Siam Thanat Hack Co., Ltd.

NCSA Cloud Security Standard B.E. 2567 (2024)

A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsibilities, and implementation evidence.

Applicability and effective date

NCSA states that the standard takes effect on 10 September 2026 and the notification places duties on agencies using public cloud services.

Thai infographic explaining: Applicability and effective date
Visual guide: Applicability and effective date
  • “Agency” covers government agencies, supervisory or regulatory agencies, and critical information infrastructure organizations under Thailand's Cybersecurity Act B.E. 2562 (2019).
  • The notification covers IaaS, PaaS, SaaS, and combined services; the Cloud Service Customer (CSC) and Cloud Service Provider (CSP) have distinct considerations.
  • Implementation must consider the impact level of the data or information system. Personal data must have, at minimum, a medium confidentiality impact level.

Shared accountability and provider evidence

The standard requires cloud customers and providers to agree and record appropriate information-security roles, duties, and responsibilities.

Thai infographic explaining: Shared accountability and provider evidence
Visual guide: Shared accountability and provider evidence
  • Before use, identify relevant legal jurisdictions, potential data-storage countries/locations, and applicable contractual requirements.
  • Customers must obtain evidence of a provider's compliance with relevant law, standards, and contractual requirements.
  • Where a per-customer audit is not feasible, providers must show independent evidence or self-assess and disclose the process and results under the standard's conditions.

Control areas to plan jointly

The annex addresses both customer processes and capabilities a provider must disclose or support.

Thai infographic explaining: Control areas to plan jointly
Visual guide: Control areas to plan jointly
  • Asset inventory and data labelling; access control, authentication, and access restriction.
  • Cryptography and key management; data-center location; secure disposal or reuse; and personal-data protection.
  • Change and capacity management, backups, event logging, vulnerability management, and network/tenant segregation.

Evidence and reporting

Turn the requirements into auditable evidence from service selection through contract review and operation.

Thai infographic explaining: Evidence and reporting
Visual guide: Evidence and reporting
  • Keep impact classification, selected requirements, contracts and responsibility allocation, provider evidence, and review results together.
  • The notification requires an agency to submit a summary implementation report to NCSA within 30 days after completion.
  • Private organizations should assess adoption against their contracts, risk, and applicable law; this page is not a legal applicability determination.

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (2024)

NCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (2024)

By NCSA

Open document (PDF) Source