Cybersecurity / NACSA Baseline

National Cyber Security Baseline Self-Assessment

A National Cyber Security Baseline self-assessment measures an organisation's controls against NACSA's minimum baseline, with the evidence behind each answer checked. NACSA's National Cyber Security Baseline sets minimum controls, and Directive No. 4 requires self-assessment against it. We facilitate the assessment, check the evidence behind each answer, and give you an honest score and a plan.

Against the National Cyber Security Baseline Evidence checked, not just answers Useful for NCII entities and their suppliers
Overview

National Cyber Security Baseline Assessment

What it is

A facilitated self-assessment against the National Cyber Security Baseline, with evidence review and a remediation plan.

Why organisations need it

NACSA has published the National Cyber Security Baseline and a self-assessment tool, and Chief Executive Directive No. 4 addresses self-assessment against it. NCII entities are expected to use it, and increasingly ask their suppliers the same questions. A self-assessment without evidence gives a flattering score that will not survive an audit.

Key features

What the engagement covers

Baseline walkthrough

Each control explained.

Evidence review

Documents and settings behind each answer.

Scoring

An honest baseline score.

Gap analysis

Missing and weak controls.

Remediation plan

Prioritised actions.

Supplier responses

Using the result to answer customer questionnaires.

Business value

What the business gets out of it

Honest score

Backed by evidence.

NACSA-aligned

Uses the national baseline.

Supplier advantage

Answer NCII customers confidently.

Clear plan

What to fix first.

Mid-level effort

No intrusive testing.

How it works

How the engagement runs

01

Kick-off

Scope and contacts.

02

Walkthrough

Controls reviewed with your team.

03

Evidence

Documents and settings checked.

04

Scoring

Baseline score.

05

Report

Gaps and plan.

Deliverables

What you receive

Baseline assessment

Completed and evidenced.

Score summary

By domain.

Gap list

Missing and weak controls.

Remediation plan

Prioritised.

Supplier response pack

For customer questionnaires.

Who it is for

Who this is built for

Industries

NCII entitiesSuppliers to NCII sectorsGovernment agenciesEnergy and utilitiesHealthcareTransport and logistics

Company sizes

SMEsMid-marketLarge enterpriseGroup structures

Departments

ITSecurityComplianceManagement
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is the baseline mandatory?

NACSA addresses self-assessment against the baseline in Chief Executive Directive No. 4 for NCII-related parties. Organisations outside that group use the baseline as a recognised national benchmark, and increasingly because their NCII customers ask about it.

We are a supplier, not an NCII entity. Is this useful?

Yes. NCII customers increasingly ask their suppliers the same baseline questions they must answer themselves. An evidenced self-assessment lets you answer those questionnaires quickly and honestly, and shows where to improve before a customer finds the gap.

Do you test systems?

We review evidence and settings behind each answer, such as configurations, records and policies, rather than accepting a yes at face value. We do not perform intrusive testing, so the assessment does not disrupt your systems.

How long does it take?

Typically two to four weeks: a facilitated self-assessment session, an evidence review against each control, then a score and a remediation plan. The time depends mostly on how quickly evidence can be gathered.

Which version do you use?

The current version of the National Cyber Security Baseline that NACSA publishes, confirmed at kick-off. If NACSA updates the baseline during the engagement, we tell you what changed and how it affects your score.