HomeFrameworksMalaysia NACSA NCSB
National Cyber Security Agency (NACSA) · Malaysia

National Cyber Security Baseline (NCSB) v1.4 compliance software

NACSA's baseline self-assessment for National Critical Information Infrastructure entities under the Cyber Security Act 2024 — 125 questions, 33 scored elements, six functions, maturity from Initial to Advanced.

At a glance
  • RegulatorNACSA — National Cyber Security Agency, Malaysia
  • InstrumentCyber Security Act 2024 (Act 854); Chief Executive Directive No. 4
  • Structure6 functions (NIST CSF 2.0) · 19 categories · 33 elements · 125 questions
  • ScoringElement score from yes / no / N/A; maturity Initial → Basic → Intermediate → Advanced
Malaysia NACSA NCSBAvailable
Overview

What Malaysia NACSA NCSB requires

Who it applies to

  • Designated NCII entities under the Cyber Security Act 2024 (Act 854)
  • Government, banking and finance, energy, water and healthcare operators in the eleven NCII sectors
  • Transport, defence, ICT and digital, agriculture, trade and science sector NCII entities
  • Suppliers preparing evidence for an NCII customer's NACSA self-assessment

The National Cyber Security Baseline is the National Cyber Security Agency's self-assessment instrument for Malaysia's National Critical Information Infrastructure (NCII) entities — the organisations designated under the Cyber Security Act 2024 (Act 854) across eleven sectors, from government, banking and finance and energy to healthcare, transport and water. The self-assessment is mandated by NACSA's Chief Executive Directive No. 4, and GRCLens carries version 1.4, generated directly from NACSA's own self-assessment workbook.

The baseline is organised by the six NIST CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond and Recover — broken into 19 categories and 33 elements, each answered through yes / no / not-applicable questions: 125 in all. Every element is scored from the answers to its questions, and the organisation's maturity is reported on NACSA's four-level scale: Initial, Basic, Intermediate and Advanced.

Unlike a control catalogue, NCSB is a maturity instrument with no published mandatory minimum: NACSA sets no floor, so nothing in GRCLens is captioned as a breach. The sector Codes of Practice issued under Act 854 are written per sector and are not centrally published, so they sit outside this baseline; the baseline is the common denominator every NCII entity reports against.

In the platform

How GRCLens supports Malaysia NACSA NCSB

Malaysia NACSA NCSB runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

NACSA's own workbook, as a questionnaire

The 125 questions are the ones in NCSB-SelfAssessment v1.4, grouped exactly as NACSA groups them, so the result reconciles line by line with the workbook an entity submits.

Scored the way NACSA scores it

Elements are scored from their questions and maturity is reported as a mean across elements — deliberately not the weakest-link floor SAMA uses, because NACSA publishes no minimum level.

Indicators traced to elements

Derived indicators — unanswered questions, claimed-but-unevidenced answers, staleness — name the elements they measure, so a number sitting beside a contradicting answer is a finding, not a spreadsheet entry.

Sector scoping

The eleven NCII sectors are carried on the assessment, so a water operator and a bank each report the baseline in their own sector context and alongside their sector regulator's framework — BNM RMiT for the financial sector.

Questions

Malaysia NACSA NCSB frequently asked questions

Who must complete the NCSB self-assessment?

Entities designated as National Critical Information Infrastructure under the Cyber Security Act 2024 across the eleven NCII sectors. NACSA's Chief Executive Directive No. 4 mandates the self-assessment; the sector lead for each sector oversees it.

Is there a minimum maturity level?

No. NACSA publishes the four-level scale — Initial, Basic, Intermediate, Advanced — but no mandatory floor, so GRCLens reports the level without captioning any result as non-compliant. That is different from SAMA CSF, which sets Level 3 as the minimum.

How does NCSB relate to BNM RMiT?

NCSB is the cross-sector baseline every NCII entity reports to NACSA; RMiT is Bank Negara Malaysia's binding policy for financial institutions. A Malaysian bank runs both, and GRCLens carries both under the Malaysia group.

Talk to us about Malaysia NACSA NCSB

Security Solution Consultants provides Malaysia NCII advisory alongside the platform, so you can combine tooling with hands-on expertise.