Independent resource. XBRL Malaysia is an independent, privately run learning site. We are not affiliated with, endorsed by, or connected to Suruhanjaya Syarikat Malaysia (SSM), the Companies Commission of Malaysia, or any Malaysian government agency. Read our full disclaimer →
ENBM
HomeGuidesGlossaryFAQAbout & Disclaimer Free Checklist

How It Works

How to Register for mPortal (SSM4U / MyCoID)

Before you can submit anything through MBRS, you need working access to mPortal. Here is what that setup actually involves, in plain terms.

Last reviewed: July 2026

A lot of first-time confusion around MBRS happens before anyone even opens mTool — simply because portal access itself is unclear. This guide covers just that first step.

Scope of this page

This describes the general shape of portal access at a conceptual level. Exact screens, buttons, and steps on SSM's systems can change; always follow the current instructions on SSM's own MBRS and SSM4U pages for the precise steps.

The two login systems involved

MBRS access runs through SSM's broader digital ecosystem, not a standalone login of its own. Two names come up constantly:

  • MyCoID — SSM's foundational company identification and portal system, used well beyond just MBRS.
  • SSM4U — the user account layer that provides access to SSM's suite of digital services, including reaching mPortal for MBRS submissions.

In practice, mPortal is not something you register for in isolation; you reach it through an SSM4U-linked account that is connected to your company's MyCoID registration.

If you already use MyCoID

If your company or your company secretary already has an active MyCoID account used for other SSM services, a separate SSM4U registration generally is not required — existing MyCoID users typically use that same login to reach mPortal. If access issues come up, they are more often a password or permissions problem than a "we need to register from scratch" problem. A forgotten password can usually be resolved through the SSM4U portal's password reset flow directly.

If you're starting from scratch

For a company or individual with no prior SSM digital account, the general shape of onboarding is: register as an SSM4U user, link that account to the company's MyCoID registration, and from there, the relevant user role (see below) gets access to mPortal for MBRS submissions.

Free Download

Getting portal access sorted before you file?

Grab the free MBRS 2.0 Filing Readiness Checklist — 20+ checks across deadlines, exemptions, and setup, in one printable page.

Get the free checklist →

The digital certificate step

Separate from basic portal login, the person who will actually submit and digitally sign a filing — the Lodger, often a company secretary, company agent, liquidator, or official receiver acting in that capacity — needs a PKI (Public Key Infrastructure) digital certificate. This is typically purchased through a registration process that mPortal directs users to (historically via a linked Digicert registration system). This certificate step is specific to the Lodger role; not everyone involved in preparing a filing needs one.

Don't leave this until deadline week

Digital certificate registration and portal access setup can take longer than expected if it's your first time, particularly if there's any mismatch between company records and the account being registered. Sort this out well before a filing deadline, not the week of it.

Common early-stage confusion

  • "Do I need to register for MBRS specifically?" — no separate MBRS-only registration exists; access comes through the SSM4U/MyCoID system generally.
  • "Does everyone preparing the filing need a digital certificate?" — no, only the person acting as Lodger who actually signs and submits the filing.
  • "I have MyCoID access already, why can't I see mPortal?" — this is usually a role or permissions issue tied to what the account is authorised to do for that specific company, rather than a missing registration.