โ† Back to global tracker
๐Ÿ‡ฒ๐Ÿ‡พ

Country deep dive

Malaysia

Asia-Pacific ยท MY ยท Non-EU
Last updated: 21 July 2026
Compliance model: Centralised clearance (MyInvois)
UBL 2.1
XML or JSON
55
Mandatory data fields
72 hrs
Rejection/cancellation window
8
Supported document types
7 yrs
Archive requirement
01

Compliance timeline

Malaysia's rollout works top-down by turnover tier, with a relaxation period running well past each tier's formal start date.

2024
Aug 2024In effect
Phase 1 โ€” businesses above RM100 million turnover

The largest taxpayers become the first mandatory cohort, establishing MyInvois as the national clearance platform.

2025
Jan 2025In effect
Phase 2 โ€” RM25 million to RM100 million

Mid-large businesses join the mandate.

Jul 2025In effect
Phase 3 โ€” RM5 million to RM25 million

The mandate extends further down the turnover scale toward mid-sized companies.

January 2026
1 Jan 2026In effect
Phase 4 โ€” RM1 million to RM5 million turnover

A relaxation period (no penalties for submission errors) runs alongside this phase, extended to 31 December 2027.

July 2026
1 Jul 2026In effect
Related/subsidiary companies of RM1m+ groups included

Businesses below RM1 million individually but part of a related-company group at or above that threshold are captured regardless of their own standalone revenue.

02

File format & data specification

Malaysia genuinely supports two serialisations of the same underlying UBL 2.1 structure โ€” pick whichever fits your stack, not a fixed single format.

Format

Data structureUBL 2.1 (Universal Business Language)
Accepted serialisationsXML or JSON
Digital certificateMandatory, issued by a recognised Malaysian Certificate Authority

Both XML and JSON carry the same UBL 2.1 data model โ€” choose based on what integrates more cleanly with your existing ERP, not a compliance preference.

Mandatory data fields

Field count55 specific data fields
CoversSeller/buyer details, transaction items, quantities, prices, taxes, totals, payment information
Reference fieldsTIN, MSIC code, tax classification

Validation failures at LHDN fail closed โ€” the document is rejected outright rather than accepted with a warning, so getting these 55 fields right the first time genuinely matters.

Document types (8 total)

Standard typesInvoice, credit note, debit note, refund note
Self-billed variantsFour equivalents, for self-billing scenarios

Self-billed invoices are treated as a genuinely distinct document type set, not just a flag on the standard invoice type โ€” plan your integration accordingly if you use self-billing.

Peppol as a separate track

Managed byMDEC (Malaysia Digital Economy Corporation)
Used forCross-border and B2G invoice exchange
Format differenceMyInvois typically uses UBL 2.1 JSON; Peppol uses UBL 2.1 XML with PINT

A business can and often does use both tracks simultaneously โ€” MyInvois for domestic compliance, Peppol for government procurement or international clients โ€” but they're genuinely different protocols requiring separate handling.

03

Transmission protocol

MyInvois is a genuine clearance platform: LHDN validates in real time and assigns identifiers before an invoice carries legal weight.

Submission methods

Manual entry via MyInvois PortalDirect API integrationAccredited/Peppol-linked solutions

API submission is recommended for moderate-to-high invoice volumes โ€” it enables direct ERP integration and automated batch processing that manual portal entry can't match.

API mechanics

AuthenticationOAuth 2.0, scope "InvoicingAPI"
IdentityTaxpayer TIN + NRIC/BRN
EndpointPOST to /api/v1.0/documents/submit
CredentialsEnvironment-specific โ€” sandbox and production are separate

Don't reuse sandbox credentials in production or vice versa โ€” LHDN issues distinct client ID/secret pairs for each environment via the MyInvois developer portal.

Validation lifecycle

NewProcessingSubmittedApproved / Rejected

On successful validation, MyInvois returns a UUID immediately and a Long ID once server-side validation completes โ€” build your status polling around both identifiers.

The 72-hour window

Buyer rejection requestWithin 72 hours of validation
Issuer cancellationWithin 72 hours of approval
After the windowMust issue a credit/debit note instead

Trying to cancel outside this window returns an "OperationPeriodOver" error โ€” plan your correction workflow around credit/debit notes as the fallback path, not cancellation.

04

Getting set up with MyInvois

Getting API credentials is a genuine multi-step identity-verification process, not a self-serve signup.

Determine your applicable phase

Check your FY2022 audited accounts (or first available tax return) against the current turnover tier to confirm when your obligation actually begins.

Register on the MyInvois developer portal

Complete identity verification using your TIN and BRN (or NRIC for individuals), and apply for API access โ€” LHDN issues a client ID and client secret for the OAuth 2.0 flow.

Obtain a digital certificate

Source this from a recognised Malaysian Certificate Authority โ€” every submitted document must be digitally signed.

Map your data to UBL 2.1

Ensure your ERP or invoicing software can generate all 55 mandatory fields correctly, in either XML or JSON โ€” validation failures fail closed with no partial acceptance.

Test thoroughly in the sandbox environment

Use your separate sandbox credentials to validate the full submission โ†’ validation โ†’ status-polling flow before switching to production.

Brief sales and finance teams

Sales needs to capture accurate TINs at the deal stage; finance needs a daily rejection-queue monitoring routine, since fixes need to happen fast within the 72-hour window.

Check group structure for related-company exposure

Confirm whether being part of an RM1m+ group brings you into scope even if your own standalone revenue sits below that threshold.

05

Related considerations

Non-compliance ties back into Malaysia's general Income Tax Act framework rather than a standalone e-invoicing fine schedule.

LHDN โ€” MyInvois / e-Invoice