Gotchaa Lab
Back to Blog
cybersecuritypenetration-testingmalaysiacompliancevapt

Penetration Testing Malaysia: How to Tell a Real Pentest From a Scan

19 August 2026·5 min read·By Gotchaa Lab
Penetration Testing Malaysia: How to Tell a Real Pentest From a Scan

TL;DR

  • A web application penetration test in Malaysia usually lands between RM5,000 and RM45,000. Anything under RM3,000 is almost always an automated scan with a report template.
  • Since the Cyber Security Act 2024, penetration testing is one of only two cyber security services that need a licence in Malaysia. The licence costs a vendor RM1,000 a year and NACSA publishes every holder in a public register.
  • Check the register before you compare quotes. A vendor who skipped a RM1,000 licence is telling you something about how they handle the rest of the job.

Ask five Malaysian security vendors what a penetration test costs and you get five ranges, none of them comparable. Published figures run from RM5,000 to over RM150,000. The ranges are not wrong, just useless on their own, because "pentest" now covers two different products sold under one name.

Since 2024, penetration testing has been a licensed activity in Malaysia. Almost no vendor leads with that, and it filters more of them than any price comparison.

How much does penetration testing cost in Malaysia?

Rough bands, from what Malaysian providers publish and what we charge for our own cybersecurity work:

ScopeTypical rangeWhat you get
Single web applicationRM5,000 to RM20,000Manual testing of auth, roles, payment flows, APIs
Larger web app or API suiteRM15,000 to RM45,000Multiple roles, integrations, deeper exploitation
Full infrastructureRM20,000 to RM80,000Servers, network config, cloud, mobile, compliance docs
Automated scan onlyUnder RM3,000A tool ran. Nobody read the output.

Watch that last row. A scanner licence costs a vendor a few hundred ringgit a month. At RM1,500, the maths only works if a tool did everything and a template wrote the report.

What moves a penetration testing quote

Scope comes first, and it is not page count. What matters is how many user roles and permission boundaries exist, because the interesting bugs live at the boundaries.

After that, whether a human exploits or only reports. Confirming a flagged SQL injection is real, and showing what it pulls out, takes hours. Listing it takes seconds.

Retest. Many quotes exclude it. You fix everything, then pay again to prove you fixed it. Ask up front, because it changes the real cost by a third.

Box colour. Black box (no credentials) is cheaper and shallower. Grey box (a normal user login) finds far more for a modest increase, and suits almost every Malaysian SME.

Check the licence before you check the price

The Cyber Security Act 2024 came into operation on 26 August 2024. Its licensing regulations single out exactly two services as requiring a licence: managed security operations centre monitoring, and penetration testing. NACSA's own FAQ defines the second:

A penetration testing service under the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024 [P.U. (A) 221/2024] is a service for assessing, testing or evaluating the level of cyber security of a computer or computer system, by searching for vulnerabilities on, and compromising, the cyber security defences of the computer or computer system.

Source: FAQ, Licensing of Cyber Security Service Provider, NACSA

Applications opened on 1 October 2024. The fee is what makes this a useful buyer's filter:

The NACSA licensing portal fee table, showing RM400 for individuals and RM1,000 for companies per year for penetration testing service The application guide on NACSA's licensing portal, captured 19 August 2026.

The licence is valid for a period of one (1) year and the payment of the non-refundable fee needs to be completed during the application.

Penetration Testing Service: Individual RM400.00, Companies RM1,000.00 (per year)

Source: Licensing Portal for Cyber Security Service Providers, NACSA

RM1,000 a year is the entire barrier. A vendor charging RM20,000 for an engagement who has not paid it is not saving you money. Under section 27(5) of the Act, providing the service unlicensed carries a fine of up to RM500,000, up to ten years in prison, or both.

Two details before you sign. A subcontractor testing on behalf of your main contractor needs their own licence, so ask who is holding the keyboard. And applicants must show NACSA proof of certifications for the assigned staff, so the licence does some of your due diligence.

NACSA publishes every holder in a searchable register on the same portal. It takes a minute to check.

Our take: the licensing regime is the most useful thing to happen to Malaysian security buyers in years, and it is badly under-used. Buyers still open three quotes and pick the middle one. The register turns a judgement call into a lookup.

When a cheap scan is the right call

We run VAPT for a living and we will still say this: plenty of Malaysian businesses do not need a full penetration test yet.

Running a WordPress site with a contact form and no customer accounts? A RM2,000 scan plus fixing what it finds is honest value. The test earns its price when something behind the login is worth stealing, or when a client, an auditor or PDPA exposure means you need evidence someone competent looked.

What you should not do is buy the scan and file it as a penetration test. The report says "no critical vulnerabilities found" either way. Our post on cloud security mistakes covers what scanners miss.

Five questions to ask before you sign

  1. What is your NACSA licence number?
  2. Is one retest included after we remediate?
  3. Grey box or black box, and why that one for our app?
  4. How many hours are manual testing, as opposed to tool time?
  5. Can we see a redacted sample report?

If a vendor gets defensive about question one or four, you have your answer.

Want a straight quote with scope and retest written down? WhatsApp us and tell us what you are running.

General information only, not legal or professional cybersecurity advice. Licensing requirements and fees may change, so verify with NACSA. Prices are estimates and vary by scope.

References

  1. Cyber Security Act 2024 (Act 854), NACSA
  2. FAQ, Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024, NACSA
  3. Licensing Portal for Cyber Security Service Providers, NACSA
  4. Unveiling Malaysia's Cyber Security Act 2024, Tay & Partners
  5. Malaysia's New Cyber Security Act 2024, Mayer Brown
  6. Pentest Companies in Malaysia 2026, DeepStrike
  7. Pentest Cost in Malaysia, Flawtrack

Share this article

Frequently Asked Questions

How much should a penetration test cost in Malaysia?
For a single web application, expect roughly RM5,000 to RM20,000 depending on how many user roles, integrations and payment flows the app has. Published Malaysian provider ranges go wider, from about RM5,000 for a narrow scope to over RM150,000 for large infrastructure work. A full infrastructure assessment covering servers, network configuration, cloud environments and compliance documentation typically runs RM20,000 to RM80,000. Treat any quote under RM3,000 as a scan, not a test.
Does my penetration testing vendor need a licence in Malaysia?
Yes, in most cases. Under the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024, anyone who provides or advertises penetration testing services in Malaysia must hold a licence from NACSA. The regulations do not apply where the service is provided by a government entity, where a person provides it only to a related company, or where the computer system being tested sits outside Malaysia. Subcontractors who do the testing on behalf of a main contractor need their own licence, and foreign companies serving Malaysian clients need one too.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment runs automated tools against your systems and lists what they flag. A penetration test takes those findings and has a human try to actually exploit them, chaining small weaknesses into a real path in. The scan tells you a door might be unlocked. The test walks through it and shows you what is on the other side. VAPT means both together, which is what most Malaysian engagements are scoped as.
What is penetration testing called in Malay?
The Cyber Security Act 2024 and its licensing regulations use the English term penetration testing service. In everyday Malay usage it is commonly rendered as ujian penembusan, though most Malaysian vendor and government material keeps the English term.

Need help building this for your business?

We help Malaysian companies turn ideas like these into working software. Free consultation, no obligation.