National Cyber Security Baseline (NCSB) v1.4 compliance software
NACSA's baseline self-assessment for National Critical Information Infrastructure entities under the Cyber Security Act 2024 — 125 questions, 33 scored elements, six functions, maturity from Initial to Advanced.
- RegulatorNACSA — National Cyber Security Agency, Malaysia
- InstrumentCyber Security Act 2024 (Act 854); Chief Executive Directive No. 4
- Structure6 functions (NIST CSF 2.0) · 19 categories · 33 elements · 125 questions
- ScoringElement score from yes / no / N/A; maturity Initial → Basic → Intermediate → Advanced
What Malaysia NACSA NCSB requires
Who it applies to
- Designated NCII entities under the Cyber Security Act 2024 (Act 854)
- Government, banking and finance, energy, water and healthcare operators in the eleven NCII sectors
- Transport, defence, ICT and digital, agriculture, trade and science sector NCII entities
- Suppliers preparing evidence for an NCII customer's NACSA self-assessment
The National Cyber Security Baseline is the National Cyber Security Agency's self-assessment instrument for Malaysia's National Critical Information Infrastructure (NCII) entities — the organisations designated under the Cyber Security Act 2024 (Act 854) across eleven sectors, from government, banking and finance and energy to healthcare, transport and water. The self-assessment is mandated by NACSA's Chief Executive Directive No. 4, and GRCLens carries version 1.4, generated directly from NACSA's own self-assessment workbook.
The baseline is organised by the six NIST CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond and Recover — broken into 19 categories and 33 elements, each answered through yes / no / not-applicable questions: 125 in all. Every element is scored from the answers to its questions, and the organisation's maturity is reported on NACSA's four-level scale: Initial, Basic, Intermediate and Advanced.
Unlike a control catalogue, NCSB is a maturity instrument with no published mandatory minimum: NACSA sets no floor, so nothing in GRCLens is captioned as a breach. The sector Codes of Practice issued under Act 854 are written per sector and are not centrally published, so they sit outside this baseline; the baseline is the common denominator every NCII entity reports against.
How GRCLens supports Malaysia NACSA NCSB
Malaysia NACSA NCSB runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
NACSA's own workbook, as a questionnaire
The 125 questions are the ones in NCSB-SelfAssessment v1.4, grouped exactly as NACSA groups them, so the result reconciles line by line with the workbook an entity submits.
Scored the way NACSA scores it
Elements are scored from their questions and maturity is reported as a mean across elements — deliberately not the weakest-link floor SAMA uses, because NACSA publishes no minimum level.
Indicators traced to elements
Derived indicators — unanswered questions, claimed-but-unevidenced answers, staleness — name the elements they measure, so a number sitting beside a contradicting answer is a finding, not a spreadsheet entry.
Sector scoping
The eleven NCII sectors are carried on the assessment, so a water operator and a bank each report the baseline in their own sector context and alongside their sector regulator's framework — BNM RMiT for the financial sector.
Malaysia NACSA NCSB frequently asked questions
Who must complete the NCSB self-assessment?
Entities designated as National Critical Information Infrastructure under the Cyber Security Act 2024 across the eleven NCII sectors. NACSA's Chief Executive Directive No. 4 mandates the self-assessment; the sector lead for each sector oversees it.
Is there a minimum maturity level?
No. NACSA publishes the four-level scale — Initial, Basic, Intermediate, Advanced — but no mandatory floor, so GRCLens reports the level without captioning any result as non-compliant. That is different from SAMA CSF, which sets Level 3 as the minimum.
How does NCSB relate to BNM RMiT?
NCSB is the cross-sector baseline every NCII entity reports to NACSA; RMiT is Bank Negara Malaysia's binding policy for financial institutions. A Malaysian bank runs both, and GRCLens carries both under the Malaysia group.
One platform, many obligations

Talk to us about Malaysia NACSA NCSB
Security Solution Consultants provides Malaysia NCII advisory alongside the platform, so you can combine tooling with hands-on expertise.