メインコンテンツへスキップ

Malaysia Cybersecurity Laws and Licensing in 2026: What the Cyber Security Act, Computer Crimes Act, and MCMC Rules Mean for Your Software

Malaysia Cybersecurity Laws and Licensing in 2026: What the Cyber Security Act, Computer Crimes Act, and MCMC Rules Mean for Your Software

If your Malaysian business runs a website, a mobile app, a SaaS platform, or even a customer portal, a stack of cybersecurity laws now applies to you. Most founders I speak to can name the PDPA. Almost none can name the Cyber Security Act 2024, and that is the one that can redesign your entire hosting and incident-response strategy.

I’m Eric, the Technical Founder at Nodesify Technology. We architect enterprise software out of our Johor headquarters, and over the last 18 months the compliance conversation has shifted. Boards used to ask only about data protection. Now they ask about cyber defence obligations, critical infrastructure designation, and whether the software they are buying needs a class licence from the MCMC.

This guide maps the three pieces of Malaysian law that actually govern how you build and operate software in 2026: the Cyber Security Act 2024, the Computer Crimes Act 1997, and the Communications and Multimedia Act 1998 (which backs MCMC licensing). I will keep it practical. No legal jargon without a translation into an engineering decision.

Important: This guide is general information about Malaysian law as it stands in 2026, not legal advice. For a formal opinion on your specific obligations, engage a qualified Advocate and Solicitor of the High Court of Malaya.

The Three Laws That Govern Malaysian Software

Most Malaysian enterprises touch three distinct cybersecurity legal regimes. They sit on top of the PDPA, not instead of it.

LawRegulatorWhat It GovernsWho It Bites
Cyber Security Act 2024 (Act 854)NACSANational cyber defence and critical infrastructure protectionDesignated NCII entities and their vendors
Computer Crimes Act 1997 (Act 563)PDRM / Attorney GeneralUnauthorised access and modification of computer systemsAnyone who accesses or modifies systems without authority
Communications and Multimedia Act 1998 (Act 588)MCMCLicensing of online service, network, and cloud providersService providers above licensing thresholds

Read those rows in order of escalation. The PDPA is about protecting data subjects. The Cyber Security Act is about protecting the nation. The Computer Crimes Act is about prosecuting offenders. The CMA 1998 is about licensing the service itself.

What Is the Cyber Security Act 2024?

The Cyber Security Act 2024 (Act 854) is Malaysia’s primary cybersecurity statute. Administered by the National Cyber Security Agency (NACSA) under the oversight of the National Cyber Security Committee, it came into force on 26 August 2024 together with four subsidiary regulations. You can read the official framework on the NACSA Act 854 page.

The Act’s core mechanism is the National Critical Information Infrastructure (NCII) designation. NACSA identifies the systems, networks, and assets whose disruption would harm national security, the economy, public order, or the government, and designates their operators as NCII entities. Once designated, those entities face hard obligations: risk assessments, cybersecurity audits, incident reporting to NACSA, and adherence to codes of practice issued by the National Cyber Security Committee.

This is the part most Malaysian SMEs misunderstand. The CSA 2024 is not a general cybersecurity law that applies to every business with a website. It targets critical infrastructure: telecommunications, energy, water, transport, banking, government, healthcare, and similar sectors, plus the vendors that serve them. A typical SME e-commerce site is not an NCII entity. But the cloud provider hosting it, the data centre it sits in, and the bank processing its payments very likely are.

The practical question is not “am I an NCII entity?” but “am I a vendor to an NCII entity?” Because NCII obligations cascade down the supply chain. If you build software for a bank, a telco, a utility, or a government agency, your customer will pass their CSA obligations straight into your contract. That is where the Act reaches the average Malaysian software firm.

The Computer Crimes Act 1997: The Offence Layer

The Computer Crimes Act 1997 (Act 563) is older but it is the statute that criminalises unauthorised access to computer systems in Malaysia. Enforced by the Royal Malaysia Police (PDRM) with prosecutions brought by the Attorney General’s Chambers, it covers three core offences:

  1. Unauthorised access (Section 3). Accessing a computer without authority carries up to RM50,000 fine and/or 1 year imprisonment.
  2. Unauthorised access with intent to commit further offences (Section 4). This is the “I broke in to steal something” charge, carrying up to RM150,000 fine and/or 5 years imprisonment.
  3. Unauthorised modification of computer contents (Section 5). This covers malware, ransomware, and destructive edits. Conviction carries up to RM100,000 fine and/or 7 years imprisonment.

For software operators, the CCA matters in two directions. First, anyone who attacks your system commits an offence under the CCA, and that is what you rely on when you report a breach to PDRM. Second, the CCA is the reason you need authorisation boundaries baked into your software. If an employee, a contractor, or an offshore vendor accesses your systems beyond the scope you authorised, that can be a criminal matter, not just an employment one.

This is why least-privilege access, scoped API tokens, and audit logging are not optional. They are the evidence you would need to prove authorisation was exceeded.

MCMC Licensing Under the Communications and Multimedia Act 1998

The Communications and Multimedia Act 1998 (Act 588) gives the Malaysian Communications and Multimedia Commission (MCMC) the power to licence the provision of online, network, and cloud services in Malaysia. The MCMC issues two broad categories of licence:

  • Individual licences for services with significant national impact, granted by the Minister on MCMC recommendation.
  • Class licences, where providers register with the MCMC and operate under standard conditions. The most relevant categories for software firms are the Applications Service Provider Class Licence and the Network Service Provider Class Licence.

The MCMC updated its Licensing Guidebook in 2025. Two thresholds matter for Malaysian software businesses.

The 8-Million-User Rule for Large Platforms

Under the updated framework, Applications Service Providers with at least 8 million users in Malaysia must obtain an ASP(C) class licence from the MCMC. This rule is aimed squarely at large messaging, social media, and internet platforms. It is the legal basis behind the licensing of major global platforms operating in Malaysia. A standard SME app or website does not hit this threshold.

The class licence is valid for one year and must be renewed annually. The MCMC publishes the register of individual licences publicly.

Cloud Service Provider Licensing Since 1 January 2022

This is the threshold that catches more Malaysian software businesses. Since 1 January 2022, the MCMC requires Cloud Service Providers operating in Malaysia to hold a class licence. If you provision, host, or operate cloud infrastructure for Malaysian customers, you fall in scope. The application runs through the MCMC licensing department, with a registration fee and a Form D submission.

For most Nodesify clients the question is reversed: you are not the cloud provider, but your vendor is. The hosting decision is where this regulation lands on your project. If you operate Malaysian customer data on cloud infrastructure, you want that infrastructure to sit with an MCMC-licensed provider.

Sectoral Overlays: Bank Negara, MyDIGITAL, and PDPA

Three more regimes layer on top for specific industries.

Bank Negara Malaysia’s Risk Management in Technology (RMiT) policy sets the technology risk bar for licensed financial institutions. If you build for a bank, an insurer, or a fintech under Bank Negara supervision, RMiT dictates your hosting tier, your separation of duties, your incident reporting timelines, and your third-party risk management. The RMiT is why financial sector software in Malaysia costs more and takes longer. It is also why it is harder to displace once you are in.

MyDIGITAL and the Digital Sector push government and GLC procurement toward providers that meet baseline cybersecurity and data governance standards. Government RFPs increasingly score vendors on certification and compliance posture, not just price.

The PDPA sits underneath all of this. Cybersecurity law is about protecting systems. The PDPA is about protecting the personal data inside those systems. They are complementary, not substitutes. We cover the PDPA side in depth in our Malaysia PDPA Compliance for Website Development guide, and how it extends to vendor contracts in our PDPA data processor obligations article.

How These Laws Map to Engineering Decisions

Here is where the regulation stops being abstract and starts changing how we ship software.

Legal ObligationEngineering Translation
CSA 2024 incident reportingCentralised logging, alerting, and a documented incident-response runbook that can produce a report to NACSA (or to your NCII customer) within required windows.
CCA 1997 authorisation boundariesRole-based access control, scoped and expiring API tokens, and audit logs that prove who did what. No shared admin accounts.
CMA 1998 cloud provider licensingHosting on MCMC-licensed cloud infrastructure, or on infrastructure whose provider is registered, when serving Malaysian customers.
Bank Negara RMiTTiered hosting environments, segregation of duties, change management evidence, and third-party risk assessments for every vendor.
PDPA Security PrincipleTLS 1.3 in transit, AES-256 at rest, WAF, rate limiting, and breach-detection plumbing.

When every row on that table is a deliberate architecture decision, you end up with software that is defensible under all four regimes at once.

The Cybersecurity Compliance Checklist for Malaysian Software

Before you sign off your next build, confirm the spec covers the following:

  • Hosting on infrastructure whose provider is licensed or registered with the MCMC where applicable.
  • Role-based access control with no shared accounts and a full audit trail.
  • Scoped, expiring API tokens and secrets management rather than long-lived credentials.
  • Centralised security logging and alerting with retention long enough to support incident investigation.
  • A documented incident-response runbook naming the regulator you would notify (NACSA, MCMC, PDPD, or Bank Negara, depending on your sector).
  • TLS 1.3 in transit and AES-256 at rest, with a Web Application Firewall and rate limiting in front of every public endpoint.
  • Third-party risk assessment for every vendor that touches the system, mapping them to your regulatory obligations.
  • A Malaysian-registered contractual counterparty who carries legal accountability under Malaysian jurisdiction.

If your current vendor cannot evidence every box, that is the gap the 2024 Act and the MCMC framework are designed to expose.

Frequently Asked Questions About Malaysian Cybersecurity Law

Does the Cyber Security Act 2024 apply to my Malaysian business?

The Cyber Security Act 2024 applies directly to entities designated as National Critical Information Infrastructure (NCII) by NACSA, which covers critical sectors such as banking, telecommunications, energy, and government. A typical Malaysian SME website is not an NCII entity. However, if you build software for, or supply services to, an NCII entity such as a bank or a telco, your customer’s CSA obligations will flow into your contract through procurement and vendor risk requirements.

Do I need an MCMC licence for my website or app?

Most Malaysian websites and apps do not require an MCMC licence. The Communications and Multimedia Act 1998 requires an Applications Service Provider Class Licence for service providers with at least 8 million users in Malaysia, which targets large messaging, social media, and internet platforms. Cloud Service Providers operating in Malaysia have required an MCMC class licence since 1 January 2022. If you only operate a standard business website or app, you are generally below these thresholds, but your hosting provider may need to be licensed.

What is the penalty for unauthorised access under the Computer Crimes Act?

Under Section 3 of the Computer Crimes Act 1997, unauthorised access to a computer carries a fine of up to RM50,000 and/or imprisonment of up to 1 year. Unauthorised access with intent to commit further offences (Section 4) carries up to RM150,000 and/or 5 years. Unauthorised modification of computer contents (Section 5), which includes malware and ransomware, carries up to RM100,000 and/or 7 years.

How does the Cyber Security Act 2024 affect software vendors?

If you supply software, hosting, or managed services to a designated NCII entity, the NCII entity will pass its CSA 2024 obligations down through your contract. This typically requires you to meet specified cybersecurity standards, undergo risk assessments, support incident reporting, and accept audit rights. Vendors that cannot evidence these controls are increasingly disqualified from regulated procurement.

Is the PDPA the same as cybersecurity law?

No. The Personal Data Protection Act 2010 governs the protection of personal data and the rights of data subjects. Cybersecurity laws such as the Cyber Security Act 2024 and the Computer Crimes Act 1997 govern the protection of computer systems and the prosecution of cyber offences. They are complementary. A breach of cybersecurity controls often triggers PDPA breach notification duties as well.

Build It Defensible the First Time

Malaysia’s cybersecurity legal framework matured fast between 2022 and 2026. The Cyber Security Act 2024, the Computer Crimes Act 1997, and MCMC licensing now form a coherent regime that reaches into how you host, how you authorise access, and how you respond to incidents. If you are planning a new website, an app, or an enterprise system, the cheapest moment to satisfy these obligations is at the architecture stage, not after an audit letter arrives.

That is what we do at Nodesify Technology. We engineer software for Malaysian enterprises from our Johor HQ, with a local Architectural Core that keeps you legally protected under Malaysian law. Start with a Technical Roadmap and Architecture Audit and we will map your stack against the CSA, the CCA, and MCMC requirements before a single line of code gets written. If you are heading toward ISO/IEC 27001, our ISO 27001 alignment guide explains how the Annex A controls reinforce every one of these legal duties.

Industry Statistics & Citations

  • Regulatory Compliance: The Cyber Security Act 2024 (Act 854) mandates strict licensing for critical national information infrastructure (CNII) entities, with non-compliance resulting in massive fines.
  • Breach Costs: The average cost of a data breach in the ASEAN region reached USD 3.2 million in 2025.
  • Citation: IBM Security, “Cost of a Data Breach Report: ASEAN Region”, 2025.

To learn more about digital transformation strategies, regulatory compliance (PDPA & Cybersecurity Act 2024), and system modernization roadmaps, read our comprehensive Ultimate Guide to Enterprise Digital Transformation in Malaysia.

Photo of Eric Tong

Eric Tong

Technical Founder

Eric is the Technical Founder at Nodesify, specialising in AI-driven automation, distributed systems, and enterprise cloud architecture. He helps Malaysian enterprises architect systems that satisfy the Cyber Security Act 2024, the Computer Crimes Act 1997, and MCMC licensing obligations.

Nodesifyブログを購読する

Nodesifyとつながりを保ち、インボックスで新しいブログ投稿を受け取ります。

Nodesifyは、その プライバシーポリシー に従ってデータを処理します。

プロジェクトにご興味がありますか?

構築、自動化、または近代化したい内容についてお聞かせください。

問い合わせる

ご意見やご質問はありますか?

皆様からのご連絡をお待ちしております。

お問い合わせ