Penetration testing under Thai SEC requirements
The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.
What to confirm under the applicable Thai SEC requirements
Define critical systems from the actual licence and service, then align testing, reporting, and remediation evidence with the notice governing that business.

- SEC IT requirements distinguish vulnerability assessment from penetration testing, so scanner output alone is not a replacement for a penetration test.
- Public-network-connected systems and networks have annual and significant-change testing conditions under the relevant requirements.
- For digital-asset businesses, scope should include actual critical services such as trading, wallet or custody, customer portals, APIs, and infrastructure rather than only a website.
- For digital-asset requirements, confirm the current 30-day post-result and 90-day post-test reporting timelines against the latest applicable notice.
SEC Penetration Testing Requirements
SECURITIES AND EXCHANGE COMMISSION
Information technology requirements for regulated businesses, designed to ensure important systems are appropriately tested, reported, and remediated.
Core Penetration Testing requirements
- Internet-facing application systems and networks must be tested at least annually and whenever they undergo a significant change.
- Other systems require an assessment of intrusion risk through internal networks to determine an appropriate testing scope.
- Testing must be performed by an internal or external specialist independent of the system owner and development. Scanner-only testing is a vulnerability assessment and cannot replace Penetration Testing.
- Identified vulnerabilities must be remediated and mitigated promptly. Reports must be retained for at least two years and provided to the SEC on request.
- Reports should identify the tester, date, scope, vulnerabilities, detection methods, risk ratings, and recommended remediation.
Applicable requirements depend on the business's licence and governing notices. Confirm them with Compliance or legal counsel before defining scope.
Penetration Testing Requirements for Digital Asset Businesses
SEC / DIGITAL ASSET BUSINESS
Thai SEC requirements for licensed digital-asset businesses, not requirements issued by the Stock Exchange of Thailand.
ข้อกำหนดโดยตรงสำหรับระบบงานสำคัญ
- ครอบคลุมผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลตามประเภทใบอนุญาตที่เกี่ยวข้อง เช่น Exchange, Broker, Dealer, Advisory Service และ Fund Manager
- ข้อ 18 กำหนดให้ทดสอบเจาะระบบงานสำคัญก่อนเริ่มให้บริการ และหลังเริ่มให้บริการอย่างน้อยปีละ 1 ครั้ง โดยบุคคลที่เป็นอิสระจากหน่วยงาน IT ที่รับผิดชอบระบบ
- ต้องรายงานผลต่อสำนักงาน ก.ล.ต. ภายใน 30 วันนับจากวันที่ได้รับผลอย่างเป็นทางการ และไม่เกิน 90 วันนับจากวันที่สิ้นสุดกระบวนการทดสอบ
- Scope ต้องเชื่อมกับระบบงานสำคัญจริงของใบอนุญาต เช่น Trading, Wallet/Custody, Customer Portal, API, Infrastructure และระบบสนับสนุนที่มีผลต่อบริการ
ธุรกิจสินทรัพย์ดิจิทัลอยู่ภายใต้สำนักงาน ก.ล.ต. ไม่ใช่ SET และรายละเอียดที่ใช้จริงขึ้นกับประเภทใบอนุญาตและประกาศฉบับประมวลล่าสุด
