MCMC Compliance in Malaysia: Licensing, Security, and the Online Safety Act 2025

Primary Guard · July 21, 2026 · 8 min read

MCMC compliance now spans CMA 1998 licensing, the 2025 social media licence regime, and the Online Safety Act 2025. What providers must do to stay compliant.

Compliance with the Malaysian Communications and Multimedia Commission (MCMC) has changed more in the past two years than in the previous decade. A new licensing regime brought large social media and messaging platforms under regulation from 1 January 2025, and the Online Safety Act 2025 came into force on 1 January 2026, placing fresh legal duties on licensed providers. For communications, content, and digital service providers operating in Malaysia, the compliance surface is now wider, and the security and data-protection obligations that come with it are real.

This guide explains what MCMC compliance covers in 2026: the licensing framework under the Communications and Multimedia Act 1998, the newer social media licensing rules, the Online Safety Act, and the security and data obligations these place on providers. It is written for network, applications, and content service providers, digital platforms, and the security and compliance teams that support them.

What is MCMC, and what does it regulate?

The MCMC is Malaysia's regulator for the communications and multimedia sector, operating under the Communications and Multimedia Act 1998, known as the CMA. The CMA governs who may provide communications and multimedia services in Malaysia and on what terms, and it gives the MCMC broad powers over licensees, including the power to require them to assist in preventing offences committed through their networks or services.

Licensing under the CMA falls into categories of licensable activity, provided under either an individual licence or a class licence. The categories most relevant to digital services are:

  • Network Facilities Provider
  • Network Service Provider
  • Applications Service Provider
  • Content Applications Service Provider
  • Being a licensee is not a one-off administrative status: it carries continuing duties, including a general duty to use best endeavours to prevent a network, applications, or content service from being used in connection with any offence under Malaysian law.

    The 2025 social media and messaging licensing regime

    The most significant recent expansion of MCMC's remit is the licensing framework for internet messaging and social media services. Gazetted on 1 August 2024 and effective from 1 January 2025, it requires service providers with at least 8 million users in Malaysia to obtain an Applications Service Provider Class licence from the MCMC. Before this, such providers were exempt from licensing. The stated aim is to address rising cybercrime, including online fraud, cyberbullying, and sexual crimes against children, by placing clearer responsibility on platforms.

    Operating without the required licence after the grace period is an offence under Section 126 of the CMA. On conviction, a provider can face a fine of up to RM500,000 or imprisonment of up to five years, or both, with an additional daily fine of RM1,000 for each day the offence continues after conviction.

    To bring large, often foreign-based platforms into the regime efficiently, the CMA was amended to introduce a deeming provision under Section 46A, effective from 11 February 2025. This allows service providers to be deemed registered as class licensees through a Ministerial Declaration, without a formal registration process. Once deemed a licensee, a provider is treated in law as a class licensee and is subject to the same obligations under the CMA, its subsidiary legislation, and other applicable regulatory instruments. The provision was designed to close a gap for providers operating remotely from outside Malaysia.

    Alongside licensing, the MCMC has set conduct expectations for these providers:

  • Implementing robust policies and measures for user safety
  • Simplifying complaint procedures
  • Moderating content to prevent online harm
  • Incorporating child safety measures
  • Adopting strategies to address the risks of deepfakes and AI-generated content Providers are also expected to implement robust security measures to protect user data from unauthorised access, breaches, and misuse.
  • The Online Safety Act 2025

    The Online Safety Act 2025, formally Act 866, is the other major development. It received Royal Assent on 6 May 2025, was published in the Federal Gazette on 22 May 2025, and came into force on 1 January 2026. It places new legal duties on major online platforms and licensed communications providers to protect users from harmful content, with a strong focus on children and families. The law applies to service providers holding Applications Service Provider, Content Applications Service Provider, or Network Service Provider licences under the CMA. Individual users are not regulated under the Act.

    A central obligation is that licensed ASPs and CASPs must establish a mechanism to make priority harmful content inaccessible to all users once the Act is in effect. Priority harmful content includes child sexual abuse material and content relating to financial fraud, categories that sit squarely at the intersection of online safety and cyber security. Licensees are also expected to mitigate the risk of user exposure to harmful content more broadly, reinforcing the CMA's existing best-endeavours duty to prevent services being used in connection with offences.

    The security and data obligations inside MCMC compliance

    It is easy to read the MCMC framework as purely a matter of licensing and content policy. For security and compliance teams, though, several obligations are squarely technical.

    Protecting user data. Providers are expected to implement robust security measures to protect user data from unauthorised access, breaches, and misuse. That is a data security and breach-prevention obligation, and it overlaps directly with Malaysia's Personal Data Protection Act, which most licensees are also subject to.

    Keeping services resilient and clean. Network and applications providers carry a duty to prevent their infrastructure being used in connection with offences. In practice this calls for the ability to detect abuse, fraud, and malicious activity traversing their services, and to respond to it.

    Blocking fraud and abuse content. The Online Safety Act's requirement to make financial-fraud content inaccessible pushes platforms towards active detection of scam and phishing infrastructure, an area where threat intelligence and fraud detection capabilities matter.

    Availability. Large consumer platforms are high-value targets for denial-of-service and application-layer attacks. Sustaining service availability is both a commercial necessity and part of operating responsibly as a licensee.

    It is worth being clear about the boundary. Content moderation and online-safety governance are ultimately the platform's own responsibility, and much of MCMC compliance is legal and policy work rather than security engineering. But the data-protection, resilience, fraud-detection, and availability dimensions are genuine cyber security problems that a security partner can help address.

    How to approach MCMC compliance

    Start by confirming your licensing position, then map your obligations under both the CMA and the Online Safety Act, and identify which are legal or policy duties and which are technical:

  • Whether your service requires an individual or class licence
  • Whether the 8 million user threshold brings you into the social media regime
  • Whether the Section 46A deeming provision applies to you
  • On the technical side, prioritise the data-protection and resilience obligations:

  • Put in place the security measures needed to protect user data and demonstrate that protection
  • Build or contract the detection capability needed to identify abuse and fraud on your services
  • Ensure your infrastructure can withstand availability attacks

Align this work with your PDPA obligations so you are not solving the same data-protection problem twice.

Where a managed security partner fits

Several MCMC-related obligations map onto security capabilities. Protecting large consumer platforms from availability and application-layer attacks aligns with web security and content delivery services. Detecting fraud, scam infrastructure, and abuse of services aligns with threat intelligence. Continuous monitoring and incident response across the environment align with a managed detection and response and security operations centre model. And the underlying user-data protection obligation aligns with a structured security services programme.

Primary Guard works with providers across Malaysia, Indonesia, and Thailand on these dimensions, and a free assessment is a practical way to understand where your security posture stands against your obligations. Because most licensees also process personal data, this guide is best read alongside our PDPA compliance guide, which covers the data-protection duties that run in parallel with MCMC compliance.

Key takeaways

MCMC compliance in 2026 spans three layers: the long-standing CMA licensing framework, the 2025 social media and messaging licensing regime, and the Online Safety Act 2025. For most providers, the legal and content-policy duties sit with legal and compliance teams, but the obligations to protect user data, keep services resilient, and block fraud and abuse are genuine security problems. Treating the security dimensions as part of the compliance programme, rather than a separate concern, is what keeps a licensee both compliant and defensible.


This article is provided for general information and does not constitute legal advice. Providers should refer to the Communications and Multimedia Act 1998, the Online Safety Act 2025, and MCMC's guidelines, and consult qualified advisers on their specific obligations.

Frequently Asked Questions

Who needs an MCMC licence in Malaysia?

Providers of licensable communications and multimedia activities, including network facilities, network services, applications services, and content applications services, need a licence under the Communications and Multimedia Act 1998. Since 1 January 2025, social media and internet messaging providers with at least 8 million users in Malaysia must also hold an Applications Service Provider Class licence.

What is the penalty for operating without an MCMC licence?

Operating without a required licence is an offence under Section 126 of the CMA. On conviction, the penalty can be a fine of up to RM500,000 or imprisonment of up to five years, or both, with an additional daily fine of RM1,000 while the offence continues.

What is the Online Safety Act 2025?

The Online Safety Act 2025, Act 866, came into force on 1 January 2026. It places duties on licensed ASP, CASP, and NSP providers to protect users from harmful content, including a requirement to make priority harmful content such as child sexual abuse material and financial-fraud content inaccessible to all users.

Does MCMC compliance include cyber security obligations?

Yes, in part. Licensees must implement robust measures to protect user data from unauthorised access and breaches, take steps to prevent their services being used for offences, and, under the Online Safety Act, block financial-fraud content. These are security and data-protection obligations alongside the licensing and content-policy duties.

What is the Section 46A deeming provision?

Introduced by 2025 amendments and effective from 11 February 2025, Section 46A allows service providers to be deemed registered as class licensees through a Ministerial Declaration, without formal registration. Deemed licensees are subject to the same obligations as other class licensees under the CMA.

How does MCMC compliance relate to the PDPA?

They overlap. MCMC requires licensees to protect user data, and the Personal Data Protection Act sets Malaysia's general data-protection obligations. Most licensees are subject to both and should align their data-protection controls across the two.