External Attack Surface Management in Malaysia: Act 854, NACSA and the Licensing Trap
Malaysia has the most prescriptive attack surface requirement in the region, and a licensing regime that catches most people by surprise. Both deserve attention, and the second one first if you are a vendor.
The Cyber Security Act 2024
Act 854 received assent on 18 June 2024 and commenced on 26 August 2024. Four sets of regulations came into force the same day, covering risk assessment and audit, incident notification, licensing, and compounding of offences.
The Act designates National Critical Information Infrastructure entities across eleven sectors: government, banking and finance, transportation, defence and national security, information and communication and digital, healthcare services, water and sewerage and waste management, energy, agriculture and plantation, trade and industry and economy, and science and technology and innovation. Only entities actually designated by a sector lead are bound by Part IV.
A small precision worth having: the Act has a single Schedule, not a First and Second Schedule. Licensable services come from a separate instrument, P.U.(A) 221.
The asset discovery obligations
Section 20(2) is unusual and easy to miss. Where an NCII entity "procures or has come into possession or control of any additional computer or computer system" that it believes is NCII, it must report that to the sector lead unprompted. Section 20(3) requires notification of material changes to design, configuration, security or operation within 30 days. Failure carries a penalty of RM100,000 or two years.
An obligation to report newly acquired systems presupposes that you know when you have acquired one. In an organisation of any size, cloud accounts, subdomains and third-party services appear without central approval constantly. Meeting section 20(2) reliably requires detection, not paperwork.
The NACSA Code of Practice is more direct still. Section 16.1.1.1 states that "all systems connected to the NCII entity's network must undergo vulnerability scanning", and requires monitoring of CVE list data feeds. Section 16.2.1.1 requires the vulnerability assessment plan to state its frequency, whether monthly, quarterly or after major updates. Section 8.1.1.1 requires an IT asset inventory of all computers and systems, reviewed annually or on change under 8.1.4.1.
On cadence, P.U.(A) 219 requires a risk assessment at least annually and an audit at least once every two years.
Incident reporting timeframes, which are not 72 hours
This gets misreported constantly. Under P.U.(A) 220, notification is immediate by electronic means, followed by prescribed particulars within six hours, and supplementary information within 14 days. The penalty is RM500,000 or ten years.
The 72-hour figure that circulates belongs to the amended PDPA, which is a separate regime with a separate regulator. Conflating the two will cost you in an audit.
The licensing trap
This is the part that changes commercial decisions, so we are stating it plainly even though it complicates our own sales process.
P.U.(A) 221 makes two categories of cybersecurity service licensable: managed SOC monitoring, and penetration testing. Regulation 5(c) defines penetration testing to include "identifying and measuring the cyber security vulnerabilities of a computer or computer system, indicating vulnerabilities and preparing appropriate mitigation procedures". No exploitation is required for the definition to bite. That reads onto vulnerability assessment, and by extension onto continuous external scanning. NACSA has published no carve-out for vulnerability assessment, scanning or attack surface management.
Regulation 4(a) separately captures acquiring, identifying or "scanning" information for the purpose of identifying or detecting cyber security threats.
Foreign vendors are in scope. Section 3(1) applies "whatever his nationality or citizenship, outside as well as within Malaysia", and regulation 2(2)(c) disapplies the regime only where the target system is located outside Malaysia. The test is where the asset sits, not where the vendor is incorporated. NACSA's own FAQ confirms that a foreign company providing cybersecurity services to companies located in Malaysia must apply for a licence.
A company licence is RM1,000 per year, valid one year, with a separate licence required per service. Sub-contractors must be licensed too. Providing a licensable service without a licence carries RM500,000 or ten years under section 27(5). The grace period expired on 28 February 2025, so full liability has applied since 1 March 2025.
What we advise
If you are a Malaysian NCII entity, the Code of Practice already requires vulnerability scanning of all connected systems and CVE feed monitoring. Continuous external attack surface monitoring is the efficient way to meet section 20(2) and the scanning obligation together rather than as two separate programmes.
If you are a vendor considering the Malaysian market, resolve licensing before you build pipeline. We would rather tell you this now than after a contract is signed.