Cyber Security Act 2024 Malaysia: NACSA Licensing Deadlines and Penalties Explained

Malaysia Cyber Security Act 2024 (Act 854) imposes legally binding obligations on operators of National Critical Information Infrastructure, with penalties reaching up to RM500,000 and imprisonment of up to 10 years for the most serious violations. Enacted in June 2024 and enforced by the National Cyber Security Agency (NACSA), Act 854 marks a decisive shift from voluntary cybersecurity frameworks to mandatory, enforceable compliance law in Malaysia. For C-suite leaders and IT heads operating across the 11 designated NCII sectors, understanding what the Act requires — and the consequences of non-compliance — is no longer optional.
What is the Cyber Security Act 2024 (Act 854)?
Act 854 is Malaysia primary federal cybersecurity law, published in the Federal Gazette and brought into force in stages through 2024 and 2025. It consolidates the country’s approach to protecting critical digital infrastructure under a single legislative framework, giving NACSA statutory authority to regulate, investigate, and prosecute cybersecurity failures.
The Act establishes three interlocking obligations that every covered organisation must meet:
- Incident reporting — mandatory notification to NACSA within prescribed timeframes
- NCII sector compliance — risk assessments, audits, and security directives for all 11 NCII sectors
- Licensing of cybersecurity service providers — any party delivering cybersecurity services to NCII entities must hold a valid NACSA licence
Act 854 does not replace existing regulations such as Bank Negara Malaysia’s Risk Management in Technology (RMiT) framework, the Personal Data Protection Act (PDPA), or MCMC licensing requirements. It operates alongside these instruments, meaning organisations in regulated sectors now face layered compliance obligations from multiple authorities simultaneously.
The 11 NCII sectors: who is covered?
NACSA designates 11 National Critical Information Infrastructure sectors whose operators must comply with the full suite of Act 854 obligations. If your organisation operates, manages, or provides essential services within any of these sectors, you are in scope regardless of company size or ownership structure.
The 11 designated NCII sectors
- Government
- Banking and Finance
- Energy
- Water and Waste Management
- Transportation
- Healthcare
- Information and Communications
- Digital Economy
- Defence and Security
- Emergency Services
- Space
Sector regulators — including Bank Negara Malaysia for financial institutions and the Energy Commission for energy operators — work alongside NACSA to enforce sector-specific directives. This means a bank, for example, must satisfy both the BNM RMiT obligations and Act 854 NCII requirements concurrently.
Critically, the definition of an NCII operator extends beyond direct service providers. An organisation that operates ICT systems upon which a critical service depends may also fall within scope. Organisations uncertain about their NCII status should conduct a formal scoping exercise — a step covered under the NACSA Risk Assessment (NCSB) framework that Simply Data recommends as the starting point for all Act 854 compliance engagements.
The 72-hour incident reporting obligation
The 72-hour incident reporting rule is the most operationally demanding provision in Act 854 for most organisations. NCII sector operators must notify NACSA within 72 hours of becoming aware that a cybersecurity incident has occurred. This clock starts from the moment the organisation has reasonable grounds to believe an incident has taken place — not from the point of confirmed, forensically verified breach.
What counts as a cybersecurity incident under Act 854?
Act 854 defines a cybersecurity incident broadly to include any act or omission that compromises the confidentiality, integrity, or availability of a network service, system, or data. This covers ransomware attacks, data exfiltration, DDoS attacks, unauthorised access, and insider threats. The MITRE ATT&CK framework catalogues the full range of adversarial techniques that commonly trigger incident classification — from initial access through to impact — and can serve as a reference for triage teams determining whether an event crosses the reporting threshold.
Two-stage reporting timeline
| Stage | Deadline | What to submit |
|---|---|---|
| Initial notification | Within 72 hours of awareness | Incident type, affected systems, estimated scope, immediate containment actions taken |
| Detailed written report | Within 14 days of initial notification | Full incident timeline, root cause analysis, impact assessment, remediation steps, and recurrence prevention measures |
Failure to submit the initial notification within 72 hours is a strict-liability offence. Organisations cannot use ongoing forensic investigation as a reason to delay notification — NACSA expects notification based on available information, with updates to follow. Organisations without a tested incident response plan and a pre-designated NACSA reporting contact are at significant risk of missing this deadline during an active attack.
NACSA licensed service providers: what organisations need to know
Act 854 introduces a mandatory licensing regime for cybersecurity service providers operating within or for NCII sectors. Any organisation providing cybersecurity services — including managed detection and response, penetration testing, SOC operations, incident response, and security consultancy — to an NCII entity must hold a valid NACSA Cybersecurity Service Provider licence.
Licensing categories under NACSA
NACSA has defined licensing tiers based on the type and scope of cybersecurity services delivered. Relevant categories include:
- Managed Security Services (MSS) — for SOC operators, MSSPs, and monitoring providers
- Vulnerability Assessment and Penetration Testing (VAPT) — for pen test firms and red teams
- Incident Response Services — for digital forensics and IR consultancies
- Security Risk Assessment — for consultancies conducting risk and compliance advisory work
NCII sector organisations bear responsibility for ensuring that any third-party cybersecurity service provider they engage holds the appropriate NACSA licence. Engaging an unlicensed provider does not absolve the NCII operator of regulatory exposure — auditors may treat this as a failure of due diligence in vendor management. Simply Data recommends documenting licence verification as a standing procurement control, reviewed at each contract renewal.
What happens if your current provider is not yet licensed?
If your incumbent security provider has not obtained a NACSA licence, your organisation faces a compliance gap that needs to be addressed immediately. A security posture assessment can help you map which of your current third-party relationships carry Act 854 licensing exposure and prioritise remediation.
Penalty structure: the full breakdown
Act 854 establishes a tiered penalty structure calibrated to the severity and nature of each offence. The following table summarises the primary penalty provisions relevant to NCII operators and cybersecurity service providers.
Act 854 penalty table
| Offence | Maximum fine | Maximum imprisonment | Notes |
|---|---|---|---|
| Failure to report cybersecurity incident within 72 hours | RM50,000 | 3 years | Per incident; repeat offences attract doubled penalties |
| Failure to submit detailed incident report within 14 days | RM50,000 | 3 years | Separate offence from initial notification failure |
| Providing cybersecurity services without a NACSA licence | RM500,000 | 10 years | Applies to service providers; daily continuing offence for ongoing violations |
| Failure to comply with a NACSA directive or audit request | RM100,000 | 3 years | Includes failure to cooperate with NACSA investigations |
| Obstruction of a NACSA officer | RM200,000 | 5 years | Applies to individuals, not just organisations |
| False or misleading statements to NACSA | RM200,000 | 5 years | Includes incomplete or inaccurate incident reports |
Directors, officers, and senior managers can be held personally liable under Act 854’s corporate liability provisions. Where a body corporate commits an offence, any officer who consented to or connived in the act faces the same penalties as the organisation itself. This significantly raises the personal stakes for CISOs, CTOs, and board members who oversee cybersecurity governance.
Compliance timeline: key deadlines for Act 854
NACSA has implemented a phased rollout to allow NCII sector organisations to build compliance capacity. The table below reflects the operative timeline based on NACSA guidance as of 2025–2026.
Act 854 compliance phases
| Phase | Timeline | Required action | Status |
|---|---|---|---|
| NCII registration and scoping | H2 2024 | Identify NCII assets; register with sector regulator; confirm NCII operator status | Enforcement active |
| Risk assessment submission | H2 2024 – Q1 2025 | Conduct NACSA-framework risk assessment; submit findings to NACSA | Enforcement active |
| Incident response plan (IRP) implementation | Q1 2025 | Documented, tested IRP covering 72-hour notification; NACSA reporting contacts registered | Enforcement active |
| Licensed service provider engagement | From 2025 onward | All cybersecurity vendors serving NCII entities must hold valid NACSA licence | Enforcement active |
| Annual audit and re-assessment | Recurring — annually | Ongoing risk assessment updates; NACSA audit cooperation; licence renewals | Ongoing |
Organisations that have not yet completed Phase 1 and Phase 2 obligations are operating in a state of non-compliance. Given that NACSA officers now have statutory authority to conduct investigations and issue directives without prior notice, the window for quiet preparation has closed. A structured security blueprint and compliance roadmap is the fastest way to identify gaps and build a defensible compliance posture before an audit is triggered.
How Act 854 intersects with PDPA, RMiT, and ISO 27001
Malaysian organisations in regulated sectors must navigate Act 854 alongside several existing compliance frameworks. Understanding the overlaps helps prioritise effort and avoid duplicating work.
PDPA (Personal Data Protection Act)
The PDPA governs personal data processing obligations for commercial entities. A cybersecurity incident that results in personal data exposure triggers both PDPA notification obligations (to the Personal Data Protection Commissioner) and Act 854 incident reporting obligations (to NACSA). Organisations should ensure their incident response plans address both notification tracks simultaneously, with separate templated communications for each authority.
BNM Risk Management in Technology (RMiT)
Bank Negara Malaysia’s RMiT framework already mandates robust technology risk management for financial institutions, including incident reporting, third-party risk management, and business continuity requirements. Act 854 adds a parallel layer — financial institutions must now satisfy both RMiT and NCII obligations, which share many controls but are administered by different authorities (BNM and NACSA respectively).
ISO 27001
ISO 27001 certification provides a strong foundation for Act 854 compliance. The standard’s Annex A controls map closely to NACSA’s risk assessment requirements, and an existing ISMS can significantly accelerate the time and cost of completing the mandatory NCII risk assessment. However, ISO 27001 certification alone does not constitute Act 854 compliance — formal NACSA submission and licensing steps remain mandatory regardless of certification status.
Protect Your Organisation with Simply Data
Simply Data is a NACSA-engaged cybersecurity consultancy with deep expertise in Act 854 compliance, NCII risk assessment, and security programme design for Malaysian enterprises. Whether you are at the beginning of your compliance journey or need to close specific gaps before a NACSA audit, our team delivers structured, evidence-based outcomes.
Our Act 854 compliance services include:
- NACSA Risk Assessment (NCSB) — scoping, gap analysis, and formal risk assessment submission aligned to NACSA requirements
- Security Posture Assessment (SPA) — independent technical review of your current controls against Act 854 obligations, including third-party vendor licensing verification
- Security Blueprint Consultancy — end-to-end compliance roadmap covering incident response planning, IRP testing, NACSA notification workflows, and governance documentation
Non-compliance with the Cyber Security Act 2024 is not a future risk — it is a present legal exposure. Contact Simply Data today for a confidential compliance readiness conversation and take the first step toward a defensible, audit-ready cybersecurity posture.
Frequently Asked Questions
What is the Cyber Security Act 2024 Malaysia?
The Cyber Security Act 2024 (Act 854) is Malaysia primary federal legislation governing cybersecurity obligations. Enacted in June 2024 and enforced by NACSA (National Cyber Security Agency), it mandates incident reporting, licensed service provider requirements, and compliance obligations for operators of National Critical Information Infrastructure (NCII). Penalties for non-compliance reach up to RM500,000 and/or imprisonment of up to 10 years.
Who must comply with the Cyber Security Act 2024?
Compliance is mandatory for all NCII sector operators across 11 designated sectors, including government, banking and finance, energy, water, transportation, healthcare, information and communications, digital economy, defence and security, emergency services, and space. Organisations operating in these sectors must meet incident reporting, licensing, and risk assessment obligations under Act 854.
What are the penalties under the Cyber Security Act 2024 Malaysia?
Penalties under Act 854 vary by offence. Failure to report a cybersecurity incident within 72 hours carries a fine of up to RM50,000 and/or imprisonment of up to 3 years. Providing cybersecurity services without a NACSA licence attracts fines up to RM500,000 and/or imprisonment up to 10 years. Repeated or aggravated offences may attract double penalties.
What is the 72-hour incident reporting rule under the Cyber Security Act 2024?
Under Act 854, NCII sector operators must notify NACSA of any cybersecurity incident within 72 hours of becoming aware of it. This initial report must be followed by a detailed written report within 14 days. The 72-hour clock starts from the moment the operator has reasonable grounds to believe a cybersecurity incident has occurred, not from confirmed verification.
Do I need a NACSA licence to provide cybersecurity services in Malaysia?
Yes. Under the Cyber Security Act 2024, any organisation providing cybersecurity services to NCII sector entities must obtain a NACSA Cybersecurity Service Provider licence. This applies to managed security service providers (MSSPs), penetration testing firms, SOC operators, and incident response consultancies. Operating without a licence is a criminal offence under Act 854.
When do NACSA licensing deadlines take effect under the Cyber Security Act 2024?
NACSA has released a phased compliance timeline under Act 854. NCII sector operators were expected to complete initial registration and risk assessments in 2024, with full licensing enforcement for cybersecurity service providers commencing from 2025. Organisations that have not yet completed their NACSA Risk Assessment or licensed service provider engagement are at immediate regulatory risk.


