NCSA Cloud Security Standard B.E. 2567 (2024)
A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsibilities, and implementation evidence.
Applicability and effective date
NCSA states that the standard takes effect on 10 September 2026 and the notification places duties on agencies using public cloud services.

- “Agency” covers government agencies, supervisory or regulatory agencies, and critical information infrastructure organizations under Thailand's Cybersecurity Act B.E. 2562 (2019).
- The notification covers IaaS, PaaS, SaaS, and combined services; the Cloud Service Customer (CSC) and Cloud Service Provider (CSP) have distinct considerations.
- Implementation must consider the impact level of the data or information system. Personal data must have, at minimum, a medium confidentiality impact level.
Control areas to plan jointly
The annex addresses both customer processes and capabilities a provider must disclose or support.

- Asset inventory and data labelling; access control, authentication, and access restriction.
- Cryptography and key management; data-center location; secure disposal or reuse; and personal-data protection.
- Change and capacity management, backups, event logging, vulnerability management, and network/tenant segregation.
Evidence and reporting
Turn the requirements into auditable evidence from service selection through contract review and operation.

- Keep impact classification, selected requirements, contracts and responsibility allocation, provider evidence, and review results together.
- The notification requires an agency to submit a summary implementation report to NCSA within 30 days after completion.
- Private organizations should assess adoption against their contracts, risk, and applicable law; this page is not a legal applicability determination.

