Home / Doing Business in Malaysia / Business / Cybersecurity

🧭 Practical ✓ Published: 8 Aug 2026 3 min read Next review 8 Aug 2027

Cyber Security Act 2024: NCII Obligations for Malaysian Businesses

Malaysia's Cyber Security Act 2024 (Act 854) places binding duties on entities designated as National Critical Information Infrastructure — annual risk assessments, biennial audits, fast incident reporting to NACSA, and codes of practice, with penalties reaching RM500,000 and 10 years' jail.

30-second answer Reviewed 8 Aug 2026

If your organisation is designated as National Critical Information Infrastructure (NCII) under the Cyber Security Act 2024, you must conduct a cybersecurity risk assessment at least once a year, undergo an audit at least once every two years, comply with your sector's code of practice, and report cyber incidents to NACSA within 6 hours (with a follow-up report within 14 days). The most serious breaches carry a fine up to RM500,000, up to 10 years' imprisonment, or both. The Act came into force on 26 August 2024.

  • The Act came into force on 26 August 2024 and binds designated NCII entities, not every business.
  • NCII entities must run a risk assessment at least annually and an audit at least once every two years.
  • Cyber incidents must be reported to NACSA within 6 hours, with a follow-up report within 14 days.
  • Top penalties reach a fine of up to RM500,000, imprisonment up to 10 years, or both.

Who this applies to: Operators of essential systems in sectors such as government, banking and finance, energy, telecommunications, healthcare, water, transport and defence that may be designated as NCII — plus their compliance, legal and IT security teams.

On this page
Full explanation ≈3 min

A six-hour clock starts the moment your security team realises something is wrong. That is the reality Malaysia’s Cyber Security Act 2024 (Act 854) created for operators of the country’s most essential digital systems when it came into force on 26 August 2024.

The law does not touch every business. Its binding duties fall on a specific group: entities designated as National Critical Information Infrastructure (NCII) — the computer systems and networks whose disruption would seriously affect national security, the economy, public health or safety.

Who counts as an NCII entity?

You do not opt in. Under the Act, an organisation becomes an NCII entity only when a NCII sector lead or the Chief Executive of NACSA designates it as such, and designated entities are entered on official registers. Sector leads oversee fields such as government, banking and finance, energy, telecommunications, healthcare, water, transport and defence.

If your organisation is designated, the compliance obligations below apply to you directly. If it is not, the Act’s separate licensing regime for cybersecurity service providers may still be relevant.

What are the core obligations?

Once designated, an NCII entity carries four recurring duties:

ObligationWhat it requires
Risk assessmentConduct a cybersecurity risk assessment at least once a year
AuditUndergo a cybersecurity audit at least once every two years
Code of practiceImplement the measures and standards in the sector’s code of practice
Incident reportingNotify NACSA of cyber incidents within a fixed timeframe

The Chief Executive of NACSA can direct more frequent assessments or audits when circumstances warrant — for example, after a major change to an entity’s infrastructure.

How fast must incidents be reported?

This is where the Act is most demanding. Under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024, a designated entity must:

  • Send an initial notification within 6 hours of the incident coming to its knowledge; then
  • Submit a follow-up report within 14 days with fuller detail.

The obligation is triggered by knowledge of an incident, not by confirmation of damage — so detection and escalation processes need to be fast enough to meet the window.

What happens if you fail to comply?

The Act attaches criminal penalties to each of the core NCII duties:

  • Failing to implement a code of practice, or failing to report an incident — a fine up to RM500,000, imprisonment up to 10 years, or both.
  • Providing licensable cybersecurity services without a licence — a fine up to RM500,000, imprisonment up to 10 years, or both.
  • Failing to conduct or submit a risk assessment or audit — a fine up to RM200,000, imprisonment up to 3 years, or both.

The Act is supported by subsidiary regulations issued in 2024, including the Period for Cyber Security Risk Assessment and Audit Regulations, the Licensing of Cyber Security Service Providers Regulations, the Notification of Cyber Security Incident Regulations, and the Compounding of Offences Regulations.

What’s next

Confirm whether your organisation has been — or is likely to be — designated as an NCII entity by your sector lead. If so, map the annual risk-assessment and biennial audit cycle onto your calendar, adopt your sector’s code of practice, and build an incident-response runbook that can produce a NACSA notification inside the six-hour window. Read the full text of Act 854 and its 2024 regulations before finalising any compliance programme, and take formal legal advice — this article is general information, not legal advice.

Frequently asked 3
Does the Cyber Security Act 2024 apply to every Malaysian company?

No. Its core duties bind entities formally designated as National Critical Information Infrastructure (NCII) by a sector lead or the Chief Executive of NACSA. Separately, anyone providing certain cybersecurity services needs a licence.

How fast must an NCII entity report a cyber incident?

An initial notification must reach NACSA within 6 hours of the incident coming to the entity's knowledge, followed by a fuller report within 14 days, under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024.

What is the maximum penalty under the Act?

For failures such as not complying with a code of practice or not reporting an incident, the penalty is a fine up to RM500,000, imprisonment up to 10 years, or both.

Sources & history 6 sources
⚑ Awaiting expert verification

The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:

  • Exact Act 854 section numbers for NCII designation, code of practice, risk assessment/audit and incident notification — published law-firm summaries differ (some cite s.20, others s.22 for assessment/audit), so confirm each against the gazetted text of Act 854.
  • That the 6-hour initial notification and 14-day follow-up windows are stated in the Cyber Security (Notification of Cyber Security Incident) Regulations 2024, per the regulation's own wording.
  • That the annual risk-assessment and biennial audit frequencies come from the Cyber Security (Period for Cyber Security Risk Assessment and Audit) Regulations 2024.
  • The current official list of NCII sectors and sector leads, and whether a given organisation has in fact been designated.

Sources

  1. Cyber Security Act 2024 [Act 854] — National Cyber Security Agency (NACSA)
  2. Malaysia's New Cyber Security Act 2024 – A Summary and Brief Comparative Analysis — Mayer Brown
  3. An Overview of Malaysia Cyber Security Act 2024 — Securiti
  4. Introduction of the new Cyber Security Act 2024 (CSA) and Supporting Regulations — Donovan & Ho
  5. Cyber Security Regulations 2024 – Essential Reporting, Audit and Licensing Obligations — Halim Hong & Quek
  6. Malaysia's Cybersecurity Act 2024: What Businesses Need to Know — Vigilant Asia

Change history

Version Date Change By
01.00 7 Aug 2026 Approved and published.
More in Business View all 107 →