This topic falls under a sensitive category and is presented descriptively and neutrally.
The Cyber Security Act 2024 (Act 854) is Malaysia's first standalone cybersecurity statute, in force since 26 August 2024. It empowers the National Cyber Security Agency (NACSA) and its Chief Executive to designate National Critical Information Infrastructure (NCII) entities across 11 sectors, requires those entities to follow a code of practice, report cyber incidents rapidly, and undergo periodic risk assessment and audit, and introduces a licensing regime for two categories of cybersecurity service providers. The Act is national-security legislation with extraterritorial reach and penalties reaching RM500,000 and up to 10 years' imprisonment.
- Act 854 and its four subsidiary regulations came into force on 26 August 2024; the Act received Royal Assent on 18 June 2024 and was published in the gazette on 26 June 2024.
- The Act names 11 NCII sectors, from government and banking to energy and healthcare; obligations fall only on entities NACSA designates, not on all private companies.
- Designated NCII entities must report a cyber incident immediately, then supply particulars within 6 hours and supplementary information within 14 days.
- NCII entities must run a cyber security risk assessment at least once a year and be audited at least once every two years.
- Providing managed security operation centre (SOC) monitoring or penetration testing services in or from Malaysia requires a NACSA licence.
- Serious offences carry fines up to RM500,000 and imprisonment up to 10 years; lesser breaches carry fines of RM200,000 or RM100,000 with shorter jail terms.
Who this applies to: Operators in critical sectors, compliance and IT-security leaders, cybersecurity vendors, and lawyers advising on Malaysian technology regulation.
On this page
For years, Malaysia policed cyberattacks with borrowed tools — the Computer Crimes Act, the Communications and Multimedia Act, sector circulars from Bank Negara and the central bank’s peers. None of them said, in one place, who must protect the country’s critical systems, how fast a breach must be reported, or who is even allowed to sell a penetration test. The Cyber Security Act 2024 does. It is Malaysia’s first standalone cybersecurity law, and it treats certain networks the way earlier laws treated dams and power stations: as national infrastructure the state has a right to regulate.
This is national-security legislation. It gives a government agency the power to designate private and public systems as “critical,” to compel their operators to open up to audits, and to license the firms that test them. That framing matters — the Act is written from the standpoint of protecting the nation, not primarily protecting consumers or their data. This guide explains what it actually requires, whom it binds, and where the hard lines are.
What is the Cyber Security Act 2024?
The Cyber Security Act 2024 is enacted as Act 854. It received Royal Assent on 18 June 2024 and was published in the gazette on 26 June 2024; then, together with its four subsidiary regulations, it came into operation on 26 August 2024. The Prime Minister appointed that commencement date under the power in subsection 1(2) of the Act. (Royal Assent, gazette publication and commencement are three distinct events — a reader cross-checking the Attorney General’s Chambers portal will see the assent date of 18 June, not the 26 June gazette date.)
The statute does several things at once:
- It establishes a National Cyber Security Committee as a governance body for national cyber policy.
- It sets out the duties and powers of the National Cyber Security Agency (NACSA) and its Chief Executive, who is the day-to-day regulator under the Act.
- It creates the concept of National Critical Information Infrastructure (NCII) and a mechanism to designate the entities that own or operate it.
- It imposes a code of practice, incident-reporting, risk-assessment and audit duties on those entities.
- It introduces a licensing regime for specified cybersecurity service providers.
- It backs all of this with criminal penalties and an administrative compounding option.
Crucially, the Act is not a general data-privacy law. Personal-data protection in Malaysia lives in a separate statute, the Personal Data Protection Act 2010. The Cyber Security Act is about the security and resilience of critical systems — availability, integrity, and the state’s ability to coordinate a response when those systems are attacked.
Who does the Act actually bind?
This is the single most misread part of the law. The Cyber Security Act does not impose obligations on every business in Malaysia. Its core duties attach only to entities that NACSA’s Chief Executive formally designates as NCII entities.
An organisation therefore sits in one of three positions:
| Position | Who it covers | What the Act requires |
|---|---|---|
| Designated NCII entity | Owners/operators of critical infrastructure named by the Chief Executive | Full duties: code of practice, incident reporting, risk assessment, audit |
| Cybersecurity service provider | Firms selling regulated services (SOC monitoring, penetration testing) | Must hold a NACSA licence, regardless of NCII status |
| Everyone else | Ordinary private companies not designated and not selling regulated services | No obligations under this Act |
So a mid-sized retailer with no critical role and no security-services business has nothing to file under Act 854. A bank designated as an NCII entity carries the full weight of it. A boutique firm that only runs penetration tests must be licensed even though it operates no critical infrastructure of its own.
The Act also has extraterritorial application: it can reach an offence committed in relation to national critical information infrastructure that is wholly or partly in Malaysia, even where elements of the conduct occur abroad.
appliesTo: operators in the 11 critical sectors, their compliance and IT-security leaders, cybersecurity vendors, and lawyers advising on Malaysian technology regulation.
What are the 11 NCII sectors?
National Critical Information Infrastructure is, in essence, computer systems and networks whose disruption or destruction would harm Malaysia’s security, defence, foreign relations, economy, public health, public safety, or public order. The Act organises this critical landscape into 11 sectors, each with a designated NCII Sector Lead responsible for that domain:
- Government
- Banking and finance
- Transportation
- Defence and national security
- Information, communication and digital
- Healthcare services
- Water, sewerage and waste management
- Energy
- Agriculture and plantation
- Trade, industry and economy
- Science, technology and innovation
Being in one of these sectors does not, by itself, make an organisation an NCII entity. Designation is a specific act: the relevant Sector Lead recommends candidates, and the Chief Executive decides whether to designate them and enters them into a register. Only after designation do the compliance duties bite.
The sector structure matters operationally because a designated entity answers to two authorities — the Chief Executive at NACSA and its own Sector Lead — for reporting and coordination.
What must a designated NCII entity do?
Once designated, an NCII entity inherits a set of continuing duties. They fall into four buckets.
1. Follow the code of practice. Each NCII entity must implement the measures, standards and processes set out in the applicable code of practice for its sector. This is the baseline security-controls obligation.
2. Report cyber incidents — fast. Under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024, an authorised person of the entity must, on becoming aware of an incident that has or might have occurred:
- notify the Chief Executive and the relevant Sector Lead immediately, by electronic means;
- submit further particulars within 6 hours of becoming aware of the incident; and
- provide supplementary information within 14 days.
Both the 6-hour and 14-day filings are made through the National Cyber Coordination and Command Centre System (NC4S), the electronic channel named in the Regulations, and both clocks run from when the incident comes to the entity’s knowledge — the same trigger as the immediate first notification.
The tight initial window is deliberate. The Act’s premise is national coordination — NACSA can only orchestrate a cross-sector response if it hears about incidents in near-real time, not weeks later in a breach post-mortem.
3. Assess risk and submit to audit. Under the Cyber Security (Period of Cyber Security Risk Assessment and Audit) Regulations 2024, a designated entity must:
- conduct a cyber security risk assessment at least once a year; and
- undergo an audit by an approved auditor at least once every two years.
4. Keep records and cooperate. Entities must maintain the records the Act and its regulations require, respond to directions from the Chief Executive, and participate in exercises and remediation the regulator orders.
Here is the practical cadence for a newly designated entity:
| Trigger | Duty | Timing |
|---|---|---|
| Designation as NCII entity | Implement the sector code of practice | On and after designation |
| Cyber incident comes to the entity’s knowledge | Notify Chief Executive + Sector Lead | Immediately (electronic) |
| Awareness of the incident | Submit further particulars (via NC4S) | Within 6 hours |
| Awareness of the incident | Submit supplementary information (via NC4S) | Within 14 days |
| Ongoing | Cyber security risk assessment | At least yearly |
| Ongoing | Independent audit by approved auditor | At least every two years |
Who needs a cybersecurity licence?
Separately from the NCII regime, the Act licenses the people who sell certain security services. Under section 27 of the Act and the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024, two prescribed services require a licence:
- Managed security operation centre (SOC) monitoring services — continuous monitoring of an organisation’s security posture through data acquisition and threat identification.
- Penetration testing services — assessing security by searching for vulnerabilities and simulating attacks.
If you provide either service in or from Malaysia — whether as a company or an individual — you need a NACSA licence. The Chief Executive approves, refuses, and attaches conditions to licences, and maintains the register of licensees. Licences cannot be freely transferred, and licensees must keep prescribed records.
A common trap: the licensing duty is independent of NCII status. A small consultancy that runs penetration tests for ordinary commercial clients — none of them critical infrastructure — still needs the licence. Conversely, an NCII entity that performs SOC monitoring only for its own internal systems is generally consuming the service, not selling it, and the licensing question turns on whether it is providing the service to others.
What are the penalties?
The Act is enforced through criminal offences, and the numbers are meant to concentrate the mind of a board. Every provision number, fine and imprisonment term in the table below has been verified line-by-line against the gazetted text of Act 854.
| Breach | Provision | Maximum fine | Maximum imprisonment |
|---|---|---|---|
| Failing to comply with a code of practice | s.21(5) | RM500,000 | 10 years |
| Failing to notify a cyber security incident | s.23(2) | RM500,000 | 10 years |
| Providing a regulated service without a licence | s.27(5) | RM500,000 | 10 years |
| Failing to conduct risk assessment / audit | s.22(7) | RM200,000 | 3 years |
| Unauthorised transfer of a licence | s.34(2) | RM200,000 | 3 years |
| Failing to maintain required records | s.32(3) | RM100,000 | 2 years |
This is a representative selection; the Act carries further offences at similar lesser levels — for example, an NCII entity failing to provide information on its NCII (s.20(6), RM100,000 / 2 years), failing to respond to a directive to recover from an incident (s.35(5), RM200,000 / 3 years), and non-compliance with the Chief Executive’s directions or with a cyber security exercise (s.22(8), s.24(4)). Most offences follow the standard Malaysian drafting style — a fine or imprisonment or both, at the court’s discretion — but a few, including s.22(8) and s.24(4), are fine-only with no imprisonment term. The heaviest exposure — half a million ringgit and a decade in prison — attaches to the offences the state treats as most damaging to national resilience: ignoring the security baseline, staying silent about an incident, and operating in the licensed space without authority.
The Act is paired with the Cyber Security (Compounding of Offences) Regulations 2024, which allow certain offences to be settled administratively by paying a compound rather than proceeding to prosecution — a pressure-release valve for less serious breaches.
How does this fit with Malaysia’s other laws?
The Cyber Security Act does not stand alone, and organisations frequently owe duties under several regimes at once.
- Personal Data Protection Act 2010 (PDPA). Governs how personal data is collected, used and secured. A breach involving personal data can trigger PDPA duties and, if the victim is an NCII entity, Cyber Security Act reporting.
- Communications and Multimedia Act 1998. Regulates the communications and multimedia industry and remains the backbone for that sector’s licensing.
- Computer Crimes Act 1997. Criminalises unauthorised access and related conduct — the offender-facing counterpart to the Cyber Security Act’s operator-facing duties.
- Sector regulation. Bank Negara Malaysia’s technology-risk requirements for financial institutions, and equivalent rules from other regulators, continue to apply on top of Act 854.
The mental model: the Cyber Security Act sets a national floor for critical-infrastructure resilience and coordination, while the PDPA protects individuals’ data, and sector regulators layer industry-specific controls above both.
A decision framework: does Act 854 apply to me?
Work through these questions in order.
- Has NACSA’s Chief Executive designated your organisation as an NCII entity? If yes, you owe the full code-of-practice, incident-reporting, risk-assessment and audit duties. If no, continue.
- Do you provide managed SOC monitoring or penetration testing services in or from Malaysia? If yes, you need a NACSA licence — independent of NCII status. If no, continue.
- Do you operate in one of the 11 sectors but have not been designated? You have no active duties yet, but you are a candidate for designation. Track NACSA guidance and prepare, because designation can arrive.
- None of the above? The Act imposes no direct obligations on you today, though your critical suppliers may pass requirements down by contract.
Common mistakes and misconceptions
- “Every Malaysian company must now comply.” False. Core duties apply only to designated NCII entities. The confusion comes from conflating the Act’s broad sectors with actual designation.
- “We’re not critical infrastructure, so the licensing rules don’t touch us.” Wrong if you sell SOC monitoring or penetration testing. Licensing is triggered by the service, not by whether you own critical systems.
- “We’ll report the breach once forensics are done.” Dangerous. The clock starts at awareness: immediate notification, particulars within 6 hours, supplementary detail within 14 days. Waiting for a full post-mortem breaches the timeline.
- “Complying with the PDPA covers us.” No. Data-protection compliance does not discharge Cyber Security Act duties, and vice versa. They are different statutes with different regulators.
- “Section numbers and fines are soft guidance.” They are criminal provisions. Treat the RM500,000 / 10-year exposure as a board-level risk, not an IT footnote.
- “An overseas incident is out of scope.” Not necessarily — the Act reaches offences relating to NCII that is wholly or partly in Malaysia, even with a foreign element.
What’s next
If your organisation could plausibly be designated — anyone operating meaningful systems in the 11 sectors — the sensible moves are to map your critical assets now, stand up an incident-notification process that can hit an immediate/6-hour/14-day cadence, and schedule the annual risk assessment and biennial audit before a designation letter forces the pace. If you sell SOC monitoring or penetration testing, confirm your NACSA licensing status before your next engagement.
Watch three things as the regime matures: the sector-specific codes of practice, which put concrete controls behind the general duty; NACSA’s guidance on who gets designated and how the register is maintained; and enforcement practice, which will show whether the compounding route or full prosecution becomes the norm. Because this is national-security legislation, expect the details to be tightened by direction and subsidiary instrument rather than by frequent amendment of the Act itself.
Always confirm current requirements against the primary sources — the Act as published by the Attorney General’s Chambers and NACSA’s official guidance — before making compliance decisions, as regulations and codes of practice continue to evolve.
When did the Cyber Security Act 2024 come into force?
The Act (Act 854) received Royal Assent on 18 June 2024, was published in the gazette on 26 June 2024, and — together with its four subsidiary regulations — came into operation on 26 August 2024.
Does the Act apply to every company in Malaysia?
No. Substantive obligations apply only to entities that NACSA's Chief Executive formally designates as National Critical Information Infrastructure (NCII) entities. A business that is not designated has no compliance duties under the Act, though the separate licensing rules can still apply if it sells regulated cybersecurity services.
Which cybersecurity services need a licence?
Two prescribed services require a NACSA licence: managed security operation centre (SOC) monitoring services and penetration testing services. Providing either in or from Malaysia without a licence is an offence.
How fast must an NCII entity report a cyber incident?
The Notification of Cyber Security Incident Regulations 2024 require an authorised person to notify immediately by electronic means, then submit further particulars within 6 hours of becoming aware of the incident and supplementary information within 14 days, both through the National Cyber Coordination and Command Centre System (NC4S).
What are the penalties for non-compliance?
Penalties scale with the offence. Failing to comply with a code of practice, failing to notify an incident, or operating without a licence can each attract a fine up to RM500,000 or imprisonment up to 10 years, or both. Lesser breaches carry fines of RM200,000 or RM100,000 with shorter jail terms.
Is this the same as Malaysia's data protection law?
No. The Cyber Security Act governs the security and resilience of critical infrastructure. Personal-data privacy is governed separately by the Personal Data Protection Act 2010. An organisation can be subject to both.
Sources
- Cyber Security Act 2024 [Act 854] — National Cyber Security Agency (NACSA)
- Cyber Security Act 2024 — Federal Legislation Portal — Attorney General's Chambers of Malaysia
- Laws of Malaysia — Act 854 Cyber Security Act 2024 (full gazetted text) — Premier's Department of Sarawak (reproducing Laws of Malaysia Act 854)
- Malaysia Cyber Security Act 2024 and subsidiary regulations — in force on 26 August 2024 — Global Compliance News (Baker McKenzie)
- Malaysia's New Cyber Security Act 2024 – A Summary and Brief Comparative Analysis — Mayer Brown
- Unveiling Malaysia's Cyber Security Act 2024: Strengthening Our Digital Fortress — Tay & Partners
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 14 Aug 2026 | Approved and published. | — |