From April 13 next year, home routers will have to meet new security requirements before they can be sold in Singapore. These include unique login credentials and default automatic downloads of security patches.
The new mandate aims to improve the security of these devices, which are popular targets for malicious hackers seeking to compromise home networks, according to the Infocomm Media Development Authority (IMDA) regulator. As part of the country’s technical specifications for Residential Gateways, the enhanced security requirements were finalized following a prior consultation process that sought feedback from the public.

While these orders are set to come into effect from April 13, 2021, home routers that were previously approved by IMDA will be allowed to remain on sale until October 12 next year.
Users of existing home routers will not need to replace their current routers, but are encouraged to purchase devices that comply with IMDA security requirements when they next upgrade or replace them. Users should also regularly update their device firmware.
“Home routers are often the first point of entry for cyberattacks targeting the public, as they are the key bridge between the internet and residents’ home networks,” IMDA said in a statement on Monday. “[The] minimum security requirements for home routers [will] provide a safer and more secure internet experience for users and enhance the resilience of Singapore’s telecommunications networks.”
The government agency added that the move came amid the continued adoption of networked smart devices in homes, such as cameras and baby monitors, which has led to higher risks of cyberattacks targeting such devices. It noted that Japan imposed similar requirements in April this year.
In Singapore, enhanced security requirements include randomized and unique login credentials for each device, minimum password, disabling system services and interfaces considered vulnerable, default automatic firmware update for security patches, secure authentication of access to device management interfaces, and validation of data inputs to the device to protect against remote hacking.
