Cyber security compliance in Malaysia
Malaysia now has a statutory cybersecurity regime for critical infrastructure, a refreshed technology risk policy for financial institutions, and a data protection law whose 2024 amendments took effect in stages through 2025. The dates matter, and several of them are commonly misquoted. This page sets out what applies and from when.
- Frameworks listed6
- Issuing bodies4
- Framework pages2
- Platform languagesEnglish and Arabic
- DeploymentSaaS, private cloud or on-premises
Cybersecurity and data protection frameworks in Malaysia
Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.
Cyber Security Act 2024 (Act 854) and its regulations
National critical information infrastructure (NCII) entities in the 11 sectors in the Act's Schedule. In force since 26 August 2024
Read the guide →National Cyber Security Baseline (NCSB) v1.4
NCII entities, which must complete a baseline self-assessment within two weeks of designation
Open the framework page →Risk Management in Technology (RMiT)
Banks, insurers and takaful operators, prescribed development financial institutions, e-money issuers and designated payment system operators. Revised version effective 28 November 2025
Open the framework page →Management of Customer Information and Permitted Disclosures
BNM-regulated institutions. Reissued, effective 31 October 2025
Guidelines on Technology Risk Management
Capital market entities. In force since 19 August 2024
Personal Data Protection Act 2010, as amended in 2024
Organisations processing personal data in commercial transactions. Amendments phased in from 1 January to 1 June 2025
Read the guide →Which cybersecurity laws apply in Malaysia?
For critical infrastructure, the Cyber Security Act 2024 (Act 854). It came into force on 26 August 2024. The 26 June 2024 date that is often quoted is the gazette date. Four regulations took effect on the same day: risk assessment at least yearly and audit at least every two years, incident notification, licensing, and compounding of offences.
Financial institutions add Bank Negara Malaysia's Risk Management in Technology policy, and capital market entities the Securities Commission's technology risk guidelines. Everyone processing personal data in commercial transactions is subject to the amended Personal Data Protection Act.
What must an NCII entity do under Act 854?
Complete a National Cyber Security Baseline self-assessment within two weeks of designation under NACSA's Chief Executive Directive No. 4, follow the code of practice for its sector, conduct a risk assessment at least yearly and an audit by a NACSA-approved auditor at least every two years.
Incident notification is tight: notify immediately, give further particulars within 6 hours and full details within 14 days, through NACSA's national cyber coordination centre. The licensing regulation covers only managed security operations centre monitoring and penetration testing services, not all security services as is sometimes claimed.
What changed in BNM's RMiT?
BNM issued a revised Risk Management in Technology policy effective 28 November 2025, and its policy page lists a further update dated 25 September 2026. References to the June 2023 version are out of date. BNM has enforced it: in January 2026 it penalised Bank Rakyat RM1 million for breaches of RMiT and of its customer information policy.
When did the PDPA amendments take effect?
In three stages, not all on 1 January 2025. Administrative provisions came first, on 1 January 2025. On 1 April 2025 came the change to data controller terminology, biometric data as sensitive data, processors bound by the Security Principle, the higher RM1 million penalty and removal of the transfer whitelist. On 1 June 2025 came the mandatory data protection officer, breach notification and data portability.
Breaches are notified to the Commissioner within 72 hours and to affected individuals within 7 days. A data protection officer is required above 20,000 data subjects, or 10,000 where sensitive or financial data is involved, or where processing involves systematic monitoring.
Which language do Malaysian regulations use?
Acts are issued in Malay and English, with the Malay text authoritative unless prescribed otherwise, and NACSA's directives are published in Malay only. BNM and Securities Commission documents are in English. GRCLens records obligations in English with references to the source text, so auditors can trace each control to the authoritative wording.
How GRCLens runs Malaysian frameworks together
NCSB, RMiT and PDPA obligations share one control model in GRCLens with ISO/IEC 27001 and NIST CSF, so a bank designated as NCII evidences each control once for NACSA and BNM. The NCSB maturity scale, RMiT gap analysis and incident clocks are tracked as their own indicators. The platform can be hosted in Malaysia or fully on-premises.
Official portals and publications
Cyber compliance in Malaysia: common questions
When did Malaysia's Cyber Security Act 2024 come into force?
26 August 2024. The Act was gazetted on 26 June 2024, which is the date often misquoted as commencement.
How fast must an NCII entity report a cyber incident in Malaysia?
Immediately, with further particulars within 6 hours and full details within 14 days, under the incident notification regulation made under Act 854.
Which version of BNM RMiT is current?
The revised policy effective 28 November 2025. BNM's page lists a further update to the policy document dated 25 September 2026.
When is a data protection officer required under Malaysia's PDPA?
From 1 June 2025, where an organisation processes data of more than 20,000 individuals, more than 10,000 where sensitive or financial data is involved, or conducts systematic monitoring.
Does NACSA licensing cover all cybersecurity services?
No. It covers managed security operations centre monitoring and penetration testing services only.
Sources
Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Malaysia's frameworks on one platform
See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security and compliance services in Malaysia from Security Solution Consultants.