CIDB Pekeliling Bil. 1/2026

Mandatory ISO 37001 Certification by 1 January 2027,
or no SPKK

From 1 January 2027, every Grade G7 contractor needs a valid ISO 37001 certificate to apply for or renew their SPKK. No grandfather clause. No grace period. No SPKK means no government tender.

45 minutes, no cost, no obligation · Trial needs no credit card

What the circular says

The requirement, in plain language.

CIDB Pekeliling Bil. 1/2026 makes certification to ISO 37001 Anti-Bribery Management Systems a condition of holding Grade G7 registration. It applies to both new applications and renewals from 1 January 2027 — being registered already does not exempt you.

The certificate must come from a certification body accredited by DSM/JSM, or by an accreditation body that is a signatory to the IAF Multilateral Recognition Arrangement. A certificate from an unaccredited body will not satisfy the requirement.

Separately, MACC policy already bars contractors without anti-bribery certification from tenders above RM100 million — so for the largest G7 firms the commercial consequence has already started.

6–9 months

Standalone implementation

3–4 months

Integrated with existing ISO

Q2 2026

When CB slots should have been booked

Here is the part most people selling you something will not say: if you are starting from a blank page today, the conventional path no longer fits. What still works is compressing the documentation-and-evidence phase from five months to about six weeks, so you can book Stage 1 in November and Stage 2 in December.

That is what the software is for. You should know this now rather than in November.

Your position, not the average one

How urgent is this for you?

When does your SPKK expire?

The single question that decides how urgent this is for you. Renewal dates are staggered — two G7 contractors can be in completely different positions.

Indicative only. Timelines assume certification body audit capacity is available when you need it — in practice that is the binding constraint, and it tightens as the deadline nears.

The compressed path

What twenty weeks actually looks like.

Not a marketing timeline. This is the sequence ISO 37001 requires, with the documentation phase already done for you.

1

Weeks 1–2

Foundation

Appoint your Anti-Bribery Function, adopt the policy set, and set the scope of your management system. The documents are already written — this is review and approval, not drafting.

2

Weeks 3–6

Risk & controls

Build the bribery risk register against your actual project and procurement exposure. Run due diligence on your material business associates. Turn on the gift, COI and whistleblowing channels.

3

Weeks 7–10

Evidence

Training delivered and recorded, commitments signed across the roster, declarations flowing. This is the phase auditors actually examine — it is evidence of operation, and it cannot be back-dated.

4

Weeks 11–14

Internal audit & management review

Run the internal audit, raise and close nonconformances, hold the management review. ISO 37001 requires both to have happened before Stage 2.

5

Weeks 15–20

Stage 1 and Stage 2

Your certification body audits documentation, then operation. Book these slots now — audit capacity, not your paperwork, is what decides whether you make the date.

What you actually get

Setup and implementation in weeks, not months.

Most of the effort in an ISO 37001 implementation goes into writing documentation and assembling evidence. Ethytude ships with that structure already in place, so your team spends its time on decisions and records rather than drafting from a blank page.

Ready to use from day one

Bribery risk register
Due diligence
Gifts & hospitality
Conflict of interest
Whistleblowing channel
Training & screening
Internal audit & NCAR
Anti-bribery commitments
Document library
Policies & controls
ABF appointment
Management review

We are not a certification body.

Ethytude cannot certify you, and neither can any other software. You still need an accredited certification body, and in most cases a consultant to design the system around how your business actually works. The consultant designs it. The accredited CB certifies it. Ethytude is what it runs on — day to day, and at every surveillance audit after the first one.

Pricing

Straight talk. Just seats.

Every module on every plan — tiers differ only by login users. Non-login roster staff are unlimited throughout.

Starter

RM6,000

per year · billed annually

Up to 50 login users

Start free trial

Business

RM20,000

per year · billed annually

Up to 200 login users

Start free trial

Enterprise

RM35,000

per year · billed annually

Up to 500 login users

Start free trial

The most useful 45 minutes you’ll spend on this

Book a free gap review.

We look at your renewal date, what you already have, and what is genuinely achievable in the time left — and tell you honestly if it isn’t. No cost, no obligation, and no pitch if the answer is that you need something other than us.

45 minutes, no cost, no obligation. We use your details only to arrange and prepare for this review — see our privacy policy.

Questions worth asking.

Does Ethytude certify us?+

No. Certification can only come from a certification body accredited by DSM/JSM or under an IAF MLA signatory. Ethytude is the system your management system runs on — it produces the records and evidence an auditor inspects. Consultant designs it, accredited CB certifies it, Ethytude is what it runs on.

Will an auditor accept what comes out of it?+

An auditor doesn't accept or reject software — they inspect records. Ethytude produces the ones they ask for: approved and versioned policies, a maintained risk register, due diligence files, declarations with approval trails, training records, internal audit and corrective action reports, and management review minutes. The evidence pack assembles them into a single PDF bundle.

We already have ISO 9001. Does that help?+

Considerably. An organisation with an existing ISO management system typically reaches certification in 3–4 months rather than 6–9, because the governance structures, document control and internal audit habits already exist. You are extending a system rather than building one.

We're G1–G6. Does this apply to us?+

The ISO 37001 condition in Pekeliling Bil. 1/2026 applies to Grade G7. But MACC Act 2009 Section 17A applies to every commercial organisation in Malaysia regardless of grade — a company is liable for the corrupt acts of its people unless it can show it had adequate procedures in place. The requirement differs; the exposure doesn't.

What if we miss 1 January 2027?+

You cannot apply for or renew your SPKK until you hold the certificate, which means no government tenders in the interim. The practical questions become how short you can make that gap and how your renewal timing can be managed. That is a conversation worth having early rather than in December.

How long does setup actually take?+

The account exists in minutes and the 31 documents are already in it. Populating your risk register, roster and due diligence records is the real work — most organisations are running properly inside two weeks, and we do a setup call with you on day one rather than leaving you to find it.

The date does not move.

Find out where you actually stand — then decide what to do about it.