Siam Thanat Hack Co., Ltd.

NCSA Cloud Security Standard B.E. 2567 (2024)

A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsibilities, and implementation evidence.

Executive Summary and Mandate Overview
Target Audience Government Agencies, State Enterprises, and Cloud Service Providers (CSPs) in Thailand
Mandatory Frequency At least annual security assessment and review
Required Scope Cloud Infrastructure (IaaS, PaaS, and SaaS), IAM Roles, Containers, Workload Vulnerability Assessment
Non-Compliance Risk Non-compliance with NCSA Cloud Standard 2024 and cloud breach exposure

Applicability and effective date

The standard is officially in effect as of 10 September 2026, establishing mandatory duties for agencies using public cloud services under the National Cloud Security Framework.

Infographic explaining: Applicability and effective date
Visual guide: Applicability and effective date
  • “Agency” covers government agencies, supervisory or regulatory agencies, and critical information infrastructure organizations under Thailand's Cybersecurity Act B.E. 2562 (2019).
  • The notification covers IaaS, PaaS, SaaS, and combined services, establishing distinct security domains for Cloud Service Customers (CSCs) and Cloud Service Providers (CSPs).
  • Implementation must consider the impact level of the data or information system. Personal data must have, at minimum, a medium confidentiality impact level.

Shared accountability and provider evidence

The standard requires cloud customers and providers to agree and record appropriate information-security roles, duties, and responsibilities.

Infographic explaining: Shared accountability and provider evidence
Visual guide: Shared accountability and provider evidence
  • Before use, identify relevant legal jurisdictions, potential data-storage countries or locations, and applicable contractual requirements.
  • Customers must obtain evidence of a provider's compliance with relevant law, standards, and contractual requirements.
  • Where a per-customer audit is not feasible, providers must show independent evidence or self-assess and disclose the process and results under the standard's conditions.

Control areas to plan jointly

The annex addresses both customer processes and capabilities a provider must disclose or support.

Infographic explaining: Control areas to plan jointly
Visual guide: Control areas to plan jointly
  • Asset inventory and data labelling; access control, authentication, and access restriction.
  • Cryptography and key management; data-center location; secure disposal or reuse; and personal-data protection.
  • Technical vulnerability management (Clause 5.2.6.8 (a)) encompassing vulnerability assessment, risk-based prioritization, and patch remediation across OS, containers, applications, and third-party libraries.
  • Security testing and penetration testing agreements (Clause 5.2.9.2 (a)) establishing customer testing rights, cadence, and protocols with strict guarantees against cross-tenant disruption.

Evidence and reporting

Turn the requirements into auditable evidence from service selection through contract review and operation.

Infographic explaining: Evidence and reporting
Visual guide: Evidence and reporting
  • Keep impact classification, selected requirements, contracts, responsibility allocation, provider evidence, and review results together.
  • The notification requires an agency to submit a summary implementation report to NCSA within 30 days after completion, utilizing the official CSC Self-Assessment framework (version 1.0).
  • Access official publications, the 2026-2030 integration plan, and self-assessment templates on NCSA's dedicated portal at cloudsecurity.ncsa.or.th.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Chapters 1 and 2 (Clauses 5.1.2.1 and 5.2.9.1) Cloud Architecture and SLA Security Audit Audit cloud service contracts, SLA terms, and Shared Responsibility Matrices across IaaS, PaaS, and SaaS workloads Prior to deployment and reviewed at least annually
Chapters 3 and 4 (Clauses 5.2.1 and 5.2.7) Cloud Configuration and Isolation Audit (CSPM) Audit IAM roles, least privilege access, cryptographic key management, data encryption, and network perimeters Pre-migration and at least annually
Chapter 5 (Clauses 5.2.6.8 and 5.2.9.2) Technical Vulnerability Assessment and Cloud Penetration Testing Execute Vulnerability Assessments (VA) across OS, containers, applications, and dependencies, plus cross-tenant safe penetration testing Regular vulnerability scanning and annual penetration testing

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview of NCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (Royal Gazette Edition)

NCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (Royal Gazette Edition)

By Royal Thai Government Gazette

Open document (PDF) Download Source NCSA Cloud Security Portal

First-page preview of Cloud Security Standard Self-Assessment for Cloud Service Customer (Version 1.0)

Cloud Security Standard Self-Assessment for Cloud Service Customer (Version 1.0)

By NCSA

Open document (PDF) Download (PDF) Download (.docx) Source NCSA Cloud Security Portal