Penetration testing under Thai SEC requirements
The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.
What to confirm under the applicable Thai SEC requirements
Define critical systems from the actual licence and service, then align testing, reporting, and remediation evidence with the notice governing that business.

- SEC IT requirements distinguish vulnerability assessment from penetration testing, so scanner output alone is not a replacement for a penetration test.
- Public-network-connected systems and networks have annual and significant-change testing conditions under the relevant requirements.
- For digital-asset businesses, scope should include actual critical services such as trading, wallet or custody, customer portals, APIs, and infrastructure rather than only a website.
- For digital-asset requirements, confirm the current 30-day post-result and 90-day post-test reporting timelines against the latest applicable notice.
SEC Penetration Testing Requirements
SECURITIES AND EXCHANGE COMMISSION
Information technology requirements for regulated businesses, designed to ensure important systems are appropriately tested, reported, and remediated.
Core Penetration Testing requirements
- Internet-facing application systems and networks must be tested at least annually and whenever they undergo a significant change.
- Other systems require an assessment of intrusion risk through internal networks to determine an appropriate testing scope.
- Testing must be performed by an internal or external specialist independent of the system owner and development. Scanner-only testing is a vulnerability assessment and cannot replace Penetration Testing.
- Identified vulnerabilities must be remediated and mitigated promptly. Reports must be retained for at least two years and provided to the SEC on request.
- Reports should identify the tester, date, scope, vulnerabilities, detection methods, risk ratings, and recommended remediation.
Applicable requirements depend on the business's licence and governing notices. Confirm them with Compliance or legal counsel before defining scope.
Penetration Testing Requirements for Digital Asset Businesses
SEC / DIGITAL ASSET BUSINESS
Thai SEC requirements for licensed digital-asset businesses, not requirements issued by the Stock Exchange of Thailand.
Direct requirements for critical systems
- It covers relevant licensed digital-asset business types, including exchanges, brokers, dealers, advisory services, and fund managers.
- Clause 18 requires Penetration Testing of critical systems before service commencement and at least annually after commencement, performed by a person independent of the IT unit responsible for the systems.
- Results must be reported to the SEC within 30 days of receiving the official result and no later than 90 days after the testing process ends.
- Scope should reflect the license's actual critical systems, such as trading, wallet or custody, customer portals, APIs, infrastructure, and supporting systems affecting the service.
Digital-asset businesses are regulated by the Thai SEC, not the Stock Exchange of Thailand. Applicable details depend on license type and the latest consolidated rules.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| SorThor 38/2565 / NorPor 6/2567 | Internet-facing penetration testing for securities businesses | Order Placement Engines, Mobile Trading Apps, Client Portals, Trading APIs | At least annually and after significant system changes |
| Digital-asset clause 18 | Penetration testing of critical digital-asset systems | Crypto Exchanges, Matching Engines, Hot and Cold Wallets, Key Custody APIs | Before go-live and at least annually thereafter |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
