← All countries

Malaysia

NIST bloc Standard-taker

Malaysia's post-quantum transition is led by CyberSecurity Malaysia, the national cyber security specialist agency, which has published a Post-Quantum Cryptography Migration Framework and a technical guide on adopting and implementing post-quantum cryptographic solutions, and offers migration consultancy, awareness and workshop services to government agencies, critical infrastructure operators and private organisations. This work sits alongside the national MyKriptografi and MySEAL cryptography programmes. The Ministry of Digital, working with the National Cyber Security Agency (NACSA) and the domain registry MYNIC, has publicly framed the move to post-quantum cryptography as an urgent necessity, including the need to replace at-risk protocols such as DNSSEC. The published material is guidance rather than binding law, and no dated national migration timeline is set out in the ingested documents.

Governance credibility

Governance credibility for MalaysiaA six-axis reading out of two: Relevance 1.0 / 2, Coherence 1.5 / 2, Effectiveness 1.0 / 2, Efficiency 1.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Malaysia, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance1.0 / 2High
Coherence1.5 / 2High
Effectiveness1.0 / 2High
Efficiency1.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • CyberSecurity Malaysia Post-Quantum Cryptography Migration Framework national Guidance

The Cyber Security Act 2024, in force since 26 August 2024, places binding cyber security duties on designated national critical information infrastructure entities, including risk assessment, audit and incident reporting, but it does not mandate post-quantum cryptography specifically. Migration to the NIST post-quantum baseline is set out in the CyberSecurity Malaysia and NACSA Migration Framework, which is technical guidance and is not in itself legally binding.

Standards and algorithms

No standards or algorithms specified.

Hybrid stance

None stated

Migration timeline

No published migration timeline.

Target completion: None stated

Governmental and standards bodies

  • CyberSecurity Malaysia national cyber security specialist agency, publishes the PQC Migration Framework, adoption recommendations and PQC migration services
  • NACSA National Cyber Security Agency, sets national cyber security policy and participates in the post-quantum transition messaging
  • Ministry of Digital government ministry framing the move to post-quantum cryptography as an urgent national necessity, including replacing at-risk DNSSEC protocols
  • MYNIC national domain name registry, partner in the quantum-and-internet-security awareness programme

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →