These Terms of Service have been structured in accordance with the applicable requirements of the accreditation bodies. These Codes apply also to certification outside accredited schemes.


CyberSecurity Malaysia provides services to persons, firms or companies (each a “Client”). CyberSecurity Malaysia may provide its services directly or, in its absolute discretion, through (a) its own employees, (b) any affiliated company or (c) any other person or organisation, as may be entrusted by CyberSecurity Malaysia. Where part of the work is subcontracted to others, CyberSecurity Malaysia retains full responsibility for granting, maintaining, extending, reducing, suspending or withdrawing certification and for ensuring that properly documented agreements are in place.

CyberSecurity Malaysia will notify its clients of any changes to the requirements for certification within a reasonable timeframe.


CyberSecurity Malaysia maintains confidentiality at all levels of its organisation concerning information obtained in the course of its business. No information will be disclosed to any third party unless in response to legal process or required by an accreditation body as part of the accreditation process. The client's name, location, scope of certification and contact numbers may be entered into relevant directories.

CyberSecurity Malaysia protects your personal data, the data collected by CyberSecurity Malaysia in this form will not be used for any other purpose than the purpose it was collected unless consented by you ,will not sell,transfer, share with a third party, will not retain for longer period than necessary, will take necessary measures to protect your personal data.


A copy of the organisation chart of CyberSecurity Malaysia, showing the responsibility and reporting structure of the organisation, and documentation identifying the legal status of CyberSecurity Malaysia are available on request.


On receipt of a completed Inquiry Form (provide by CyberSecurity Malaysia upon request), a quotation is sent to the Client outlining the costs of the services together with an acceptance sheet. Once the acceptance sheet is returned, together with any due payments and controlled copies of relevant documentation and samples, the project will be allocated to an auditor who will be responsible for ensuring that the services are carried out in accordance with the procedures of CyberSecurity Malaysia.


In order to obtain and retain certification, the Client shall comply with the following procedures and rules:
(a) the Client shall make available to CyberSecurity Malaysia all documents, samples of products, drawings, specifications and other information required by CyberSecurity Malaysia to complete the assessment programme and shall appoint a designated person who is authorised to maintain contact with CyberSecurity Malaysia;
(b) CyberSecurity Malaysia, if not satisfied that all certification requirements are met, shall inform the Client of those aspects in which the application has failed;
(c) when the Client can show that remedial action has been taken by it, within the time limit specified by CyberSecurity Malaysia, to meet all the requirements, CyberSecurity Malaysia will arrange, at additional cost to the Client, to repeat only the necessary parts of the assessment;
(d) if the Client fails to take acceptable remedial action within the specified time limit it may be necessary for CyberSecurity Malaysia, at additional cost, to repeat the assessment in full;
(e) identification of conformity shall refer only to the sites or products assessed as specified in the Certificate and Assessment Schedule (if any) or other attachments which may accompany the Certificate.


When CyberSecurity Malaysia is satisfied that the Client meets all the certification requirements, it will inform the Client and issue a Certificate. The Certificate shall remain the property of CyberSecurity Malaysia and may only be copied or reproduced for the benefit of a third party if the word “copy” is marked thereon.

The Certificate will be published at http://csm27001.cybersecurity.my/org-cert.html and will remain valid unless surveillance reveals that the management system of the Client no longer meet the standards, norms or regulations.


Upon issuance of a Certificate, CyberSecurity Malaysia may also authorise the Client to use a designated certification mark. A Client’s right to use any such mark is contingent on maintaining a valid Certificate in respect of the certified management system or products and compliance with the regulations governing the use of the mark issued by CyberSecurity Malaysia. A Client who has been authorised to use the mark of an accrediting body must also comply with the rules governing the mark of such body. Improper use of such a mark is non-conformity with certification requirements and could result in suspension of certification.


Periodic surveillances shall be carried out and shall cover aspects of the management system, documentation, manufacturing and distributing processes and products, depending on the type of certification services provided, at the discretion of the nominated auditor. The Client shall give access to all sites or products for surveillance purposes whenever deemed necessary and CyberSecurity Malaysia shall reserve the right to make unannounced visits as required.

The Client shall maintain a register recording all customer complaints and safety-related incidents reported by an enforcing authority or users relating to those covered by the Certificate and make this available to CyberSecurity Malaysia on request.

The Client shall be informed of the results of each surveillance visit.


Clients wishing to revalidate Certificates approaching the end of their cycles shall apply under the procedure set forth in Clause 5. Clients are generally informed of the requirement for renewal of the certification during the pre-renewal visit which is the last surveillance visit of each cycle.


In order to extend the scope of a Certificate to cover additional sites or processes, Client shall complete a new Inquiry Form. The application procedure outlined in Clause 5 will be followed and an assessment will be carried out on those areas/processes not previously covered. The cost of extending the scope of certification will be based on the nature and programme of work.

Following a successful assessment an amended Certificate or Assessment Schedule, as the case may be, will be issued covering those aspects covered by the extended Certificate. Although the original Certificate will normally remain in force, it may be necessary in some instances to issue a new Certificate. In such cases the Client must return the superseded Certificate to CyberSecurity Malaysia.


The Client shall inform CyberSecurity Malaysia, in writing, of any intended modification to the management system or process which may affect compliance with the standards, norms or regulations. CyberSecurity Malaysia will determine whether the notified changes require additional assessment. Failure to notify CyberSecurity Malaysia of any intended modification may result in suspension of the Certificate.


In compliance with the applicable Regulations governing the relevant mark(s), a Client may render public that its relevant management system or products have been certified and may print the relevant certification mark on stationery and publicity materials relating to the scope of certification.

In any case, the Client shall ensure that its announcements and advertising material do not create confusion or could otherwise mislead third parties about certified and non-certified systems, products or sites.


CyberSecurity Malaysia shall take suitable action, at the expense of the Client, to deal with incorrect or misleading references to certification or use of Certificates and certification marks. These include suspension or withdrawal of Certificate, legal action and/or publication of the transgression.


A Certificate may be suspended by CyberSecurity Malaysia for a limited period in cases such as the following:
(a) if a Corrective Action Request has not been satisfactorily complied with within the designated time limit; or
(b) if a case of misuse as described in Clause 14 is not corrected by suitable retractions or other appropriate remedial measures by the Client; or
(c) a certified client organisation ceases to supply the product, process or service or some part of it (which is the subject matter of the certification) for an extended period of time, exceeding two (2) months; or
(d) a certified client organisation is not allowing to conduct surveillance or re-certification audits in the required time frame.
CyberSecurity Malaysia will confirm in writing to the Client the suspension of a Certificate. At the same time, CyberSecurity Malaysia shall indicate under which conditions the suspension will be removed. At the end of the suspension period, an investigation will be carried out to determine whether the indicated conditions for reinstating the Certificate have been fulfilled. On fulfilment of these conditions the suspension shall be lifted and the Client notified of the Certificate reinstatement. If the conditions are not fulfilled the Certificate shall be withdrawn.
All costs incurred by CyberSecurity Malaysia in suspending and reinstating a Certificate will be charged to the Client.


A Certificate may be withdrawn if (i) the Client takes inadequate measures in case of suspension; (ii) the certified process (service) do not conform to the standards, norms or regulations or are no longer offered; or (iii) CyberSecurity Malaysia terminates its contract with the Client. In any of these cases, CyberSecurity Malaysia has the right to withdraw the Certificate by informing the Client in writing.

The Client may give notice of appeal (see Clause 19).

In cases of withdrawal, no reimbursement of assessment fees shall be given and withdrawal of the Certificate shall be published by CyberSecurity Malaysia and notified to the appropriate accreditation body, if any.


A Certificate will be cancelled if (i) the Client advises CyberSecurity Malaysia in writing that it does not wish to renew the Certificate or goes out of business, (ii) the Client no longer offers the process (service) or (iii) the Client does not timely commence application for renewal.

In cases of cancellation no reimbursement of assessment fees shall be given and cancellation of the Certificate shall be published by CyberSecurity Malaysia and notified to the appropriate accreditation body, if any.


CyberSecurity Malaysia, in its absolute discretion, generally recognises the certificates issued by other accredited organisations where this does not compromise the integrity of information security management system certification scheme.


The Client may, through the Complaints and Appeals Procedure request reconsideration of a decision made by CyberSecurity Malaysia. Appeals can be filed by any client organisation to CyberSecurity Malaysia and may be filed for reasons associated with:
(a) Rejection of application;
(b) Rejection of conducting audit; and
(c) Reconsideration of the suspension or withdrawal of certification.
Notification of the intention to appeal must be made in writing and received by CyberSecurity Malaysia within seven (7) business days from receipt of notification by CyberSecurity Malaysia, supported by relevant facts and data for consideration during the Complaints and Appeals Procedure. The minimum information required are:
(a) The name of the appellant;
(b) Contact details for the appellant;
(c) The application/audit/certification decision that is the subject of the appeal; and
(d) Description of the appeal.
If the required information cannot be supplied, the appeal is automatically rejected and a formal rejection letter is prepared and sent to the appellant.
All appeals are forwarded to CyberSecurity Malaysia and are put before the appeal’s committee of CyberSecurity Malaysia. CyberSecurity Malaysia shall be required to submit evidence to support its decision to withhold, suspend or withdraw the Certificate.
Any appeals received are fully investigated, documented and appropriate follow-up action taken within ten (10) business days. The decision of the appeal's committee shall be final and binding on both the Client and CyberSecurity Malaysia. Once the decision regarding an appeal has been made, no counter-claim by either party in dispute can be made to amend or change this decision.
In instances where the appeal has been successful and the Certificate issued or reinstated, no claim can be made against CyberSecurity Malaysia for reimbursement of costs or any other losses incurred as a result of the withholding, suspension or withdrawal notification.


Any complaint regarding the certification activities of CyberSecurity Malaysia or relating to a certified client shall be made in writing, without delay, and addressed to the Scheme Manager. If the complaint is made against the Scheme Manager, the letter of complaint shall be addressed to the ISCB Head of Department of CyberSecurity Malaysia.
The minimum information required are:
(a) The name of the complainant;
(b) Contact details for the complainant;
(c) The certification activity that is the subject of the complaint; and
(d) Description of the complaint.
If the required information cannot be supplied, the complaint is automatically rejected and a formal rejection letter is prepared and sent to the complainant.
Any complaints received are fully investigated, documented and appropriate follow-up action taken within ten (10) business days.