Home / Doing Business in Malaysia / Technology & AI / Cybersecurity

🧭 Practical 🔒 Sensitive — security ✓ Published: 3 Aug 2026 4 min read Next review 3 Aug 2027

NACSA and CyberSecurity Malaysia: Who Does What

Malaysia runs two national cyber bodies that are easy to confuse. NACSA is the policy, coordination and regulatory lead under the Prime Minister's Department; CyberSecurity Malaysia is the technical specialist agency under the Ministry of Digital that runs incident response (MyCERT/Cyber999) and security certification.

🔒 Sensitive content — Security

This topic falls under a sensitive category and is presented descriptively and neutrally.

30-second answer Reviewed 3 Aug 2026

NACSA (the National Cyber Security Agency) is Malaysia's lead agency for cyber security policy, national coordination and regulation, sitting under the National Security Council in the Prime Minister's Department; it administers the Cyber Security Act 2024 [Act 854], including licensing of cyber security service providers. CyberSecurity Malaysia is the national technical specialist agency under the Ministry of Digital — a Company Limited by Guarantee — that delivers hands-on services such as incident response through MyCERT and its Cyber999 helpline, digital forensics, and security certification. In short: NACSA sets and enforces the rules; CyberSecurity Malaysia provides the technical response and assurance work.

  • NACSA is the national lead agency for cyber security, established February 2017 under the National Security Council, Prime Minister's Department
  • CyberSecurity Malaysia is a Company Limited by Guarantee, incorporated 14 March 2006, now under the Ministry of Digital
  • NACSA administers the Cyber Security Act 2024 [Act 854], gazetted 26 June 2024 and in force from 26 August 2024
  • Under Act 854, applications to provide cyber security services are made to NACSA's Chief Executive — for managed SOC monitoring and penetration testing services
  • CyberSecurity Malaysia runs MyCERT and the Cyber999 helpline, the national point of contact for reporting computer security incidents
  • MyCERT was formed on 13 January 1997 and operates from the office of CyberSecurity Malaysia

Who this applies to: Businesses, IT and security teams, students and anyone trying to work out which Malaysian government body handles cyber security policy, licensing, or incident response.

On this page
Full explanation ≈4 min

Two Malaysian government bodies carry “cyber security” in their name, and people route the wrong thing to the wrong one all the time — a licence question to the incident hotline, a hacked-account report to the policy agency. The names sound interchangeable. Their jobs are not.

Which is which?

One is a regulator; the other is a doer. NACSA — the National Cyber Security Agency — is the national lead for policy, coordination and law. CyberSecurity Malaysia is the national technical specialist agency that does the hands-on work: responding to incidents, running forensics, certifying products.

NACSACyberSecurity Malaysia
Full nameNational Cyber Security AgencyCyberSecurity Malaysia
TypeGovernment agency (national lead)Company Limited by Guarantee
Sits underNational Security Council, Prime Minister’s DepartmentMinistry of Digital
EstablishedFebruary 2017Incorporated 14 March 2006
Primary rolePolicy, coordination, regulationTechnical services and assurance
Flagship functionAdministers the Cyber Security Act 2024Incident response via MyCERT / Cyber999

What does NACSA do?

NACSA describes itself as the national lead agency for cyber security matters. It was established in February 2017 and operates under the National Security Council within the Prime Minister’s Department, at the Perdana Putra building in Putrajaya.

Its remit is national and strategic:

  • Developing and implementing national cyber security policies and strategies.
  • Protecting National Critical Information Infrastructure (NCII).
  • Coordinating national expertise to counter cyber threats.
  • Spearheading awareness and capacity-building programmes.
  • Advising organisations on cyber risk management.
  • Building regional and global cyber security partnerships.

The role that most changed after 2024 is regulatory. NACSA administers the Cyber Security Act 2024 [Act 854], which was gazetted on 26 June 2024 and came into force on 26 August 2024. According to NACSA, the Act now supersedes the earlier National Security Council Directive No. 26 (The National Cyber Security Management), which the National Security Council has repealed. The Act sets out, among other things, provisions to regulate cyber security service providers, the duties of NACSA’s Chief Executive, and the obligations of NCII sector leads and entities.

What does the Cyber Security Act 2024 make NACSA responsible for?

Two things stand out for organisations. First, the Act creates a framework around NCII — the systems whose disruption would seriously affect national security, the economy or public services. Second, it introduces provisions to regulate cyber security service providers through licensing.

Under NACSA’s licensing framework, an application to provide cyber security services is made to the Chief Executive, and NACSA identifies two regulated service categories:

  1. Managed security operation centre (SOC) monitoring service.
  2. Penetration testing service.

Providers offering these services in Malaysia apply to NACSA for a licence. This is the concrete, day-to-day reason a business might deal directly with NACSA rather than with CyberSecurity Malaysia.

What does CyberSecurity Malaysia do?

CyberSecurity Malaysia is the national cyber security specialist agency, now under the purview of the Ministry of Digital. It is structured as a Company Limited by Guarantee, incorporated on 14 March 2006 after Cabinet approval to spin it off from MIMOS Berhad into an independent national entity.

Where NACSA writes and enforces the rules, CyberSecurity Malaysia provides the technical muscle:

ServiceWhat it covers
MyCERT / Cyber999Reporting and handling of computer security incidents
Digital forensicsAccredited forensic laboratory services
Security certificationISMS and Common Criteria product evaluation
MySEFMalaysian Security Evaluation Facility
TrainingCyberGuru competency and certification programmes

Where do most people actually meet these agencies?

For the public, the everyday touchpoint is Cyber999. It is operated by MyCERT — the Malaysia Computer Emergency Response Team — which was formed on 13 January 1997 and operates from the office of CyberSecurity Malaysia. Cyber999 is the national point of contact for reporting computer security incidents, from fraud and hacked accounts to malware, and it accepts reports through an online form and a mobile app.

So the simple routing rule: if something has been compromised and you need help now, that is CyberSecurity Malaysia’s MyCERT/Cyber999. If your question is about national policy, NCII obligations, or a service-provider licence, that is NACSA.

What’s next

If you run a business, first work out which body your issue belongs to — a live incident goes to Cyber999, while licensing, NCII duties and compliance questions go to NACSA. Cyber security service providers offering managed SOC monitoring or penetration testing should check the licensing requirements at nacsa.gov.my. For the exact obligations under the Cyber Security Act 2024, read the Act text via the Attorney General’s Chambers legislation portal rather than relying on summaries, and confirm current service and reporting channels at cybersecurity.my and mycert.org.my.

Frequently asked 3
What is the difference between NACSA and CyberSecurity Malaysia?

NACSA is the policy, coordination and regulatory lead under the Prime Minister's Department, and it administers the Cyber Security Act 2024. CyberSecurity Malaysia is the technical specialist agency under the Ministry of Digital that provides incident response, digital forensics and security certification.

Who do I report a cyber incident to in Malaysia?

The national point of contact for reporting computer security incidents is Cyber999, operated by MyCERT, which operates from the office of CyberSecurity Malaysia.

Which agency issues cyber security service provider licences?

Under the Cyber Security Act 2024 [Act 854], an application to provide cyber security services is made to the Chief Executive of NACSA. The regulated categories are managed security operation centre (SOC) monitoring service and penetration testing service.

Sources & history 4 sources
⚑ Awaiting expert verification

The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:

  • Whether additional cyber security service categories beyond managed SOC monitoring and penetration testing have been designated as regulated under subsequent regulations to Act 854.
  • The specific CyberSecurity Malaysia service lines listed in the services table (digital forensics laboratory, ISMS and Common Criteria certification, MySEF, CyberGuru training) — confirm each against the current CyberSecurity Malaysia corporate/services pages, as they were not individually re-fetched in this pass.
  • Current, live Cyber999 reporting channels (online form and mobile app) — confirm against cybersecurity.my / mycert.org.my before publication.
  • That NACSA remains located at the Perdana Putra building, Putrajaya.

Sources

  1. National Cyber Security Agency (NACSA) — Official Portal — National Cyber Security Agency (NACSA)
  2. Cyber Security Act 2024 [Act 854] — National Cyber Security Agency (NACSA)
  3. Corporate Overview — CyberSecurity Malaysia
  4. MyCERT — Malaysia Computer Emergency Response Team — MyCERT, CyberSecurity Malaysia

Change history

Version Date Change By
01.00 1 Aug 2026 Approved and published.
More in Cybersecurity View all 3 →
Related knowledge