# Cyber Security Act 2024: NCII Obligations for Malaysian Businesses

> Malaysia's Cyber Security Act 2024 (Act 854) places binding duties on entities designated as National Critical Information Infrastructure — annual risk assessments, biennial audits, fast incident reporting to NACSA, and codes of practice, with penalties reaching RM500,000 and 10 years' jail.

- Category: business
- Language: en
- Status: published
- Updated: 2026-08-07
- Canonical: https://negaraku.md/en/business/cyber-security-act-malaysia

---

A six-hour clock starts the moment your security team realises something is wrong. That is the reality Malaysia's **Cyber Security Act 2024 (Act 854)** created for operators of the country's most essential digital systems when it came into force on **26 August 2024**.

The law does not touch every business. Its binding duties fall on a specific group: entities designated as **National Critical Information Infrastructure (NCII)** — the computer systems and networks whose disruption would seriously affect national security, the economy, public health or safety.

## Who counts as an NCII entity?

You do not opt in. Under the Act, an organisation becomes an NCII entity only when a NCII sector lead or the Chief Executive of NACSA designates it as such, and designated entities are entered on official registers. Sector leads oversee fields such as government, banking and finance, energy, telecommunications, healthcare, water, transport and defence.

If your organisation is designated, the compliance obligations below apply to you directly. If it is not, the Act's separate licensing regime for cybersecurity service providers may still be relevant.

## What are the core obligations?

Once designated, an NCII entity carries four recurring duties:

| Obligation | What it requires |
|---|---|
| Risk assessment | Conduct a cybersecurity risk assessment **at least once a year** |
| Audit | Undergo a cybersecurity audit **at least once every two years** |
| Code of practice | Implement the measures and standards in the sector's code of practice |
| Incident reporting | Notify NACSA of cyber incidents within a fixed timeframe |

The Chief Executive of NACSA can direct more frequent assessments or audits when circumstances warrant — for example, after a major change to an entity's infrastructure.

## How fast must incidents be reported?

This is where the Act is most demanding. Under the **Cyber Security (Notification of Cyber Security Incident) Regulations 2024**, a designated entity must:

- Send an **initial notification within 6 hours** of the incident coming to its knowledge; then
- Submit a **follow-up report within 14 days** with fuller detail.

The obligation is triggered by knowledge of an incident, not by confirmation of damage — so detection and escalation processes need to be fast enough to meet the window.

## What happens if you fail to comply?

The Act attaches criminal penalties to each of the core NCII duties:

- **Failing to implement a code of practice**, or **failing to report an incident** — a fine up to **RM500,000**, imprisonment up to **10 years**, or both.
- **Providing licensable cybersecurity services without a licence** — a fine up to **RM500,000**, imprisonment up to **10 years**, or both.
- **Failing to conduct or submit a risk assessment or audit** — a fine up to **RM200,000**, imprisonment up to **3 years**, or both.

The Act is supported by subsidiary regulations issued in 2024, including the Period for Cyber Security Risk Assessment and Audit Regulations, the Licensing of Cyber Security Service Providers Regulations, the Notification of Cyber Security Incident Regulations, and the Compounding of Offences Regulations.

## What's next

Confirm whether your organisation has been — or is likely to be — designated as an NCII entity by your sector lead. If so, map the annual risk-assessment and biennial audit cycle onto your calendar, adopt your sector's code of practice, and build an incident-response runbook that can produce a NACSA notification inside the six-hour window. Read the full text of Act 854 and its 2024 regulations before finalising any compliance programme, and take formal legal advice — this article is general information, not legal advice.

## Sources

- Cyber Security Act 2024 [Act 854] — https://www.nacsa.gov.my/act854.php (National Cyber Security Agency (NACSA))
- Malaysia's New Cyber Security Act 2024 – A Summary and Brief Comparative Analysis — https://www.mayerbrown.com/en/insights/publications/2024/12/malaysias-new-cyber-security-act-2024-a-summary-and-brief-comparative-analysis (Mayer Brown)
- An Overview of Malaysia Cyber Security Act 2024 — https://securiti.ai/overview-of-malaysia-cyber-securitiy-act-2024/ (Securiti)
- Introduction of the new Cyber Security Act 2024 (CSA) and Supporting Regulations — https://dnh.com.my/introduction-of-the-new-cyber-security-act-2024-csa-and-supporting-regulations/ (Donovan & Ho)
- Cyber Security Regulations 2024 – Essential Reporting, Audit and Licensing Obligations — https://hhq.com.my/posts/cyber-security-regulations-2024-essential-reporting-audit-and-licensing-obligations/ (Halim Hong & Quek)
- Malaysia's Cybersecurity Act 2024: What Businesses Need to Know — https://www.vigilantasia.com.my/malaysia-cybersecurity-act/ (Vigilant Asia)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
