Malaysia's National Cyber Security Agency (NACSA) issued Direction No. 8 under the Cyber Security Act 2024 (Act 854), making independent cybersecurity audits mandatory for all designated National Critical Information Infrastructure (NCII) entities.
The Direction is enforceable from 17 July 2025. For most NCII entities, the first audit window is already open.
This guide explains what Direction No. 8 requires, who is covered, what a compliant audit involves, and how to select a qualified auditor.
What Is NACSA Direction No. 8?
NACSA Direction No. 8 is a mandatory directive issued under Section 25 of the Cyber Security Act 2024 (Act 854), requiring all NCII entities to undergo an independent cybersecurity audit at least once every two years.
The Direction applies to the cybersecurity controls, governance frameworks, and technical security posture of NCII entities. It is not a paper-based compliance review — it requires evidence-based audit of whether cybersecurity controls are operating effectively, not merely documented.
Audit reports must be submitted to the NACSA Chief Executive within 30 days of audit completion, with specific reporting requirements under the Direction.
Non-compliance with Act 854 carries enforcement consequences including financial penalties and potential operational restrictions.
Who Is Covered? Defining NCII Entities Under Act 854
An NCII entity is any organisation designated by the Government of Malaysia as operating or owning critical information infrastructure in one of the eleven critical sectors listed under the Cyber Security Act 2024:
- Government
- Banking and Finance
- Transportation
- Defence and National Security
- Information and Communications
- Health Services
- Water and Wastewater
- Energy
- Food and Agriculture
- Land Public Transport
- Emergency Services
If your organisation has received a written designation notice from NACSA directly, or from your sector regulator (Bank Negara Malaysia for banking and finance, MCMC for information and communications, etc.), you are an NCII entity and Direction No. 8 applies.
If you are uncertain about your designation status, contact NACSA's NCII Division directly or consult with a qualified NACSA auditor to confirm scope.
What Does a Compliant NACSA Direction 8 Audit Require?
Direction No. 8 specifies two audit tracks, and a compliant audit must address both:
Compliance-Based Audit Track
The compliance track assesses the entity's adherence to:
- The Cyber Security Act 2024 (Act 854) and all operative Directions
- Applicable NACSA sector-specific Codes of Practice
- Relevant international standards where referenced (ISO 27001, NIST CSF)
Deliverables include a documented compliance gap register against each applicable requirement, with a prioritised remediation plan and timeline.
Risk-Based Audit Track
The risk-based track goes beyond compliance checklists to assess whether the entity's cybersecurity controls are effective against its actual threat environment:
- Threat and vulnerability analysis relevant to the entity's sector and operating context
- Control design adequacy — are controls fit for purpose against identified threats?
- Control operating effectiveness — are controls functioning as designed in practice?
- Residual risk assessment — what risk remains after controls are applied?
This track cannot be completed through document review alone. It requires direct evidence gathering, testing, and practitioner judgement.
Technical Testing Requirements
For most NCII entities, Direction 8 audits will require technical testing components, including:
Vulnerability Assessment and Penetration Testing (VAPT): Identification and exploitation of vulnerabilities in systems, networks, and applications. VAPT must be conducted by qualified practitioners, not automated scanning tools alone.
Security Operations Centre (SOC) Review: Assessment of the entity's SOC capability — detection coverage, alert triage processes, incident escalation, and response effectiveness.
Identity and Access Management (IAM) Assessment: Review of privileged access controls, account lifecycle management, authentication mechanisms, and separation of duties.
Cloud Security Review (where applicable): For NCII entities with material cloud infrastructure — configuration review, shared responsibility model compliance, and cloud-specific threat assessment.
The 30-Day Reporting Window — What It Means in Practice
The 30-day submission window is measured from completion of the audit, not from its commencement. This has a practical implication: an NCII entity that commences an audit in August must have the audit completed and the report submitted to NACSA by the end of the submission window following completion.
The audit report submitted to NACSA must meet NACSA's specified reporting format, cover both audit tracks, and include the auditor's independent findings — not the entity's own characterisation of its security posture.
NCII entities should also retain the full audit workpapers and evidence pack for a minimum period — NACSA reserves the right to request these for supervisory review.
Practical recommendation: Build 2–3 weeks of buffer between the end of audit fieldwork and the 30-day NACSA submission deadline. Complex organisations, particularly those with multiple systems and sectors, routinely underestimate the time required to produce a compliant audit report.
NACSA Direction No. 9 — What Comes After Direction 8
Direction No. 9, also issued under Act 854, addresses Post-Quantum Cryptography (PQC) migration requirements for NCII entities. Direction No. 9 requires NCII entities to assess their cryptographic exposure to quantum computing threats and develop a migration roadmap to quantum-safe cryptographic standards.
For NCII entities in the banking and finance sector, Direction No. 9 intersects with Bank Negara Malaysia's own cryptography requirements and with SWIFT's growing PQC guidance for financial institutions.
ORP2b's PQC methodology was developed through an active engagement with a Gulf central bank and is adapted for Malaysian NCII entities under Direction No. 9.
How ORP2bTech Delivers NACSA Direction 8 Audits
ORP2bTech Sdn Berhad is ORP2b's Malaysia-incorporated subsidiary, established to deliver technology risk, cyber assurance, and AI governance under BNM and NACSA frameworks.
As a CCP Partner of Cybersecurity Malaysia, ORP2bTech carries the national cybersecurity competency credential required for credible NACSA audit delivery.
Our audit methodology covers four tracks:
- Compliance audit — systematic review against Act 854, applicable NACSA Directions, and sector-specific codes of practice. Output: compliance gap register and prioritised remediation plan.
- Risk-based audit — threat modelling, control design and effectiveness assessment, and residual risk evaluation. Not a checklist — evidence-driven with practitioner sign-off.
- Technical testing — VAPT, SOC effectiveness review, IAM assessment, and cloud security review where applicable. Conducted by certified practitioners with sector-specific experience.
- NACSA reporting — compliant audit report submitted within the 30-day window, with an internal governance copy for board reporting and senior management use.
Every ORP2bTech audit is led by a named senior practitioner, not a project team with rotating resources. The practitioner who scopes the engagement leads the fieldwork and signs the report.
Frequently Asked Questions on NACSA Direction 8
How do I know if my organisation is a designated NCII entity?
Designated NCII entities receive written notification from NACSA or their sector regulator. If you have not received a designation notice and are uncertain, contact NACSA directly or engage a qualified auditor to assess your scope.
Can we use our existing IT audit firm for the NACSA Direction 8 audit?
The Direction requires an independent cybersecurity audit. Your existing IT auditor may qualify if they have the technical capabilities required under Direction 8 — including VAPT capability, sector experience, and familiarity with the NACSA reporting format. Verify their credentials before engaging.
How long does a NACSA Direction 8 audit take?
For a mid-size NCII entity, allow 6–10 weeks from engagement commencement to submission of the report to NACSA. Larger or more complex entities with multiple systems, sectors, or third-party dependencies may require 12–16 weeks.
What is the penalty for non-compliance with Direction 8?
The Cyber Security Act 2024 provides for penalties including fines up to RM 500,000 for certain categories of breach, with escalating consequences for repeat or severe non-compliance. Consult your legal counsel for entity-specific penalty exposure.
Does ORP2bTech operate outside Malaysia?
ORP2bTech's NACSA audit capability is Malaysia-specific. ORP2b's broader cyber and technology risk assurance services operate across APAC and the Middle East — including Singapore, UAE, Hong Kong, and GCC markets.
Engage ORP2bTech for Your NACSA Direction 8 Audit
ORP2b is currently in active engagement process for Direction 8 audit work with designated NCII entities.
All engagements are scoped within 24 hours. Initial conversations are led by a senior practitioner.
Contact: ask@orp2b.com
Direct: rajitpunshi@orp2b.com