Malaysia Mobile App Certification - FAQ

Frequently Asked Questions (FAQ) on MAC

Scheme: A scheme is a formal system with strict rules, processes, and certification to ensure compliance. For MAC, it defines the official standards for mobile app security.

Guideline: A guideline is advisory. It gives examples, tips, and best practices to help developers follow the scheme more effectively.

Analogy: Think of a scheme as the driving licence system (rules, tests, certification). A guideline is the driving handbook that helps you understand how to drive safely.

App stores (Google Play & Apple) mainly check for policy compliance and scan for obvious threats. These checks do not guarantee your app meets national security standards.

MAC Certification goes deeper:

  • Validates your app against Malaysia’s official security requirements.
  • Builds public trust and regulatory confidence.
  • Demonstrates commitment to protecting users.

Analogy: App store checks are like immigration control at the airport (basic ID verification). MAC is like customs inspection (thorough security audit).

Both improve app security, but they serve different purposes:

Category Mobile Penetration Testing (MPT) MAC Certification
Objective Find vulnerabilities through simulated attacks. Prove compliance with certified security standards.
Approach Red Team testing and runtime analysis. Formal structured assessment by a certified lab.
Deliverable Developer vulnerability report. Official ISCB Certification Letter & audit checklist.
Recognition Internal or organizational level. National-level recognition (by CSM).
Use Case Improves internal DevSecOps & reduces risk. Enables compliance, public trust & eligibility for tenders.

No. The MAC Scheme is not a full penetration test.

It includes penetration-like elements (e.g., code analysis, vulnerability checks), but the process is:

  • Structured
  • Checklist-based
  • Focused on compliance with Malaysian standards

A full penetration test is open-ended and adversarial, while MAC is compliance-driven.

App updates are reviewed to ensure security compliance is maintained. A yearly re-test is mandatory.

Update Process:

  1. Submit a Self-Declaration Form describing the update.
  2. The committee reviews the change.
  3. No re-certification: Minor updates that don’t affect the app’s core structure.
  4. Re-certification required: Major updates that impact the kernel or core security.