Skip to content
  • Case Studies
  • Cybersecurity Readiness Assessment
simply data logo
  • About
    • About Us
    • Innovation
      • SD Platform Overview
    • Certifications & Awards
  • Our Services
    • CyberSecurity Services
      • DFIR (Digital Forensics and Incident Response)
      • Compromise Assessment
      • Security Operations Center (SOC) Managed Service
        • SD-Cyber Deception
        • Threat Intelligence
        • Managed Detection and Response (MDR)
        • Cloud Security Posture Management (CSPM)
        • Web Defacement Monitoring
        • In-house Automation Script Development
        • Advanced Malware Analysis & Threat Intelligence
        • Office 365 Monitoring
        • SaaS Monitoring
      • Extended Threat Intelligence
        • Dark Web Monitoring
        • Attack Surface Management
        • Cyber Risk Management
        • Supply Chain Intelligence
      • Security Posture Assessment (SPA)
      • VAPT & Penetration Testing
      • Network & Security Configuration Audit & Hardening
      • Phishing Email Simulation
      • SOAR Security Services
      • OT Cybersecurity Services
      • Managed Security Service Provider (MSSP)
    • Managed Network & Security Services
    • Application Performance Monitoring (APM)
      • APM as a Service (APMaaS)
      • Cloud Monitoring
      • Database Performance Monitoring
      • Web Application Monitoring
      • Synthetic Testing Monitoring
      • Real User Monitoring (RUM)
      • Application Stress Test / Load Test Services
    • Consultancy Services
      • NCSB Risk Assessment
      • Security BluePrint™ Consultancy Services
    • Agentic AI & Automation
      • SD Unified Platform (SDP)
      • Agentic AI SOC
      • AI Automation
      • SD Monitoring — 100% Data Ingestion Visibility | SD Unified Platform
      • SDP-Portal — Customer-Facing SOC Visibility | SD Unified Platform
      • AI Threat Hunting — Chat-Driven Investigation by SD Unified Platform
    • Supported Platform
      • TrendAI Vision One
    CyberSecurity Services
    • VAPT & Penetration Testing
    • Cyber - 911 - DFIR Services
    • Compromise Assessment
    • Security Operations Center (SOC)
    • Extended Threat Intelligence
    • Security Posture Assessment (SPA) Services
    • Network & Security Configuration Audit & Hardening
    • Phishing Email Simulation
    • AI Automation
    • OT Cyber Security
    • SOAR Security
    • MSSP (Managed Security Service Provider)
    Managed Network & Security Services
    • Managed Network & Security Services
    Consultancy Services
    • NCSB Risk Assessment
    • Security BluePrint™ Consultancy Services
    Agentic AI & Automation
    • SD Unified Platform
    • Agentic AI SOC
    • AI Automation
    • SD Monitoring
    • SDP-Portal
    • AI Threat Hunting
    Application Performance Monitoring
    • APM as a Service (APMaaS)
    • Cloud Monitoring
    • Database Performance Monitoring
    • Web Application Monitoring
    • Synthetic Testing Monitoring
    • Real User Monitoring (RUM)
    • Stress Test / Load Test – Performance Assessment
    Supported Platform
    • TrendAI Vision One

    Not Sure What Security Threats Your Organization is Facing?

    We can help. Contact us now for a free consultation and protect your business from potential risks.

    Contact Us
  • Technology Vendor Partners
  • Blog & News
  • Contact
    • Contact Us
    • Become a Simply Data Partner

Under Attack?

Submit your message through our contact form or call us at +603 5886 2714.

    Regulatory & Compliance

    Cyber Security Act 2024 Malaysia: NACSA Licensing Deadlines and Penalties Explained

    August 3, 2026
    cyber security act 2024 nacsa licensing penalties

    Home – Cyber Security Act 2024 Malaysia: NACSA Licensing Deadlines and Penalties Explained

    Malaysia Cyber Security Act 2024 (Act 854) imposes legally binding obligations on operators of National Critical Information Infrastructure, with penalties reaching up to RM500,000 and imprisonment of up to 10 years for the most serious violations. Enacted in June 2024 and enforced by the National Cyber Security Agency (NACSA), Act 854 marks a decisive shift from voluntary cybersecurity frameworks to mandatory, enforceable compliance law in Malaysia. For C-suite leaders and IT heads operating across the 11 designated NCII sectors, understanding what the Act requires — and the consequences of non-compliance — is no longer optional.

    What is the Cyber Security Act 2024 (Act 854)?

    Act 854 is Malaysia primary federal cybersecurity law, published in the Federal Gazette and brought into force in stages through 2024 and 2025. It consolidates the country’s approach to protecting critical digital infrastructure under a single legislative framework, giving NACSA statutory authority to regulate, investigate, and prosecute cybersecurity failures.

    The Act establishes three interlocking obligations that every covered organisation must meet:

    • Incident reporting — mandatory notification to NACSA within prescribed timeframes
    • NCII sector compliance — risk assessments, audits, and security directives for all 11 NCII sectors
    • Licensing of cybersecurity service providers — any party delivering cybersecurity services to NCII entities must hold a valid NACSA licence

    Act 854 does not replace existing regulations such as Bank Negara Malaysia’s Risk Management in Technology (RMiT) framework, the Personal Data Protection Act (PDPA), or MCMC licensing requirements. It operates alongside these instruments, meaning organisations in regulated sectors now face layered compliance obligations from multiple authorities simultaneously.

    The 11 NCII sectors: who is covered?

    NACSA designates 11 National Critical Information Infrastructure sectors whose operators must comply with the full suite of Act 854 obligations. If your organisation operates, manages, or provides essential services within any of these sectors, you are in scope regardless of company size or ownership structure.

    The 11 designated NCII sectors

    • Government
    • Banking and Finance
    • Energy
    • Water and Waste Management
    • Transportation
    • Healthcare
    • Information and Communications
    • Digital Economy
    • Defence and Security
    • Emergency Services
    • Space

    Sector regulators — including Bank Negara Malaysia for financial institutions and the Energy Commission for energy operators — work alongside NACSA to enforce sector-specific directives. This means a bank, for example, must satisfy both the BNM RMiT obligations and Act 854 NCII requirements concurrently.

    Critically, the definition of an NCII operator extends beyond direct service providers. An organisation that operates ICT systems upon which a critical service depends may also fall within scope. Organisations uncertain about their NCII status should conduct a formal scoping exercise — a step covered under the NACSA Risk Assessment (NCSB) framework that Simply Data recommends as the starting point for all Act 854 compliance engagements.

    The 72-hour incident reporting obligation

    The 72-hour incident reporting rule is the most operationally demanding provision in Act 854 for most organisations. NCII sector operators must notify NACSA within 72 hours of becoming aware that a cybersecurity incident has occurred. This clock starts from the moment the organisation has reasonable grounds to believe an incident has taken place — not from the point of confirmed, forensically verified breach.

    What counts as a cybersecurity incident under Act 854?

    Act 854 defines a cybersecurity incident broadly to include any act or omission that compromises the confidentiality, integrity, or availability of a network service, system, or data. This covers ransomware attacks, data exfiltration, DDoS attacks, unauthorised access, and insider threats. The MITRE ATT&CK framework catalogues the full range of adversarial techniques that commonly trigger incident classification — from initial access through to impact — and can serve as a reference for triage teams determining whether an event crosses the reporting threshold.

    Two-stage reporting timeline

    StageDeadlineWhat to submit
    Initial notificationWithin 72 hours of awarenessIncident type, affected systems, estimated scope, immediate containment actions taken
    Detailed written reportWithin 14 days of initial notificationFull incident timeline, root cause analysis, impact assessment, remediation steps, and recurrence prevention measures

    Failure to submit the initial notification within 72 hours is a strict-liability offence. Organisations cannot use ongoing forensic investigation as a reason to delay notification — NACSA expects notification based on available information, with updates to follow. Organisations without a tested incident response plan and a pre-designated NACSA reporting contact are at significant risk of missing this deadline during an active attack.

    NACSA licensed service providers: what organisations need to know

    Act 854 introduces a mandatory licensing regime for cybersecurity service providers operating within or for NCII sectors. Any organisation providing cybersecurity services — including managed detection and response, penetration testing, SOC operations, incident response, and security consultancy — to an NCII entity must hold a valid NACSA Cybersecurity Service Provider licence.

    Licensing categories under NACSA

    NACSA has defined licensing tiers based on the type and scope of cybersecurity services delivered. Relevant categories include:

    • Managed Security Services (MSS) — for SOC operators, MSSPs, and monitoring providers
    • Vulnerability Assessment and Penetration Testing (VAPT) — for pen test firms and red teams
    • Incident Response Services — for digital forensics and IR consultancies
    • Security Risk Assessment — for consultancies conducting risk and compliance advisory work

    NCII sector organisations bear responsibility for ensuring that any third-party cybersecurity service provider they engage holds the appropriate NACSA licence. Engaging an unlicensed provider does not absolve the NCII operator of regulatory exposure — auditors may treat this as a failure of due diligence in vendor management. Simply Data recommends documenting licence verification as a standing procurement control, reviewed at each contract renewal.

    What happens if your current provider is not yet licensed?

    If your incumbent security provider has not obtained a NACSA licence, your organisation faces a compliance gap that needs to be addressed immediately. A security posture assessment can help you map which of your current third-party relationships carry Act 854 licensing exposure and prioritise remediation.

    Penalty structure: the full breakdown

    Act 854 establishes a tiered penalty structure calibrated to the severity and nature of each offence. The following table summarises the primary penalty provisions relevant to NCII operators and cybersecurity service providers.

    Act 854 penalty table

    OffenceMaximum fineMaximum imprisonmentNotes
    Failure to report cybersecurity incident within 72 hoursRM50,0003 yearsPer incident; repeat offences attract doubled penalties
    Failure to submit detailed incident report within 14 daysRM50,0003 yearsSeparate offence from initial notification failure
    Providing cybersecurity services without a NACSA licenceRM500,00010 yearsApplies to service providers; daily continuing offence for ongoing violations
    Failure to comply with a NACSA directive or audit requestRM100,0003 yearsIncludes failure to cooperate with NACSA investigations
    Obstruction of a NACSA officerRM200,0005 yearsApplies to individuals, not just organisations
    False or misleading statements to NACSARM200,0005 yearsIncludes incomplete or inaccurate incident reports

    Directors, officers, and senior managers can be held personally liable under Act 854’s corporate liability provisions. Where a body corporate commits an offence, any officer who consented to or connived in the act faces the same penalties as the organisation itself. This significantly raises the personal stakes for CISOs, CTOs, and board members who oversee cybersecurity governance.

    Compliance timeline: key deadlines for Act 854

    NACSA has implemented a phased rollout to allow NCII sector organisations to build compliance capacity. The table below reflects the operative timeline based on NACSA guidance as of 2025–2026.

    Act 854 compliance phases

    PhaseTimelineRequired actionStatus
    NCII registration and scopingH2 2024Identify NCII assets; register with sector regulator; confirm NCII operator statusEnforcement active
    Risk assessment submissionH2 2024 – Q1 2025Conduct NACSA-framework risk assessment; submit findings to NACSAEnforcement active
    Incident response plan (IRP) implementationQ1 2025Documented, tested IRP covering 72-hour notification; NACSA reporting contacts registeredEnforcement active
    Licensed service provider engagementFrom 2025 onwardAll cybersecurity vendors serving NCII entities must hold valid NACSA licenceEnforcement active
    Annual audit and re-assessmentRecurring — annuallyOngoing risk assessment updates; NACSA audit cooperation; licence renewalsOngoing

    Organisations that have not yet completed Phase 1 and Phase 2 obligations are operating in a state of non-compliance. Given that NACSA officers now have statutory authority to conduct investigations and issue directives without prior notice, the window for quiet preparation has closed. A structured security blueprint and compliance roadmap is the fastest way to identify gaps and build a defensible compliance posture before an audit is triggered.

    How Act 854 intersects with PDPA, RMiT, and ISO 27001

    Malaysian organisations in regulated sectors must navigate Act 854 alongside several existing compliance frameworks. Understanding the overlaps helps prioritise effort and avoid duplicating work.

    PDPA (Personal Data Protection Act)

    The PDPA governs personal data processing obligations for commercial entities. A cybersecurity incident that results in personal data exposure triggers both PDPA notification obligations (to the Personal Data Protection Commissioner) and Act 854 incident reporting obligations (to NACSA). Organisations should ensure their incident response plans address both notification tracks simultaneously, with separate templated communications for each authority.

    BNM Risk Management in Technology (RMiT)

    Bank Negara Malaysia’s RMiT framework already mandates robust technology risk management for financial institutions, including incident reporting, third-party risk management, and business continuity requirements. Act 854 adds a parallel layer — financial institutions must now satisfy both RMiT and NCII obligations, which share many controls but are administered by different authorities (BNM and NACSA respectively).

    ISO 27001

    ISO 27001 certification provides a strong foundation for Act 854 compliance. The standard’s Annex A controls map closely to NACSA’s risk assessment requirements, and an existing ISMS can significantly accelerate the time and cost of completing the mandatory NCII risk assessment. However, ISO 27001 certification alone does not constitute Act 854 compliance — formal NACSA submission and licensing steps remain mandatory regardless of certification status.

    Protect Your Organisation with Simply Data

    Simply Data is a NACSA-engaged cybersecurity consultancy with deep expertise in Act 854 compliance, NCII risk assessment, and security programme design for Malaysian enterprises. Whether you are at the beginning of your compliance journey or need to close specific gaps before a NACSA audit, our team delivers structured, evidence-based outcomes.

    Our Act 854 compliance services include:

    • NACSA Risk Assessment (NCSB) — scoping, gap analysis, and formal risk assessment submission aligned to NACSA requirements
    • Security Posture Assessment (SPA) — independent technical review of your current controls against Act 854 obligations, including third-party vendor licensing verification
    • Security Blueprint Consultancy — end-to-end compliance roadmap covering incident response planning, IRP testing, NACSA notification workflows, and governance documentation

    Non-compliance with the Cyber Security Act 2024 is not a future risk — it is a present legal exposure. Contact Simply Data today for a confidential compliance readiness conversation and take the first step toward a defensible, audit-ready cybersecurity posture.

    Frequently Asked Questions

    What is the Cyber Security Act 2024 Malaysia?

    The Cyber Security Act 2024 (Act 854) is Malaysia primary federal legislation governing cybersecurity obligations. Enacted in June 2024 and enforced by NACSA (National Cyber Security Agency), it mandates incident reporting, licensed service provider requirements, and compliance obligations for operators of National Critical Information Infrastructure (NCII). Penalties for non-compliance reach up to RM500,000 and/or imprisonment of up to 10 years.

    Who must comply with the Cyber Security Act 2024?

    Compliance is mandatory for all NCII sector operators across 11 designated sectors, including government, banking and finance, energy, water, transportation, healthcare, information and communications, digital economy, defence and security, emergency services, and space. Organisations operating in these sectors must meet incident reporting, licensing, and risk assessment obligations under Act 854.

    What are the penalties under the Cyber Security Act 2024 Malaysia?

    Penalties under Act 854 vary by offence. Failure to report a cybersecurity incident within 72 hours carries a fine of up to RM50,000 and/or imprisonment of up to 3 years. Providing cybersecurity services without a NACSA licence attracts fines up to RM500,000 and/or imprisonment up to 10 years. Repeated or aggravated offences may attract double penalties.

    What is the 72-hour incident reporting rule under the Cyber Security Act 2024?

    Under Act 854, NCII sector operators must notify NACSA of any cybersecurity incident within 72 hours of becoming aware of it. This initial report must be followed by a detailed written report within 14 days. The 72-hour clock starts from the moment the operator has reasonable grounds to believe a cybersecurity incident has occurred, not from confirmed verification.

    Do I need a NACSA licence to provide cybersecurity services in Malaysia?

    Yes. Under the Cyber Security Act 2024, any organisation providing cybersecurity services to NCII sector entities must obtain a NACSA Cybersecurity Service Provider licence. This applies to managed security service providers (MSSPs), penetration testing firms, SOC operators, and incident response consultancies. Operating without a licence is a criminal offence under Act 854.

    When do NACSA licensing deadlines take effect under the Cyber Security Act 2024?

    NACSA has released a phased compliance timeline under Act 854. NCII sector operators were expected to complete initial registration and risk assessments in 2024, with full licensing enforcement for cybersecurity service providers commencing from 2025. Organisations that have not yet completed their NACSA Risk Assessment or licensed service provider engagement are at immediate regulatory risk.

    • Compliance
    • cybersecurity-malaysia
    • Malaysia
    • nacsa
    • Regulatory

    Post navigation

    Previous

    Search

    Categories

    • Announcements (9)
    • Cybersecurity Tips (46)
    • Industry Insights & Trends (18)
    • Regulatory & Compliance (10)
    • Service Spotlight (13)

    Recent posts

    • cyber security act 2024 nacsa licensing penalties
      Cyber Security Act 2024 Malaysia: NACSA Licensing Deadlines and Penalties Explained
    • ransomware malaysia critical infrastructure ktmb
      Ransomware Hits Malaysian Critical Infrastructure: Lessons From the KTMB Leak-Site Claim
    • managed security services malaysia 1 1024x683
      Managed Security Services Malaysia: How to Choose the Right MSSP for Your Business

    Tags

    2026 Trends AI Cybersecurity AI Threats apm Bank Negara RMiT Certification Company News Compliance Cost-Benefit Analysis CVE cyber-security-act cybersecurity-malaysia Cybersecurity Malaysia Cyber SOC Cyber Threats DFIR Dwell Time Incident Response iso27001 Malaysia Malaysia Cybersecurity Malaysia Cybersecurity 2025 Managed Services Managed SOC MDR nacsa Network Security Patch Management PDPA penetration-testing Proactive Cybersecurity Ransomware ROI SIEM SME Budget SME Security soc SOC Malaysia stockbrokers threat-intelligence Threat Hunting Threat Report vapt Vulnerability Web Application Security

    Related posts

    ransomware malaysia critical infrastructure ktmb
    Industry Insights & Trends

    Ransomware Hits Malaysian Critical Infrastructure: Lessons From the KTMB Leak-Site Claim

    July 30, 2026

    A ransomware group reportedly claimed KTMB on a public leak site. Learn what Malaysian NCII operators must do under the Cyber Security Act 2024 — and a 6-step hardening checklist.

    Broker cybersecurity compliance Malaysia — 2026 readiness guide for stockbrokers
    Regulatory & Compliance

    Cybersecurity Compliance for Malaysian Stockbrokers: A Practical Readiness Guide (2026)

    July 21, 2026

    After the 2025 trading breach, Malaysian brokers face rising cyber-compliance expectations. A practical, framework-aligned 2026 readiness guide — and how to close the gap.

    DDoS attack flooding a Malaysia web hosting network while the origin server stays healthy
    Cybersecurity Tips

    What a Real DDoS Attack Looks Like: Lessons From a Live Incident

    July 8, 2026

    A real DDoS attack on a Malaysia web hosting company took our site offline with Cloudflare 525 errors — here’s what happened and how to defend.

    simply data logo

    Started in 2022, Simply Data is a CREST certified and NACSA Licensed (No. 20007-01 & 20007-02) Cyber Security company in Malaysia that provides cyber security services including Network & Security IT Managed Service, Security Operation Centre (SOC), Cyber Threat Intelligence, Vulnerability Assessment & Penetration Testing (VAPT) service, Application Performance Monitoring (APM) services, and more.

    • B-03A-03, 3RD Floor, Block B Setiawalk, Persiaran Wawasan, Pusat Bandar Puchong, 47100 Puchong, Selangor
    • +603 5886 2714
    • contactus@simplydata.com.my
    Quick Links
    • Home
    • About Us
    • Innovation
    • Technology Vendor Partners
    • Blog / News
    • Career Opportunities
      Hiring
    • Become a Simply Data Partner
    • Cybersecurity Readiness Assessment
    • Malaysia CyberSecurity Act 854
    CyberSecurity Services
    • Cyber - 911 - DFIR Services
    • Compromise Assessment
    • Security Operations Center (SOC)
    • Extended Threat Intelligence
    • Security Posture Assessment (SPA) Services
    • Network & Security Configuration Audit & Hardening
    • Phishing Email Simulation
    Managed Network & Security Services
    • Managed Network & Security Services
    Observability Application Performance Monitoring
    • Observability APM as a Service
    • Cloud Monitoring
    • Database Performance Monitoring
    • Web Application Monitoring
    • Synthetic Testing Monitoring
    • Real User Monitoring
    • Stress Test / Load Test – Performance Assessment
    Consultancy Services
    • NCSB Risk Assessment
    • Security BluePrint™ Consultancy Services

    © 2025 Simply Data Sdn Bhd. All rights reserved.

    • Terms & Conditions
    • Data Protection & User Privacy
    • Privacy Policy
    • Cookie Policy