What We CoverOur ApproachClient StoriesInsightsAboutSchedule a Consultation
All insights

Singapore's DC-CFA2 data centre approvals: what the new generation of facilities means for construction and operational insurance

Four operators have been approved under Singapore's DC-CFA2 programme to develop 200MW of new data centre capacity. The facilities they are building incorporate BESS infrastructure, advanced liquid cooling, and novel green energy systems that create a materially different insurance profile from previous generation data centres. Here is what the construction and operational insurance implications look like.

The Straits Times reported on 21 August 2026 that four operators have been approved to develop new data centre capacity in Singapore under the government's second Data Centre Call for Application, known as DC-CFA2. The approved projects will collectively bring at least 200 megawatts of new capacity online, the most significant addition to Singapore's data centre market since the moratorium on new construction was lifted.

The DC-CFA2 programme, launched jointly by the Economic Development Board and the Infocomm Media Development Authority in December 2025, set requirements that go significantly beyond those of the initial 2023 allocation. Approved operators must achieve a Power Usage Effectiveness ratio of 1.25 or better at full load, source a minimum of 50 per cent of their electricity from green energy pathways, and meet Green Mark Platinum certification standards. The framework reflects Singapore's stated objective of making sustainability a prerequisite for market access rather than an optional enhancement.

For the data centre sector, the significance of the DC-CFA2 approvals extends beyond the capacity addition. The sustainability and technical requirements that successful applicants have committed to deliver represent a meaningful shift in the physical design, engineering systems, and risk profile of the facilities being built. And that shift has direct implications for how these facilities, and the contractors building them, approach insurance.

What the DC-CFA2 requirements mean for the facilities being built

The technical standards that DC-CFA2 operators must meet are not incremental improvements on conventional data centre design. They reflect a step change in the engineering approach required to achieve a PUE of 1.25 or better at scale, in Singapore's tropical climate, while sourcing the majority of power from non-grid sources.

Three specific engineering dimensions create the most significant insurance considerations.

Battery energy storage systems at scale. Meeting the 50 per cent green energy requirement will in most cases involve significant battery energy storage infrastructure, whether as part of an on-site solar and storage configuration, as part of a fuel cell and storage arrangement, or as a buffer for intermittent renewable supply. Lithium-ion battery energy storage systems, which are the most commercially proven technology at data centre scale, carry a specific and well-documented fire risk. Thermal runaway in a lithium-ion battery pack is extremely difficult to suppress with conventional systems and can sustain combustion for many hours.

The 2024 Singapore data centre battery fire, which burned for more than 36 hours and significantly disrupted cloud services for downstream clients according to a sigma report on data centre risks published in 2026, illustrated this risk profile in the Singapore market context. For DC-CFA2 facilities that incorporate BESS infrastructure at significantly larger scale than previous generation facilities, the fire suppression design, the remediation cost provisions in the property insurance, and the business interruption coverage during a BESS incident require specific attention in the insurance programme.

Advanced liquid cooling infrastructure. Achieving a PUE of 1.25 at the compute densities required for AI workloads is not achievable with conventional air cooling. DC-CFA2 facilities will incorporate direct liquid cooling, immersion cooling, or rear-door heat exchanger systems at scale. These cooling approaches introduce different failure modes from air-cooled infrastructure: coolant leaks, pump failures, heat exchanger contamination, and interactions between cooling fluid and electronic components.

For construction-phase insurance under a Contractor's All Risk policy, specialist mechanical and electrical infrastructure of this kind requires specific attention to how the policy addresses testing and commissioning of cooling systems handed over in stages, damage to high-value compute infrastructure during coolant system testing, and latent defects in cooling system components that manifest after practical completion.

For operational-phase insurance under an Industrial All Risk policy, the cooling system is a critical single point of failure. A cooling system failure in a high-density AI compute environment can cause thermal shutdown of servers within minutes. The business interruption sum insured needs to reflect the revenue impact of a realistic cooling failure scenario at the contracted SLA level, not only the cost of repairing the physical cooling infrastructure.

Fuel cell, hydrogen, and novel green energy pathways. The DC-CFA2 programme explicitly incentivises operators that adopt innovative green energy pathways including fuel cells with carbon capture, low-carbon hydrogen, and bioenergy. These technologies, while commercially proven in other sectors, are relatively new to data centre applications at hyperscale. The risk profile of a fuel cell installation or a hydrogen infrastructure system at a data centre is different from the risk profile of a conventional diesel generator backup system, and it requires underwriters who have experience with these energy systems to price and structure the cover appropriately.

The construction phase: CAR insurance for next-generation facilities

The construction of a DC-CFA2 compliant data centre is a complex multi-year programme involving structural works, specialist electrical infrastructure, advanced cooling systems, battery energy storage installation, and in some cases novel green energy infrastructure. Each of these elements carries its own risk profile during the construction period.

Contractor's All Risk insurance for a data centre construction project of this type needs to address several specific considerations.

The contract works sum insured must reflect the full replacement value of the infrastructure being constructed at any given stage, including the specialist mechanical and electrical components that represent a significant proportion of total project cost and that have long lead times for procurement if damaged.

The third-party liability section needs to address the specific risks of construction activity at or adjacent to operational data centre facilities, as many DC-CFA2 projects involve expansion of existing campuses. Damage to an adjacent operational facility from construction activities, or disruption to an operational facility's power or cooling supply during construction, creates third-party liability with significant potential quantum.

The testing and commissioning provisions for specialist systems, including cooling infrastructure, battery energy storage systems, and power distribution equipment, need to be specifically addressed. Damage to specialist equipment during commissioning, before practical completion and transfer to the operator's IAR policy, requires clear coverage under the CAR policy.

For main contractors and specialist subcontractors working on DC-CFA2 projects, confirming the coverage scope before works commence is a practical step that is more useful than discovering a gap when an incident occurs.

You can read more about our CAR cover on the products page.

The operational phase: IAR and cyber insurance for the facility in service

Once a DC-CFA2 facility is operational, the insurance programme shifts from construction risk to operational risk. Two products address the primary exposures.

Industrial All Risk insurance covers physical loss or damage to the facility and its infrastructure, and business interruption during the period the facility cannot operate normally following an insured event. For a DC-CFA2 facility, the business interruption sum insured is the most consequential coverage decision.

Data centre revenue under colocation and cloud service agreements is contractual and continuous. A facility that cannot provide power, cooling, or connectivity to tenants is in breach of its service level agreements from the first minute of the outage. The business interruption indemnity period needs to reflect the time required not only to repair the physical damage but to restore the facility to operational status and resume contracted service levels, which may be significantly longer than the physical repair timeline.

For the BESS infrastructure specifically, the IAR policy needs to address the suppression and remediation costs of a lithium-ion battery fire, which are materially different from the costs of suppressing and remediating a conventional property fire. These costs include the extended suppression effort, specialist remediation of battery residue, environmental management of fire suppression discharge, and the procurement and replacement timeline for BESS units, which may involve significant lead times.

Cyber insurance for a DC-CFA2 facility addresses two distinct risk dimensions.

The first is the facility's operational technology systems: the power management systems, cooling control systems, environmental monitoring systems, and physical access control systems that manage the facility's physical operations. These systems are increasingly networked and increasingly exposed to the same threat landscape as conventional IT systems. A cyber attack on a facility's OT infrastructure can cause physical consequences, as demonstrated by incidents in other sectors where manipulation of industrial control systems caused physical damage to equipment.

The second is the colocation tenant dimension. Tenants whose data and workloads are hosted at the facility carry their own cyber exposures arising from incidents in their own systems. For the facility operator, the relevant question is whether a cyber incident originating in a tenant's environment creates any liability for the operator, and whether the facility's own cyber policy is structured to address OT risks rather than only conventional IT infrastructure.

You can read more about our IAR cover and cyber insurance on the products page. Our existing post on Data Centre Insurance in Singapore covers the broader insurance framework for operators, tenants, and contractors.

What the DC-CFA2 approvals mean for the insurance market

The approval of four projects under DC-CFA2 signals that Singapore's data centre expansion will continue at a meaningful pace, with the next generation of facilities incorporating engineering systems that are materially more complex than those of the previous generation.

For the insurance market, the DC-CFA2 generation of facilities creates a need for underwriting expertise that goes beyond standard data centre property insurance. The combination of large-scale BESS infrastructure, advanced cooling systems, AI compute density, and novel green energy pathways produces a risk profile that requires underwriters and advisers who understand both the technical engineering and the insurance coverage dimensions of these systems.

For contractors, subcontractors, and specialist trade firms working on DC-CFA2 projects, the construction insurance requirements flowing through the main contract and subcontract conditions reflect the complexity of the project and the potential quantum of a construction-phase incident at this scale.

If you are a data centre operator, a construction contractor, or a specialist subcontractor working on Singapore's next generation of data centre projects and would like to understand how the insurance programme should be structured for the specific engineering systems involved, we would be glad to work through it with you.

This article provides general information only. It is not insurance or legal advice. Information on DC-CFA2 requirements sourced from EDB, IMDA, and published industry analysis. The Straits Times report on DC-CFA2 approvals published 21 August 2026 is the news hook for this post. Battery fire incident data sourced from a sigma report on data centre risks published in 2026. Market valuation data sourced from ResearchAndMarkets Singapore Data Centre Market report published January 2026. Policy availability, terms, conditions, and exclusions vary by insurer and product, and cover is subject to the full policy wording. Please contact TZY CO for advice on your specific situation.

Wondering how this applies to your business?

Schedule a Consultationor message us on WhatsApp →
Back to all insights