Last reviewed: 3 October 2026
The short answer: the Act's main duties apply to designated National Critical Information Infrastructure (NCII) entities. Most small businesses are not one. But two groups of SMEs can still be affected: suppliers to NCII entities, and businesses that sell certain cybersecurity services.
The Cyber Security Act 2024 (Act 854) has been in force since 26 August 2024. It sets up duties for entities that run critical infrastructure and creates a licensing regime for some cybersecurity service providers.
NCII entities operate systems whose disruption would seriously harm the nation. They come from designated sectors, for example banking and finance, energy, healthcare, transport, water, and information and communications. The authorities designate entities and notify them. You are not an NCII entity just because you work in one of these sectors, so if you are unsure, ask your sector lead or NACSA.
Failing to report an incident or to implement the code of practice can bring fines of up to RM500,000 and/or up to 10 years in prison.
If you supply an NCII entity or a regulated institution (a bank, for example), expect security questionnaires and contract clauses that pass their duties down to you, including fast incident reporting.
If you offer managed security operation centre monitoring or penetration testing, or advertise yourself as a provider, you need a licence from NACSA. Services to a related company, and services for systems located outside Malaysia, are exempt.
General information, not legal advice. Reviewed 3 October 2026 against published legal summaries. Check the primary sources from the Department of Personal Data Protection and the National Cyber Security Agency (NACSA), and take advice from a qualified adviser, before relying on this.