Cybersecurity Act B.E. 2562 (2019) and Penetration Testing
The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.
Using testing in the cybersecurity risk-assessment cycle
The Act establishes assessment and audit expectations for in-scope entities. Penetration testing can evidence technical risk but does not replace the whole governance process.

- Identify critical services, supporting systems, and infrastructure dependencies before fixing an assessment scope.
- Section 54 states that CII organisations must arrange cybersecurity risk assessment and audit at least annually, subject to the Act's applicable conditions.
- Assessment evidence should connect threat, vulnerability, impact, control owner, and remediation rather than consider a scan or pentest in isolation.
- Confirm the reporting framework and 30-day timing against the actual entity and responsible authority.
NATIONAL CYBERSECURITY / RISK & AUDIT
The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.
Statutory duties
- Section 44 requires government agencies, regulators or supervisors, and critical information infrastructure (CII) organizations to create a code of practice and standards framework whose minimum content includes an annual cybersecurity inspection and risk-assessment plan.
- Section 54 specifically requires CII organizations to arrange a cybersecurity risk assessment and cybersecurity audit at least annually, then send a summary to NCSA within thirty days after completion.
Role of Penetration Testing
- Penetration Testing is technical evidence supporting risk assessment and audit, not the whole audit.
- Clauses 21.3.4 and 21.3.6 of the B.E. 2564 (2021) Code of Practice use recommendatory risk-and-need wording for Penetration Testing, focusing on critical and Internet-facing services.
- When performed, scope should cover the relevant host, network, and application layers, and testers should be independent of the systems and processes under assessment.
The Act does not require every organization to conduct annual Penetration Testing. Keep the statutory risk-assessment and audit duties distinct from the technical testing method selected to support them.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| Sections 49 to 54 | CII Baseline Security Standards and Risk Assessment | Critical Information Infrastructure (CII) across 7 sectors, OT and SCADA Systems | At least annually |
| NCSA Directive 2022 | Cybersecurity Incident Notification and Security Testing Framework | Core Network Assets, Critical Enterprise Applications, Control Systems | Regular NCSA evaluation cycle |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
