Siam Thanat Hack Co., Ltd.

Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

Executive Summary and Mandate Overview
Target Audience Critical Information Infrastructure (CII) entities across 7 designated sectors
Mandatory Frequency Annual cybersecurity risk assessment and audit (Sec 54); not a named pentest mandate
Required Scope CII Core Systems, Operational Technology (OT and SCADA), Enterprise Network
Non-Compliance Risk Court and NCSA enforcement orders, fines up to 300,000 THB and daily penalties (Sec 75)

Using testing in the cybersecurity risk-assessment cycle

The Act establishes assessment and audit expectations for in-scope entities. Penetration testing can evidence technical risk but does not replace the whole governance process.

Thai infographic explaining: Using testing in the cybersecurity risk-assessment cycle
Visual summary: Using testing in the cybersecurity risk-assessment cycle
  • Identify critical services, supporting systems, and infrastructure dependencies before fixing an assessment scope.
  • Section 54 states that CII organisations must arrange cybersecurity risk assessment and audit at least annually, subject to the Act's applicable conditions.
  • Assessment evidence should connect threat, vulnerability, impact, control owner, and remediation rather than consider a scan or pentest in isolation.
  • Confirm the reporting framework and 30-day timing against the actual entity and responsible authority.

NATIONAL CYBERSECURITY / RISK & AUDIT

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

Statutory duties

  • Section 44 requires government agencies, regulators or supervisors, and critical information infrastructure (CII) organizations to create a code of practice and standards framework whose minimum content includes an annual cybersecurity inspection and risk-assessment plan.
  • Section 54 specifically requires CII organizations to arrange a cybersecurity risk assessment and cybersecurity audit at least annually, then send a summary to NCSA within thirty days after completion.

Role of Penetration Testing

  • Penetration Testing is technical evidence supporting risk assessment and audit, not the whole audit.
  • Clauses 21.3.4 and 21.3.6 of the B.E. 2564 (2021) Code of Practice use recommendatory risk-and-need wording for Penetration Testing, focusing on critical and Internet-facing services.
  • When performed, scope should cover the relevant host, network, and application layers, and testers should be independent of the systems and processes under assessment.
Requirement boundary

The Act does not require every organization to conduct annual Penetration Testing. Keep the statutory risk-assessment and audit duties distinct from the technical testing method selected to support them.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Sections 49 to 54 CII Baseline Security Standards and Risk Assessment Critical Information Infrastructure (CII) across 7 sectors, OT and SCADA Systems At least annually
NCSA Directive 2022 Cybersecurity Incident Notification and Security Testing Framework Core Network Assets, Critical Enterprise Applications, Control Systems Regular NCSA evaluation cycle

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview of Cybersecurity Act B.E. 2562 (2019)

Cybersecurity Act B.E. 2562 (2019)

By Royal Thai Government Gazette

Open document (PDF) Download Source