The Short Answer: Five CAs Hold Licences
Under the Digital Signature Act 1997 (DSA), exactly five certification authorities (CAs) currently hold valid licences to issue digital signature certificates in Malaysia. The register is maintained by the Malaysian Communications and Multimedia Commission (MCMC); as of 26 August 2026 it lists:
- Pos Digicert Sdn Bhd
- MSC Trustgate.Com Sdn Bhd
- Raffcomm Technologies Sdn Bhd
- TM Technology Services Sdn Bhd
- Vista Kencana Sdn Bhd
Only certificates issued by these licensed entities qualify as secure digital signatures with statutory effect under Malaysian law. If you are preparing e-invoices for LHDN MyInvois, bidding for government work, or closing high-value bank and corporate transactions, this register — not a reseller's marketing page — is the source to trust.
For a wider view of how CAs operate across browsers and e-signature ecosystems, see our certificate authority list guide.
The Official MCMC Register of Licensed CAs
The table below reproduces the MCMC's list of certification authorities and recognition, queried on 26 August 2026. Licence records change, so treat it as a snapshot and confirm current status on mcmc.gov.my before you buy.
Four details deserve attention:
- Licence numbers carry an iteration count. The figure in parentheses — for example LPBP-1/2025 (5) — marks the licence iteration; renewal issues a new reference.
- Validity periods are not uniform. Some licences run for five years, others for three; check the effective and expiry dates.
- All five publish service terms and certificate practice statements on their websites. Pos Digicert and MSC Trustgate are the most compared in procurement; Raffcomm, TM Technology Services, and Vista Kencana cover specialised and regional demand.
- The register is the legal source of truth. Company registration numbers tie each licence to a specific legal entity, which matters during acquisitions and renames.
Recognised Repositories and Date/Time Stamp Services
The same MCMC register contains three lists, and the same five entities appear in all three.
- Licensed certification authorities (LPBP series) — authorised to issue digital signature certificates.
- Recognised repositories (PPR series) — authorised to operate certificate repositories, the online directories where issued certificates and revocation information are published.
- Recognised date/time stamp services (PPTM series) — authorised to provide trusted timestamps that record when a signature was created.
This matters in practice: issuance, repository lookup, and timestamp evidence usually come from one licensed trust chain — the three things an auditor asks about when a signed transaction is challenged.
The Legal Framework: Digital Signature Act 1997
The Digital Signature Act 1997 is the core statute for digital signatures in Malaysia, and its central mechanic is simple to state:
- A digital signature produced with an asymmetric cryptosystem (a public/private key pair) using a certificate issued by a licensed CA is a secure digital signature.
- A secure digital signature is treated as satisfying legal requirements for signatures under Malaysian law.
The regulator is MCMC, which appoints a Controller of Certification Authorities to run the licensing regime; the Digital Signature Regulations 1998 set out the procedural rules.
Two misconceptions in older blog posts are worth correcting:
- MCMC is the licensing authority, not a passive supervisor. It issues licences, maintains the register, and takes action against non-compliant operators.
- MIMOS is not a licensed CA in the current register. It has historical significance in Malaysian cryptography, but it is not among the five entities licensed to issue commercial certificates today.
For a deeper walkthrough of the statute and how it affects signing teams, see our guide to the Malaysia Digital Signature Act for business teams.
Everyday electronic signatures and contracts rest on a different footing, supported by the Electronic Commerce Act 2006, the Contracts Act 1950, and the Evidence Act 1950. In practice, you rarely need a CA certificate for ordinary commercial agreements — but for e-invoicing and statutory digital signatures, you do.
Why a Licensed CA Matters for Your Business
Three scenarios drive most demand for licensed CA certificates in Malaysia.
LHDN e-Invoicing (MyInvois). Under LHDN's e-invoice framework, invoices submitted through MyInvois must be signed with a valid digital certificate issued by a Malaysian-recognised CA, matching the specified X.509 certificate profile.
Government procurement and regulated filings. Tenders, declarations, and filings increasingly demand secure digital signatures so signer identity and document integrity can be verified after the fact. A certificate from a provider outside the register lacks the statutory weight of a DSA secure digital signature.
Bank and corporate signing. Loan documentation, board resolutions, and high-value contracts often require certificates with recognised legal status. If a signature is later disputed, the first question is whether the issuing CA was licensed on the date of signing.
One legal detail can catch teams off guard: section 12(3) of the DSA lets an expired-licence CA keep operating if it has applied for renewal, so the register can lag reality. Confirm current status directly with the CA and MCMC before deadline-sensitive transactions.
How to Verify a CA Licence on the MCMC Website
Do not rely on a vendor's description of its own licence. The authoritative check takes a few minutes:
- Open mcmc.gov.my.
- Navigate to the digital signature section.
- Open the list of licensees.
- Match the company name, company registration number, and licence number against the register.
- Confirm the validity period covers the date you plan to sign.
Run this check even for certificates you already hold — companies are renamed and acquired.
How to Buy a Digital Certificate from a Licensed CA
The buying process touches procurement, IT, and the signatory whose identity is being certified.
- Request a quote. Contact the CA (or an authorised reseller) with your use case: e-invoicing, tender submissions, or corporate signing.
- Issue a purchase order. The CA quotes per-certificate pricing for a defined validity period — one year is common — so compare quotes rather than assuming a standard rate.
- Submit identity documents. The CA verifies the applicant's identity and, for company certificates, the company's registration details and authorised signatories.
- Complete verification. Verification may be online, in person, or both, depending on the certificate class.
- Receive and install the certificate. Certificates are typically delivered as software or roaming certificates and configured into your signing environment — ERP, e-invoice submission system, or document workflow.
- Plan the renewal. Mark the expiry date; renewal repeats the identity verification steps.
If your shortlist comes down to the two most-cited providers, Pos Digicert is the frequent first choice for e-invoicing because of its distribution and MyInvois promotion, while MSC Trustgate is Malaysia's established trust services operator. Compare on integration fit, certificate class, and validity period rather than price alone, and confirm both against the register.
When You Need a CA Certificate vs When You Need E-Signature
A licensed CA certificate is the right tool when the law or a counterparty requires a secure digital signature: e-invoicing, regulated filings, or contracts that explicitly call for digital signatures.
Most everyday agreements — NDAs, quotes, HR documents, vendor contracts — do not require a CA certificate; they are validly executed with ordinary electronic signatures under the Electronic Commerce Act 2006. Most Malaysian teams run both: CA certificates for the statutory lane, and an e-signature platform for the commercial lane.
Outside Malaysia, the same logic applies under different frameworks; see our guides to eIDAS-compliant electronic signatures and Indonesia digital identity signatures.
Sign Malaysia-Compliant Agreements with Nota Sign
For the commercial lane — agreements you sign every week — Nota Sign, FaDaDa's global e-signature platform, runs the broader agreement workflow: send, sign, store, and export evidence, without per-seat fees. CA certificates handle the statutory lane.
Nota Sign has been ranked No. 1 in China's e-signature software market by IDC for consecutive years, supports legal validity across 100+ countries and regions, and offers APAC compliance depth: national digital identity integration (iAM Smart, Singpass), SES/AES/QES signature levels, and regional data centers. Small teams pay no per-seat fees; mid-market and enterprise buyers can request tailored plans.
Building a compliant signing stack for Malaysia means pairing CA certificates for statutory documents with a dependable platform for everything else — talk to our team to map your workflows.









