturer, distributor, reseller, logistics importer and deploying integrator are often five different companies. Decide which one carries the registration before the first container ships.

The five application types, and which one your device needs

IMDA runs a risk-based framework: the lower the interference and network risk, the lighter the process. Registration rests on a Supplier's Declaration of Conformity supported by a technical file.

Application typeWhat it coversFeeRegistration period
ESER — Enhanced Simplified Equipment RegistrationShort-range and low-power devices: alarms, RFID, radio detection, on-site paging, vehicle radar, remote controls, telecommand, telemetry, wireless microphones and video transmitters, wireless LAN and Bluetooth. Also DECT cordless phones, PMR446/MCR446 under 500 mW, DVB-T2 receiver decoders and complex multi-line equipment such as PABX and ISDN.Free of charge5 years
SER — Simplified Equipment RegistrationMobile terminals such as 5G, LTE and GMPCS handsets. Broadband access equipment such as ADSL and cable modems. IoT user equipment.$100, plus $50 family series fee5 years
GER — General Equipment RegistrationMandatory for mobile and IoT base station or repeater systems, land mobile radio and walkie-talkies, TV white space devices, UWB, DSRC, and short-range devices whose operation requires IMDA's approval. Also available voluntarily for ESER/SER equipment where the applicant wants IMDA to evaluate it.$350 or $500, plus $50 family series fee5 years
GER-CB — General Equipment Registration by Certification BodiesAll equipment types, but only usable by authorised certification-body applicants recognised by IMDA under MRA Phase II.$100, plus $50 family series fee5 years
COFC — Confirmation of ConformityVoluntary. For telecommunication equipment exempted from registration, where no approval for sale is required — useful when a customer or a customs broker wants a document anyway.$100 self-declaration, $350 with IMDA evaluationLifetime

Renewal, where applicable, is $50. Note the split that catches IoT teams most often: IoT user equipment sits under SER, while an IoT base station or repeater is mandatory GER. A sensor and the gateway it talks to are frequently not on the same track, do not cost the same and do not clear in the same time.

Your deviceLikely routeWhat to watch
Wi-Fi or Bluetooth sensor, tag or beaconESER, freeFastest path. The evidence obligation does not disappear — you still hold the conformity file for post-market checks
LoRa or sub-GHz end deviceESER, freeMust operate on Singapore's 917–925 MHz plan, not a US or EU band file
LoRa or LPWAN gatewayESER or GERGER once output power or operating conditions require IMDA's approval. Confirm the classification before you order
NB-IoT or LTE-M sensor, meter or trackerSER, $100IoT user equipment. IMDA TS IOT sets the requirements for low-power wide-area devices in the authorised cellular bands
Embedded cellular module inside a productSER, $100The finished product is registered, not just the module. A module certificate supports the file, it does not replace it
Voice-capable cellular deviceSER, $100IMDA TS CMT (Mar 2026) applies: VoLTE, emergency calling, emergency cell broadcast from 1 Apr 2026, and 2G off by factory default from 31 Dec 2026
Private cellular or IoT base station, repeaterGER, $350–500IMDA TS CBS applies, and operating it needs a separate network licence and spectrum
UWB tag or anchor for precise locationGER, $350–500Mandatory GER. Budget the longer technical evaluation
DSRC roadside or in-vehicle unitGER, $350–500Mandatory GER under IMDA TS DSRC
Wi-Fi router or residential gatewayESER plus CLSThe one product class where the security label is compulsory. Both the IMDA compliance label and the CSA Cybersecurity Label must be affixed
Excluded outright: Some equipment cannot be registered at all. Scanning receivers, military communication equipment, telephone voice-changing equipment and radio equipment operating in 880–915 MHz, 925–960 MHz, 1900–1980 MHz or 2110–2170 MHz (other than cellular mobile phones or equipment IMDA approves) are Prohibited Telecommunication Equipment under the Third Schedule of the Telecommunications (Dealers) Regulations. Importing or re-exporting them for use in Singapore needs prior IMDA approval. Those bands are the public cellular downlink and uplink — which is why signal boosters and repeaters bought online are a recurring enforcement problem.

Documents, labels and what an application actually needs

The form is rarely the bottleneck; the technical file is. IMDA expects the equipment to comply with the applicable Line Terminal Equipment Standards or Radio-communication Equipment Standards, and expects supporting documents to be complete at submission. A credible pack carries the model identifier and hardware revision, firmware branch, supported bands and output power, antenna details, RF exposure evidence where relevant, EMC and electrical-safety reports, user documentation, product photographs, label artwork and module certificates.

Overseas evidence helps: FCC, ETSI and CE reports are widely used to support a Singapore declaration and local retesting is often unnecessary, particularly where an IMDA-recognised mutual recognition arrangement applies — that is what GER-CB under MRA Phase II exists for. But foreign approval is supporting evidence, not a Singapore passport; it does not carry Singapore-specific requirements such as the band plan, TS CMT's cellular behaviours or TS RG-SEC's router security. Once registered, the device must carry the IMDA compliance label with the dealer's registration number, per IMDA's Telecommunication Equipment Labels and Advertisements Requirements — plus the CSA Cybersecurity Label for Wi-Fi routers.

Firmware is a regulatory event, not just maintenance: Band enablement, power tables, antenna changes, new radio modules, Wi-Fi channel availability, DFS behaviour, SIM handling and emergency-call behaviour can all move with a firmware release. A compliance-affecting change can require re-registration before the modified equipment is supplied for local use. Put advance-notice obligations for hardware, radio, antenna and firmware changes into your supplier contracts.

The band-plan trap: why a working device still fails here

This is the failure mode that surprises teams with a shipping product. The hardware is fine and the radio works. It simply transmits on a plan Singapore has not allocated, and no paperwork fixes that after the fact. Lock the band file to Singapore at the factory, then register.

TechnologySingapore positionGoverning specThe usual import mistake
LoRa and sub-GHz SRD917–925 MHz. IMDA TS SRD Issue 1 Revision 3 amended the band from 920–925 MHz to 917–925 MHzIMDA TS SRD (Sep 2023)Shipping US 902–928 MHz firmware, or assuming an unmodified AS923 profile fits without checking channel and power limits
Wi-Fi 6E and Wi-Fi 7 in 6 GHzLower band only — 5,945–6,425 MHz was added by TS SRD Rev 3. The upper 6 GHz range is not open for licence-exempt Wi-FiIMDA TS SRD (Sep 2023)Designing a channel plan around three 320 MHz channels. Singapore fits one — see Wi-Fi 7 explained
Cellular IoT (NB-IoT, LTE-M)Low-power wide-area IoT devices operate in the authorised cellular bands; TS IOT sets the minimum technical requirementsIMDA TS IOT (Nov 2017)Ordering a module SKU built for a North American or European band set, then discovering the local operator does not run those bands
Cellular voice-capable terminalsVoLTE, emergency calling and emergency cell broadcast requirements, plus 2G disabled by factory defaultIMDA TS CMT (Mar 2026)Treating a cellular product with a voice path as a data-only device
Cellular device network behaviourSecurity requirements to guard against network storms for cellular devices, in force since 2 Jan 2023IMDA TS CD-SEC (Jul 2022)Fleet firmware that reconnects aggressively after an outage — a signalling-storm risk regulators now test for
UWBRegistrable, but mandatory GERIMDA TS UWBAssuming a US or EU UWB channel plan and power mask transfers unchanged
Cellular base stations and repeatersRegistrable under GER; operating them is a separate licence questionIMDA TS CBS (Dec 2024)Buying a repeater to fix in-building coverage without checking it is not prohibited equipment

One practical consequence for fleet buyers: a single global SKU rarely survives contact with Singapore unless the vendor already ships a Singapore band file. Ask for it by name, ask which firmware branch carries it, and make the answer a contractual deliverable rather than a support-ticket discovery.

CLS(IoT): what the four levels actually test

CSA launched the Cybersecurity Labelling Scheme for IoT in October 2020, the first of its kind in the Asia-Pacific. It rates consumer smart devices on their cybersecurity provisions so buyers can tell a hardened product from a cheap one. It began with Wi-Fi routers and smart home hubs and now covers all categories of consumer IoT — IP cameras, smart locks, lighting, printers, televisions, speakers, toys, health trackers and thermostats. As of mid-February 2026, 870 products had attained a label. The scheme has four levels, shown as one to four asterisks. Each level corresponds to the highest assessment tier the product has completed, and the tiers run in sequence — a Level 3 product has passed Tiers 1, 2 and 3.

LevelAssessment tierWhat is actually testedApplication fee
Level 1 ★Tier 1 — security baselineBaseline requirements derived from ETSI EN 303 645: no universal default passwords, a working vulnerability disclosure process, and availability of software updates. Eliminates the common mistakes behind most opportunistic attacks.$57
Level 2 ★★Tier 2 — adherence to international standardsAll mandatory provisions of ETSI EN 303 645, not just the baseline subset. In router terms this means secure communications, secure storage of sensitive data and stronger authentication.$142
Level 3 ★★★Tier 3 — lifecycle plus binary analysisSecurity built into the development lifecycle along the lines of the IMDA IoT Cyber Security Guide — threat modelling, secure engineering, secure supply chain, security testing. Plus a laboratory binary analysis against the declared software bill of materials, checking for known critical weaknesses, vulnerabilities or malware.$633
Level 4 ★★★★Tier 4 — penetration testingStructured penetration testing by an approved laboratory, for basic resistance against common attacks.$2,347
Mutual recognitionDevices already labelled under the Finnish, German or Korean schemes enter through the recognition route rather than repeating assessment.$51
CLS-ReadyA separate category for developers preparing products against the scheme's requirements ahead of a product application.$2,370

Those fees took effect on 1 April 2025 and cut the higher levels sharply — Level 2 fell from $418 to $142, Level 4 from $3,810 to $2,347. At Levels 3 and 4 the laboratory work, not the application fee, is the real cost.

Mandatory or voluntary? The router rule and the 2027 change

CLS is voluntary for almost everything. The exception is Wi-Fi routers: since 2 May 2022 every Wi-Fi router sold for local use has had to comply with IMDA's Technical Specification for Security Requirements for Residential Gateways (IMDA TS RG-SEC) and attain at least CLS Level 1. Compliance with TS RG-SEC qualifies a router for Level 1, and GoBusiness handles both registrations in one place.

That bar is rising. On 2 March 2026, at the MDDI Committee of Supply debates, CSA announced it will work with IMDA to raise the mandatory requirement for residential routers from Level 1 to Level 2 by end-2027. The stated reason is concrete: in a 2025 global operation, attackers were found to have infected over 2,700 Singapore devices, including routers, as part of a botnet. Level 1 addresses default passwords and patching; Level 2 adds the encryption, authentication and secure-storage requirements Level 1 leaves out. IMDA published Issue 2 of TS RG-SEC in June 2026; the enforcement date and final requirements are still being settled between the two agencies.

If you build or resell routers or gateways: Assume your current Level 1 registration will need re-assessment against the updated specification. A product designed in 2026 that will still be selling in 2028 should be engineered to Level 2 now, not retrofitted later. Track the CLS(IoT) Updates page — the requirement is confirmed, the compliance mechanics are not yet.

How to apply, which labs, and mutual recognition

Applications go through GoBusiness, which has hosted the whole CLS process including payment since September 2023. The important process change came on 1 April 2025: Level 1 and Level 2 applications must now be reviewed by an approved CLS Testing Laboratory before submission, and applications filed without one are not processed. Levels 3 and 4 already required laboratory work. In practice, self-declaration as a solo activity is gone from the scheme.

CSA publishes the approved-laboratory list, which stood at eleven laboratories as of March 2026 — seven with Singapore addresses, including Ensign InfoSecurity, KPMG Services, SGS Brightsight Singapore, Setsco-An Security, T-Systems Singapore, TÜV SÜD PSB and UL Verification Services, plus laboratories in Germany and the Netherlands. The list changes; check it before scoping a budget. If your product already carries a label from a partner scheme, mutual recognition removes duplicate testing.

Partner schemeRecognised in Singapore asNotes
Finland — Traficom Cybersecurity LabelCLS Level 3 and aboveLevel 3 and Level 4 applications can be granted both labels at once through a single application
Germany — BSI IT Security LabelCLS Level 2 and aboveMRA first signed in 2022 and extended in October 2024; home gateways are covered
Republic of Korea — KISA Certificate of IoT Cybersecurity (CIC)CIC Basic Level recognised as CLS Level 3The Korean scheme has three levels — Lite, Basic and Standard — with third-party lab testing at all of them
United Kingdom — PSTI Act Statement of ComplianceCLS Level 1 and aboveCLS-labelled products are also deemed compliant with the UK PSTI requirements
Connectivity Standards AllianceMutual recognition arrangement signed 19 March 2024Reduces duplicated testing across the Alliance's Product Security Verified mark
One recognition, not a chain: A CLS label obtained through mutual recognition cannot be used to apply for another partner scheme. A developer holding the Traficom label can obtain the CLS label through recognition, but cannot then use that CLS label to apply for Germany's IT Security Label. Plan the entry point around your largest market, not the cheapest test.

Why enterprise buyers should care when CLS is not mandatory

Industrial sensors, factory gateways, building controllers and fleet trackers are not consumer IoT, so CLS does not bind them. Three reasons it still matters.

  • It is becoming a procurement field, not a marketing badge. A CLS level is one of the few device-security signals a buyer can put in a tender as a pass/fail criterion and check against a published product list.
  • The tiers are a usable specification even unlabelled. ETSI EN 303 645's fourteen provisions, an SBOM, a vulnerability disclosure policy and a stated update lifetime are reasonable contractual asks for an industrial device whether or not anyone applies for a label.
  • Mixed estates are the real risk surface. Consumer-grade access points, cameras and smart plugs end up on enterprise sites constantly — pantries, meeting rooms, showrooms, satellite offices. The unmanaged consumer device is usually the weakest node on an industrial network.

For the systems layer above the device, Singapore Standard SS 711:2025, “IoT security for Smart Nation — Concepts and common requirements”, supersedes TR 64:2018 and sets out IoT threat modelling and four security design principles: secure by defaults, rigour in defence, accountability and resiliency. SS 695:2023 handles the interoperability half. The IMDA IoT Cyber Security Guide, updated to Version 2 in October 2025, turns both into checklists and case studies aimed at enterprise deployers and their vendors. All three are worth reading before you write an IoT tender.

Wireless connectivity playbook for Singapore deployments

Most Singapore deployments end up hybrid: low-power wide-area for the sensors, Wi-Fi or cellular for anything that moves or carries video. The table below ranks the options by the thing engineering comparisons usually omit — how much regulatory work each choice creates.

OptionRangePowerLatencyMobilityRelative costBest fitRegulatory friction
Wi-Fi 6/6E/7Indoor, per-APMains or frequent chargeLowIn-building roamingLow per device, higher per siteCameras, tablets, human–robot collaboration, high-throughput indoorLow — ESER, free, licence-exempt. Only the lower 6 GHz band is open
Bluetooth, Zigbee, Thread, NFCMetres to tens of metresCoin cell to yearsLowLocal onlyLowestBeacons, wearables, local control, commissioningLow — ESER, free, within TS SRD limits
UWBRoom-scaleModerateVery lowLocal, high precisionModerateCentimetre-accurate location, access control, robot dockingHigher — mandatory GER with technical evaluation
LoRaWAN and LPWANKilometresMulti-year batterySecondsStatic or slowLow per nodeMeters, environmental sensing, smart buildings, asset trackingLow for end devices — ESER on 917–925 MHz. Gateways may fall to GER
NB-IoT and LTE-MNationwide, deep indoorMulti-year batterySub-second to secondsLTE-M handles moving assetsLow device, per-SIM recurringMetering, tracking, lifts, remote plantModerate — SER at $100, operator spectrum, no separate network licence
4G, 5G SA and RedCapNationwideMains or large batteryLowFullModerate to highVideo analytics, mobile robots, vehicles, teleoperationModerate — SER, plus TS CMT and TS CD-SEC obligations for cellular behaviour
Private 5G or campus networkSite-wideMainsVery low, controllableFull on siteHighestManufacturing, ports, logistics yards, deterministic controlHighest — GER base stations plus an IMDA network licence and spectrum via IRIS

Three Singapore-specific notes. Cellular coverage is genuinely nationwide and standalone 5G is the norm, which removes a planning constraint that still exists elsewhere. LoRaWAN does not have to be built from scratch — SPTel operates a nationwide sensor network on solar-powered LoRaWAN gateways reaching most of the heartland, so a pilot can start with coverage-as-a-service instead of infrastructure. And the 6 GHz constraint is real: with only the lower 500 MHz open, dense Wi-Fi 7 designs here lean on 160 MHz channel plans and Multi-Link Operation rather than blanket 320 MHz channels.

For the technology deep-dives behind this table, see LoRaWAN in 2026, private 4G and 5G networks, private 5G for enterprise and satellite NTN IoT for sites beyond terrestrial coverage. IoT for business covers the architecture and protocol layer that sits above the radio.

The enterprise layer: 5G, edge AI and autonomous mobile robots

Singapore's IoT story has moved past sensors reporting temperature. The active frontier is robots and edge inference sharing the same site network as the sensors, and that changes the engineering and the security picture at once.

IMDA's own programme is the clearest signal. In November 2025 it launched AMR x Digital Leaders, bringing autonomous mobile robots to 500 local enterprises over three years with partners including Singapore Polytechnic, Panasonic, dConstruct Robotics and CapitaLand's SMARTLab. IMDA's study of around 50 digitally mature enterprises across built environment, manufacturing, logistics and hospitality found 80% of those without deployments planned to adopt AMRs within two years — but 65% were unsure which solution fit, and 70% of interested enterprises hit integration problems, particularly multi-floor operation in Singapore's high-rise environment. IMDA is co-funding pre-approved lift-integration solutions precisely because the lift is where AMR projects stall. Enterprises already running AMRs reported a 22% increase in workforce retention, and 25% better workplace safety within the built environment sector.

Elsewhere, Hyundai Motor Group's Innovation Centre Singapore runs a building-wide 5G network feeding a digital-twin manufacturing platform, and JTC's Punggol Digital District runs its Open Digital Platform across tens of thousands of sensors and building systems. Three design consequences follow for anyone mixing robots, sensors and AI on one site.

  • Hybrid by default, not by accident. Wi-Fi carries cameras and tablets, private or public 5G carries mobile robots and anything needing deterministic latency, LPWAN carries battery sensors. Decide which traffic class lives where before procurement — each has a different registration path.
  • Interoperability is the scaling constraint. A single-vendor robot fleet works; a mixed fleet that also talks to lifts, doors and the building management system does not, unless the interfaces were specified up front. SS 695:2023 exists for exactly this.
  • Robots widen the blast radius. A compromised sensor leaks data; a compromised AMR moves through controlled space, holds building-system credentials and can call a lift. Segment robot traffic from sensor traffic and from corporate IT, apply SS 711's design principles to the fleet-management platform, and treat the robot vendor's cloud as a third-party dependency with an exit plan.

The 10-step compliance roadmap, design to deployment

  1. Classify every device. List each radio, antenna, interface and firmware branch, and decide per SKU whether it is consumer IoT, enterprise IoT, user equipment or infrastructure. This step determines every route that follows.
  2. Lock the band plan to Singapore. Check frequency, channel and output-power limits against the current IMDA technical specification for that device class before ordering production firmware.
  3. Appoint the Singapore applicant. Incorporate, or name the distributor or representative holding the Telecommunication Dealer's Licence, and confirm the licence class matches local sale versus re-export.
  4. Choose the registration route. ESER, SER, GER, GER-CB or COFC — and price it, including the family-series fee if you are registering a range.
  5. Assemble the technical file. Supplier's Declaration of Conformity, test reports, photographs, label artwork, manuals, antenna and module evidence, RF exposure and safety data.
  6. Submit through GoBusiness and answer queries quickly. Incomplete submissions, not hard technical failures, are what stretch timelines.
  7. Run the CLS track in parallel where it applies. Engage an approved testing laboratory early — a lab review is required before Level 1 and Level 2 applications, so it is a lead-time item, not a rubber stamp.
  8. Design the security baseline into the deployment, not just the device: unique credentials, enforced updates, secure boot, encryption in transit and at rest, segmentation, an SBOM and supply-chain controls, following SS 711:2025 and the IMDA IoT Cyber Security Guide.
  9. Settle the network architecture and any extra licences. Public cellular needs no network licence; a private or campus network needs one from IMDA through IRIS, plus spectrum, and the base stations need GER.
  10. Label, record and diarise. Affix the IMDA compliance label with the dealer registration number (and the CSA label for routers), keep the evidence for the five-year term, and diarise renewal and specification reviews.
Verify before you file: Fees, processing targets, approved-laboratory lists, specification revisions and scheme scope all change, and several changed in the last eighteen months — CLS fees on 1 April 2025, TS CMT in March 2026, TS RG-SEC in June 2026. Every figure here comes from IMDA and CSA publications current at the time of writing. Confirm the live position on the IMDA equipment registration pages, the CSA CLS(IoT) pages and GoBusiness before you budget, quote or submit. This is a practical compliance guide, not legal advice.

Common mistakes that cost weeks

  • Choosing the wrong scheme. Filing a base station under SER, or a sensor under GER because someone assumed IoT is high-risk. The routing is published; read it before you pay.
  • No local dealer licence. The most expensive mistake, because it surfaces late. There is no registration route for a foreign entity acting alone, and appointing a distributor is a commercial negotiation, not a form.
  • US or EU band plan left in the firmware. Especially sub-GHz. Singapore's SRD band is 917–925 MHz; a US 902–928 MHz build is not registrable and not fixable at the border.
  • Treating CLS as optional marketing. For routers it is compulsory and the bar rises to Level 2 by end-2027. For everything else it is increasingly a procurement requirement — slower, but equally real.
  • Ignoring the gateway. Teams harden the sensor and leave the router, gateway or edge box on default credentials with no update path. That device is the one on the botnet lists.
  • Confusing consumer CLS with industrial security programmes. A four-asterisk consumer label says nothing about OT segmentation, safety instrumented systems or IEC 62443 zones — see the IEC 62443 OT security guide for plant environments.
  • Assuming registration grants spectrum rights. A registered radio can still be unusable if operating it needs an assignment, a station licence or a network licence.
  • Forgetting renewal. Five years passes. Renewal is cheap; an expired registration discovered during a customer audit is not.

The pre-launch checklist

If you are building the vendor side of this — sourcing an integrator, a sensor supplier or a private-network partner — the directory lists IoT companies in Singapore, system integrators, telecommunications providers and robotics companies.

Frequently asked questions

Is IMDA registration required for all IoT devices in Singapore?

It is required for most radio-emitting equipment sold or supplied for local use. The route depends on the device: short-range and low-power radios such as Wi-Fi, Bluetooth and LoRa go through ESER, which is free; IoT user equipment goes through SER at $100; IoT base stations, repeaters, UWB and DSRC devices require GER. Equipment that IMDA exempts from registration can optionally take a Confirmation of Conformity instead.

Can an overseas manufacturer register equipment with IMDA directly?

No. Applicants must be equipment suppliers or dealers holding a valid IMDA Telecommunication Dealer's Licence, which requires a Singapore-registered entity with a UEN. An overseas manufacturer either incorporates locally or appoints a Singapore distributor, importer or authorised representative that holds the licence to apply on its behalf.

How much does IMDA equipment registration cost?

ESER is free. SER is $100. GER is $350 or $500 depending on the equipment type. GER-CB is $100. A Confirmation of Conformity is $100 by self-declaration or $350 with IMDA evaluation. A $50 family series fee applies to SER, GER and GER-CB, and renewal is $50. Confirm current fees on IMDA's equipment registration page before budgeting.

How long is an IMDA equipment registration valid?

Five years for ESER, SER, GER and GER-CB, renewable at $50. A Confirmation of Conformity has lifetime validity. A compliance-affecting hardware, antenna or firmware change can require re-registration before the modified equipment is supplied for local use, regardless of how much of the five years remains.

Do I need local testing, or will FCC and CE reports do?

Local retesting is often unnecessary. FCC, ETSI and CE reports are widely used to support a Singapore Supplier's Declaration of Conformity, and the GER-CB route exists for certification bodies recognised under MRA Phase II. But foreign approval is supporting evidence rather than a substitute: it does not carry Singapore-specific requirements such as the local band plan or the cellular and router security specifications.

Is CLS mandatory for enterprise or industrial IoT?

No. The only mandatory scope is Wi-Fi routers and residential gateways, which must comply with IMDA TS RG-SEC and hold at least CLS Level 1. For all other devices the label is voluntary. Enterprises still routinely require CLS levels or equivalent evidence in tenders, because it is one of the few device-security signals that can be checked against a published product list.

What is the difference between CLS Level 1, 2, 3 and 4?

Each level corresponds to an assessment tier, completed in sequence. Level 1 covers baseline requirements from ETSI EN 303 645: unique default passwords, vulnerability disclosure and software updates. Level 2 requires all mandatory ETSI EN 303 645 provisions. Level 3 adds security in the development lifecycle plus a laboratory binary analysis against the software bill of materials. Level 4 adds penetration testing by an approved laboratory.

When do Singapore Wi-Fi routers have to reach CLS Level 2?

By end-2027. CSA announced on 2 March 2026 that it will work with IMDA to raise the mandatory requirement for residential routers from Level 1 to Level 2, citing sophisticated attacks against encryption, authentication and storage. IMDA published Issue 2 of TS RG-SEC in June 2026. The requirement is confirmed; the final compliance mechanics are still being settled.

Which frequency band should a LoRa device use in Singapore?

917 to 925 MHz. IMDA TS SRD Issue 1 Revision 3, published in September 2023, amended the sub-GHz short-range device band from 920-925 MHz to 917-925 MHz. A device shipped with a US 902-928 MHz band file must be locked to the Singapore channels and power limits before registration; it cannot be corrected after import.

Does Singapore allow Wi-Fi 6E and Wi-Fi 7 in the 6 GHz band?

Yes, but only the lower portion. IMDA TS SRD Revision 3 added 5,945 to 6,425 MHz for licence-exempt wireless LAN use; the upper part of the 6 GHz band has not been opened. In practice that means one 320 MHz channel rather than the three available in full-band markets, so dense enterprise designs here rely on 160 MHz channel plans plus Multi-Link Operation.

Do I need a separate licence to run a private 5G network in Singapore?

Yes. Registering the base stations under GER covers the equipment; operating the network does not follow automatically. A private or campus network needs a Network Licence (Localised Private Network) from IMDA, applied for through the IRIS portal, together with the relevant spectrum arrangement. Engage IMDA early, because this is the longest lead-time item in a private-network project.

How long does IMDA equipment registration take?

ESER, being a self-declaration route, can clear very quickly. SER and GER carry published processing targets that assume a complete submission, and GER involves a manual technical evaluation, so it is the slowest of the three. The variable is almost never IMDA's queue — it is whether the technical file, labels and photographs are complete and internally consistent at submission. Check the current published processing times before you commit to a launch date.

Sources and further reading