Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

CSA STAR Certification in Malaysia | NCCP & PDPA

CSA STAR Certification in Malaysia covering NCCP, Cyber Security Act, NCII, PDPA, BNM RMiT, industries, locations, cost and requirements.

  1. Home
  2. Knowledge Centre
  3. CSA STAR Certification in Malaysia | NCCP & PDPA

CSA STAR Certification in Malaysia: NCCP, Cyber Security Act, PDPA & Cloud Compliance

CSA STAR Certification in Malaysia: NCCP, Cyber Security Act, PDPA & Cloud Compliance
Learn about CSA STAR Certification in Malaysia, including NCCP, Cyber Security Act 2024, NCII, PDPA, BNM RMiT, industries, locations, cost and requirements.

CSA STAR Certification in Malaysia: NCCP, Cyber Security Act 2024, PDPA & Cloud Compliance

SCS Certification – Malaysia Office

SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia

Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification

http://www.scscertification.com/contactus.php

Cloud services are now part of everyday business infrastructure in Malaysia. Banks use cloud platforms for digital services, manufacturers depend on connected systems, healthcare organisations manage sensitive information electronically, and technology companies deliver SaaS applications to customers across Malaysia and overseas.

As cloud adoption grows, customers are asking a straightforward question: how can a cloud service provider demonstrate that its security controls are actually working?

CSA STAR provides one recognised route for demonstrating cloud-security assurance.

The Cloud Security Alliance (CSA) STAR programme is designed around transparency, cloud security controls and independent assurance. The programme uses the Cloud Controls Matrix (CCM) as its central control framework. CSA describes Level 1 as a self-assessment route and Level 2 as a third-party assurance route, including STAR Certification and STAR Attestation. STAR Certification combines ISO/IEC 27001 requirements with CSA CCM, while STAR Attestation combines SOC 2 with CCM.

For Malaysian organisations, however, CSA STAR should not be viewed in isolation. A practical cloud-security programme may also need to consider Malaysia's National Cloud Computing Policy, the Cyber Security Act 2024, the Personal Data Protection Act 2010 and its amendments, sector-specific requirements, contractual obligations and financial-sector technology-risk requirements.

This makes a Malaysia-specific approach more useful than simply following a generic CSA STAR checklist.

What Is CSA STAR Certification in Malaysia?

CSA STAR is the Cloud Security Alliance's Security, Trust, Assurance and Risk programme for demonstrating cloud-security and privacy assurance.

There are different routes within the STAR programme.

Level 1 uses the Consensus Assessments Initiative Questionnaire (CAIQ) and CCM for a self-assessment. Level 2 provides independent third-party assurance. CSA STAR Certification is associated with ISO/IEC 27001 and CCM, while STAR Attestation is associated with SOC 2 and CCM.

For a Malaysian cloud service provider, the value of CSA STAR can be particularly relevant when enterprise customers, financial institutions, multinational companies or public-sector customers ask for evidence of cloud-security controls.

Why CSA STAR Matters for Malaysian Cloud Service Providers

A Malaysian cloud provider may face security questions from several directions.

A customer may ask about access control. Another may request evidence of vulnerability management. A bank may ask about technology risk. An international customer may require ISO/IEC 27001, SOC 2 or CSA STAR evidence.

Instead of answering every customer questionnaire separately, a structured assurance programme can provide a clearer way to communicate the organisation's control environment.

CSA states that the STAR Registry is publicly accessible and is intended to document security and privacy controls provided by cloud offerings.

For Malaysian providers, this can be useful when entering markets outside Malaysia as well as when competing for domestic enterprise contracts.

CSA STAR and Malaysia's National Cloud Computing Policy

Malaysia's National Cloud Computing Policy (NCCP) was launched in August 2025. The Ministry of Digital describes it as a national policy intended to support a secure, sovereign, inclusive and sustainable cloud ecosystem. Its five pillars cover public-sector transformation, private-sector growth, secure data protection and privacy, digital inclusivity and environmental sustainability.

The NCCP is therefore highly relevant to organisations building or operating cloud services in Malaysia.

CSA STAR does not replace the NCCP. Instead, organisations can use cloud-security assurance frameworks such as CSA CCM as part of a broader control environment that supports cloud governance.

Malaysia's NCCP itself identifies relevant laws and standards affecting cloud computing, including the Personal Data Protection Act 2010, Communications and Multimedia Act 1998 and Cyber Security Act 2024.

CSA STAR and the Cyber Security Act 2024

The Cyber Security Act 2024 [Act 854] is an important part of Malaysia's cyber-security landscape.

NACSA states that the Act establishes arrangements concerning the National Cyber Security Committee, NACSA leadership, National Critical Information Infrastructure (NCII) sector leads and NCII entities, cyber-security threats and incidents affecting NCII, and licensing of specified cyber-security service providers.

The Act came into operation on 26 August 2024.

CSA STAR does not make an organisation automatically compliant with Act 854.

Instead, Malaysian organisations should map applicable statutory and regulatory obligations against their own control framework.

For an organisation connected to NCII, that distinction is especially important.

CSA STAR and Malaysian NCII Requirements

Organisations operating within Malaysia's NCII environment may have obligations that go beyond a normal commercial cloud-security programme.

The Cyber Security Act addresses the management of cyber-security risks and incidents involving NCII. NACSA also publishes regulations covering cyber-security risk assessment and audit, incident notification and licensing of cyber-security service providers.

CSA STAR can support evidence of structured cloud-security controls, but it should not be presented as a substitute for statutory NCII obligations.

CSA STAR and the Personal Data Protection Act

Malaysia's Personal Data Protection Act 2010 [Act 709] is another important consideration for commercial organisations processing personal data.

Malaysia's National Cloud Computing Policy identifies the Act as applicable to processing of personal data in commercial transactions and notes requirements concerning data protection principles, security measures, Data Protection Officers, breach notification and data-subject rights.

For cloud providers processing personal data for customers, security controls therefore need to be considered alongside contractual and privacy obligations.

CSA CCM can help organise technical and organisational security controls, but it does not replace Malaysian privacy law.

CSA STAR, Data Protection Officers and Breach Management

A Malaysian organisation should determine whether the relevant PDPA requirements apply to its activities and whether it has obligations concerning a Data Protection Officer, personal-data breach management and related governance.

A mature CSA STAR preparation programme should therefore include:

  • data classification;
  • access management;
  • privileged-access controls;
  • encryption;
  • incident response;
  • logging;
  • monitoring;
  • supplier management;
  • backup and recovery;
  • vulnerability management;
  • privacy governance;
  • documented responsibilities.

The exact legal obligation should always be assessed against the organisation's activities and current Malaysian requirements.

CSA STAR and Cross-Border Data Transfers

Many Malaysian technology companies serve customers outside Malaysia.

A cloud provider may therefore need to understand:

  • where data is stored;
  • where support personnel can access it;
  • which subprocessors are involved;
  • how data is transferred;
  • what contractual safeguards apply;
  • how customers are informed about processing;
  • how deletion and retention are managed.

CSA STAR can provide evidence around security controls, while applicable Malaysian privacy requirements and contractual obligations need to be addressed separately.

CSA STAR and Bank Negara Malaysia RMiT

Financial institutions are one of the strongest potential use cases for cloud-security assurance in Malaysia.

Bank Negara Malaysia's Risk Management in Technology (RMiT) framework addresses technology and cyber risks in the financial sector. BNM's revised RMiT policy was issued on 28 November 2025, with the stated aim of strengthening technology and cyber-risk management, service resilience and trust in financial services.

The BNM policy environment continues to evolve, so Malaysian financial institutions and their technology suppliers should check the current applicable BNM requirements rather than rely on an old checklist.

CSA STAR can be useful as supporting cloud-security assurance where it aligns with the organisation's risk-management and customer requirements.

CSA STAR for Malaysian FinTech Companies

Malaysia's FinTech sector increasingly depends on APIs, cloud infrastructure, SaaS applications, digital payments, mobile platforms and third-party technology services.

A FinTech company preparing for CSA STAR should pay particular attention to:

  • identity and access management;
  • application security;
  • secure software development;
  • API security;
  • encryption;
  • customer-data protection;
  • third-party risk;
  • incident response;
  • business continuity;
  • monitoring;
  • change management.

The objective should be to demonstrate that cloud-security controls operate consistently rather than merely creating documents for an audit.

CSA STAR for Malaysian Banking and Islamic Banking Technology

Banks and Islamic financial institutions operate in a highly controlled technology environment.

A cloud provider serving Malaysian financial institutions may encounter customer requirements covering:

  • technology governance;
  • information security;
  • resilience;
  • outsourcing;
  • privileged access;
  • data protection;
  • audit rights;
  • incident reporting;
  • disaster recovery;
  • supplier monitoring.

CSA STAR can strengthen the provider's security-assurance package when appropriately scoped.

CSA STAR for Malaysian Payment-Service Providers

Payment technology companies can face demanding customer due-diligence requirements.

A Malaysia-focused CSA STAR programme should consider payment processing architecture, APIs, authentication, monitoring, incident response, encryption, vulnerability management and supplier dependencies.

Where Bank Negara Malaysia requirements apply, the organisation should separately evaluate the relevant current policy documents.

CSA STAR for Malaysian Semiconductor and Electronics Companies

Penang and other Malaysian technology clusters are home to semiconductor, electronics and advanced manufacturing businesses.

These companies increasingly use cloud platforms for:

  • engineering collaboration;
  • production analytics;
  • supply-chain management;
  • ERP;
  • research data;
  • design information;
  • remote administration;
  • IoT systems.

A cloud provider serving these businesses may use CSA STAR to demonstrate a structured security-control environment.

CSA STAR for Malaysian Manufacturing

Malaysia's manufacturing sector increasingly combines operational technology with cloud-based analytics and enterprise systems.

Manufacturing organisations should consider controls around:

  • production data;
  • industrial networks;
  • remote access;
  • supplier connectivity;
  • identity management;
  • backup;
  • recovery;
  • endpoint security;
  • vulnerability management.

CSA STAR can complement an organisation's wider information-security programme.

CSA STAR for Malaysian Healthcare Technology

Healthcare organisations and healthcare technology providers handle highly sensitive information.

Relevant control areas include:

  • access control;
  • data classification;
  • encryption;
  • audit logging;
  • incident response;
  • backup;
  • disaster recovery;
  • supplier management;
  • secure application development.

CSA STAR should be positioned as a cloud-security assurance framework, not as a replacement for Malaysian healthcare or privacy requirements.

CSA STAR for Malaysian Telecommunications

Telecommunications and digital infrastructure companies operate large-scale, highly connected environments.

Cloud-security assessments may include:

  • network security;
  • privileged access;
  • availability;
  • resilience;
  • monitoring;
  • vulnerability management;
  • incident response;
  • supplier controls.

The Communications and Multimedia Act 1998 is identified in Malaysia's National Cloud Computing Policy as relevant to certain cloud service providers, including PaaS and IaaS providers subject to the applicable licensing framework.

CSA STAR for Malaysian Data Centres

Data centres are central to Malaysia's cloud and digital-infrastructure expansion.

A data-centre operator or cloud service provider may need to demonstrate controls covering:

  • physical security;
  • environmental controls;
  • access management;
  • availability;
  • redundancy;
  • business continuity;
  • incident management;
  • change control;
  • supplier management.

CSA STAR can provide a cloud-security assurance layer when the relevant service scope is clearly defined.

CSA STAR in Kuala Lumpur

Kuala Lumpur is a major commercial and technology market for Malaysian cloud providers, financial institutions, technology companies and enterprise customers.

A CSA STAR programme in Kuala Lumpur should focus on the actual cloud services being offered and the customer assurance requirements attached to those services.

CSA STAR in Cyberjaya

Cyberjaya is particularly relevant to Malaysia's digital and technology ecosystem.

Cloud providers, managed service providers, software companies and digital businesses operating in Cyberjaya may find CSA STAR useful when demonstrating security assurance to enterprise and public-sector customers.

CSA STAR in Putrajaya

Putrajaya is important for organisations working with government digital services and public-sector technology.

The Malaysia-specific cloud assurance discussion should therefore consider government procurement expectations, cloud security, data governance and applicable public-sector requirements.

CSA STAR in Selangor

Selangor contains major commercial, industrial, logistics and technology activity.

Companies in Petaling Jaya, Shah Alam, Subang Jaya, Klang and surrounding business areas may encounter customer requirements for ISO 27001, SOC 2, CSA STAR or similar security evidence.

CSA STAR in Penang

Penang is particularly relevant to semiconductor, electronics, manufacturing, engineering and technology organisations.

Cloud service providers serving these industries can use CSA STAR to provide structured evidence of cloud-security controls.

CSA STAR in Johor

Johor's industrial, logistics, technology and data-centre development makes cloud security increasingly important.

Organisations in Johor Bahru and Iskandar Malaysia can consider CSA STAR where enterprise customers require independent assurance of cloud controls.

CSA STAR in Melaka

Melaka's manufacturing, technology, healthcare and service sectors provide additional applications for cloud-security assurance.

A Malaysia-specific CSA STAR assessment should be scoped around the actual services and information processed.

CSA STAR in Perak

Perak-based manufacturers, service providers and technology companies using cloud systems can use CSA STAR preparation to improve control visibility and customer confidence.

CSA STAR in Sarawak

Sarawak's energy, infrastructure, government, utilities and technology activities create different cloud-security requirements from those found in Kuala Lumpur.

The control scope should therefore reflect the actual services, data and customer obligations involved.

CSA STAR in Sabah

Sabah-based organisations using cloud applications or delivering technology services can consider CSA STAR when enterprise customers request independent security assurance.

CSA STAR Certification Requirements in Malaysia

The exact requirements depend on the STAR route selected.

For STAR Certification, the organisation needs an appropriate ISO/IEC 27001 foundation and must address the applicable CSA Cloud Controls Matrix requirements. CSA describes STAR Certification as an extension or supplement to the ISO/IEC 27001 assessment process rather than a replacement for ISO certification.

Typical preparation areas include:

  • scope definition;
  • cloud-service architecture;
  • risk assessment;
  • governance;
  • access control;
  • asset management;
  • cryptography;
  • operations security;
  • supplier management;
  • incident response;
  • business continuity;
  • monitoring;
  • compliance;
  • evidence management.

CSA STAR Certification Process in Malaysia

A practical implementation can follow these stages:

  1. Define the cloud service scope.
  2. Identify applicable Malaysian legal and regulatory requirements.
  3. Review existing ISO/IEC 27001 and information-security controls.
  4. Map controls against CSA CCM.
  5. Conduct a gap assessment.
  6. Address control gaps.
  7. Implement and operate required controls.
  8. Collect objective evidence.
  9. Complete internal review and readiness activities.
  10. Arrange the appropriate independent assessment.
  11. Address findings.
  12. Complete the STAR submission or certification process applicable to the selected route.

CSA STAR Certification Cost in Malaysia

There is no single fixed Malaysian price.

Cost depends on:

  • organisation size;
  • number of employees;
  • cloud-service scope;
  • number of locations;
  • existing ISO/IEC 27001 maturity;
  • number of systems;
  • complexity of infrastructure;
  • audit duration;
  • readiness level;
  • consulting requirements;
  • certification or attestation route.

CSA publishes separate fee information for STAR Level 2 certification and attestation, while the overall Malaysian project cost also depends on the organisation's implementation and assessment arrangements.

A proper quotation should therefore be based on the defined scope rather than a generic advertised figure.

How to Get CSA STAR Certification Faster in Malaysia

The fastest approach is usually not to skip controls.

It is to reduce rework.

A Malaysian organisation can improve project speed by:

  • defining the scope early;
  • using an existing ISO/IEC 27001 ISMS;
  • mapping existing controls to CSA CCM;
  • identifying regulatory requirements early;
  • assigning control owners;
  • centralising evidence;
  • completing internal audits;
  • closing gaps before the external assessment;
  • avoiding unnecessary scope expansion.

CSA STAR vs ISO 27001 in Malaysia

ISO/IEC 27001 and CSA STAR are not identical.

ISO/IEC 27001 focuses on an information-security management system.

CSA STAR Certification adds the CSA Cloud Controls Matrix to the ISO/IEC 27001 certification context.

For Malaysian cloud providers, combining the two can provide stronger evidence to customers that both information-security management and cloud-specific controls have been addressed.

CSA STAR vs SOC 2 in Malaysia

SOC 2 is an attestation framework based on AICPA criteria.

CSA STAR Attestation combines SOC 2 with CSA CCM.

CSA STAR Certification instead uses ISO/IEC 27001 together with CSA CCM.

The better route depends on customer expectations, market, existing certifications and contractual requirements.

Is CSA STAR Mandatory in Malaysia?

CSA STAR is not a universal Malaysian statutory certification requirement for every cloud service provider.

However, a customer, tender, financial institution or international business partner may request CSA STAR or equivalent evidence as part of vendor due diligence.

Applicable Malaysian laws and sector regulations must be evaluated separately.

Important Malaysian Legal and Regulatory References

Relevant Malaysian cloud-security considerations may include:

  • National Cloud Computing Policy;
  • Personal Data Protection Act 2010 [Act 709];
  • Cyber Security Act 2024 [Act 854];
  • Communications and Multimedia Act 1998 [Act 588];
  • applicable NCII requirements;
  • applicable Bank Negara Malaysia requirements;
  • sector-specific regulatory requirements;
  • contractual and customer security requirements.

The National Cloud Computing Policy itself identifies key laws and standards relevant to Malaysian cloud computing.

Authoritative References for Malaysian CSA STAR and Cloud Security

For CSA STAR requirements, the primary reference should be the Cloud Security Alliance's STAR programme and registry. CSA identifies CCM as the foundation of the STAR programme and provides separate guidance for Level 1, STAR Certification and STAR Attestation.

For Malaysian cloud policy, the Ministry of Digital's National Cloud Computing Policy should be consulted.

For Malaysian cyber-security legislation, NACSA's official legal resources should be checked, particularly for the Cyber Security Act 2024 and associated regulations.

For financial-sector technology risk, organisations should consult the current Bank Negara Malaysia policy documents applicable to their activities.

Need CSA STAR Certification Support in Malaysia?

SCS Certification can support organisations in understanding CSA STAR requirements, reviewing their existing controls, identifying gaps, preparing documentation and developing an assessment-ready cloud-security management approach.

For Malaysian cloud providers, SaaS companies, data-centre operators, FinTech organisations, financial technology suppliers, manufacturers, healthcare technology providers and other technology businesses, the first step should be defining the exact service scope and applicable Malaysian requirements.

Contact SCS Certification to discuss your CSA STAR requirements in Malaysia.

UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

CSA STAR Certification is a cloud-security assurance route that combines ISO/IEC 27001 requirements with the CSA Cloud Controls Matrix for an independent assessment of a cloud service provider.
Yes. Malaysian cloud service providers can pursue the applicable CSA STAR assessment route through the CSA STAR programme and an appropriate assessment or certification body.
CSA STAR is not a universal statutory certification requirement for every Malaysian cloud provider, although customers, tenders and regulated organisations may request it.
Level 1 is a self-assessment based on the CSA Cloud Controls Matrix and CAIQ, which can be submitted to the CSA STAR Registry.
Level 2 provides independent third-party assurance through STAR Certification or STAR Attestation.
STAR Certification is associated with ISO/IEC 27001 and CCM, while STAR Attestation combines SOC 2 with CCM.
CSA CCM is a cloud-specific security-control framework used as a foundation of the CSA STAR programme.
CAIQ is the Consensus Assessments Initiative Questionnaire used to document cloud-security controls for STAR Level 1.
Yes, a Malaysian SaaS company can assess whether its cloud service scope and assurance objectives are suitable for the STAR programme.
Yes, an IaaS provider can consider CSA STAR when demonstrating security controls to customers and stakeholders.
Yes. PaaS providers can use CSA STAR to provide structured evidence of cloud-security controls.
Yes. Data-centre and cloud infrastructure companies can consider CSA STAR where their services fall within the relevant cloud-service scope.
No. CSA states that STAR Certification supplements the ISO/IEC 27001 certification process rather than replacing it.
Yes. STAR Certification is built around ISO/IEC 27001 together with CSA CCM, making an existing ISMS useful during preparation.
It can provide structured third-party assurance that may help address customer security due diligence.
Requirements depend on the selected STAR route but generally involve defined scope, security controls, evidence, risk management and independent assessment.
The first step is normally to define the cloud service scope and determine the applicable STAR assessment route.
The duration depends on the organisation's existing controls, scope, ISO/IEC 27001 maturity, evidence availability and assessment findings.
Cost varies according to organisation size, scope, readiness, assessment requirements and implementation effort.
A meaningful quotation should be based on the actual cloud-service scope rather than a generic price.
Clear scope definition, existing ISO/IEC 27001 controls, early CCM mapping and organised evidence can reduce unnecessary project delays.
STAR Certification provides certification through the applicable Level 2 certification route; Level 1 is a self-assessment rather than the same type of certification.
CSA states that STAR Certification certificates follow the normal ISO/IEC 27001 protocol and expire after three years unless updated.
CSA states that STAR Attestation listings expire after one year unless updated.
CSA STAR is a global cloud-security assurance programme with a public registry used to communicate cloud-security and privacy assurance.
It can strengthen transparency and provide customers with structured evidence of cloud-security controls.
Yes. FinTech organisations can use cloud-security assurance to address customer, partner and enterprise due-diligence requirements.
It can be useful for cloud providers and technology suppliers serving banks, subject to the bank's own regulatory and contractual requirements.
CSA STAR can support cloud-security assurance, but it does not replace applicable Bank Negara Malaysia requirements.
RMiT is Bank Negara Malaysia's Risk Management in Technology policy framework for applicable financial institutions and related entities.
CSA STAR may provide useful security evidence, but organisations must separately assess the current RMiT requirements applicable to their activities.
Yes. Payment technology companies can use cloud-security controls and independent assurance to strengthen customer confidence.
It can be useful where the provider's cloud-service customers request independent security assurance.
Yes. InsurTech providers handling sensitive information and cloud platforms may benefit from structured cloud-security assurance.
It can support security assurance for cloud services used by Islamic financial technology providers, subject to applicable regulatory requirements.
Yes. Healthcare technology providers can use CSA STAR to demonstrate structured controls for cloud-based services.
It can be relevant to cloud providers and technology suppliers serving hospitals, although CSA STAR does not replace healthcare-specific legal obligations.
It can support cloud-security assurance for systems handling research, business and sensitive operational information.
Yes. Semiconductor companies using cloud engineering, analytics or collaboration platforms may benefit from cloud-security assurance.
Yes. Penang's semiconductor and electronics ecosystem makes cloud-security assurance relevant to many technology suppliers and service providers.
It can support assurance for cloud services used in engineering, ERP, supply-chain and production environments.
Yes. Manufacturers using cloud ERP, IoT, analytics and connected systems can use structured cloud controls to strengthen security governance.
It can support cloud-security assurance for connected manufacturing, supply-chain and enterprise systems.
Yes. Logistics organisations using cloud fleet, tracking, warehouse and customer platforms may benefit from security assurance.
It can support security assurance for cloud platforms used in logistics, maritime operations and connected infrastructure.
Cloud providers supporting Malaysian energy and oil-and-gas organisations can use CSA STAR to demonstrate structured security controls.
Yes. Energy organisations increasingly use digital platforms and cloud services, making cloud-security assurance relevant.
Yes. Telecom and digital infrastructure providers can use cloud-security assurance to address customer and enterprise requirements.
Yes. MSPs operating cloud environments can use STAR assurance to demonstrate security capabilities to enterprise customers.
It can help cloud-based cybersecurity providers demonstrate security controls for their own hosted services.
Yes. AI companies using cloud infrastructure can consider STAR assurance for the security of their underlying cloud services.
Yes. Data-centre operators providing cloud-related services can evaluate CSA STAR based on their service scope.
Depending on the organisation and activity, considerations may include the Personal Data Protection Act 2010, Cyber Security Act 2024, Communications and Multimedia Act 1998 and sector-specific requirements.
No. CSA STAR does not replace Malaysia's personal-data protection legislation.
No. The Cyber Security Act 2024 contains statutory requirements that must be evaluated independently.
Act 854 is Malaysian cyber-security legislation covering areas including NCII governance, cyber-security threats and incidents and specified cyber-security service-provider licensing.
It can support security-control assurance, but NCII entities must separately address their statutory obligations under the Cyber Security Act and related regulations.
Not automatically. An NCII entity must determine the applicable statutory assessment and audit requirements separately.
The NCCP is Malaysia's national policy framework for developing a secure, sovereign, inclusive and sustainable cloud ecosystem.
The NCCP should not be interpreted as making CSA STAR universally mandatory for all cloud providers; organisations should review the specific applicable policy and procurement requirements.
CSA STAR can provide a structured cloud-security assurance layer that aligns with broader objectives around secure and trusted cloud adoption.
The NCCP addresses cloud adoption across public and private sectors, with specific policy objectives applying to different stakeholder groups.
It can support security controls, but privacy compliance must be evaluated against applicable Malaysian law.
CSA CCM contains controls addressing security areas such as cryptography and data protection, subject to the applicable version and assessment scope.
Yes. Access control is a fundamental area of cloud-security control assessment.
Incident management is an important part of a mature cloud-security control environment.
Business continuity and resilience are relevant control areas for cloud-service providers.
Supplier and third-party risk are important considerations when assessing cloud-service security.
Vulnerability management is an important security-control area for cloud environments.
The exact testing requirements depend on the applicable controls and assessment scope, but vulnerability and security testing should be appropriately addressed.
Yes. Existing ISO/IEC 27001 controls can provide a useful foundation for mapping against CSA CCM.
Yes. A SOC 2 environment may provide useful evidence, particularly when considering the STAR Attestation route, subject to the applicable requirements.
Yes. STAR Certification is designed to operate alongside ISO/IEC 27001 and adds the cloud-specific CSA CCM layer.
No. SOC 2 and CSA STAR are different assurance frameworks, although STAR Attestation combines SOC 2 with CSA CCM.
They serve different purposes. ISO 27001 addresses the ISMS, while STAR Certification adds CSA CCM's cloud-specific control perspective.
The appropriate choice depends on customer expectations, existing assurance programmes, market requirements and the organisation's cloud-security objectives.
Malaysian organisations in Kuala Lumpur can work with an appropriate CSA-recognised or otherwise eligible assessment route based on the selected STAR programme.
Yes. Technology and cloud organisations operating in Cyberjaya can pursue the applicable STAR assessment route.
Yes. Organisations serving the public sector from Putrajaya can evaluate CSA STAR where cloud-security assurance is commercially or contractually relevant.
Yes. Selangor-based cloud providers and technology organisations can pursue the applicable CSA STAR route.
Yes. Penang-based technology, semiconductor and manufacturing organisations can consider CSA STAR for relevant cloud services.
Yes. Johor-based technology, industrial and data-centre organisations can evaluate CSA STAR.
Yes. Melaka-based technology and manufacturing companies can consider the programme where relevant.
Yes. Perak-based cloud and technology service providers can evaluate CSA STAR based on their service scope.
Yes. Sarawak-based cloud and technology organisations can consider CSA STAR where customers require cloud-security assurance.
Yes. Sabah-based technology and cloud service providers can evaluate the applicable STAR route.
Define scope, map CSA CCM controls, identify Malaysian legal requirements, implement controls, collect evidence and complete readiness reviews before the independent assessment.
Typical evidence can include policies, risk assessments, asset records, access-control records, incident records, supplier assessments, continuity plans, technical evidence and monitoring records.
SCS Certification can be contacted to discuss the organisation's CSA STAR requirements, scope, gap assessment and preparation needs.
SCS Certification can discuss preparation support for Malaysian organisations seeking to understand and address CSA STAR requirements.
Start with service scope, map existing ISO/IEC 27001 and security controls against CSA CCM, identify Malaysian regulatory obligations and then prepare objective evidence for the selected assessment route.
Begin with a defined cloud-service scope and a structured gap assessment rather than immediately attempting to prepare every possible control.
Consider customer expectations, risk profile, existing certifications, market requirements and the level of independent assurance required.
Registry visibility can make security-assurance information easier for prospective customers and partners to review.
It can strengthen customer confidence, support vendor due diligence and help demonstrate a structured approach to cloud-security assurance.
The most useful starting point is the organisation's cloud-service scope, current ISO/IEC 27001 or security controls, customer requirements and applicable Malaysian regulatory obligations.
Organisations can contact SCS Certification through the enquiry link provided at the beginning of this article to discuss Malaysia-specific CSA STAR requirements.