🌐ENESDEFR
← Back to global tracker
🇲🇾

Country deep dive

Malaysia

Asia-Pacific · MY
Last updated: 2026-07-21
Compliance model: Centralised clearance (MyInvois)
🎚️Malaysia's MyInvois clearance mandate is rolling out top-down by company turnover, already covering businesses down to the RM1–5 million tier as of 2026. Each tier gets a relaxation period after its formal start date before enforcement tightens.
E-invoicing mandate
B2G ACTIVE B2G in scope; the flow mirrors B2B and follows the same turnover phase dates
B2B ACTIVE Final wave RM1m-5m live 1 Jan 2026; under RM1m exempt, Phase 5 cancelled
B2C ACTIVE Monthly consolidated e-invoice; an individual one required above RM10,000
NO MANDATE
E-reporting
MyInvois is clearance; the consolidated B2C e-invoice is filed in that platform, not a separate report.
7 yrs
Archiving
Records kept 7 years from end of year of assessment, Income Tax Act 1967 s.82A
REQUIRED
Digital signature
XAdES signature with a Malaysian CA X.509 certificate on API submissions
UBL 2.1
XML or JSON
55
Mandatory data fields
72 hrs
Rejection/cancellation window
8
Supported document types
01

Compliance timeline

Malaysia's rollout works top-down by turnover tier, with a relaxation period running well past each tier's formal start date.

2024
2024-08-01In effect
Phase 1 — businesses above RM100 million turnover

The largest taxpayers become the first mandatory cohort, establishing MyInvois as the national clearance platform.

2025
2025-01-01In effect
Phase 2 — RM25 million to RM100 million

Mid-large businesses join the mandate.

2025
2025-07-01In effect
Phase 3 — RM5 million to RM25 million

The mandate extends further down the turnover scale toward mid-sized companies.

2026
2026-01-01In effect
MyInvois Phase 4 — turnover RM1m–5m

Businesses with annual turnover between RM1 million and RM5 million entered the mandate, with a relaxation period (no penalties for submission errors) extended to 31 December 2027.

2026
2026-07-01In effect
Related/subsidiary companies of RM1m+ groups

Businesses below RM1 million turnover that are subsidiaries or related companies of an RM1 million+ group must still comply, regardless of their own individual revenue.

02

File format & data specification

Malaysia genuinely supports two serialisations of the same underlying UBL 2.1 structure — pick whichever fits your stack, not a fixed single format.

Format & standard

Data structureUBL 2.1 (Universal Business Language)
Accepted serialisationsXML or JSON
Digital certificateMandatory, issued by a recognised Malaysian Certificate Authority

Both XML and JSON carry the same UBL 2.1 data model — choose based on what integrates more cleanly with your existing ERP, not a compliance preference.

Identifiers & registration

The identifier combinationA business entity needs its TIN AND its business registration number, both. A Malaysian individual may use a MyKad number alone. The SST registration number is included where applicable, otherwise the literal NA.
RegistrationLog in through MyTax to reach the MyInvois Portal. API submitters additionally register their ERP in the portal to self-provision a client ID and secret, and need an organisation digital certificate from a Malaysian certification authority.
Who accredits whatThe tax authority accredits nothing — a taxpayer submitting by portal or direct API needs no approved vendor. Accreditation exists only on the Peppol route. "MDEC-accredited software required" is wrong for most submitters.
Managed byMDEC (Malaysia Digital Economy Corporation)
Used forCross-border and B2G invoice exchange
Format differenceMyInvois typically uses UBL 2.1 JSON; Peppol uses UBL 2.1 XML with PINT

Mandatory content

Field count55 specific data fields
CoversSeller/buyer details, transaction items, quantities, prices, taxes, totals, payment information
Reference fieldsTIN, MSIC code, tax classification

Validation failures at LHDN fail closed — the document is rejected outright rather than accepted with a warning, so getting these 55 fields right the first time genuinely matters.

Archiving

Period and basisSeven years under Income Tax Act 1967 s.82A, counted from the end of the year of assessment rather than from the invoice — which pushes the real horizon past seven years for most documents.
SignatureRequired. The signature is part of what makes the stored document valid, so it must survive archiving intact.

Document types (8 total)

Standard typesInvoice, credit note, debit note, refund note
Self-billed variantsFour equivalents, for self-billing scenarios

Self-billed invoices are treated as a genuinely distinct document type set, not just a flag on the standard invoice type — plan your integration accordingly if you use self-billing.

03

Scope & transmission

MyInvois is a genuine clearance platform: LHDN validates in real time and assigns identifiers before an invoice carries legal weight.

API mechanics

AuthenticationOAuth 2.0, scope "InvoicingAPI"
IdentityTaxpayer TIN + NRIC/BRN
EndpointPOST to /api/v1.0/documents/submit
CredentialsEnvironment-specific — sandbox and production are separate

Don't reuse sandbox credentials in production or vice versa — LHDN issues distinct client ID/secret pairs for each environment via the MyInvois developer portal.

The 72-hour window

Buyer rejection requestWithin 72 hours of validation
Issuer cancellationWithin 72 hours of approval
After the windowMust issue a credit/debit note instead

Trying to cancel outside this window returns an "OperationPeriodOver" error — plan your correction workflow around credit/debit notes as the fallback path, not cancellation.

Submission methods

  • Manual entry via MyInvois Portal
  • Direct API integration
  • Accredited/Peppol-linked solutions

API submission is recommended for moderate-to-high invoice volumes — it enables direct ERP integration and automated batch processing that manual portal entry can't match.

Validation lifecycle

NewProcessingSubmittedApproved / Rejected

On successful validation, MyInvois returns a UUID immediately and a Long ID once server-side validation completes — build your status polling around both identifiers.

04

Getting compliant

Getting API credentials is a genuine multi-step identity-verification process, not a self-serve signup.

Determine your applicable phase

Check your FY2022 audited accounts (or first available tax return) against the current turnover tier to confirm when your obligation actually begins.

Register on the MyInvois developer portal

Complete identity verification using your TIN and BRN (or NRIC for individuals), and apply for API access — LHDN issues a client ID and client secret for the OAuth 2.0 flow.

Obtain a digital certificate

Source this from a recognised Malaysian Certificate Authority — every submitted document must be digitally signed.

Map your data to UBL 2.1

Ensure your ERP or invoicing software can generate all 55 mandatory fields correctly, in either XML or JSON — validation failures fail closed with no partial acceptance.

Test thoroughly in the sandbox environment

Use your separate sandbox credentials to validate the full submission → validation → status-polling flow before switching to production.

Brief sales and finance teams

Sales needs to capture accurate TINs at the deal stage; finance needs a daily rejection-queue monitoring routine, since fixes need to happen fast within the 72-hour window.

Check group structure for related-company exposure

Confirm whether being part of an RM1m+ group brings you into scope even if your own standalone revenue sits below that threshold.

05

Penalties & enforcement

Non-compliance ties back into Malaysia's general Income Tax Act framework rather than a standalone e-invoicing fine schedule.

06

Related jurisdictions — Asia-Pacific

Other countries in the same region, ordered by their next dated milestone. Each links to a full briefing.