<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=2253229985023706&amp;ev=PageView&amp;noscript=1">

back to HRMI

Cyber Security Compliance Malaysia: What Act 854 Requires

Read Time 7 mins | 08 Sep 2026 | Written by: Hastin Lia

Compliance officer reviewing Malaysia cyber security regulation requirements on a laptop in an office

Cyber security compliance in Malaysia now runs on the Cyber Security Act 2024 (Act 854), in force since 26 August 2024. It applies mainly to organisations designated as National Critical Information Infrastructure (NCII) across eleven sectors. Those entities must run annual risk assessments, pass a biennial audit, and report incidents to NACSA. As of 2026 that cadence is fully running, and the first assessment and audit cycles have already come due.

If you landed on a guide built around a "Cybersecurity Act 2017", close it. That framing is out of date and still common in third-party summaries. The operative law is Act 854, and its obligations are specific enough that guessing is expensive.

What Act 854 changed in 2024

Malaysia previously governed cyber security through policy and sectoral guidance rather than a single statute carrying criminal penalties. Act 854 changed that: it created a statutory framework, defined the role of the National Cyber Security Agency (NACSA), and attached fines and imprisonment to a defined set of duties.

The Act was gazetted on 26 June 2024 and came into operation on 26 August 2024, per NACSA's official Act 854 page.

Who cyber security compliance in Malaysia applies to

The Act is built around National Critical Information Infrastructure. NCII means a computer or computer system whose disruption would damage key national or government functions, public safety, public health, or public order.

Designation is made by the NCII sector lead for each sector, not by NACSA itself. The eleven sectors are set out in the Schedule to Act 854, and are listed in full in PwC Malaysia's Act 854 publication:

  • Government
  • Banking and finance
  • Transportation
  • Defence and national security
  • Healthcare services
  • Water, sewerage and waste management
  • Energy
  • Agriculture and plantation
  • Trade, industry and economy
  • Science, technology and innovation
  • Information, communication and digital

Two clarifications matter more than the list itself.

Operating in one of these sectors does not automatically make you NCII. The test turns on whether you own or operate the infrastructure itself, which is why two firms in the same sector can land on opposite sides of it. A mid-sized logistics firm sits in transportation; that alone does not designate it.

Most SMEs are not NCII entities. If you are not designated and do not sell cyber security services, Act 854's NCII duties do not fall on you. That disappoints companies told otherwise by a vendor, but acting on the wrong reading wastes budget. One route does catch smaller companies regardless of size, covered below.

How to confirm whether you are designated

There is no public register to look yourself up in, which is why so many organisations stay unsure. Three steps resolve it.

Identify your sector lead. That lead agency is the office that would have notified you. If you are unsure which body holds the role for your industry, your primary regulator or ministry contact can point you to it.

Check whether you have received formal notification. Designation arrives through official communication, not inference. If nothing has come and your systems do not plausibly meet the NCII test, you are most likely outside the regime.

Assess the disruption test honestly anyway. An organisation that clearly meets the test set out above should expect designation eventually and can prepare rather than wait.

Cyber security compliance duties in Malaysia for NCII entities

Four duties carry the weight.

Follow the sector code of practice. Each sector lead issues a code of practice that translates the Act into operational requirements for that industry.

Run a cyber security risk assessment at least once a year. Like the audit cycle below, this period comes from the Cyber Security (Period for Cyber Security Risk Assessment and Audit) Regulations 2024, not from the Act itself. Annual is the floor.

Undergo an audit at least once every two years, performed by an auditor approved by the Chief Executive of NACSA under section 22(1)(b), as summarised in PwC Malaysia's Act 854 publication. An internal review, however rigorous, does not discharge it.

Report cyber security incidents to the Chief Executive of NACSA and the relevant sector lead. Failing this is one of the Act's top-tier offences under section 23(2), alongside providing a licensable cyber security service without a licence under section 27(5). The figures are in the table below.

Penalties

FailureMaximum fineMaximum imprisonment
Failure to conduct the required risk assessment or auditRM200,0003 years
Failure to report a cyber security incidentRM500,00010 years

Both offences allow a fine, imprisonment, or both. The gap between the two rows is the useful signal: Malaysia penalises staying silent about an incident more heavily than failing to assess for one.

Figures as set out in PwC Malaysia's Act 854 publication and Mayer Brown's summary.

Licensing for cyber security service providers

Companies that provide certain cyber security services in or from Malaysia need a licence from NACSA under Part VI of the Act, a regime covered in Mayer Brown's summary. This obligation is separate from NCII designation and turns on what you sell rather than what you operate.

The consequence organisations miss is on the buying side: an unlicensed vendor becomes a supply-chain problem you inherit, so a provider's licence position is now a reasonable procurement question.

Act 854 and the PDPA are different obligations

These two laws get merged in conversation constantly, and the merge causes real gaps. They protect different things.

Cyber Security Act 2024 (Act 854)Personal Data Protection Act 2010
ProtectsNational critical systems and their continuityPersonal data of individuals
Applies toDesignated NCII entities; licensed service providersOrganisations processing personal data commercially
Core dutiesSector code compliance; incident reporting to NACSALawful processing, security safeguards, data subject rights, breach notification
RegulatorNACSAPersonal Data Protection Commissioner

An organisation can fall under one, both, or neither. A designated hospital sits under both; a retailer with a customer database and no designation sits under the PDPA alone. Our complete guide to the PDPA in Malaysia covers that second obligation.

Where compliance programmes actually fail

Both the assessment and the audit examine controls, which is where organisations concentrate spending and rarely where they fail.

Reporting duties are triggered by incidents, and incidents routinely begin with a person: someone approves a payment, reuses a password, or opens an attachment. A control set can be well documented while the behaviour it depends on goes unmeasured, and an audit will not necessarily surface that.

This is the gap human risk management addresses: treating employee behaviour as measurable risk rather than an awareness formality. Structured cyber security awareness training for employees turns that from an annual slide deck into evidence you can put in front of an auditor.

For organisations working through designation and the duties that follow, SiberMate's Act 854 compliance solution maps the people layer to the Act's requirements.

Common mistakes

Scoping the assessment to IT systems alone. Designated infrastructure often reaches operational technology and third-party dependencies that never appear in an IT asset inventory, and those are the dependencies an outage tends to travel through.

Booking the audit late in the two-year window. Approved auditors are a limited pool and demand concentrates near deadlines. Wait until month 22 and the calendar, not your controls, becomes the binding constraint.

Building the evidence trail only at audit time. Records reconstructed after the fact are weaker and slower to assemble than contemporaneous ones.

Assuming existing PDPA work already covers Act 854. Data protection programmes answer a different regulator and a different question. Mapping that evidence across leaves the continuity and incident-reporting duties unaddressed.

Waiting for enforcement to clarify things. The cadence runs whether or not a prosecution has happened. Start your first annual assessment after the first enforcement action and you are already a full cycle behind.

Frequently asked questions

What is compliance in cyber security?

It means meeting the security duties that a law, regulator, or sector code places on your organisation, then holding evidence that you met them. In Malaysia, that evidence usually takes the form of risk assessments, audit reports, and incident records.

What are the key cyber security policies in Malaysia?

The Cyber Security Act 2024 (Act 854) governs national critical infrastructure. The Personal Data Protection Act 2010 governs personal data. NACSA issues guidance and sector codes of practice beneath the Act, and individual regulators add sectoral requirements.

Does the Cyber Security Act 2024 apply to small businesses?

Generally no. NCII duties fall on designated entities. The exception is companies providing certain cyber security services, which need a NACSA licence regardless of size.

How often must an NCII entity be audited?

At least once every two years, by a NACSA-approved auditor. Risk assessments run on a separate, annual cycle.

What happens if an incident goes unreported?

Failure to report carries a fine of up to RM500,000, imprisonment of up to 10 years, or both.

See how your people layer maps to Act 854 requirements

Hastin Lia

Hastin Lia, Digital Marketing at SiberMate, writes about cybersecurity, data privacy, and human cyber risk management, turning complex security topics—from PDPA compliance to phishing simulations—into clear, actionable guidance for everyday teams.

WhatsApp Icon Mira