Skip to content
solutions@huorgcology.com

275 Beach Road, #03-00, Singapore 199459

SME tech after PSG: EDGE grants, InvoiceNow-ready systems, and the security duties that sit under a Singapore website

October 3, 2026

The grant most Singapore SMEs were told to use for digital projects has closed. Enterprise Singapore's EDGE Grant page states that the Enterprise Development Grant (EDG), Market Readiness Assistance (MRA) and Productivity Solutions Grant (PSG) ceased on 29 September 2026, and that from 30 September 2026 new applications go to EDGE. At the same time, GST businesses are being pushed onto InvoiceNow-capable finance systems. The website and the accounts file are no longer separate IT jobs you can hand to two vendors and forget.

This is for owners about to rebuild a site, move accounting or HR onto a cloud system, or take card and customer data for the first time. If you run a foreign-owned company here and expect a local grant to pay for your Singapore site, read the ownership section first.

PSG is closed for new projects

What continues is narrower than people hope:

  • Applications for EDG, MRA, or PSG submitted before 30 September 2026 are still assessed under those schemes (EDGE FAQ).
  • Ongoing projects continue, and claims can be submitted on completion.
  • There are no new applications under those three schemes.

For reference, PSG offered support of up to 50% and up to $30,000, with a group-sales and headcount test and a 30% local-equity test. None of that applies to new applications. If a Cyber Security Agency page still lists PSG cybersecurity solutions, check whether the same solution now sits under EDGE or on the current CSA or IMDA list before you rely on it.

If a vendor's proposal still says "we will put this through PSG", ask them to rewrite the funding section before you sign.

EDGE is not a flat 70% voucher

EDGE covers "over 150 activities" across eight business areas, including Automation and Digitalisation, Business Strategy, Financial Management, Innovation, Internationalisation, Standards and Sustainability. Check the live page for the current list of areas.

The headline is support of up to 70% for SMEs and up to 50% for non-SMEs, and levels differ by activity. The annual cap is $100,000 across all activities, refreshed on 1 April. Support is disbursed on a reimbursement basis: claims are submitted once the activity is completed and full payment has been made. You pay first, and the grant, if approved, comes back later. Cash flow has to survive that gap.

Two examples show why the rate should not be flattened into one number:

  • Business Strategic Planning: up to 50% for SMEs and 30% for non-SMEs, not 70% and 50%.
  • Integrated ERP: up to 50% for SMEs (up to $30,000) and 30% (up to $18,000) for non-SMEs, with the cost of the activity capped at $60,000. Digital and automation support counts toward a $30,000 sub-cap within the $100,000 annual cap. The EDGE FAQ says the sub-cap covers single-function digital solutions, integrated enterprise systems and selected automation.

Activity pages also state that work must not have started, and that no payment or deposit may be made, before the application is submitted. A deposit "to hold the price" can take the spend outside the grant before anyone has read your application.

EnterpriseSG states on its PSG page that there are no compulsory application fees, and that fees quoted by third parties are not endorsed by the Government. If someone invoices you for "EDGE processing", that invoice is theirs, not EnterpriseSG's.

The 30% local-ownership gate

The EDGE FAQ is plain about ownership. The applicant must be registered in Singapore, with at least 30% Singapore citizen or PR ownership. EDGE activity pages add that this is measured by ultimate individual ownership, direct or indirect.

If your Singapore company is wholly foreign-owned, it does not meet the EDGE ownership test. The same test applied under PSG, so its closure did not open a route for foreign-owned groups. Plan the system on its own commercial and compliance merits, without counting on a grant.

Foreign companies still need working finance, HR and web systems in Singapore. Build them sensibly, and do not put "the grant will cover 70%" into the business case unless ownership and activity eligibility are confirmed on EnterpriseSG's current pages.

Pick systems that can file, not only systems that look modern

For GST-registered businesses, InvoiceNow changes what "good finance software" means. IRAS's onboarding path for off-the-shelf users is short:

  1. Choose an IMDA-accredited InvoiceNow-Ready solution.
  2. Obtain a Peppol ID via the solution provider or access point, using the UEN.
  3. Switch on the GST submission feature.

In-house systems go through an accredited Access Point. IRAS says onboarding may take as little as three months and that most businesses finish within a year, depending on readiness. That is not a promise. For InvoiceNow onboarding questions, IMDA's contact is einvoice@imda.gov.sg.

Mandate dates are covered in HuOrgCology's YA 2026 and InvoiceNow article. In short: new voluntary GST registrations on or after 1 April 2026 already need InvoiceNow, and remaining GST-registered businesses are phased from 1 April 2028 through 1 April 2031 by 2025 annual supplies. IRAS's e-Tax Guide says the legislative amendments for the remaining group will be enacted later, so the later phases are not yet in the Goods and Services Tax Act 1993.

ACRA XBRL filing and IRAS Form C-S software links also sit with your finance system. Lists change, so confirm any product on the official IMDA InvoiceNow-Ready list, and on any EDGE pre-approved list, in the week you choose it.

A small site is still an organisation under the PDPA

If your Singapore site collects personal data, you are an organisation under the Personal Data Protection Act for that processing. Enquiry forms, newsletter sign-ups, customer accounts, and payment details all count. "We are small" is not a category the Act uses to let you skip the basics.

The basics are legal duties, not best practice:

  • Designate at least one individual as your data protection officer, and make the business contact information of that person publicly available (for example on the website).

  • Put reasonable security arrangements in place that match the data you hold, and check what your vendors and hosting providers do with it.

Have a simple way to assess a suspected breach. It does not need to be a 40-page policy, but someone in the business must know where it is and own it.

Under Part 6A of the PDPA (in force since 1 February 2021, with the Personal Data Protection (Notification of Data Breaches) Regulations 2021), a data breach is notifiable if it is likely to result in significant harm to individuals, or if it is of significant scale, meaning 500 or more individuals are affected. The steps are:

  • Assess a suspected breach promptly.
  • Notify the Personal Data Protection Commission (PDPC) as soon as practicable and no later than three calendar days after you decide the breach is notifiable.
  • Tell affected individuals as soon as practicable where significant harm is likely, at the same time as or after notifying PDPC.
  • If a data intermediary suffers a breach, it must tell you without undue delay.

PDPC's guide on managing and notifying data breaches, dated 15 March 2021, explains the counting: day one is the day after the determination, so a determination on 1 January means notify by 4 January. If the number affected is uncertain, notify when there is reason to believe it is at least 500. PDPC also has a current page, "Report Your Organisation's Data Breach" (published 22 April 2026), and you should check PDPC for the latest edition of the guide.

Under section 48J of the PDPA, the maximum financial penalty for an organisation that intentionally or negligently breaches its data protection obligations, including the breach notification duties in Part 6A, is 10% of its annual turnover in Singapore if that turnover exceeds $10 million, and $1 million in any other case (in force since 1 October 2022). Those are statutory maximums, not a forecast.

Security funding and the basics that do the work

For cybersecurity spend, use the current CSA and IMDA pre-approved lists where they still exist. If an older recommendation pointed you to PSG, check what replaces it under EDGE or today's lists. Ordinary controls do the quiet work: access control, backups, vendor contracts that say who holds which data, and patching. None of that is glamorous, and all of it is cheaper than explaining a missing backup.

SMS sender IDs: only if you text customers under a sender name

A website on a monitor seen from behind a shoulder, content fully out of focus.

If your business sends SMS to Singapore mobiles under an alphanumeric sender ID, the full SMS Sender ID Registry has applied since 31 January 2023. Organisations had to register with SGNIC, use an IMDA-licensed participating aggregator, and hold a Singapore UEN. Check IMDA or SGNIC for the current rules before you set this up.

Three questions before you buy

Before you sign a hosting, accounting or HR-system contract, ask three questions. Is EDGE even open to this ownership structure? Does the finance system need to be InvoiceNow-capable for your GST date? Does the site collect personal data that needs a named person responsible?

We can help you work through those three questions before you commit to a vendor. We do not approve grants. For a short systems-and-eligibility conversation, write to solutions@huorgcology.com or call +65 9789 4150.

Legislation, regulators and sources

Legislation and regulators referred to: Personal Data Protection Act 2012 (Part 6A) and Personal Data Protection (Notification of Data Breaches) Regulations 2021; Goods and Services Tax Act 1993; regulators and agencies: Enterprise Singapore, IRAS, PDPC, IMDA, CSA, ACRA.

  • Enterprise Singapore, EDGE Grant page (as at October 2026); EDGE FAQ; activity pages for Business Strategic Planning and Integrated ERP; PSG page (scheme ceased 29 September 2026).

  • IRAS, GST InvoiceNow Requirement; e-Tax Guide on adopting the GST InvoiceNow requirement.

  • PDPC, Report Your Organisation's Data Breach (published 22 April 2026); Guide on Managing and Notifying Data Breaches under the PDPA (15 March 2021 edition).

  • CSA, PSG cybersecurity solutions page (historical).

  • IMDA, Full SMS Sender ID Registry regime factsheet (from 31 January 2023).

This article is general information for Singapore SMEs and foreign companies operating here. It is not grant, PDPA, or cybersecurity legal advice.

Need support applying this insight?

Speak with our team for practical, Singapore-focused support across corporate, accounting, HR, and technology operations.

← Back to Insights