NCSA Cloud Security Standard B.E. 2567 (2024)
A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsibilities, and implementation evidence.
Applicability and effective date
The standard is officially in effect as of 10 September 2026, establishing mandatory duties for agencies using public cloud services under the National Cloud Security Framework.

- “Agency” covers government agencies, supervisory or regulatory agencies, and critical information infrastructure organizations under Thailand's Cybersecurity Act B.E. 2562 (2019).
- The notification covers IaaS, PaaS, SaaS, and combined services, establishing distinct security domains for Cloud Service Customers (CSCs) and Cloud Service Providers (CSPs).
- Implementation must consider the impact level of the data or information system. Personal data must have, at minimum, a medium confidentiality impact level.
Control areas to plan jointly
The annex addresses both customer processes and capabilities a provider must disclose or support.

- Asset inventory and data labelling; access control, authentication, and access restriction.
- Cryptography and key management; data-center location; secure disposal or reuse; and personal-data protection.
- Technical vulnerability management (Clause 5.2.6.8 (a)) encompassing vulnerability assessment, risk-based prioritization, and patch remediation across OS, containers, applications, and third-party libraries.
- Security testing and penetration testing agreements (Clause 5.2.9.2 (a)) establishing customer testing rights, cadence, and protocols with strict guarantees against cross-tenant disruption.
Evidence and reporting
Turn the requirements into auditable evidence from service selection through contract review and operation.

- Keep impact classification, selected requirements, contracts, responsibility allocation, provider evidence, and review results together.
- The notification requires an agency to submit a summary implementation report to NCSA within 30 days after completion, utilizing the official CSC Self-Assessment framework (version 1.0).
- Access official publications, the 2026-2030 integration plan, and self-assessment templates on NCSA's dedicated portal at cloudsecurity.ncsa.or.th.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| Chapters 1 and 2 (Clauses 5.1.2.1 and 5.2.9.1) | Cloud Architecture and SLA Security Audit | Audit cloud service contracts, SLA terms, and Shared Responsibility Matrices across IaaS, PaaS, and SaaS workloads | Prior to deployment and reviewed at least annually |
| Chapters 3 and 4 (Clauses 5.2.1 and 5.2.7) | Cloud Configuration and Isolation Audit (CSPM) | Audit IAM roles, least privilege access, cryptographic key management, data encryption, and network perimeters | Pre-migration and at least annually |
| Chapter 5 (Clauses 5.2.6.8 and 5.2.9.2) | Technical Vulnerability Assessment and Cloud Penetration Testing | Execute Vulnerability Assessments (VA) across OS, containers, applications, and dependencies, plus cross-tenant safe penetration testing | Regular vulnerability scanning and annual penetration testing |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.

