NACSA licence in progress
NACSA licence application submitted

NACSA & Cyber Security Act 2024

Malaysia's Cyber Security Act 2024 (Act 854) mandates cybersecurity requirements for National Critical Information Infrastructure (NCII). We help you comply.

Get compliance assessmentView all compliance
UNDERSTANDING

What is the Cyber Security Act 2024?

The Cyber Security Act 2024 (Act 854) establishes Malaysia's legal framework for protecting National Critical Information Infrastructure (NCII) from cyber threats.

Administered by the National Cyber Security Agency (NACSA), the Act mandates that operators of critical infrastructure implement comprehensive cybersecurity measures and undergo regular assessments by licensed providers.

Non-compliance penalties: fines up to RM 500,000 and/or imprisonment up to 10 years for serious violations.

Affected sectors

Government
Banking & finance
Transport
Defence & national security
Information & communications
Healthcare
Water, sewerage & waste
Energy
Agriculture & plantation
Trade, industry & economy
Science, technology & innovation
REQUIREMENTS

Key compliance requirements

1

Risk assessment

Conduct regular cybersecurity risk assessments to identify threats and vulnerabilities to NCII systems.

2

Security measures

Implement appropriate cybersecurity measures based on risk assessment findings.

3

Incident reporting

Report cybersecurity incidents to NACSA within prescribed timeframes.

4

Audit & compliance

Undergo periodic cybersecurity audits by licensed service providers.

5

Personnel security

Ensure personnel handling NCII systems meet security clearance requirements.

6

Recovery planning

Maintain incident response and business continuity plans for NCII systems.

HOW WE HELP

NACSA compliance services

As a CSSP licence applicant, we deliver cybersecurity assessments aligned to NACSA requirements for critical infrastructure operators.

NCII gap assessment

Evaluate your current security posture against NACSA requirements and identify compliance gaps.

Penetration testing

Testing services aligned to NACSA requirements for critical infrastructure systems (CSSP licence application submitted).

Security audit

Comprehensive security audits meeting NACSA standards and reporting requirements.

Incident response

24/7 incident response services with NACSA-aligned reporting capabilities.

Applicability & Scope

Who Must Comply

Entities designated under the 11 National Critical Information Infrastructure (NCII) sectors in Malaysia under the Cyber Security Act 2024 (Act 854).

Statutory Penalties & Enforcement

Directors and officers face fines up to RM500,000 or up to 10 years imprisonment for failure to conduct risk assessments or report incidents under Act 854.

nCrypt Audit Deliverables & Technical Scope

NCII asset discovery reports, Cyber Risk Assessment (CRA) findings, Threat Intelligence integrations, and mandatory NACSA incident response playbooks.

Frequently asked questions

Ensure NACSA compliance

Work with a CSSP licence applicant to meet your obligations under the Cyber Security Act 2024.

Get compliance assessmentView all services

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.