This topic falls under a sensitive category and is presented descriptively and neutrally.
NACSA (the National Cyber Security Agency) is Malaysia's lead agency for cyber security policy, national coordination and regulation, sitting under the National Security Council in the Prime Minister's Department; it administers the Cyber Security Act 2024 [Act 854], including licensing of cyber security service providers. CyberSecurity Malaysia is the national technical specialist agency under the Ministry of Digital — a Company Limited by Guarantee — that delivers hands-on services such as incident response through MyCERT and its Cyber999 helpline, digital forensics, and security certification. In short: NACSA sets and enforces the rules; CyberSecurity Malaysia provides the technical response and assurance work.
- NACSA is the national lead agency for cyber security, established February 2017 under the National Security Council, Prime Minister's Department
- CyberSecurity Malaysia is a Company Limited by Guarantee, incorporated 14 March 2006, now under the Ministry of Digital
- NACSA administers the Cyber Security Act 2024 [Act 854], gazetted 26 June 2024 and in force from 26 August 2024
- Under Act 854, applications to provide cyber security services are made to NACSA's Chief Executive — for managed SOC monitoring and penetration testing services
- CyberSecurity Malaysia runs MyCERT and the Cyber999 helpline, the national point of contact for reporting computer security incidents
- MyCERT was formed on 13 January 1997 and operates from the office of CyberSecurity Malaysia
Who this applies to: Businesses, IT and security teams, students and anyone trying to work out which Malaysian government body handles cyber security policy, licensing, or incident response.
On this page
Two Malaysian government bodies carry “cyber security” in their name, and people route the wrong thing to the wrong one all the time — a licence question to the incident hotline, a hacked-account report to the policy agency. The names sound interchangeable. Their jobs are not.
Which is which?
One is a regulator; the other is a doer. NACSA — the National Cyber Security Agency — is the national lead for policy, coordination and law. CyberSecurity Malaysia is the national technical specialist agency that does the hands-on work: responding to incidents, running forensics, certifying products.
| NACSA | CyberSecurity Malaysia | |
|---|---|---|
| Full name | National Cyber Security Agency | CyberSecurity Malaysia |
| Type | Government agency (national lead) | Company Limited by Guarantee |
| Sits under | National Security Council, Prime Minister’s Department | Ministry of Digital |
| Established | February 2017 | Incorporated 14 March 2006 |
| Primary role | Policy, coordination, regulation | Technical services and assurance |
| Flagship function | Administers the Cyber Security Act 2024 | Incident response via MyCERT / Cyber999 |
What does NACSA do?
NACSA describes itself as the national lead agency for cyber security matters. It was established in February 2017 and operates under the National Security Council within the Prime Minister’s Department, at the Perdana Putra building in Putrajaya.
Its remit is national and strategic:
- Developing and implementing national cyber security policies and strategies.
- Protecting National Critical Information Infrastructure (NCII).
- Coordinating national expertise to counter cyber threats.
- Spearheading awareness and capacity-building programmes.
- Advising organisations on cyber risk management.
- Building regional and global cyber security partnerships.
The role that most changed after 2024 is regulatory. NACSA administers the Cyber Security Act 2024 [Act 854], which was gazetted on 26 June 2024 and came into force on 26 August 2024. According to NACSA, the Act now supersedes the earlier National Security Council Directive No. 26 (The National Cyber Security Management), which the National Security Council has repealed. The Act sets out, among other things, provisions to regulate cyber security service providers, the duties of NACSA’s Chief Executive, and the obligations of NCII sector leads and entities.
What does the Cyber Security Act 2024 make NACSA responsible for?
Two things stand out for organisations. First, the Act creates a framework around NCII — the systems whose disruption would seriously affect national security, the economy or public services. Second, it introduces provisions to regulate cyber security service providers through licensing.
Under NACSA’s licensing framework, an application to provide cyber security services is made to the Chief Executive, and NACSA identifies two regulated service categories:
- Managed security operation centre (SOC) monitoring service.
- Penetration testing service.
Providers offering these services in Malaysia apply to NACSA for a licence. This is the concrete, day-to-day reason a business might deal directly with NACSA rather than with CyberSecurity Malaysia.
What does CyberSecurity Malaysia do?
CyberSecurity Malaysia is the national cyber security specialist agency, now under the purview of the Ministry of Digital. It is structured as a Company Limited by Guarantee, incorporated on 14 March 2006 after Cabinet approval to spin it off from MIMOS Berhad into an independent national entity.
Where NACSA writes and enforces the rules, CyberSecurity Malaysia provides the technical muscle:
| Service | What it covers |
|---|---|
| MyCERT / Cyber999 | Reporting and handling of computer security incidents |
| Digital forensics | Accredited forensic laboratory services |
| Security certification | ISMS and Common Criteria product evaluation |
| MySEF | Malaysian Security Evaluation Facility |
| Training | CyberGuru competency and certification programmes |
Where do most people actually meet these agencies?
For the public, the everyday touchpoint is Cyber999. It is operated by MyCERT — the Malaysia Computer Emergency Response Team — which was formed on 13 January 1997 and operates from the office of CyberSecurity Malaysia. Cyber999 is the national point of contact for reporting computer security incidents, from fraud and hacked accounts to malware, and it accepts reports through an online form and a mobile app.
So the simple routing rule: if something has been compromised and you need help now, that is CyberSecurity Malaysia’s MyCERT/Cyber999. If your question is about national policy, NCII obligations, or a service-provider licence, that is NACSA.
What’s next
If you run a business, first work out which body your issue belongs to — a live
incident goes to Cyber999, while licensing, NCII duties and compliance questions
go to NACSA. Cyber security service providers offering managed SOC monitoring or
penetration testing should check the licensing requirements at nacsa.gov.my.
For the exact obligations under the Cyber Security Act 2024, read the Act text
via the Attorney General’s Chambers legislation portal rather than relying on
summaries, and confirm current service and reporting channels at
cybersecurity.my and mycert.org.my.
What is the difference between NACSA and CyberSecurity Malaysia?
NACSA is the policy, coordination and regulatory lead under the Prime Minister's Department, and it administers the Cyber Security Act 2024. CyberSecurity Malaysia is the technical specialist agency under the Ministry of Digital that provides incident response, digital forensics and security certification.
Who do I report a cyber incident to in Malaysia?
The national point of contact for reporting computer security incidents is Cyber999, operated by MyCERT, which operates from the office of CyberSecurity Malaysia.
Which agency issues cyber security service provider licences?
Under the Cyber Security Act 2024 [Act 854], an application to provide cyber security services is made to the Chief Executive of NACSA. The regulated categories are managed security operation centre (SOC) monitoring service and penetration testing service.
The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:
- Whether additional cyber security service categories beyond managed SOC monitoring and penetration testing have been designated as regulated under subsequent regulations to Act 854.
- The specific CyberSecurity Malaysia service lines listed in the services table (digital forensics laboratory, ISMS and Common Criteria certification, MySEF, CyberGuru training) — confirm each against the current CyberSecurity Malaysia corporate/services pages, as they were not individually re-fetched in this pass.
- Current, live Cyber999 reporting channels (online form and mobile app) — confirm against cybersecurity.my / mycert.org.my before publication.
- That NACSA remains located at the Perdana Putra building, Putrajaya.
Sources
- National Cyber Security Agency (NACSA) — Official Portal — National Cyber Security Agency (NACSA)
- Cyber Security Act 2024 [Act 854] — National Cyber Security Agency (NACSA)
- Corporate Overview — CyberSecurity Malaysia
- MyCERT — Malaysia Computer Emergency Response Team — MyCERT, CyberSecurity Malaysia
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 1 Aug 2026 | Approved and published. | — |