Malaysia - Cyber Security Act (Act 854)

Cyber Security Act 2024

Akta Keselamatan Siber 2024

Malaysia

RAI-MY-NA-CYBSE20-2024
Effective: August 26, 2024
In Force(In Force)
ActGovernance and OversightRisk ManagementEnforcement and Penalties
Export PDF

The Cyber Security Act 2024 (Act 854) establishes a regulatory framework for national cybersecurity in Malaysia, including designation and protection of National Critical Information Infrastructure (NCII), mandatory incident reporting, periodic risk assessments and audits, licensing of certain cybersecurity service providers, and enforcement powers for the National Cyber Security Agency (NACSA). The Act received Royal Assent on 18 June 2024, was gazetted on 26 June 2024 and brought into force on 26 August 2024 together with subsidiary regulations.

Summary

The Cyber Security Act 2024 (Akta Keselamatan Siber 2024, Act 854) is Malaysia’s primary statutory framework to strengthen the security of digital infrastructure and to manage cyber threats and incidents affecting National Critical Information Infrastructure (NCII). Enacted by Parliament in March–April 2024, the Act received Royal Assent on 18 June 2024 and was published in the Federal Gazette on 26 June 2024. The Prime Minister, as the minister responsible for cybersecurity, designated 26 August 2024 as the date the Act and key subsidiary regulations came into force. The Act establishes institutional arrangements — most notably strengthening the role and functions of the National Cyber Security Agency (NACSA) and creating the National Cybersecurity Committee (Jawatankuasa Keselamatan Siber Negara) — and provides the executive with powers to designate NCII sectors and sector heads and to require NCII entities to comply with security obligations.

Key operational obligations under the Act and the subsidiary regulations (gazetted in August 2024) include mandatory incident reporting (including expedited initial reporting requirements for NCII incidents via the National Cyber Coordination and Command Centre System (NC4)), scheduled risk assessments and audits (annual risk assessment and audit cycles or as directed by the Chief Executive of NACSA), licensing requirements for specified cybersecurity service providers (notably managed security operations and penetration testing services), and mechanisms for compounding offences. The regulations published under the Act are: Cyber Security (Period for Cyber Security Risk Assessment and Audit) Regulations 2024 [P.U.(A) 219/2024]; Cyber Security (Notification of Cybersecurity Incidents) Regulations 2024 [P.U.(A) 220/2024]; Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024 [P.U.(A) 221/2024]; and Cyber Security (Compounding of Offences) Regulations 2024 [P.U.(A) 222/2024]. These subsidiary instruments set operational detail including timelines for assessments/audits, the form and timing of incident notifications, licensing fees and application/renewal procedures (examples in licensing regs show application fees of RM400 for individuals and RM1,000 for companies for certain services), and the compounding regime for prescribed offences.

The Act empowers NACSA and the Chief Executive with investigatory, directive and enforcement powers, including the authority to issue technical directions to NCII heads and entities, require remedial actions and require records, reports or audits. The Act provides for penalties for contraventions; several lower-level infractions can be compounded under the Compounding Regulations, while other breaches are subject to criminal prosecution (fines, custodial sentences or both depending on the offence). The Act also emphasises confidentiality and protections for the NCII entity list (sector heads are listed publicly, but the full list of NCII entities is treated as classified by NACSA) while preserving obligations for rapid notification so that national coordination, mitigation and response can be effected.

Interplay with existing Malaysian laws (Computer Crimes Act 1997; Communications and Multimedia Act 1998; Personal Data Protection Act 2010; and other government cyber policies and circulars) is important: the Cyber Security Act focuses on systemic protection and operational resilience of NCII and regulatory oversight of cybersecurity services, but does not replace general criminal law or data-protection duties. Implementation and enforcement will rely heavily on NACSA, sector heads, and new licensing and audit regimes; operators of critical sectors (defence, finance, healthcare, energy, water, transport and others) should follow the Act’s compliance requirements and subsidiary regulations closely. For official announcements and texts, see government releases and the published subsidiary regulations. (Sources: Prime Minister’s Office announcement and government portals; press reporting and professional legal alerts summarising the Act and regulations.)

Full article

Read full text ↗

Overview

The Cyber Security Act 2024 (Act 854) is a comprehensive statute designed to strengthen Malaysia’s national cyber resilience by creating a clear regulatory framework for the protection, management and oversight of National Critical Information Infrastructure (NCII). The Act sets out institutional roles (notably enhancing the authority of the National Cyber Security Agency, NACSA), prescribes duties for NCII sector heads and NCII entities, and enables subsidiary regulations covering incident notification, risk assessment and audit cycles, licensing of certain cybersecurity service providers, and compounding of offences. The Act received Royal Assent on 18 June 2024, was published in the Federal Gazette on 26 June 2024, and the Prime Minister designated 26 August 2024 as the date the Act and the principal regulations came into force. For official statements and implementation details see the Prime Minister’s Office and relevant government portals such as the Ministry of Digital Affairs and the national information service. Examples of published summaries and implementation notices are available from the Government Information Department and national news portals. See official Department of Information notice and the Ministry of Digital Affairs commentary on implementation.

Definitions

The Act defines core concepts used throughout the regulatory framework, including: "National Critical Information Infrastructure (NCII)" (systems and assets whose disruption would have significant national impact), "NCII sector" and "NCII entity" (sector heads and operative entities within each sector), "cybersecurity incident" (a security event resulting in compromise, damage or unauthorized access to systems), "authorised person" (designated staff within NCII entities responsible for compliance and reporting) and "Chief Executive" (the head of NACSA). The subsidiary regulations expand operational definitions for "risk assessment", "audit", "notification window" and specific licensing categories such as managed Security Operation Centre (SOC) monitoring and penetration testing services. Throughout the Act the language balances operational specificity with delegated regulation so that NACSA and the responsible minister can issue implementing rules and technical directions.

Governance and Institutional Framework

The Act establishes and clarifies institutional responsibilities: the Prime Minister remains the minister responsible for cybersecurity and may appoint sector heads and direct other measures as necessary. NACSA is given strengthened statutory powers and a defined role; the Act details the Chief Executive’s authority to issue directives, require audits, coordinate incident response through the National Cyber Coordination and Command Centre (NC4), and to liaise internationally. The statute also provides for the formation of the National Cybersecurity Committee (Jawatankuasa Keselamatan Siber Negara) to coordinate inter‑agency policy, and imposes duties on NCII sector heads (to ensure compliance by their sector’s entities). For government announcements and background on the institutional set-up, see the Prime Minister’s Office publicity and the Ministry of Digital Affairs materials; implementation guidance was published alongside the regulations in August 2024. See official notices at RTM/News Service and the Ministry briefing digital ministry release.

Key Focus Areas

The Act focuses on: (1) protection of NCII through designation, minimum-security and mandatory remediation directions; (2) rapid incident notification and national coordination via NC4, including an initial notification window and follow-ups; (3) periodic risk assessments and statutory audit cycles with specified minimum frequencies, while permitting NACSA to require more frequent reviews where necessary; (4) licensing and oversight of specified cybersecurity service providers (managed SOC and penetration testing), with application and renewal fees and fit-and-proper requirements; (5) enforcement mechanisms including criminal sanctions and an administrative compounding regime designed to resolve certain lower-level contraventions; and (6) obligations on sector heads and authorised persons to ensure compliance. The subsidiary regulations (Period for Cyber Security Risk Assessment and Audit; Notification of Cybersecurity Incidents; Licensing of Cyber Security Service Provider; Compounding of Offences) provide the operational detail for these focus areas and were published in the Federal Gazette in August 2024; see legal practice briefings summarising the regulatory schedule (for example, professional analyses summarise the content and immediate compliance impacts). For practical guidance and Q&A see commentary by legal and industry advisors such as Baker McKenzie InsightPlus and press coverage in national outlets.

Implementation Framework

Implementation follows a mixed approach: (a) primary obligations are set in statute; (b) the minister and NACSA issue regulations, technical standards and directives to operationalize those obligations; (c) NCII sectors and entities must implement governance, technical controls, incident detection and reporting processes consistent with the regulations; and (d) cybersecurity service providers performing regulated services must obtain licences under the licensing regulations and comply with continuing requirements. The Compounding Regulations provide a mechanism for administrative settlement of designated offences; licensing regulations set fees and application/renewal criteria (examples of fees are included in the licensing instrument). NACSA is expected to publish guidance and sectoral notices to aid compliance and to coordinate capacity-building with other ministries and agencies; see government briefing notes and sectoral guidance from the Ministry of Digital Affairs and NACSA outreach programs.

Monitoring and Evaluation

The Act provides for ongoing monitoring through periodic statutory risk assessments, audits and reporting obligations. NACSA and sector heads will monitor compliance using audits, inspection powers and mandatory incident notifications routed through NC4. The regulations specify minimum assessment/audit frequency (annual risk assessments; audits at least once every two years or more frequently where directed) and reporting formats. Monitoring also includes post-incident reviews and follow-up directives to ensure lessons learned feed into continuous improvement. The compounding and enforcement regime will be used to measure compliance levels and deter non-compliance while preserving prosecutorial options for serious breaches; independent or inter-agency evaluations are expected over time to measure outcomes and refine thresholds and technical standards.

Penalties, Liability, and Appeals

The Act prescribes criminal offences for defined breaches and empowers administrative compounding for certain contraventions under the Compounding Regulations. Penalties may include financial fines and, depending on the offence, custodial sentences where criminal liability attaches; compounding provides an administrative settlement alternative for specified infractions. The licensing regime creates grounds for suspension or revocation of licences for non-compliance. The Act and regulations preserve rights to judicial review and appeals where appropriate (for example, decisions by the minister or NACSA that affect licences or designations). Specific compounding schedules and penalty tables were published with the regulations; see the Compounding Regulations for the listed offences and amounts and the Licensing Regulations for licence sanctions. (See government gazette notices and the reproduced regulation texts for details.)

Relationship to Other Instruments

The Cyber Security Act is designed to operate alongside existing Malaysian laws (including the Computer Crimes Act 1997, the Communications and Multimedia Act 1998, and data protection laws) and policy instruments (national cyber strategies and public sector cyber circulars). It does not replace general criminal law or data-protection obligations but creates a sectoral, resilience-focused overlay for NCII and a regulatory path for cybersecurity services. Agencies responsible for communications, critical infrastructure, data protection and national security coordinate implementation and enforcement. Many public-sector circulars and guidelines cross-reference Act 854, and sectoral policies (e.g., for finance, health, energy) are being updated to reflect NCII obligations. See cross-references in public sector materials and legal commentaries summarising overlaps and interactions.

International Alignment

The Act and its regulations are framed to align Malaysia’s national practice with international good practice for critical infrastructure protection, incident reporting, vulnerability management and cooperation with foreign CERTs/CSIRTs. NACSA and the PMO emphasise international cooperation and information sharing; licensing and technical directions are intended to be technology and standard‑neutral while allowing alignment with recognised cybersecurity frameworks. The law’s structure is consistent with approaches seen in other jurisdictions that combine designation of critical infrastructure, mandatory incident reporting and regulated cybersecurity service markets; comparative legal analyses and international practitioner guidance will inform Malaysia’s further rule‑making and cross-border cooperation mechanisms.

Implementation Timeline

EventDate
Passed Dewan Rakyat2024-03-27
Passed Dewan Negara2024-04-03
Royal Assent2024-06-18
Gazetted (Act)2024-06-26
Subsidiary regulations published (Federal Gazette)2024-08-22
Act and regulations brought into force2024-08-26

Compliance Checklist

RequirementEntityAction
NCII designation and obligationsDesignated NCII entities & sector headsConfirm designation; implement governance and technical controls; appoint authorised persons
Incident notificationNCII entities / authorised personsEstablish detection & reporting procedures; notify NC4 within regulated windows
Risk assessment & auditNCII entitiesConduct annual risk assessments and regular audits per the Regulation
Licensing of service providersManaged SOC/pen testing vendorsApply for and maintain licence; comply with licence conditions
Compounding & penaltiesAll regulated entitiesMaintain records and remediation capability to avoid sanctions

Sources and References

SourceType
AKTA KESELAMATAN SIBER 2024 (Akta 854) mula berkuat kuasa pada 26 Ogos 2024Primary Source
Ministry of Digital / official implementation statementPrimary Source
Baker McKenzie InsightPlus summarySecondary / Practitioner Analysis
The Star coverage on Act 854 (gazetting & regulations)Press
Reproduction of P.U.(A)219/2024 Period for Risk Assessment and Audit (Federal Gazette reproduction)Primary Source (regulation text reproduced)

© Regulations.AI · updated on 13-Jun-2026