CIDB Pekeliling Bil. 1/2026
From 1 January 2027, every Grade G7 contractor needs a valid ISO 37001 certificate to apply for or renew their SPKK. No grandfather clause. No grace period. No SPKK means no government tender.
45 minutes, no cost, no obligation · Trial needs no credit card
What the circular says
CIDB Pekeliling Bil. 1/2026 makes certification to ISO 37001 Anti-Bribery Management Systems a condition of holding Grade G7 registration. It applies to both new applications and renewals from 1 January 2027 — being registered already does not exempt you.
The certificate must come from a certification body accredited by DSM/JSM, or by an accreditation body that is a signatory to the IAF Multilateral Recognition Arrangement. A certificate from an unaccredited body will not satisfy the requirement.
Separately, MACC policy already bars contractors without anti-bribery certification from tenders above RM100 million — so for the largest G7 firms the commercial consequence has already started.
6–9 months
Standalone implementation
3–4 months
Integrated with existing ISO
Q2 2026
When CB slots should have been booked
Here is the part most people selling you something will not say: if you are starting from a blank page today, the conventional path no longer fits. What still works is compressing the documentation-and-evidence phase from five months to about six weeks, so you can book Stage 1 in November and Stage 2 in December.
That is what the software is for. You should know this now rather than in November.
Your position, not the average one
The single question that decides how urgent this is for you. Renewal dates are staggered — two G7 contractors can be in completely different positions.
Indicative only. Timelines assume certification body audit capacity is available when you need it — in practice that is the binding constraint, and it tightens as the deadline nears.
The compressed path
Not a marketing timeline. This is the sequence ISO 37001 requires, with the documentation phase already done for you.
Weeks 1–2
Appoint your Anti-Bribery Function, adopt the policy set, and set the scope of your management system. The documents are already written — this is review and approval, not drafting.
Weeks 3–6
Build the bribery risk register against your actual project and procurement exposure. Run due diligence on your material business associates. Turn on the gift, COI and whistleblowing channels.
Weeks 7–10
Training delivered and recorded, commitments signed across the roster, declarations flowing. This is the phase auditors actually examine — it is evidence of operation, and it cannot be back-dated.
Weeks 11–14
Run the internal audit, raise and close nonconformances, hold the management review. ISO 37001 requires both to have happened before Stage 2.
Weeks 15–20
Your certification body audits documentation, then operation. Book these slots now — audit capacity, not your paperwork, is what decides whether you make the date.
What you actually get
Most of the effort in an ISO 37001 implementation goes into writing documentation and assembling evidence. Ethytude ships with that structure already in place, so your team spends its time on decisions and records rather than drafting from a blank page.
Ready to use from day one
Ethytude cannot certify you, and neither can any other software. You still need an accredited certification body, and in most cases a consultant to design the system around how your business actually works. The consultant designs it. The accredited CB certifies it. Ethytude is what it runs on — day to day, and at every surveillance audit after the first one.
Pricing
Every module on every plan — tiers differ only by login users. Non-login roster staff are unlimited throughout.
The most useful 45 minutes you’ll spend on this
We look at your renewal date, what you already have, and what is genuinely achievable in the time left — and tell you honestly if it isn’t. No cost, no obligation, and no pitch if the answer is that you need something other than us.
No. Certification can only come from a certification body accredited by DSM/JSM or under an IAF MLA signatory. Ethytude is the system your management system runs on — it produces the records and evidence an auditor inspects. Consultant designs it, accredited CB certifies it, Ethytude is what it runs on.
An auditor doesn't accept or reject software — they inspect records. Ethytude produces the ones they ask for: approved and versioned policies, a maintained risk register, due diligence files, declarations with approval trails, training records, internal audit and corrective action reports, and management review minutes. The evidence pack assembles them into a single PDF bundle.
Considerably. An organisation with an existing ISO management system typically reaches certification in 3–4 months rather than 6–9, because the governance structures, document control and internal audit habits already exist. You are extending a system rather than building one.
The ISO 37001 condition in Pekeliling Bil. 1/2026 applies to Grade G7. But MACC Act 2009 Section 17A applies to every commercial organisation in Malaysia regardless of grade — a company is liable for the corrupt acts of its people unless it can show it had adequate procedures in place. The requirement differs; the exposure doesn't.
You cannot apply for or renew your SPKK until you hold the certificate, which means no government tenders in the interim. The practical questions become how short you can make that gap and how your renewal timing can be managed. That is a conversation worth having early rather than in December.
The account exists in minutes and the 31 documents are already in it. Populating your risk register, roster and due diligence records is the real work — most organisations are running properly inside two weeks, and we do a setup call with you on day one rather than leaving you to find it.
Find out where you actually stand — then decide what to do about it.