https://www.pearl-certification.com/wp-content/uploads/2026/08/developer-identifying-server-issues-scaled.jpg
1440
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-18 07:07:082026-08-20 01:39:19ISO 27001 certification for data centresCyber Security Act 2024 (Act 854) Compliance Audit in Malaysia
Assess your organization’s readiness against applicable Cyber Security Act 2024 requirements and identify gaps requiring attention.
Introduction to the Cyber Security Act 2024 (Act 854)
The Cyber Security Act 2024 (Act 854) is Malaysia’s landmark cybersecurity legislation designed to enhance national cyber resilience, protect critical digital infrastructure, and establish a comprehensive regulatory framework for cybersecurity governance. The Act came into force on 26 August 2024 and is administered by the National Cyber Security Agency (NACSA).
The Cyber Security Act 2024 (Act 854) establishes a legal and governance framework to safeguard the nation’s digital ecosystem, particularly the National Critical Information Infrastructure (NCII), against emerging cyber threats and incidents. It also outlines the roles and responsibilities of NCII Sector Leads, NCII Entities, and cybersecurity service providers.
What is Cyber Security Act (CSA) 2024 compliance Audit?
A Cyber Security Act 2024 compliance audit is an assessment of applicable cybersecurity requirements under Malaysia’s Cyber Security Act 2024 (Act 854), including relevant requirements for National Critical Information Infrastructure (NCII) entities. For applicable NCII entities, the Act and related regulations establish requirements relating to cybersecurity risk assessment, cybersecurity audits, incident management and other cybersecurity obligations. The specific requirements depend on the organization’s designation, sector, infrastructure and applicable NACSA directions.
Objectives of Cyber Security Act (CSA) 2024:
- Strengthen National Cybersecurity Governance
- Protect National Critical Information Infrastructure (NCII)
- Enhance Cyber Incident Response & Crisis Management
- Regulate Cybersecurity Service Provider
- Promote a Secure and Trusted Digital Environment
Who Is Subject to the Cyber Security Act 2024?
- NCII Sector Leads – Appointed sector regulators are responsible for overseeing cybersecurity compliance and coordination within their respective critical sectors
- NCII Entities – Organizations designated as National Critical Information Infrastructure (NCII) entities must comply with the Act’s requirements, including cybersecurity risk assessments, audits, incident notifications, and implementation of prescribed cybersecurity measures.
- Cybersecurity Service Providers – Organizations providing regulated cybersecurity services must obtain the necessary licences and comply with NACSA’s licensing requirements
What Is National Critical Information Infrastructure (NCII)?
National Critical Information Infrastructure (NCII) refers to critical systems, information assets, networks, functions, processes, facilities and services within an ICT environment that are important to Malaysia, where disruption or destruction may affect national defence and security, economic stability, government operations, public health and safety, national image, or individual privacy.
Whether a particular organization or infrastructure falls within the NCII framework depends on its designation and the applicable sector arrangements. Organizations should not assume that operating in an NCII sector automatically means that every entity in that sector is an NCII entity.
Any disruption, compromise, or destruction of these systems could significantly impact:
- National defence and security
- National economic stability
- Government operations
- Public health and safety
- National image and confidence










