
The Cyber Security Act 2024 came into force on 26 August 2024, and its first full compliance cycle has now run. For an organisation designated as National Critical Information Infrastructure, the Act reads less like a policy and more like a calendar: things that must happen every year, every two years, and within hours of an incident.
Designation comes first
Nothing in the Act applies until an organisation is designated as an NCII entity by its sector lead. Designation is by sector — eleven of them, each with a government sector lead reporting to NACSA — and it is the sector lead, not the entity, that decides. An organisation that believes it may be in scope should ask its sector lead rather than wait to be told, because the duties start on designation and the penalties attach to the entity.
The recurring duties
Once designated, an NCII entity must conduct a cyber security risk assessment at least once a year and undergo a cyber security audit at least once every two years, both against the Code of Practice for its sector, with the results submitted to the sector lead and NACSA. It must comply with the sector Code of Practice and any directive issued by NACSA's Chief Executive. Directive No. 4 mandates the National Cyber Security Baseline self-assessment — 125 questions across the six NIST CSF 2.0 functions, scored on a four-level maturity scale.
The Codes of Practice are written per sector and are not published centrally, which is why a cross-sector platform can carry the baseline but not the sector code; the entity has to obtain its own code from its sector lead and map it.
Incident notification
An NCII entity must notify NACSA and its sector lead of a cyber security incident that has occurred or might have occurred. The Cyber Security (Notification of Cyber Security Incident) Regulations 2024 set the mechanics: an initial electronic notification within six hours of becoming aware, and fuller particulars within fourteen days. That is a shorter first clock than the PDPA's 72 hours, and the two run in parallel when personal data is involved.
The practical consequence is that the incident-response plan needs a named person who can make the six-hour notification with incomplete information, and a process for the fourteen-day follow-up that draws on the evidence the response team is already collecting.
Service providers and penalties
Providers of penetration testing and managed security operations centre services must hold a NACSA licence; an NCII entity buying those services should check the licence before the contract. Failing to report an incident or to implement the Code of Practice carries a fine of up to RM500,000, imprisonment of up to ten years, or both; failing to conduct the required risk assessment or audit carries up to RM200,000 and the same custodial ceiling.
A working programme therefore keeps four things current and inspectable: the designation letter and sector code, the dated annual risk assessment, the dated biennial audit with its findings tracked to closure, and the NCSB self-assessment with the evidence behind each answer. GRCLens holds the baseline questionnaire as NACSA's workbook lays it out and scores it on NACSA's scale; the audit findings live in the assurance register with owners and due dates.
Keep reading

Malaysia's cyber risk landscape in 2026: three laws, one board agenda
The Cyber Security Act, the amended PDPA and Bank Negara's revised RMiT arrived within eighteen months of each other. Here is how they fit together, and what the threat picture behind them looks like.

Enhanced CIRMP Rules 2026: What to Do and When
The enhanced CIRMP Rules commenced on 10 June 2026. What nine high-risk asset classes must do, which frameworks now qualify, and the deadlines.

Saudi OTCC and CSCC: Which NCA Controls Apply?
OTCC-1:2022 covers critical OT and ICS. CSCC-1:2019 covers other critical systems. Scope, control counts, facility levels and the ECC link.