Siam Thanat Hack Co., Ltd.

NCSA Cloud Security Standard B.E. 2567 (2024)

A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsibilities, and implementation evidence.

Executive Summary and Mandate Overview
Target Audience Government Agencies, State Enterprises, and Cloud Service Providers (CSPs) in Thailand
Mandatory Frequency At least annual security assessment and review
Required Scope Cloud Infrastructure (IaaS, PaaS, and SaaS), IAM Roles, Data Encryption and Storage
Non-Compliance Risk Non-compliance with NCSA Cloud Standard 2024 and cloud breach exposure

Applicability and effective date

NCSA states that the standard takes effect on 10 September 2026 and the notification places duties on agencies using public cloud services.

Thai infographic explaining: Applicability and effective date
Visual guide: Applicability and effective date
  • “Agency” covers government agencies, supervisory or regulatory agencies, and critical information infrastructure organizations under Thailand's Cybersecurity Act B.E. 2562 (2019).
  • The notification covers IaaS, PaaS, SaaS, and combined services; the Cloud Service Customer (CSC) and Cloud Service Provider (CSP) have distinct considerations.
  • Implementation must consider the impact level of the data or information system. Personal data must have, at minimum, a medium confidentiality impact level.

Shared accountability and provider evidence

The standard requires cloud customers and providers to agree and record appropriate information-security roles, duties, and responsibilities.

Thai infographic explaining: Shared accountability and provider evidence
Visual guide: Shared accountability and provider evidence
  • Before use, identify relevant legal jurisdictions, potential data-storage countries/locations, and applicable contractual requirements.
  • Customers must obtain evidence of a provider's compliance with relevant law, standards, and contractual requirements.
  • Where a per-customer audit is not feasible, providers must show independent evidence or self-assess and disclose the process and results under the standard's conditions.

Control areas to plan jointly

The annex addresses both customer processes and capabilities a provider must disclose or support.

Thai infographic explaining: Control areas to plan jointly
Visual guide: Control areas to plan jointly
  • Asset inventory and data labelling; access control, authentication, and access restriction.
  • Cryptography and key management; data-center location; secure disposal or reuse; and personal-data protection.
  • Change and capacity management, backups, event logging, vulnerability management, and network/tenant segregation.

Evidence and reporting

Turn the requirements into auditable evidence from service selection through contract review and operation.

Thai infographic explaining: Evidence and reporting
Visual guide: Evidence and reporting
  • Keep impact classification, selected requirements, contracts and responsibility allocation, provider evidence, and review results together.
  • The notification requires an agency to submit a summary implementation report to NCSA within 30 days after completion.
  • Private organizations should assess adoption against their contracts, risk, and applicable law; this page is not a legal applicability determination.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Chapters 1 and 2 (NCSA 2024) Cloud Service Models and Shared Responsibility Framework IaaS, PaaS, and SaaS workloads for public sector entities At least annually
Chapters 3 and 4 (NCSA 2024) Access Control, Data Encryption, and Multi-Tenant Network Isolation IAM Roles, Key Management, Data Encryption, and Cloud Boundaries Pre-migration and annual

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (2024)

NCSA Notification: Cybersecurity Standards for Cloud Systems B.E. 2567 (2024)

By NCSA

Open document (PDF) Source