Cybersecurity / NACSA Directive 9

Cryptographic Inventory for NACSA Directive No. 9

NACSA Directive No. 9 requires NCII entities to provide data on their post-quantum cryptography migration, starting with an inventory of where cryptography is used. We build the inventory and prepare the submission. Migration engineering is out of scope.

In force since 22 September 2025 Submission due within 3 months of a NACSA notice Inventory and submission only, not migration engineering
Overview

Cryptographic Inventory for NACSA Directive 9

What it is

A documentation service that identifies where cryptography is used across NCII systems, applications and services, records algorithms and dependencies, and prepares the data NACSA requests.

Why organisations need it

Directive No. 9, in force since 22 September 2025, requires NCII entities to provide post-quantum cryptography migration data within three months of a written notice from NACSA, using NACSA's form, starting with a cryptographic inventory. Most organisations have never catalogued their cryptography, and three months is short for a first inventory.

Key features

What the engagement covers

Scope

NCII systems, applications and services in scope.

Discovery

Where encryption, signatures and certificates are used.

Algorithm records

Algorithms, key lengths and libraries.

Dependencies

Vendors and third-party components.

Prioritisation

Systems most exposed to quantum risk.

Submission

Data prepared in NACSA's format.

Business value

What the business gets out of it

Deadline met

Inside the three months.

A reusable inventory

Foundation for later migration.

Vendor clarity

Know what depends on suppliers.

Priorities set

Where migration matters most.

Scoped sensibly

Inventory, not engineering.

How it works

How the engagement runs

01

Notice review

Understanding the request.

02

Discovery

Interviews, documents and tooling outputs.

03

Inventory

Building the register.

04

Validation

Review with system owners.

05

Submission

Preparing the NACSA data.

Deliverables

What you receive

Cryptographic inventory

Systems, algorithms and owners.

Vendor dependency list

Third-party components.

Priority list

Exposure ranking.

NACSA submission data

In the requested format.

Next steps note

What migration will involve.

Who it is for

Who this is built for

Industries

NCII entitiesBanking and financeEnergy and utilitiesTelecommunicationsHealthcareTransportGovernment

Company sizes

NCII entities

Departments

CISOIT architectureSecurityCompliance
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Who must respond to Directive No. 9?

NCII entities that receive a written notice from NACSA, within three months of the notice.

Do you migrate our systems to post-quantum algorithms?

No. We build the inventory and prepare the submission. Migration engineering is specialist work beyond our scope.

What goes into the inventory?

Where cryptography is used, the algorithms and key lengths, the libraries and vendors involved, and the systems' importance.

How long does it take?

Usually six to ten weeks, depending on the number of systems.

Who coordinates the data at national level?

Directive No. 9 names the Malaysian cryptology technology and management centre as coordinator under NACSA.

Get started

Answer Directive 9 on time

Tell us your NCII systems and when the notice arrived. We will scope the inventory.