Siam Thanat Hack Co., Ltd.

Penetration testing under Thai SEC requirements

The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.

What to confirm under the applicable Thai SEC requirements

Define critical systems from the actual licence and service, then align testing, reporting, and remediation evidence with the notice governing that business.

Thai infographic explaining: What to confirm under the applicable Thai SEC requirements
Visual summary: What to confirm under the applicable Thai SEC requirements
  • SEC IT requirements distinguish vulnerability assessment from penetration testing, so scanner output alone is not a replacement for a penetration test.
  • Public-network-connected systems and networks have annual and significant-change testing conditions under the relevant requirements.
  • For digital-asset businesses, scope should include actual critical services such as trading, wallet or custody, customer portals, APIs, and infrastructure rather than only a website.
  • For digital-asset requirements, confirm the current 30-day post-result and 90-day post-test reporting timelines against the latest applicable notice.

SEC Penetration Testing Requirements

SECURITIES AND EXCHANGE COMMISSION

Information technology requirements for regulated businesses, designed to ensure important systems are appropriately tested, reported, and remediated.

Core Penetration Testing requirements

  • Internet-facing application systems and networks must be tested at least annually and whenever they undergo a significant change.
  • Other systems require an assessment of intrusion risk through internal networks to determine an appropriate testing scope.
  • Testing must be performed by an internal or external specialist independent of the system owner and development. Scanner-only testing is a vulnerability assessment and cannot replace Penetration Testing.
  • Identified vulnerabilities must be remediated and mitigated promptly. Reports must be retained for at least two years and provided to the SEC on request.
  • Reports should identify the tester, date, scope, vulnerabilities, detection methods, risk ratings, and recommended remediation.
Applicability

Applicable requirements depend on the business's licence and governing notices. Confirm them with Compliance or legal counsel before defining scope.

Penetration Testing Requirements for Digital Asset Businesses

SEC / DIGITAL ASSET BUSINESS

Thai SEC requirements for licensed digital-asset businesses, not requirements issued by the Stock Exchange of Thailand.

ข้อกำหนดโดยตรงสำหรับระบบงานสำคัญ

  • ครอบคลุมผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลตามประเภทใบอนุญาตที่เกี่ยวข้อง เช่น Exchange, Broker, Dealer, Advisory Service และ Fund Manager
  • ข้อ 18 กำหนดให้ทดสอบเจาะระบบงานสำคัญก่อนเริ่มให้บริการ และหลังเริ่มให้บริการอย่างน้อยปีละ 1 ครั้ง โดยบุคคลที่เป็นอิสระจากหน่วยงาน IT ที่รับผิดชอบระบบ
  • ต้องรายงานผลต่อสำนักงาน ก.ล.ต. ภายใน 30 วันนับจากวันที่ได้รับผลอย่างเป็นทางการ และไม่เกิน 90 วันนับจากวันที่สิ้นสุดกระบวนการทดสอบ
  • Scope ต้องเชื่อมกับระบบงานสำคัญจริงของใบอนุญาต เช่น Trading, Wallet/Custody, Customer Portal, API, Infrastructure และระบบสนับสนุนที่มีผลต่อบริการ
หน่วยงานที่ถูกต้องคือ ก.ล.ต.

ธุรกิจสินทรัพย์ดิจิทัลอยู่ภายใต้สำนักงาน ก.ล.ต. ไม่ใช่ SET และรายละเอียดที่ใช้จริงขึ้นกับประเภทใบอนุญาตและประกาศฉบับประมวลล่าสุด

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofSEC penetration testing requirements

SEC penetration testing requirements

By Thai SEC

Open document (PDF) Source

First-page preview ofInformation technology questions and answers

Information technology questions and answers

By Thai SEC

Open document (PDF) Source

First-page preview ofIT requirements for digital asset businesses

IT requirements for digital asset businesses

By Thai SEC

Open document (PDF) Source