Siam Thanat Hack Co., Ltd.

Penetration testing under Thai SEC requirements

The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.

Executive Summary and Mandate Overview
Target Audience Securities Firms, Asset Managers, Digital Asset Exchanges and Custodians in Thailand
Mandatory Frequency At least annually and post-major trading platform updates
Required Scope Trading Engines, Mobile Trading Apps, Crypto Vaults, Authentication APIs
Non-Compliance Risk SEC regulatory warnings, license suspension, or mandatory trading halts

What to confirm under the applicable Thai SEC requirements

Define critical systems from the actual licence and service, then align testing, reporting, and remediation evidence with the notice governing that business.

Thai infographic explaining: What to confirm under the applicable Thai SEC requirements
Visual summary: What to confirm under the applicable Thai SEC requirements
  • SEC IT requirements distinguish vulnerability assessment from penetration testing, so scanner output alone is not a replacement for a penetration test.
  • Public-network-connected systems and networks have annual and significant-change testing conditions under the relevant requirements.
  • For digital-asset businesses, scope should include actual critical services such as trading, wallet or custody, customer portals, APIs, and infrastructure rather than only a website.
  • For digital-asset requirements, confirm the current 30-day post-result and 90-day post-test reporting timelines against the latest applicable notice.

SEC Penetration Testing Requirements

SECURITIES AND EXCHANGE COMMISSION

Information technology requirements for regulated businesses, designed to ensure important systems are appropriately tested, reported, and remediated.

Core Penetration Testing requirements

  • Internet-facing application systems and networks must be tested at least annually and whenever they undergo a significant change.
  • Other systems require an assessment of intrusion risk through internal networks to determine an appropriate testing scope.
  • Testing must be performed by an internal or external specialist independent of the system owner and development. Scanner-only testing is a vulnerability assessment and cannot replace Penetration Testing.
  • Identified vulnerabilities must be remediated and mitigated promptly. Reports must be retained for at least two years and provided to the SEC on request.
  • Reports should identify the tester, date, scope, vulnerabilities, detection methods, risk ratings, and recommended remediation.
Applicability

Applicable requirements depend on the business's licence and governing notices. Confirm them with Compliance or legal counsel before defining scope.

Penetration Testing Requirements for Digital Asset Businesses

SEC / DIGITAL ASSET BUSINESS

Thai SEC requirements for licensed digital-asset businesses, not requirements issued by the Stock Exchange of Thailand.

Direct requirements for critical systems

  • It covers relevant licensed digital-asset business types, including exchanges, brokers, dealers, advisory services, and fund managers.
  • Clause 18 requires Penetration Testing of critical systems before service commencement and at least annually after commencement, performed by a person independent of the IT unit responsible for the systems.
  • Results must be reported to the SEC within 30 days of receiving the official result and no later than 90 days after the testing process ends.
  • Scope should reflect the license's actual critical systems, such as trading, wallet or custody, customer portals, APIs, infrastructure, and supporting systems affecting the service.
The regulator is the SEC

Digital-asset businesses are regulated by the Thai SEC, not the Stock Exchange of Thailand. Applicable details depend on license type and the latest consolidated rules.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
SorThor 38/2565 / NorPor 6/2567 Internet-facing penetration testing for securities businesses Order Placement Engines, Mobile Trading Apps, Client Portals, Trading APIs At least annually and after significant system changes
Digital-asset clause 18 Penetration testing of critical digital-asset systems Crypto Exchanges, Matching Engines, Hot and Cold Wallets, Key Custody APIs Before go-live and at least annually thereafter

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview of SEC penetration testing requirements

SEC penetration testing requirements

By Thai SEC

Open document (PDF) Download Source

First-page preview of Information technology questions and answers

Information technology questions and answers

By Thai SEC

Open document (PDF) Download Source

First-page preview of IT requirements for digital asset businesses

IT requirements for digital asset businesses

By Thai SEC

Open document (PDF) Download Source