CSA STAR Certification in Malaysia: NCCP, Cyber Security Act 2024, PDPA & Cloud Compliance
SCS Certification – Malaysia Office
SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia
Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification
http://www.scscertification.com/contactus.php
Cloud services are now part of everyday business infrastructure in Malaysia. Banks use cloud platforms for digital services, manufacturers depend on connected systems, healthcare organisations manage sensitive information electronically, and technology companies deliver SaaS applications to customers across Malaysia and overseas.
As cloud adoption grows, customers are asking a straightforward question: how can a cloud service provider demonstrate that its security controls are actually working?
CSA STAR provides one recognised route for demonstrating cloud-security assurance.
The Cloud Security Alliance (CSA) STAR programme is designed around transparency, cloud security controls and independent assurance. The programme uses the Cloud Controls Matrix (CCM) as its central control framework. CSA describes Level 1 as a self-assessment route and Level 2 as a third-party assurance route, including STAR Certification and STAR Attestation. STAR Certification combines ISO/IEC 27001 requirements with CSA CCM, while STAR Attestation combines SOC 2 with CCM.
For Malaysian organisations, however, CSA STAR should not be viewed in isolation. A practical cloud-security programme may also need to consider Malaysia's National Cloud Computing Policy, the Cyber Security Act 2024, the Personal Data Protection Act 2010 and its amendments, sector-specific requirements, contractual obligations and financial-sector technology-risk requirements.
This makes a Malaysia-specific approach more useful than simply following a generic CSA STAR checklist.
What Is CSA STAR Certification in Malaysia?
CSA STAR is the Cloud Security Alliance's Security, Trust, Assurance and Risk programme for demonstrating cloud-security and privacy assurance.
There are different routes within the STAR programme.
Level 1 uses the Consensus Assessments Initiative Questionnaire (CAIQ) and CCM for a self-assessment. Level 2 provides independent third-party assurance. CSA STAR Certification is associated with ISO/IEC 27001 and CCM, while STAR Attestation is associated with SOC 2 and CCM.
For a Malaysian cloud service provider, the value of CSA STAR can be particularly relevant when enterprise customers, financial institutions, multinational companies or public-sector customers ask for evidence of cloud-security controls.
Why CSA STAR Matters for Malaysian Cloud Service Providers
A Malaysian cloud provider may face security questions from several directions.
A customer may ask about access control. Another may request evidence of vulnerability management. A bank may ask about technology risk. An international customer may require ISO/IEC 27001, SOC 2 or CSA STAR evidence.
Instead of answering every customer questionnaire separately, a structured assurance programme can provide a clearer way to communicate the organisation's control environment.
CSA states that the STAR Registry is publicly accessible and is intended to document security and privacy controls provided by cloud offerings.
For Malaysian providers, this can be useful when entering markets outside Malaysia as well as when competing for domestic enterprise contracts.
CSA STAR and Malaysia's National Cloud Computing Policy
Malaysia's National Cloud Computing Policy (NCCP) was launched in August 2025. The Ministry of Digital describes it as a national policy intended to support a secure, sovereign, inclusive and sustainable cloud ecosystem. Its five pillars cover public-sector transformation, private-sector growth, secure data protection and privacy, digital inclusivity and environmental sustainability.
The NCCP is therefore highly relevant to organisations building or operating cloud services in Malaysia.
CSA STAR does not replace the NCCP. Instead, organisations can use cloud-security assurance frameworks such as CSA CCM as part of a broader control environment that supports cloud governance.
Malaysia's NCCP itself identifies relevant laws and standards affecting cloud computing, including the Personal Data Protection Act 2010, Communications and Multimedia Act 1998 and Cyber Security Act 2024.
CSA STAR and the Cyber Security Act 2024
The Cyber Security Act 2024 [Act 854] is an important part of Malaysia's cyber-security landscape.
NACSA states that the Act establishes arrangements concerning the National Cyber Security Committee, NACSA leadership, National Critical Information Infrastructure (NCII) sector leads and NCII entities, cyber-security threats and incidents affecting NCII, and licensing of specified cyber-security service providers.
The Act came into operation on 26 August 2024.
CSA STAR does not make an organisation automatically compliant with Act 854.
Instead, Malaysian organisations should map applicable statutory and regulatory obligations against their own control framework.
For an organisation connected to NCII, that distinction is especially important.
CSA STAR and Malaysian NCII Requirements
Organisations operating within Malaysia's NCII environment may have obligations that go beyond a normal commercial cloud-security programme.
The Cyber Security Act addresses the management of cyber-security risks and incidents involving NCII. NACSA also publishes regulations covering cyber-security risk assessment and audit, incident notification and licensing of cyber-security service providers.
CSA STAR can support evidence of structured cloud-security controls, but it should not be presented as a substitute for statutory NCII obligations.
CSA STAR and the Personal Data Protection Act
Malaysia's Personal Data Protection Act 2010 [Act 709] is another important consideration for commercial organisations processing personal data.
Malaysia's National Cloud Computing Policy identifies the Act as applicable to processing of personal data in commercial transactions and notes requirements concerning data protection principles, security measures, Data Protection Officers, breach notification and data-subject rights.
For cloud providers processing personal data for customers, security controls therefore need to be considered alongside contractual and privacy obligations.
CSA CCM can help organise technical and organisational security controls, but it does not replace Malaysian privacy law.
CSA STAR, Data Protection Officers and Breach Management
A Malaysian organisation should determine whether the relevant PDPA requirements apply to its activities and whether it has obligations concerning a Data Protection Officer, personal-data breach management and related governance.
A mature CSA STAR preparation programme should therefore include:
- data classification;
- access management;
- privileged-access controls;
- encryption;
- incident response;
- logging;
- monitoring;
- supplier management;
- backup and recovery;
- vulnerability management;
- privacy governance;
- documented responsibilities.
The exact legal obligation should always be assessed against the organisation's activities and current Malaysian requirements.
CSA STAR and Cross-Border Data Transfers
Many Malaysian technology companies serve customers outside Malaysia.
A cloud provider may therefore need to understand:
- where data is stored;
- where support personnel can access it;
- which subprocessors are involved;
- how data is transferred;
- what contractual safeguards apply;
- how customers are informed about processing;
- how deletion and retention are managed.
CSA STAR can provide evidence around security controls, while applicable Malaysian privacy requirements and contractual obligations need to be addressed separately.
CSA STAR and Bank Negara Malaysia RMiT
Financial institutions are one of the strongest potential use cases for cloud-security assurance in Malaysia.
Bank Negara Malaysia's Risk Management in Technology (RMiT) framework addresses technology and cyber risks in the financial sector. BNM's revised RMiT policy was issued on 28 November 2025, with the stated aim of strengthening technology and cyber-risk management, service resilience and trust in financial services.
The BNM policy environment continues to evolve, so Malaysian financial institutions and their technology suppliers should check the current applicable BNM requirements rather than rely on an old checklist.
CSA STAR can be useful as supporting cloud-security assurance where it aligns with the organisation's risk-management and customer requirements.
CSA STAR for Malaysian FinTech Companies
Malaysia's FinTech sector increasingly depends on APIs, cloud infrastructure, SaaS applications, digital payments, mobile platforms and third-party technology services.
A FinTech company preparing for CSA STAR should pay particular attention to:
- identity and access management;
- application security;
- secure software development;
- API security;
- encryption;
- customer-data protection;
- third-party risk;
- incident response;
- business continuity;
- monitoring;
- change management.
The objective should be to demonstrate that cloud-security controls operate consistently rather than merely creating documents for an audit.
CSA STAR for Malaysian Banking and Islamic Banking Technology
Banks and Islamic financial institutions operate in a highly controlled technology environment.
A cloud provider serving Malaysian financial institutions may encounter customer requirements covering:
- technology governance;
- information security;
- resilience;
- outsourcing;
- privileged access;
- data protection;
- audit rights;
- incident reporting;
- disaster recovery;
- supplier monitoring.
CSA STAR can strengthen the provider's security-assurance package when appropriately scoped.
CSA STAR for Malaysian Payment-Service Providers
Payment technology companies can face demanding customer due-diligence requirements.
A Malaysia-focused CSA STAR programme should consider payment processing architecture, APIs, authentication, monitoring, incident response, encryption, vulnerability management and supplier dependencies.
Where Bank Negara Malaysia requirements apply, the organisation should separately evaluate the relevant current policy documents.
CSA STAR for Malaysian Semiconductor and Electronics Companies
Penang and other Malaysian technology clusters are home to semiconductor, electronics and advanced manufacturing businesses.
These companies increasingly use cloud platforms for:
- engineering collaboration;
- production analytics;
- supply-chain management;
- ERP;
- research data;
- design information;
- remote administration;
- IoT systems.
A cloud provider serving these businesses may use CSA STAR to demonstrate a structured security-control environment.
CSA STAR for Malaysian Manufacturing
Malaysia's manufacturing sector increasingly combines operational technology with cloud-based analytics and enterprise systems.
Manufacturing organisations should consider controls around:
- production data;
- industrial networks;
- remote access;
- supplier connectivity;
- identity management;
- backup;
- recovery;
- endpoint security;
- vulnerability management.
CSA STAR can complement an organisation's wider information-security programme.
CSA STAR for Malaysian Healthcare Technology
Healthcare organisations and healthcare technology providers handle highly sensitive information.
Relevant control areas include:
- access control;
- data classification;
- encryption;
- audit logging;
- incident response;
- backup;
- disaster recovery;
- supplier management;
- secure application development.
CSA STAR should be positioned as a cloud-security assurance framework, not as a replacement for Malaysian healthcare or privacy requirements.
CSA STAR for Malaysian Telecommunications
Telecommunications and digital infrastructure companies operate large-scale, highly connected environments.
Cloud-security assessments may include:
- network security;
- privileged access;
- availability;
- resilience;
- monitoring;
- vulnerability management;
- incident response;
- supplier controls.
The Communications and Multimedia Act 1998 is identified in Malaysia's National Cloud Computing Policy as relevant to certain cloud service providers, including PaaS and IaaS providers subject to the applicable licensing framework.
CSA STAR for Malaysian Data Centres
Data centres are central to Malaysia's cloud and digital-infrastructure expansion.
A data-centre operator or cloud service provider may need to demonstrate controls covering:
- physical security;
- environmental controls;
- access management;
- availability;
- redundancy;
- business continuity;
- incident management;
- change control;
- supplier management.
CSA STAR can provide a cloud-security assurance layer when the relevant service scope is clearly defined.
CSA STAR in Kuala Lumpur
Kuala Lumpur is a major commercial and technology market for Malaysian cloud providers, financial institutions, technology companies and enterprise customers.
A CSA STAR programme in Kuala Lumpur should focus on the actual cloud services being offered and the customer assurance requirements attached to those services.
CSA STAR in Cyberjaya
Cyberjaya is particularly relevant to Malaysia's digital and technology ecosystem.
Cloud providers, managed service providers, software companies and digital businesses operating in Cyberjaya may find CSA STAR useful when demonstrating security assurance to enterprise and public-sector customers.
CSA STAR in Putrajaya
Putrajaya is important for organisations working with government digital services and public-sector technology.
The Malaysia-specific cloud assurance discussion should therefore consider government procurement expectations, cloud security, data governance and applicable public-sector requirements.
CSA STAR in Selangor
Selangor contains major commercial, industrial, logistics and technology activity.
Companies in Petaling Jaya, Shah Alam, Subang Jaya, Klang and surrounding business areas may encounter customer requirements for ISO 27001, SOC 2, CSA STAR or similar security evidence.
CSA STAR in Penang
Penang is particularly relevant to semiconductor, electronics, manufacturing, engineering and technology organisations.
Cloud service providers serving these industries can use CSA STAR to provide structured evidence of cloud-security controls.
CSA STAR in Johor
Johor's industrial, logistics, technology and data-centre development makes cloud security increasingly important.
Organisations in Johor Bahru and Iskandar Malaysia can consider CSA STAR where enterprise customers require independent assurance of cloud controls.
CSA STAR in Melaka
Melaka's manufacturing, technology, healthcare and service sectors provide additional applications for cloud-security assurance.
A Malaysia-specific CSA STAR assessment should be scoped around the actual services and information processed.
CSA STAR in Perak
Perak-based manufacturers, service providers and technology companies using cloud systems can use CSA STAR preparation to improve control visibility and customer confidence.
CSA STAR in Sarawak
Sarawak's energy, infrastructure, government, utilities and technology activities create different cloud-security requirements from those found in Kuala Lumpur.
The control scope should therefore reflect the actual services, data and customer obligations involved.
CSA STAR in Sabah
Sabah-based organisations using cloud applications or delivering technology services can consider CSA STAR when enterprise customers request independent security assurance.
CSA STAR Certification Requirements in Malaysia
The exact requirements depend on the STAR route selected.
For STAR Certification, the organisation needs an appropriate ISO/IEC 27001 foundation and must address the applicable CSA Cloud Controls Matrix requirements. CSA describes STAR Certification as an extension or supplement to the ISO/IEC 27001 assessment process rather than a replacement for ISO certification.
Typical preparation areas include:
- scope definition;
- cloud-service architecture;
- risk assessment;
- governance;
- access control;
- asset management;
- cryptography;
- operations security;
- supplier management;
- incident response;
- business continuity;
- monitoring;
- compliance;
- evidence management.
CSA STAR Certification Process in Malaysia
A practical implementation can follow these stages:
- Define the cloud service scope.
- Identify applicable Malaysian legal and regulatory requirements.
- Review existing ISO/IEC 27001 and information-security controls.
- Map controls against CSA CCM.
- Conduct a gap assessment.
- Address control gaps.
- Implement and operate required controls.
- Collect objective evidence.
- Complete internal review and readiness activities.
- Arrange the appropriate independent assessment.
- Address findings.
- Complete the STAR submission or certification process applicable to the selected route.
CSA STAR Certification Cost in Malaysia
There is no single fixed Malaysian price.
Cost depends on:
- organisation size;
- number of employees;
- cloud-service scope;
- number of locations;
- existing ISO/IEC 27001 maturity;
- number of systems;
- complexity of infrastructure;
- audit duration;
- readiness level;
- consulting requirements;
- certification or attestation route.
CSA publishes separate fee information for STAR Level 2 certification and attestation, while the overall Malaysian project cost also depends on the organisation's implementation and assessment arrangements.
A proper quotation should therefore be based on the defined scope rather than a generic advertised figure.
How to Get CSA STAR Certification Faster in Malaysia
The fastest approach is usually not to skip controls.
It is to reduce rework.
A Malaysian organisation can improve project speed by:
- defining the scope early;
- using an existing ISO/IEC 27001 ISMS;
- mapping existing controls to CSA CCM;
- identifying regulatory requirements early;
- assigning control owners;
- centralising evidence;
- completing internal audits;
- closing gaps before the external assessment;
- avoiding unnecessary scope expansion.
CSA STAR vs ISO 27001 in Malaysia
ISO/IEC 27001 and CSA STAR are not identical.
ISO/IEC 27001 focuses on an information-security management system.
CSA STAR Certification adds the CSA Cloud Controls Matrix to the ISO/IEC 27001 certification context.
For Malaysian cloud providers, combining the two can provide stronger evidence to customers that both information-security management and cloud-specific controls have been addressed.
CSA STAR vs SOC 2 in Malaysia
SOC 2 is an attestation framework based on AICPA criteria.
CSA STAR Attestation combines SOC 2 with CSA CCM.
CSA STAR Certification instead uses ISO/IEC 27001 together with CSA CCM.
The better route depends on customer expectations, market, existing certifications and contractual requirements.
Is CSA STAR Mandatory in Malaysia?
CSA STAR is not a universal Malaysian statutory certification requirement for every cloud service provider.
However, a customer, tender, financial institution or international business partner may request CSA STAR or equivalent evidence as part of vendor due diligence.
Applicable Malaysian laws and sector regulations must be evaluated separately.
Important Malaysian Legal and Regulatory References
Relevant Malaysian cloud-security considerations may include:
- National Cloud Computing Policy;
- Personal Data Protection Act 2010 [Act 709];
- Cyber Security Act 2024 [Act 854];
- Communications and Multimedia Act 1998 [Act 588];
- applicable NCII requirements;
- applicable Bank Negara Malaysia requirements;
- sector-specific regulatory requirements;
- contractual and customer security requirements.
The National Cloud Computing Policy itself identifies key laws and standards relevant to Malaysian cloud computing.
Authoritative References for Malaysian CSA STAR and Cloud Security
For CSA STAR requirements, the primary reference should be the Cloud Security Alliance's STAR programme and registry. CSA identifies CCM as the foundation of the STAR programme and provides separate guidance for Level 1, STAR Certification and STAR Attestation.
For Malaysian cloud policy, the Ministry of Digital's National Cloud Computing Policy should be consulted.
For Malaysian cyber-security legislation, NACSA's official legal resources should be checked, particularly for the Cyber Security Act 2024 and associated regulations.
For financial-sector technology risk, organisations should consult the current Bank Negara Malaysia policy documents applicable to their activities.
Need CSA STAR Certification Support in Malaysia?
SCS Certification can support organisations in understanding CSA STAR requirements, reviewing their existing controls, identifying gaps, preparing documentation and developing an assessment-ready cloud-security management approach.
For Malaysian cloud providers, SaaS companies, data-centre operators, FinTech organisations, financial technology suppliers, manufacturers, healthcare technology providers and other technology businesses, the first step should be defining the exact service scope and applicable Malaysian requirements.
Contact SCS Certification to discuss your CSA STAR requirements in Malaysia.
|
UAE |
Saudi Arabia |
UK |
Canada |
India |
|
SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE. |
SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia |
SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ. |
SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada. |
Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India. Bangalore: Bangalore, Karnataka, India. |
Need ISO Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.