HomeBlogMalaysia
Malaysia

The Cyber Security Act 2024, two years on: what an NCII entity actually has to do

Sep 2026 · 7 min read

An electricity substation and water treatment works at night, protected by a faint glowing shield outline

The Cyber Security Act 2024 came into force on 26 August 2024, and its first full compliance cycle has now run. For an organisation designated as National Critical Information Infrastructure, the Act reads less like a policy and more like a calendar: things that must happen every year, every two years, and within hours of an incident.

Designation comes first

Nothing in the Act applies until an organisation is designated as an NCII entity by its sector lead. Designation is by sector — eleven of them, each with a government sector lead reporting to NACSA — and it is the sector lead, not the entity, that decides. An organisation that believes it may be in scope should ask its sector lead rather than wait to be told, because the duties start on designation and the penalties attach to the entity.

The recurring duties

Once designated, an NCII entity must conduct a cyber security risk assessment at least once a year and undergo a cyber security audit at least once every two years, both against the Code of Practice for its sector, with the results submitted to the sector lead and NACSA. It must comply with the sector Code of Practice and any directive issued by NACSA's Chief Executive. Directive No. 4 mandates the National Cyber Security Baseline self-assessment — 125 questions across the six NIST CSF 2.0 functions, scored on a four-level maturity scale.

The Codes of Practice are written per sector and are not published centrally, which is why a cross-sector platform can carry the baseline but not the sector code; the entity has to obtain its own code from its sector lead and map it.

Incident notification

An NCII entity must notify NACSA and its sector lead of a cyber security incident that has occurred or might have occurred. The Cyber Security (Notification of Cyber Security Incident) Regulations 2024 set the mechanics: an initial electronic notification within six hours of becoming aware, and fuller particulars within fourteen days. That is a shorter first clock than the PDPA's 72 hours, and the two run in parallel when personal data is involved.

The practical consequence is that the incident-response plan needs a named person who can make the six-hour notification with incomplete information, and a process for the fourteen-day follow-up that draws on the evidence the response team is already collecting.

Service providers and penalties

Providers of penetration testing and managed security operations centre services must hold a NACSA licence; an NCII entity buying those services should check the licence before the contract. Failing to report an incident or to implement the Code of Practice carries a fine of up to RM500,000, imprisonment of up to ten years, or both; failing to conduct the required risk assessment or audit carries up to RM200,000 and the same custodial ceiling.

A working programme therefore keeps four things current and inspectable: the designation letter and sector code, the dated annual risk assessment, the dated biennial audit with its findings tracked to closure, and the NCSB self-assessment with the evidence behind each answer. GRCLens holds the baseline questionnaire as NACSA's workbook lays it out and scores it on NACSA's scale; the audit findings live in the assurance register with owners and due dates.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles