NCSA Website Security Standard B.E. 2568
The Website Security Standard covers governance and security operations across website architectures.
Making the NCSA website standard an operational cycle
The standard connects governance, impact assessment, self-assessment, and improvement. Technical testing should therefore cover the website's real architecture.

- Confirm that the entity and site are in scope, then classify impact before selecting controls and evidence.
- The Form Kor 1 self-assessment cycle should draw on evidence from relevant web applications, web servers, databases, and cloud or web-hosting components.
- For nonconformity, create a Form Kor 2 improvement plan with owner, due date, and follow-up method instead of closing an issue with a test report alone.
- Pentesting is technical evidence for website-security operations. It does not automatically turn the standard into a mandatory annual pentest for every site.
NCSA / WEBSITE SECURITY STANDARD
The Website Security Standard covers governance and security operations across website architectures.
ใครต้องทำและ Penetration Testing เกี่ยวข้องอย่างไร
- ใช้บังคับกับหน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) ส่วนเอกชนทั่วไปได้รับการส่งเสริมให้นำไปใช้
- ประกาศลงวันที่ 16 กันยายน 2568 และมีผลเมื่อพ้นหนึ่งปี จึงมีผลวันที่ 16 กันยายน 2569
- หน่วยงานในขอบเขตต้องประเมินตนเองตามแบบ ค๑ อย่างน้อยปีละ 1 ครั้ง ประเมินระดับผลกระทบ รายงานตามระดับ และจัดทำแผนแก้ไขแบบ ค๒ เมื่อไม่สอดคล้อง
- มาตรฐานไม่ได้ทำให้การประเมินตนเองกลายเป็นข้อบังคับ Penetration Testing รายปีโดยอัตโนมัติ แต่ Penetration Testing เป็นหลักฐานเชิงเทคนิคเพื่อพิสูจน์ Website Security Operation และช่องโหว่ที่โจมตีได้จริง
Scope ควรครอบคลุม Web Application, Web Server, Database และ Cloud หรือ Web Hosting ที่เกี่ยวข้อง ตามสถาปัตยกรรมและระดับผลกระทบของเว็บไซต์ ไม่ใช่ตรวจเฉพาะหน้าเว็บ
Practical guidance and tools for the Website Security Standard
WSS by STH turns the Website Security Standard B.E. 2568 (2025) into an actionable checklist for governance, risk assessment, development, operations, and remediation evidence.
Educational video: Website Security Standard
Watch this educational video for an introduction to the standard and its application to organizational websites.
Who should act
Appendix Kor includes Form Kor 1 for state agencies, regulators, critical information infrastructure organisations, and private entities. For private entities, the standard encourages adoption rather than imposing the same duty level as for state agencies, regulators, or CII organisations.

State agencies
Inventory agency sites that provide public information or online services, then identify the system owner and URL.
Regulators
Assign accountable owners, follow up on compliance, and retain evidence that can be audited.
CII organisations
Consider service criticality and infrastructure dependencies before prioritising remediation.
Private entities (encouraged to adopt)
Private organisations with public-facing information or online-service sites are encouraged to adopt the guidance, beginning with the site and dependencies such as cloud or web hosting.
A category appearing in Form Kor 1 does not replace the scope assessment or duties that may apply under a specific law or organisational requirement.
Using Forms Kor 1 and Kor 2
Form Kor 1 records the self-assessment. Form Kor 2 creates a remediation plan for items that the assessment identifies as still requiring improvement. Together they give every finding an owner, evidence, and follow-up path.

Form Kor 1: self-assess and retain evidence
- Record site information: entity, site owner, URL, service type, and implementation model such as on-premises, cloud service, or web hosting.
- Assess requirements and recommendations, retaining evidence such as configurations, operating records, test reports, or provider documentation.
- Use the status that matches reality: completed, in progress, or not started. Mark a requirement as still needing improvement when it is not complete.
Form Kor 2: turn remaining items into remediation
- Bring forward only items from Form Kor 1 that still need improvement, rather than duplicating completed items as plan work.
- Record the outstanding requirement, cause, initial remediation, and the remediation work that remains.
- Assign an owner and due date, then follow up and review the evidence after remediation before updating the next assessment cycle.
Field names and usage guidance are based on Appendix Kor, pages 47-49, and Form Kor 2, page 69, of the hosted standard.
