Call us now: (603) 6280 6835
Reliable International Certification Body
  • Home
  • About
    • Quality Policy and Certification Policy
    • ISO Certification Process
    • Certificate Search
  • Standard
    • ISO 9001 Certification
    • ISO 22000 Certification
    • ISO 14001 Certification
    • ISO 45001 Certification
    • ISO 27001 Certification
    • ISO 37001 Certification
    • ISO 41001 Certification
    • HACCP Certification
    • GMP Certification
    • Cyber Security Act 2024 Compliance Assessment & Audit
  • News & Resources
  • FAQ
  • Contact Us
  • Get a Quote
  • Search
  • Menu

Cyber Security Act 2024 (Act 854) Compliance Audit in Malaysia

Assess your organization’s readiness against applicable Cyber Security Act 2024 requirements and identify gaps requiring attention.

Introduction to the Cyber Security Act 2024 (Act 854)

The Cyber Security Act 2024 (Act 854) is Malaysia’s landmark cybersecurity legislation designed to enhance national cyber resilience, protect critical digital infrastructure, and establish a comprehensive regulatory framework for cybersecurity governance. The Act came into force on 26 August 2024 and is administered by the National Cyber Security Agency (NACSA).

The Cyber Security Act 2024 (Act 854) establishes a legal and governance framework to safeguard the nation’s digital ecosystem, particularly the National Critical Information Infrastructure (NCII), against emerging cyber threats and incidents. It also outlines the roles and responsibilities of NCII Sector Leads, NCII Entities, and cybersecurity service providers.

What is Cyber Security Act (CSA) 2024 compliance Audit?

A Cyber Security Act 2024 compliance audit is an assessment of applicable cybersecurity requirements under Malaysia’s Cyber Security Act 2024 (Act 854), including relevant requirements for National Critical Information Infrastructure (NCII) entities. For applicable NCII entities, the Act and related regulations establish requirements relating to cybersecurity risk assessment, cybersecurity audits, incident management and other cybersecurity obligations. The specific requirements depend on the organization’s designation, sector, infrastructure and applicable NACSA directions.

Objectives of Cyber Security Act (CSA) 2024:

  • Strengthen National Cybersecurity Governance
  • Protect National Critical Information Infrastructure (NCII)
  • Enhance Cyber Incident Response & Crisis Management
  • Regulate Cybersecurity Service Provider
  • Promote a Secure and Trusted Digital Environment

Who Is Subject to the Cyber Security Act 2024?

  • NCII Sector Leads – Appointed sector regulators are responsible for overseeing cybersecurity compliance and coordination within their respective critical sectors
  • NCII Entities – Organizations designated as National Critical Information Infrastructure (NCII) entities must comply with the Act’s requirements, including cybersecurity risk assessments, audits, incident notifications, and implementation of prescribed cybersecurity measures.
  • Cybersecurity Service Providers – Organizations providing regulated cybersecurity services must obtain the necessary licences and comply with NACSA’s licensing requirements

What Is National Critical Information Infrastructure (NCII)?

National Critical Information Infrastructure (NCII) refers to critical systems, information assets, networks, functions, processes, facilities and services within an ICT environment that are important to Malaysia, where disruption or destruction may affect national defence and security, economic stability, government operations, public health and safety, national image, or individual privacy.

Whether a particular organization or infrastructure falls within the NCII framework depends on its designation and the applicable sector arrangements. Organizations should not assume that operating in an NCII sector automatically means that every entity in that sector is an NCII entity.

Any disruption, compromise, or destruction of these systems could significantly impact:

  • National defence and security
  • National economic stability
  • Government operations
  • Public health and safety
  • National image and confidence

11 National Critical Information Infrastructure (NCII) Sectors

NCII Sectors
Enquiry for Cyber Security Act (CSA) 2024 compliance Audit

How Can NCII Entities Prepare for Act 854 Compliance?

Step 1:

Determine Applicable Obligations Understand the organization’s designation, sector, NCII scope and applicable requirements.

Step 2:

Conduct Cybersecurity Risk Assessment Identify relevant assets, threats, vulnerabilities, risks and treatment measures. Conduct a cybersecurity risk assessment at least once a year

Step 3:

Implement Applicable Cybersecurity Controls . Establish and maintain controls according to applicable requirements, sector expectations and the organization’s risk profile.

Step 4:

Establish Incident Management. Develop procedures for detecting, responding to and reporting cybersecurity incidents in accordance with applicable requirements.

Step 5:

Maintain Documentation and Evidence. Maintain relevant:
• policies
• procedures
• asset inventories
• risk assessments
• risk treatment records
• incident records
• audit records
• security monitoring evidence
• training records

Step 6:

Conduct Cyber Security Audit. Arrange the applicable cybersecurity audit in accordance with Act 854 and relevant NACSA requirements. conduct an audit at least once every two years, or more frequently if directed by the Chief Executive

Step 7:

Address Findings. Evaluate findings and implement appropriate corrective actions.

Step 8:

Continue Improvement . Review risks and cybersecurity controls regularly.

Why choose Pearl Certification?

  • Comprehensive assessment against the Cyber Security Act 2024 (Act 854) requirements
  • Identification of compliance gaps and practical recommendations for improvement
  • Our assessment is led by an experienced information security professional with more than 20 years of experience in information security governance, risk management and compliance.

Frequently Asked Questions

Does the Cyber Security Act 2024 apply to all companies in Malaysia?

No. The Cyber Security Act 2024 (Act 854) does not mean that every company in Malaysia has the same compliance obligations. The Act establishes a regulatory framework covering areas such as National Critical Information Infrastructure (NCII), NCII sector leads and entities, cybersecurity threats and incidents affecting NCII, and certain cybersecurity service providers.

For an individual organization, applicability depends on factors such as its role, sector, infrastructure and whether it falls within the relevant NCII framework. Malaysia currently identifies 11 NCII sectors, including banking and finance, transportation, healthcare, energy, government, information and communications, and other critical sectors.

How often is a cybersecurity risk assessment required?

For an NCII entity that owns or operates NCII, a cybersecurity risk assessment is required at least once every year under the Cyber Security (Period for Cyber Security Risk Assessment and Audit) Regulations 2024.

The assessment is intended to evaluate cybersecurity risks associated with the NCII and identify areas where additional risk treatment or security measures may be required.

Organizations should also consider any applicable Code of Practice, directive or specific direction issued by the NACSA Chief Executive when determining their assessment approach and scope.

How often is an NCII cybersecurity audit required?

An applicable NCII entity must undergo a cybersecurity audit at least once every two years, unless a higher frequency is directed by the Chief Executive of NACSA. It is important to distinguish the annual risk assessment from the biennial cybersecurity audit. They are separate compliance activities.

What does a Cyber Security Act 2024 audit cover?

A Cyber Security Act 2024 audit assesses whether an applicable NCII entity has established and implemented the cybersecurity arrangements required under Act 854 and the applicable regulations, Code of Practice and NACSA directives.

Depending on the organization’s NCII scope and applicable requirements, an assessment may examine areas such as:

  • cybersecurity governance and responsibilities;
  • identification and management of NCII;
  • cybersecurity risk management;
  • policies, procedures and documented controls;
  • technical and operational security measures;
  • incident management and reporting arrangements;
  • access and information security controls;
  • business continuity and recovery;
  • third-party and supply-chain risks;
  • cybersecurity preparedness and exercises; and
  • evidence demonstrating implementation and ongoing management.

The exact audit scope should not be assumed to be identical for every organization. Section 22 of Act 854 requires the audit to determine the NCII entity’s compliance with the Act, and the audit is to be carried out by an auditor approved by the Chief Executive.

This distinction is particularly important when preparing an organization for a statutory NCII audit.

Is ISO 27001 enough to comply with Act 854?

No. ISO/IEC 27001 certification should not be treated as automatic compliance with Cyber Security Act 2024 (Act 854).

ISO/IEC 27001 provides a structured framework for managing information security through an Information Security Management System (ISMS). An established ISMS can provide useful foundations for areas such as risk management, governance, policies, controls, monitoring and continual improvement.

However, Act 854 is a Malaysian legal framework with its own requirements. Applicable NCII entities may have additional obligations arising from the Act, regulations, Codes of Practice and NACSA directives. NACSA separately publishes the Act and its related regulations and directives.

Therefore, an organization should map its existing ISO 27001 controls and evidence against the specific Act 854 requirements applicable to its NCII scope, rather than assume that an ISO 27001 certificate is sufficient.

CONTACT US TODAY for Cyber Security Act 2024 Compliance Readiness Assessment/Audit

Our assessment helps organizations review their current cybersecurity governance, controls and documentation against applicable Act 854 requirements and identify areas requiring further action. Where a statutory audit under Act 854 is required, the organization should ensure that the appointed auditor meets the applicable NACSA requirements and approval arrangements.

1 + 0 = ?

Related Posts:

ISO 27001 information security management areas for data centres

ISO 27001 certification for data centres

August 18, 2026
Read more
https://www.pearl-certification.com/wp-content/uploads/2026/08/developer-identifying-server-issues-scaled.jpg 1440 2560 aisyah https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png aisyah2026-08-18 07:07:082026-08-20 01:39:19ISO 27001 certification for data centres
ISO 27001 Certification for SMEs:

ISO 27001 Certification for SMEs: Secure Your Business with Confidence

August 18, 2026
Read more
https://www.pearl-certification.com/wp-content/uploads/2026/08/standard-quality-control-collage-concept-scaled.jpg 1440 2560 aisyah https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png aisyah2026-08-18 02:47:422026-08-20 01:40:50ISO 27001 Certification for SMEs: Secure Your Business with Confidence
ISO 27001 - software companies

ISO 27001 certification for software companies

August 5, 2026
Read more
https://www.pearl-certification.com/wp-content/uploads/2026/08/person-working-html-computer-scaled.jpg 1707 2560 aisyah https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png aisyah2026-08-05 01:51:512026-08-20 01:42:50ISO 27001 certification for software companies

Pearl Certification Sdn Bhd (1311494-U)

ZP-02-11, Zest Point, Lebuhraya Bukit Jalil, 47180 Puchong, Selangor, Malaysia.

Email : info@pearl-certification.com

Tel : +603-6280 6835

Pearl ISO certification body DSM

Standards

  • ISO 9001 – Quality Management System
  • ISO 22000 – Food Safety Management System
  • ISO 45001 – Occupational Health and Safety Management System
  • ISO 14001 – Environmental Management System
  • ISO 27001 – Information Security Management System
  • ISO 37001 Certification Malaysia – Anti-Bribery Management System
  • ISO 41001 Certification Malaysia – Facility Management System
  • GMP – Good Manufacturing Practices
  • HACCP – Hazard Analysis Critical Control Point
  • Cyber Security Act 2024 Compliance Assessment & Audit
© Copyright - Pearl Certification Sdn Bhd | Privacy Policy
  • Facebook
  • Linkedin
  • Youtube
Scroll to top

This is a notification that can be used for cookie consent or other important news. It also got a modal window now! Click "learn more" to see it!

OKLearn More

Cookie and Privacy Settings

How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, you cannot refuse them without impacting how our site functions. You can block or delete them by changing your browser settings and force blocking all cookies on this website.

Other external services

We also use different external services like Google Webfonts, Google Maps and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Click to Chat
Click to Chat
Click to Chat
Click to Chat
Click to Chat