Table of Contents Show
If a state water utility runs on software your company built, or a bank routes its transaction monitoring through your servers, you could already be sitting inside Malaysia’s Critical Information Infrastructure (CNII) framework without realising it. The Cyber Security Act 2024 gives the National Cyber Security Agency (NACSA) sweeping authority to designate businesses as CNII entities, and that designation comes with obligations most companies have never had to think about before.
This is not a small compliance footnote. Getting designated changes how your business handles risk assessments, audits, incident reporting, and in some cases, who you are allowed to hire for cybersecurity work. Here is how the framework actually works, and how to tell where your business stands in it.

What Counts as Critical Information Infrastructure
CNII refers to any computer system whose disruption or destruction would seriously damage Malaysia’s national security, economy, public health, safety, or the functioning of government. The Act does not limit this to government agencies. Private companies that operate systems essential services depend on fall squarely within scope.
The Cyber Security Act 2024 sets out eleven sectors where this designation applies:
- Government
- Banking and finance
- Transportation
- Defence and national security
- Information, communication, and digital
- Healthcare services
- Water, sewerage, and waste management
- Energy
- Agriculture and plantation
- Trade, industry, and economy
- Science, technology, and innovation
Falling within one of these sectors does not automatically make you a CNII entity. What matters is whether your specific systems are critical enough to essential services that their failure would cause real harm, not just inconvenience.
How NACSA Actually Decides If Your Business Is CNII
You do not designate yourself as CNII, and you will not be left guessing about your status. The minister responsible for cybersecurity appoints a lead agency for each of the eleven sectors, based on recommendations from NACSA’s chief executive, and that lead agency carries out the actual assessment.
Under Section 17 of the Act, the sector lead can require your company to hand over information about how your systems function, including technical details of their design and what they are used for. If your systems meet the threshold, designation arrives through formal written notice. There is no silent or automatic listing.
That said, plenty of businesses end up exposed to CNII-level obligations without holding the designation themselves. A software vendor supplying a hospital, or a data centre hosting a bank’s core systems, can find these requirements pushed down through client contracts long before any formal notice from a sector lead arrives. If your biggest client operates in one of the eleven sectors, it is worth checking your contract for cybersecurity clauses that mirror the Act’s requirements.
What Obligations Kick in Once You’re Designated
Designation is not a formality you file away and forget. It brings a set of recurring obligations that need to be built into how your business actually operates.
Ongoing Risk Assessments and Audits
CNII entities must run cybersecurity risk assessments at least once a year and undergo a full security audit at least once every two years, though NACSA can require more frequent audits depending on the sector and risk profile. These are not optional internal exercises. They feed directly into how regulators assess your compliance.
Incident Reporting Deadlines
When a cybersecurity incident hits a CNII system, the clock starts immediately. You have 6 hours to submit an initial report to NACSA once the incident is discovered, followed by a more detailed report within 14 days covering the full scope, cause, and remedial steps taken.
Codes of Practice and Cybersecurity Exercises
Each sector lead issues its own code of practice that CNII entities must follow, covering technical and governance standards specific to that industry. Designated entities also need to take part in cybersecurity exercises when directed, which test how the organisation actually responds under pressure rather than just what is written in a policy document.
Understanding NACSA’s Licensing Regime for Service Providers
Separate from CNII designation, the Cyber Security Act 2024 also created a licensing requirement for companies that provide cybersecurity services in Malaysia. This applies whether or not your own business is a CNII entity.
Six categories of service now require a Cyber Security Service Provider (CSSP) licence: penetration testing and vulnerability assessment, security operations centre (SOC) monitoring, managed security services, digital forensics, incident response, and security risk assessment. If your company offers any of these, even as a smaller part of a broader IT offering, licensing applies.
Applications go through NACSA’s licensing portal, and the process typically asks for company registration details, staff certifications such as CISSP, CISM, or CEH, and payment of the applicable fee before NACSA reviews and issues the licence. For CNII entities specifically, this licensing regime matters twice over: you need to meet your own compliance obligations, and you need to confirm that any vendor handling your cybersecurity work is properly licensed before you hand over access to your systems.
The Cost of Getting This Wrong
Non-compliance under the Cyber Security Act 2024 is not a paperwork issue with a small fine attached. Penalties range from RM100,000 to RM500,000, with imprisonment terms of up to 10 years depending on the severity of the offence. Licensed service providers who breach their obligations also risk having their licence suspended or revoked outright, which can end that line of business overnight.
Beyond the legal exposure, a CNII entity that mishandles an incident, or that discovers only after the fact it was using an unlicensed vendor, faces a harder conversation with regulators and clients alike. Rebuilding trust after a breach in a sector like banking or healthcare tends to take far longer than the incident itself.
Getting Ahead of a CNII Designation
If your business touches any of the eleven CNII sectors, even indirectly through a client relationship, it is worth working out now whether your systems would meet the threshold rather than waiting for a letter from a sector lead. Reviewing your risk assessment cadence, checking whether your current vendors hold valid CSSP licences, and mapping out your incident response process ahead of time puts you in a far stronger position than scrambling after the fact.
This is exactly the kind of groundwork that benefits from an outside set of eyes. Working with an experienced cybersecurity and data privacy advisory team means you get a clear read on where your business actually stands under the Cyber Security Act 2024, and a practical plan for closing the gaps, before NACSA or a client contract forces the issue.