Scope
NCII systems, applications and services in scope.
NACSA Directive No. 9 requires NCII entities to provide data on their post-quantum cryptography migration, starting with an inventory of where cryptography is used. We build the inventory and prepare the submission. Migration engineering is out of scope.
A documentation service that identifies where cryptography is used across NCII systems, applications and services, records algorithms and dependencies, and prepares the data NACSA requests.
Directive No. 9, in force since 22 September 2025, requires NCII entities to provide post-quantum cryptography migration data within three months of a written notice from NACSA, using NACSA's form, starting with a cryptographic inventory. Most organisations have never catalogued their cryptography, and three months is short for a first inventory.
NCII systems, applications and services in scope.
Where encryption, signatures and certificates are used.
Algorithms, key lengths and libraries.
Vendors and third-party components.
Systems most exposed to quantum risk.
Data prepared in NACSA's format.
Inside the three months.
Foundation for later migration.
Know what depends on suppliers.
Where migration matters most.
Inventory, not engineering.
Understanding the request.
Interviews, documents and tooling outputs.
Building the register.
Review with system owners.
Preparing the NACSA data.
Systems, algorithms and owners.
Third-party components.
Exposure ranking.
In the requested format.
What migration will involve.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
NCII entities that receive a written notice from NACSA, within three months of the notice.
No. We build the inventory and prepare the submission. Migration engineering is specialist work beyond our scope.
Where cryptography is used, the algorithms and key lengths, the libraries and vendors involved, and the systems' importance.
Usually six to ten weeks, depending on the number of systems.
Directive No. 9 names the Malaysian cryptology technology and management centre as coordinator under NACSA.
Tell us your NCII systems and when the notice arrived. We will scope the inventory.