← All insights Compliance

Malaysia's Cyber Security Act 2024 in 2026: The NACSA Licence Your IT Vendor Must Hold, the Intra-Group Exemption That Is Narrower Than It Looks, the Six-Hour Incident Clock for NCII, and Why an Offshore SOC Is Already Inside Act 854

·14 min read

Malaysia's Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into operation on 26 August 2024, together with four sets of subsidiary regulations. Two years on, most foreign-owned companies in Malaysia still treat it as somebody else's problem — a law for banks, telcos and utilities. It is not. Act 854 reaches ordinary companies through two completely separate doors. The first is procurement: if you buy penetration testing or managed SOC monitoring for systems located in Malaysia, your supplier must hold a NACSA licence, and the offence of providing that service unlicensed carries a fine of up to RM500,000 and ten years' imprisonment. The second is designation: if your operations are designated national critical information infrastructure, a six-hour incident clock and a biennial audit obligation attach to your company directly. This guide separates the two, reads the exemptions as they are actually drafted rather than as they are usually summarised, and sets out what a foreign-owned Sdn Bhd should do about both.

One Act, two unrelated regimes

Act 854 is best understood as two statutes bound together. Part VI creates a licensing regime for cyber security service providers — it applies to whoever sells the service, anywhere, if the system is in Malaysia. Parts IV, V and VII create an NCII entity regime — duties to implement a code of practice, conduct risk assessments and audits, notify incidents, and participate in national exercises. A company can be caught by one, both, or neither, and the analysis is different in each case.

Section 3 sets the reach, and it is deliberately long: the Act has effect outside as well as within Malaysia in relation to any person whatever his nationality or citizenship, and an offence committed abroad may be dealt with as if committed in Malaysia. For NCII offences, section 3(2) requires that the national critical information infrastructure be wholly or partly in Malaysia.

Operators at a bank of monitors in a modern control room facing a large display wall
Managed security operation centre monitoring is one of only two services that currently require a NACSA licence. The other is penetration testing — and both definitions are wider than their names suggest.

The licence covers exactly two services — and the definitions are broad

Section 27(1) prohibits any person from providing any cyber security service, or advertising or in any way holding himself out as a provider of a cyber security service, unless he holds a licence issued under Part VI. Section 27(2) lets the Minister prescribe which services need a licence, and to date the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024 [P.U. (A) 221] prescribe two.

Managed security operation centre monitoring service (regulation 4) means a service for monitoring the level of cyber security of another person's computer or computer system by acquiring, identifying or scanning information stored in, processed by or transmitted through it, for the purpose of identifying or detecting cyber security threats — or determining the measures necessary to respond to or recover from a cyber security incident and prevent recurrence. Note the second limb: incident response and recovery advice sits inside the definition even without continuous monitoring.

Penetration testing service (regulation 5) means a service for assessing, testing or evaluating the cyber security level of a computer or computer system by searching for vulnerabilities and compromising its defences. The regulation then expressly includes four activities: demonstrating how vulnerabilities may be exploited; testing an organisation's ability to identify and respond to incidents through simulated penetration attempts; identifying and measuring vulnerabilities and preparing mitigation procedures; and using social engineering to assess an organisation's vulnerability. That last item is the one people miss — a phishing simulation campaign is a licensable penetration testing service.

What is not licensable — yet. Firewall installation, SIEM software licensing, security awareness training, ISO 27001 consulting, forensic investigation and general IT support are not among the two prescribed services. That is a function of the current Regulations, not of the Act: section 27(2) lets the Minister prescribe more at any time. Treat the current list as a snapshot, not a settled boundary.

Who has to hold it — including vendors who never set foot in Malaysia

The prohibition attaches to the provider, not to the buyer. But the buyer's exposure is commercial and reputational, and in a regulated group it is also a governance failure. Three points decide who is caught.

First, location of the system, not location of the provider. Regulation 2(2)(c) disapplies the Regulations where the computer or computer system in respect of which the service is provided is located outside Malaysia. Read with section 3, the corollary is uncomfortable for many groups: a SOC team sitting in Shenzhen, Bangalore or Singapore that monitors a Malaysian factory's systems is providing a licensable service in Malaysia. Physical presence is irrelevant.

Second, advertising counts. Section 27(1)(b) prohibits advertising or in any way holding yourself out as a provider. A regional website listing "penetration testing — Malaysia" is caught even before the first engagement.

Third, individuals are inside the regime. The Schedule to the Regulations prices licences separately for an individual and for a company, limited liability partnership, firm, society or other body of persons — so a freelance tester is licensable in his own right.

The intra-group exemption, read precisely

This is where secondary summaries are least reliable. There are two exemption provisions and they do different work.

Section 27(3) of the Act provides that Part VI does not apply where the cyber security service is provided by a company to its related company, and section 27(4) imports the meaning of "related company" from the Companies Act 2016. Regulation 2(2)(b) then disapplies the Regulations where the service is provided by a person, other than a company, to its related company — extending the same relief to non-corporate providers. Regulation 2(2)(a) exempts services provided by a Government Entity.

So the intra-group carve-out is real. Its limit is the definition. Under the Companies Act 2016, corporations are related where one is the holding company of the other, one is a subsidiary of the other, or both are subsidiaries of the same holding company — a test built on control, not on commercial closeness.

ArrangementLicence required?Why
Group IT company (Malaysia) monitors its wholly-owned Malaysian sister company's systemsNoCompany to related company — s.27(3)
Parent's security team abroad monitors the Malaysian subsidiary's systemsNoCompany to related company; the exemption is not territorial
Group IT company monitors a 49% associate or a 50/50 joint ventureYesNot a subsidiary — not a "related company" under CA 2016
Group IT company sells the same monitoring to third-party customersYesThe exemption covers related companies only, not the shared-services business model
External vendor runs a phishing simulation on your Malaysian staffYesSocial engineering is expressly within the penetration testing definition
Vendor tests a system hosted entirely outside MalaysiaNoRegulation 2(2)(c)

The joint-venture line is the one that bites Chinese groups most often, because Malaysian market entry so frequently runs through a 49% or 51/49 structure imposed by a licensing regime — as it does in logistics and in several other sectors. A group shared-services centre that treats "everything in the group chart" as exempt will be wrong about precisely those entities.

Fees, validity and the renewal trap

The Schedule to P.U. (A) 221 prices the licence per service, per year:

ServiceIndividualCompany, LLP, firm, society or other body of persons
Managed SOC monitoring — applicationRM400RM1,000
Penetration testing — applicationRM400RM1,000
Managed SOC monitoring — renewalRM400RM1,000
Penetration testing — renewalRM400RM1,000

A company offering both services therefore pays RM2,000 per year in fees alone, and the fee is payable on every application submitted and is not refundable — including an application that is refused. Applications are made electronically to the Chief Executive of NACSA.

Section 28 sets the qualifications: an applicant must fulfil prerequisite requirements determined by the Chief Executive and must not have been convicted of an offence involving fraud, dishonesty or moral turpitude. Section 29(4) provides that a licence is valid for the period specified in the licence — the Act fixes no statutory term, so read the instrument.

Then the trap. Section 30(1) requires a renewal application at least thirty days before expiry. Regulation 7(2) provides that any renewal application received after the licence expires is treated as a new application. There is no grace period and no back-dating: a licensee that lets the date pass is unlicensed from expiry, and section 27(1) does not care that a renewal is pending. For a service provider mid-engagement, that is not an administrative slip — it is the RM500,000 offence.

Monitoring dashboard displaying green telemetry charts and system readouts on a dark screen
Section 32 requires a licensee to log who engaged it, who performed the work, when, and what type of service was provided — and to keep those records for not less than six years.

Records: six years, five fields, criminal on failure

Section 32(1) requires a licensee, on each occasion it is engaged, to keep and maintain: the name and address of the person engaging it; the name of the person actually providing the service on its behalf; the date and time the service was provided; details of the type of service; and such other particulars as the Chief Executive determines. Under section 32(2) those records must be kept in the manner determined by the Chief Executive, retained for not less than six years from the date the service was provided, and produced to the Chief Executive on demand at any time.

Failure is an offence under section 32(3) carrying a fine of up to RM100,000 or two years' imprisonment or both. For a buyer, this provision is quietly useful: a vendor that cannot describe its record-keeping process against these five fields is telling you something about whether it is really licensed and really compliant.

The penalty map

ProvisionConductMaximum penalty
s.27(5)Providing, advertising or holding out as providing a licensable cyber security service without a licenceRM500,000 and/or 10 years
s.31(3)Contravening a condition imposed on the licenceRM100,000 and/or 2 years
s.32(3)Failing to keep, maintain, retain or produce recordsRM100,000 and/or 2 years
s.34(2)Transferring or assigning a licence (transfer is permitted only with the Chief Executive's approval)RM200,000 and/or 3 years
reg. 8, P.U. (A) 221False or misleading statement, or wilful omission, in a licence applicationRM50,000 and/or 2 years
s.21(5)NCII entity failing to implement the code of practiceRM500,000 and/or 10 years
s.23(2)NCII entity failing to notify a cyber security incident as prescribedRM500,000 and/or 10 years
s.20(6)NCII entity failing to provide NCII information or notify material changeRM100,000 and/or 2 years

Two structural provisions sit behind that table. Section 57 requires the written consent of the Public Prosecutor before any prosecution under the Act. And section 58 provides that where the offender is a company, LLP, firm, society or other body of persons, a person who at the time was a director, compliance officer, partner, manager, secretary or other similar officer — or who was in any manner responsible for or assisting in the management of its affairs — may be charged jointly or severally and, if the body is found guilty, is deemed guilty and liable to the same punishment, unless he proves the offence was committed without his knowledge, or without his consent or connivance and that he took all reasonable precautions. That is the same deeming architecture foreign directors already face under section 17A of the MACC Act, and it should be read the same way: a defence you have to build in advance, not one you can assert afterwards.

The other regime: NCII entities

The Schedule to Act 854 lists eleven national critical information infrastructure sectors: Government; Banking and finance; Transportation; Defence and national security; Information, communication and digital; Healthcare services; Water, sewerage and waste management; Energy; Agriculture and plantation; Trade, industry and economy; Science, technology and innovation. Section 62 lets the Minister amend that Schedule by order in the Gazette.

Being in a listed sector does not by itself make a company an NCII entity. Designation is an act — made by the relevant NCII sector lead, or by the Chief Executive in respect of a sector lead that itself owns or operates NCII. A private company only becomes subject to Parts IV and VII once designated. "Agriculture and plantation" and "Trade, industry and economy" are broad enough that foreign-owned manufacturers and agribusinesses should not assume they are structurally outside the scope.

Rows of server racks in a data centre aisle
Designation is an act, not a status. A company in a listed sector becomes an NCII entity only when the sector lead — or, for a sector lead itself, the Chief Executive — designates it.

Once designated, the duties are concrete:

DutyTimingSource
Provide NCII information on request; report newly acquired NCII unpromptedOn request / without waiting for a requests.20(1)–(2)
Notify a material change to design, configuration, security or operationWithin 30 days of the change being completeds.20(3)
Implement the sector code of practice (or prove an equal-or-better alternative)Ongoings.21
Conduct a cyber security risk assessmentAt least once a years.22(1)(a) and the Risk Assessment and Audit Regulations 2024
Cause an audit by an auditor approved by the Chief ExecutiveAt least once every two years, or more often if directeds.22(1)(b) and the same Regulations
Submit the risk assessment report or audit reportWithin 30 days of completions.22(2)
Notify a cyber security incident that has or might have occurredImmediate first notification; further particulars within 6 hours to the NC4S; supplementary information within 14 dayss.23 and the Notification of Cyber Security Incident Regulations 2024
Comply with directions in a national cyber security exerciseAs directeds.24
Six hours is an operational design constraint, not a policy statement. The clock runs from when the incident comes to the entity's knowledge, and the six-hour submission must already contain the incident type and description, its severity, and the method of discovery. No organisation produces that under pressure without a named authorised person, standing access to the NC4S channel, and a pre-agreed severity rubric. If your incident response plan says "notify the regulator as soon as practicable", it does not comply.

What a foreign-owned company should actually do

Fix the procurement clause first. Before the next penetration test or SOC contract, require the vendor to warrant that it holds a current NACSA licence for the specific prescribed service, to state its expiry date, to notify you immediately of suspension or revocation, and to comply with section 32 record-keeping. This costs nothing and moves the risk to the party that can control it.

Re-examine your own group arrangements. If a shared-services entity performs monitoring or testing for anything other than a holding company, subsidiary or fellow subsidiary — associates, joint ventures, franchisees, portfolio companies — that activity needs a licence. If it also sells to third parties, the exemption does not apply to that business line at all.

Map the offshore SOC. Where the monitoring team sits abroad but the monitored systems are in Malaysia, the arrangement is inside the regime. Confirm whether the intra-group exemption covers it; if the monitored entity is not a related company, license it or restructure the contract.

Decide whether designation is plausible. If you operate in energy, water, transportation, healthcare, digital infrastructure, agriculture and plantation, or trade and industry at any meaningful scale, build the annual risk assessment and the six-hour notification capability before a designation letter forces the timetable.

Do not conflate this with data protection. Act 854 protects systems; the Personal Data Protection Act protects personal data, with its own breach notification duty and its own regulator. A single incident can trigger both, on different clocks, to different authorities. Your incident plan has to run both tracks in parallel, and the directors' exposure under section 58 sits on top of the duties described in our guide to directors' duties and liabilities.

Digital padlock overlaid on network circuitry, representing information security controls
Act 854 protects systems; the PDPA protects personal data. One incident can start both clocks at once, running to different regulators on different deadlines.

The honest summary

For the large majority of foreign-owned Sdn Bhds, Act 854 is a vendor management problem and nothing more: two prescribed services, a licence you can verify, a clause you can insert, and an exemption that covers ordinary parent-and-subsidiary arrangements. The compliance cost of getting it right is close to zero.

The exposure concentrates in three places. Groups that run shared cyber security services across structures that are not strictly parent-subsidiary. Service providers themselves — including offshore teams that have never considered themselves regulated in Malaysia and are already inside section 27 with a ten-year offence attached. And companies whose sector makes designation a live possibility, for whom a six-hour clock and a NACSA-approved biennial audit have to be engineered into operations well before the letter arrives.

ONEKEY BIZ helps foreign-owned companies in Malaysia map obligations like these across the compliance stack — corporate, tax, employment, data and now cyber — and build the vendor terms and internal processes that make them routine rather than urgent. Talk to us, or start with a compliance consultation.

Frequently asked questions

Which cyber security services actually need a NACSA licence?

Only two are currently prescribed by the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024: managed security operation centre monitoring service and penetration testing service. But read the definitions rather than the labels. Managed SOC monitoring includes not only monitoring for threats but also determining the measures necessary to respond to or recover from an incident — so incident response advice is inside it. Penetration testing expressly includes using social engineering to assess vulnerability, which makes a phishing simulation campaign a licensable service. Firewall deployment, SIEM licensing, awareness training, ISO 27001 consulting and general IT support are not prescribed — but section 27(2) lets the Minister add services at any time, so treat the list as a snapshot.

Our group's IT company provides monitoring to all group entities. Are we exempt?

Partly — and the gap is where the risk lives. Section 27(3) exempts a cyber security service provided by a company to its related company, and section 27(4) takes the meaning of "related company" from the Companies Act 2016: holding company, subsidiary, or fellow subsidiary of the same holding company. That is a control test. A 49% associate, a 50/50 joint venture, a franchisee or a portfolio company is not a related company, so monitoring or testing those entities needs a licence. If the same shared-services entity also sells to third parties, the exemption does not apply to that line of business at all. This matters especially in Malaysia, where market entry is often structured as a 51/49 joint venture because a licensing regime requires it.

Our SOC team sits outside Malaysia. Does Act 854 still apply?

Yes, if the systems being monitored are in Malaysia. Section 3 gives the Act effect outside as well as within Malaysia in relation to any person whatever his nationality, and an offence committed abroad may be dealt with as if committed in Malaysia. The Regulations approach it from the other end: regulation 2(2)(c) disapplies them only where the computer or computer system in respect of which the service is provided is located outside Malaysia. So the test is where the monitored system sits, not where the team sits. An offshore SOC watching a Malaysian factory's systems is providing a licensable service — unless the monitored entity is a related company within section 27(3). Section 27(1)(b) also prohibits merely advertising or holding yourself out as a provider, which can be triggered by a regional website before any engagement begins.

What exactly is the six-hour incident clock, and who does it apply to?

It applies to designated NCII entities, not to every company. Section 23 requires an NCII entity to notify the Chief Executive of NACSA and its NCII sector lead when it comes to its knowledge that a cyber security incident has or might have occurred. Under the Notification of Cyber Security Incident Regulations 2024 the sequence is: an immediate first notification by the entity's authorised person; within six hours of the incident coming to the entity's knowledge, further particulars to the NC4S including the type and description of the incident, its severity and the method of discovery; and within fourteen days, supplementary information such as the affected NCII, the estimated number of hosts affected, particulars of the threat actor, impact and actions taken. Failure to notify as prescribed is an offence under section 23(2) carrying up to RM500,000 or ten years' imprisonment or both. Six hours is only achievable with a named authorised person, standing NC4S access and a pre-agreed severity rubric.

This article is general information only, not legal, tax or immigration advice. Policies, thresholds and official fees are set by the relevant Malaysian authorities and may change. Talk to our consultants about your specific situation.

How ONEKEY BIZ can help

Need help navigating this in Malaysia?

Our Mandarin- and English-speaking consultants handle the whole process — fixed quotes, zero hidden fees.