NACSA & Cyber Security Act 2024
Malaysia's Cyber Security Act 2024 (Act 854) mandates cybersecurity requirements for National Critical Information Infrastructure (NCII). We help you comply.
What is the Cyber Security Act 2024?
The Cyber Security Act 2024 (Act 854) establishes Malaysia's legal framework for protecting National Critical Information Infrastructure (NCII) from cyber threats.
Administered by the National Cyber Security Agency (NACSA), the Act mandates that operators of critical infrastructure implement comprehensive cybersecurity measures and undergo regular assessments by licensed providers.
Non-compliance penalties: fines up to RM 500,000 and/or imprisonment up to 10 years for serious violations.
Affected sectors
Key compliance requirements
Risk assessment
Conduct regular cybersecurity risk assessments to identify threats and vulnerabilities to NCII systems.
Security measures
Implement appropriate cybersecurity measures based on risk assessment findings.
Incident reporting
Report cybersecurity incidents to NACSA within prescribed timeframes.
Audit & compliance
Undergo periodic cybersecurity audits by licensed service providers.
Personnel security
Ensure personnel handling NCII systems meet security clearance requirements.
Recovery planning
Maintain incident response and business continuity plans for NCII systems.
NACSA compliance services
As a CSSP licence applicant, we deliver cybersecurity assessments aligned to NACSA requirements for critical infrastructure operators.
NCII gap assessment
Evaluate your current security posture against NACSA requirements and identify compliance gaps.
Penetration testing
Testing services aligned to NACSA requirements for critical infrastructure systems (CSSP licence application submitted).
Security audit
Comprehensive security audits meeting NACSA standards and reporting requirements.
Incident response
24/7 incident response services with NACSA-aligned reporting capabilities.
Applicability & Scope
Who Must Comply
Entities designated under the 11 National Critical Information Infrastructure (NCII) sectors in Malaysia under the Cyber Security Act 2024 (Act 854).
Statutory Penalties & Enforcement
Directors and officers face fines up to RM500,000 or up to 10 years imprisonment for failure to conduct risk assessments or report incidents under Act 854.
nCrypt Audit Deliverables & Technical Scope
NCII asset discovery reports, Cyber Risk Assessment (CRA) findings, Threat Intelligence integrations, and mandatory NACSA incident response playbooks.
Frequently asked questions
Ensure NACSA compliance
Work with a CSSP licence applicant to meet your obligations under the Cyber Security Act 2024.
Not sure what you need?
Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.