Malaysia's National Security Council Cites SITG-Consulting's ASEAN Post-Quantum Assessment

On 15 September 2026, Malaysia's National Security Council (Majlis Keselamatan Negara), an agency of the Prime Minister's Department, issued a statement confirming Malaysia as the only ASEAN member state at Tier 1 for post-quantum cryptography migration readiness. The assessment behind that finding is SITG-Consulting's ASEAN Post-Quantum Cryptography Readiness 2026: An Empirical Assessment of the ASEAN-10, published on 1 September.
The statement and the report were reported by:
Bernama, Malaysia's national news agency
RTM, Malaysia's national broadcaster
Business Today
Sinar Daily
Sarawak Tribune
VietnamPlus, the English-language service of Vietnam's national news agency VNA
What the Council said
The Council described the Tier 1 position as reflecting Malaysia's preparation to protect government data, financial transactions, digital identities, communications and critical services from the future threat that quantum computing poses to today's encryption.
It also described how the assessment was made: on nationally verifiable action and implementation, not on statements of intent. That sentence is the one we would ask readers to hold on to. The report was built to separate what a state has put in place from what it has announced, and a national security body has read that distinction back accurately.
Why Malaysia sits at Tier 1
Tier 1 does not mean migration is complete. No state could meet that bar today, and a framework built around it would measure nothing. Tier 1 asks whether national migration machinery exists and is operating.
Malaysia is the only ASEAN state where it demonstrably is. The assessment found four elements working together:
a Cabinet-approved national cryptography policy, MyKriptografi
a directive issued under the Cyber Security Act 2024, with a named population of organisations obliged to act
a national post-quantum migration plan with a 2030 horizon
a proof-of-concept sandbox that was operating and funding participants
Sector regulators have also begun translating the national instruments into their own requirements. Each element on its own would place a state at Tier 2. The combination, running, is what places Malaysia at Tier 1.
Where the rest of the region stands
Six states sit at Tier 2: Brunei Darussalam, Cambodia, Indonesia, Singapore, Thailand and Vietnam. Each has a named national authority and a substantive instrument. None, as at the evidence cut-off, had converted guidance into a binding obligation with a defined population.
Singapore's position illustrates the boundary. Its guidance is authoritative and its milestones are dated. On every account the assessment could retrieve or corroborate, those milestones are expressly non-mandatory. Sophistication of discourse and sophistication of governance are different things, and this assessment measures the second.
The Philippines sits at Tier 3, on funded research rather than migration machinery. Laos sits at Tier 4. Myanmar sits at Tier 5, which the report defines with care: sufficient publicly verifiable, post-quantum-specific evidence was not found under this method, on this date. It is not a finding of inactivity.
The distribution does not follow size, wealth or digital reputation. Brunei Darussalam, one of the bloc's smallest states, has published one of the fullest national frameworks reviewed in this series.
How the finding should be read
Three qualifications travel with the result, and they apply to Malaysia as much as anyone.
The classification is a point-in-time finding with an evidence cut-off of 17 August 2026. Every state, Malaysia included, will be re-tested at the next evidence pass.
The report has already moved its own findings. Two rounds of independent audit moved Cambodia up twice and the Philippines once, and every change is recorded in the document with its reasoning. Open verification items are published with the action that would close each one.
Tier 1 is a statement about national machinery, not about any individual organisation. A bank, hospital or utility operating in Malaysia is not migrated because the state has a plan. It is obliged to act, which is a different thing.
What comes next
The Council has said the next phase centres on collaboration between the lead agencies for National Critical Information Infrastructure, the operators of that infrastructure and industry partners.
This is the stage where national programmes succeed or stall. Policy sets direction. Migration happens in cryptographic inventories, supplier contracts, procurement specifications and the dependency chains that sit beneath them. The organisations named in the directive now carry the work, and their boards carry the accountability.
For boards and regulators elsewhere in ASEAN, the Malaysian sequence is the useful lesson: policy first, then a binding instrument with a named population, then a plan with a date, then a place to test before committing. The EU's Coordinated Roadmap and the United Kingdom's National Cyber Security Centre timelines follow the same order, with inventory ahead of deadline.
Read the report
The full assessment is deposited on Zenodo under a Creative Commons Attribution 4.0 licence, free to read, reuse and challenge.
SITG-Consulting (2026). ASEAN Post-Quantum Cryptography Readiness 2026: An Empirical Assessment of the ASEAN-10. Version 1.2. Zenodo. https://doi.org/10.5281/zenodo.22218529
Test it against your own retrieval and tell us where it is wrong.
Coverage
Bernama: https://www.bernama.com/en/general/news.php?id=2607391
Business Today: https://www.businesstoday.com.my/2026/09/15/malaysia-only-asean-nation-to-reach-top-tier-in-quantum-security-readiness/
Sarawak Tribune: https://www.sarawaktribune.com/malaysia-only-asean-nation-rated-tier-1-for-pqc-readiness/
Sinar Daily: Malaysia only Asean nation rated Tier 1 for PQC readiness - Sinar Daily
VietnamPlus: https://en.vietnamplus.vn/malaysia-leads-asean-in-post-quantum-security-readiness-post351996.vnp




Comments