Cyber Security Act 2024 Malaysia: The NACSA Compliance Guide
Primary Guard · July 22, 2026 · 8 min read
Malaysia's Cyber Security Act 2024 is in force. Who counts as NCII, the 6-hour incident-reporting clock, CSSP licensing, penalties, and how to comply.
Malaysia now has its first standalone cyber security law. The Cyber Security Act 2024, known as Act 854, came into force on 26 August 2024, and with it Malaysia moved from voluntary good practice to legally binding obligations for the organisations that run the country's most critical systems. If your business operates critical infrastructure, or if it sells cyber security services, the Act very likely applies to you, and it carries real penalties.
This guide explains what the Act requires in 2026: who counts as critical infrastructure, the strict incident-reporting timeline, the licensing regime for cyber security providers, the penalties, and how to approach compliance. It is written for boards, IT and security leaders, compliance teams, and cyber security service providers operating in Malaysia.
What is the Cyber Security Act 2024?
The Cyber Security Act 2024 is Malaysia's primary legislation for national cyber security. Gazetted on 26 June 2024 and in force since 26 August 2024, it is administered by the National Cyber Security Agency (NACSA), whose Chief Executive holds the main enforcement powers, and it establishes a National Cyber Security Committee chaired by the Prime Minister to set national policy.
The Act is supported by four subsidiary regulations that give it operational detail: the Notification of Cyber Security Incident Regulations 2024, the Period for Cyber Security Risk Assessment and Audit Regulations 2024, the Compounding of Offences Regulations 2024, and the Licensing of Cyber Security Service Provider Regulations 2024.
One feature worth noting early: the Act has extraterritorial reach. It can apply to offences committed outside Malaysia where those offences involve national critical information infrastructure located wholly or partly in the country.
Who must comply?
The Act applies to two distinct groups, and it is important to know which one, or both, applies to you.
National Critical Information Infrastructure (NCII) entities
NCII refers to a computer or computer system whose disruption would be detrimental to national security, defence, foreign relations, the economy, public health, public safety, or public order. The Act organises this around eleven NCII sectors:
- Government
- Banking and finance
- Transportation
- Defence and national security
- Information, communication and digital
- Healthcare services
- Water, sewerage and waste management
- Energy
- Agriculture and plantation
- Trade, industry and economy
- Science, technology and innovation
- Immediately — your designated authorised person notifies NACSA and your sector lead electronically that an incident has or may have occurred.
- Within six hours — that person submits the first report through the National Cyber Coordination and Command Centre System (NC4S). This covers the incident's nature and type, its severity (typically rated using the Common Vulnerability Scoring System), the date and time where known, and how it was discovered.
- Within fourteen days — a supplementary report follows. This covers which systems were affected, the estimated number of hosts involved, what is known about the threat actor, the impact on the entity and any connected systems, and the actions taken to contain it.
Within each sector, the Prime Minister appoints a sector lead, and those leads designate specific organisations as NCII entities. If your organisation is formally designated, the compliance obligations below apply to you directly.
Cyber security service providers
The second group is anyone who provides, or advertises or holds themselves out as providing, a licensable cyber security service in Malaysia. Under the licensing regime, these providers must hold a NACSA licence, whether or not they are themselves an NCII entity.
What NCII entities must do
Designation as an NCII entity triggers a defined set of obligations.
Baseline self-assessment
Following designation, an NCII entity must complete the National Cyber Security Baseline (NCSB) Self-Assessment within 14 days. The NCSB, introduced through a NACSA directive, sets out a minimum set of cyber security controls and best practices that act as the entity's starting blueprint.
Annual risk assessment and biennial audit
Under the risk assessment and audit rules, an NCII entity must conduct a cyber security risk assessment at least once a year, and carry out a cyber security audit at least once every two years, or more frequently if the Chief Executive directs it in a specific case. These are recurring, evidenced exercises, not one-off tasks.
Codes of practice
NCII entities must comply with the codes of practice approved by the Chief Executive for their sector. An entity may propose alternative measures, but only where those measures offer protection equal to or better than the approved code.
The incident-reporting clock
This is the obligation most likely to catch organisations out, because it runs on hours, not days, and it starts the moment an incident comes to your knowledge, before you have concluded how serious it is.
The timeline has three stops:
The practical point is stark: you cannot report inside six hours if you cannot detect and characterise an incident inside six hours. The clock rewards organisations with genuine detection and response capability and punishes those relying on periodic manual checks.
Licensing for cyber security service providers
The Act introduces a formal licensing regime for cyber security service providers, and it is drawn broadly. Anyone providing, or even advertising themselves as providing, a licensable service must hold a NACSA licence.
The regime centres on two prescribed services: managed security operations centre (SOC) monitoring and penetration testing. The licensing portal opened on 1 October 2024, with an initial grace period for applications running to 31 December 2024. Licensed providers must keep detailed records for every engagement, including the client's name and address, the provider's details, and the date, time, and nature of the service, and must retain those records for at least six years and make them available to the Chief Executive on request. A separate exemption order removes certain entities, such as some government-related bodies, from parts of the regime.
For any organisation buying penetration testing or managed SOC services in Malaysia, this changes procurement: you should be engaging a NACSA-licensed provider, and providers operating without a licence are breaking the law.
Penalties
The Act is enforced with real consequences. Serious offences, such as failing to report a cyber security incident or failing to implement an applicable code of practice, can attract a fine of up to RM500,000, imprisonment of up to ten years, or both. Providing a licensable cyber security service without a licence is itself an offence, and non-compliant providers risk licence suspension or revocation, which can halt their operations entirely. A set of lesser offences can be compounded under the compounding regulations. Beyond the legal exposure, public findings of non-compliance carry reputational cost that, for a critical-infrastructure operator, can be as damaging as the fine.
How to approach compliance
For a designated NCII entity, a sensible order of work starts with the clock you cannot control. Stand up the incident-notification process first: designate your authorised persons, register for and rehearse reporting through NC4S, and make sure your detection capability can actually surface and characterise an incident within the six-hour window. In parallel, complete or refresh the NCSB self-assessment, build the annual risk assessment and biennial audit into your calendar as standing commitments, and map your controls against the code of practice for your sector.
For a cyber security service provider, the priority is confirming your licensing position under the two prescribed services and putting in place the six-year record-keeping the regime demands.
Across both, the capability that most often needs strengthening is detection and response, because every other obligation, from the six-hour report to the annual assessment, depends on knowing what is happening in your environment.
Where a managed security partner fits
Several of the Act's obligations are, at their core, security operations capabilities. The six-hour reporting clock is only achievable if you can detect and characterise an incident within hours, which is exactly what a managed detection and response and security operations centre model is built to provide. The Act's own licensing regime centres on two services, managed SOC monitoring and penetration testing, both of which sit at the heart of what NCII entities need to demonstrate. Continuous visibility of threats and attack surface aligns with threat intelligence, and the annual risk assessment and biennial audit align with a structured security services programme.
Primary Guard operates a regional security operations and offensive security capability across Malaysia, Indonesia, and Thailand, and works with organisations to build the detection, testing, and reporting capability the Act requires. For NCII entities weighing whether to build this in-house or partner, a free assessment is a practical way to benchmark current readiness against the Act's timelines. Because the Act designates banking and finance as an NCII sector, financial institutions should read this alongside our BNM RMiT compliance guide, since they fall under both regimes at once.
Key takeaways
The Cyber Security Act 2024 makes cyber security a legal obligation for Malaysia's critical infrastructure and for the providers that serve it. The defining features are the eleven NCII sectors, the recurring risk assessments and audits, the licensing of SOC and penetration testing services, and above all the six-hour incident-reporting clock that starts the moment an incident is suspected. The organisations that treat this as an operational readiness programme, built around fast detection and rehearsed reporting, rather than a documentation exercise, are the ones that will meet the Act's demands when it matters.
This article is provided for general information and does not constitute legal advice. Organisations should refer to the Cyber Security Act 2024 and its regulations and consult qualified advisers on their specific obligations.
Frequently Asked Questions
When did the Cyber Security Act 2024 come into force?
It was gazetted on 26 June 2024 and came into force on 26 August 2024, together with its four subsidiary regulations. It is Malaysia's first standalone cyber security law.
Who does the Cyber Security Act 2024 apply to?
Two groups: designated National Critical Information Infrastructure (NCII) entities across eleven sectors, and cyber security service providers who offer licensable services in Malaysia. An organisation can fall into one or both groups.
What is the incident-reporting timeline under the Act?
An NCII entity must notify NACSA and its sector lead immediately, submit prescribed particulars through the NC4S system within six hours, and provide a supplementary report within fourteen days of the initial notification.
Which cyber security services need a NACSA licence?
The licensing regime covers managed security operations centre (SOC) monitoring and penetration testing. Anyone providing or advertising these services in Malaysia must hold a NACSA licence and keep engagement records for at least six years.
What are the penalties for non-compliance?
Serious offences, such as failing to report an incident or to implement a code of practice, can carry a fine of up to RM500,000, imprisonment of up to ten years, or both. Unlicensed provision of licensable services is an offence, and providers can face licence suspension or revocation.
How is the Cyber Security Act 2024 different from BNM RMiT?
RMiT is Bank Negara Malaysia's technology risk policy for regulated financial institutions. The Cyber Security Act is a national law covering critical infrastructure across eleven sectors, administered by NACSA. Banks sit in the NCII banking and finance sector, so many financial institutions must comply with both.