# Thailand Digital ID Framework: ETDA, DGA Standards, IAL/AAL Assurance, and Platform Security Verification

Locale: `en`

Source: `/en/compliance/thailand-digital-id/`

On this page

1. [Overview](/en/compliance/thailand-digital-id/#topic-overview)
2. [Distinguish identity proofing from authentication](/en/compliance/thailand-digital-id/#etda-digital-id-architecture)
3. [DGA 1-1 is the overview and 1-2 addresses Thai citizens](/en/compliance/thailand-digital-id/#dga-government-identity-standards)
4. [Separate electronic signatures from DPS applicability](/en/compliance/thailand-digital-id/#electronic-signatures-and-dps)
5. [Recommended tests for the deployed identity architecture](/en/compliance/thailand-digital-id/#digital-id-security-assessment)
6. [Requirements Matrix](/en/compliance/thailand-digital-id/#compliance-matrix)
7. [Readiness Assessment](/en/compliance/thailand-digital-id/#compliance-readiness-checklist)
8. [Frequently Asked Questions](/en/compliance/thailand-digital-id/#compliance-faq)
9. [Related Frameworks](/en/compliance/thailand-digital-id/#related-compliance-frameworks)

# Thailand Digital ID Framework: ETDA, DGA Standards, IAL/AAL Assurance, and Platform Security Verification

The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact.

Executive Summary and Mandate Overview

Target Audience

IdPs, RPs and government digital identity services, distinguishing licensed providers and platforms within DPS scope

Mandatory Frequency

Select schedules under operator-specific rules, policy and risk, with review after material changes. There is no common annual cycle for all services.

Required Scope

Identity proofing, authentication, electronic signatures, sessions, tokens and account recovery for the deployed architecture

Non-Compliance Risk

Impersonation, identity data leakage, weak recovery and misapplied regulatory requirements

## Distinguish identity proofing from authentication

The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact.

[![Thailand Digital ID: match standards to the service: Identity proofing: IAL, Authentication: AAL, DGA standards, Test the actual system](/assets/generated/compliance-refresh/guide-thailand-digital-id-compliance-control-summary-en-v2.webp)](/assets/generated/compliance-refresh/guide-thailand-digital-id-compliance-control-summary-en-v2.webp)

**Thailand Digital ID: match standards to the service**

Distinguish IAL, AAL and DGA standards, then select tests for the actual architecture rather than a universal testing cycle.

- **Identity proofing: IAL** — Select assurance for service risk
- **Authentication: AAL** — Choose factors and authenticators
- **DGA standards** — 1-1 is the overview and 1-2 covers Thai citizens
- **Test the actual system** — Verify tokens, sessions and recovery

- IAL concerns confidence in the claimed identity, covering identity resolution, evidence validation and identity verification at the selected level.
- AAL concerns authentication of an enrolled user. Levels 1, 2 and 3 have different factor and authenticator requirements. A biometric alone does not establish multi-factor authentication.
- The identity provider (IdP) and relying party (RP) need explicit responsibilities. A relying party is not a certificate authority.
- Read any IAL 2.1, 2.2 and 2.3 distinctions in the applicable standard and proofing method. Do not assign fixed chip-reading or liveness recipes to these levels without an exact source.

## DGA 1-1 is the overview and 1-2 addresses Thai citizens

DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality.

- Use DGS 1-1:2564 to understand roles and relationships. Its discussion of legal persons does not make DGS 1-2:2564 a corporate identity standard.
- Government service providers should assess service risk and select suitable IAL and AAL, including supported evidence sources and proofing methods.
- Set evidence retention under the law, regulation and policy applicable to the actual service. This guide does not impose a universal one-year logging period.
- Review enrollment, authenticator changes, revocation and account recovery for paths that weaken the intended assurance.

## Separate electronic signatures from DPS applicability

ETDA Recommendation 23-2563 provides guidance on electronic signatures. The DPS Royal Decree B.E. 2565 addresses qualifying digital platform services. They do not impose a common penetration-testing cycle on every service.

- The guidance distinguishes general signatures, reliable signatures, and reliable signatures using a certificate from a certification service provider. Read Sections 9, 26 and 28 in their legal context. Section 28 is not a separate definition of a third signature type.
- Select a signature method for transaction risk and verify signatory binding, document integrity and certificate trust where certificates are used.
- Check DPS applicability and any additional duties for platform size or risk. Do not transfer supervised Digital ID provider obligations to every digital platform.
- Select VA and penetration-testing schedules from the operator-specific requirements, policy and system risk. DPS Sections 18 to 20 do not establish a blanket annual penetration-testing mandate.

## Recommended tests for the deployed identity architecture

The following are STH assessment recommendations. Adapt them to deployed protocols, data and authorized scope. They are not quoted statutory requirements.

- For deployed OAuth 2.0, OIDC or SAML, verify signatures, issuer, audience, redirect URI, state, nonce and replay protection as applicable to the protocol.
- Test sessions, authenticator binding and revocation, step-up authentication and account recovery, including cross-account token misuse.
- Where biometrics are used, assess presentation attacks and privacy for supported methods. Application testing is distinct from biometric product certification.
- Use synthetic data, verify access boundaries, and retain remediation and retest evidence before acceptance.

## Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

| Reference | Mandate Title | Scope Required | Testing Cycle |
| --- | --- | --- | --- |
| **ETS 11-2566 Parts 1 to 3** | Distinguish identity proofing from authentication | The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact. | According to applicable scope and service risk, not a universal testing cycle |
| **DGS 1-1:2564 and DGS 1-2:2564** | DGA 1-1 is the overview and 1-2 addresses Thai citizens | DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality. | According to applicable scope and service risk, not a universal testing cycle |
| **ETDA Recommendation 23-2563 and DPS Royal Decree B.E. 2565** | Separate electronic signatures from DPS applicability | ETDA Recommendation 23-2563 provides guidance on electronic signatures. The DPS Royal Decree B.E. 2565 addresses qualifying digital platform services. They do not impose a common penetration-testing cycle on every service. | According to applicable scope and service risk, not a universal testing cycle |
| **STH assessment recommendations** | Recommended tests for the deployed identity architecture | The following are STH assessment recommendations. Adapt them to deployed protocols, data and authorized scope. They are not quoted statutory requirements. | According to applicable scope and service risk, not a universal testing cycle |

### Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Document service risk and the rationale for selected IAL and AAL, citing the applicable ETS 11-2566 parts.
          
          
            
            Record IdP and RP roles and applicable DGA, Digital ID and DPS scope, with data owners and evidence-retention rules.
          
          
            
            Verify signature evidence, document integrity and certificate trust where certificates are used.
          
          
            
            Test token, session, replay and account-recovery controls for deployed protocols, then track remediation and retest.

Assessment Status

Check items above to view assessment result.

[Request Pentest Quote](/en/#contact)

## Frequently Asked Questions (FAQ)

Key answers and practical guidance addressing common compliance questions.

### How do IAL and AAL differ?

IAL concerns confidence in the claimed identity, covering identity resolution, evidence validation and identity verification at the selected level. AAL concerns authentication of an enrolled user. Levels 1, 2 and 3 have different factor and authenticator requirements. A biometric alone does not establish multi-factor authentication.

### Does DGS 1-2:2564 cover legal persons?

DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality.

### Does the DPS decree require annual penetration testing of every platform?

Select VA and penetration-testing schedules from the operator-specific requirements, policy and system risk. DPS Sections 18 to 20 do not establish a blanket annual penetration-testing mandate.

## Related Compliance Frameworks and Security Standards

- [
                NDID member penetration testing requirements
                
              ](/en/compliance/ndid/)
- [
                Does Thailand's PDPA require penetration testing?
                
              ](/en/compliance/pdpa/)
- [
                Thailand Cybersecurity Act 2019 and penetration testing
                
              ](/en/compliance/cybersecurity-act/)
- [
                NCSA Website Security Standard 2025 and penetration testing
                
              ](/en/compliance/ncsa-website-standard/)

Open full-size image to zoom

## Official source documents

Current ETS 11-2566 Digital ID standards and supporting official sources

[Go to the official source ](https://www.etda.or.th/th/regulator/DigitalID/law.aspx)

- [ETS 11-2566 Part 1: framework](https://www.etda.or.th/getattachment/Regulator/DigitalID/law/ETS-DID-Part1-Framework_V01-22F.pdf.aspx?lang=th-TH)
- [ETS 11-2566 Part 2: identity proofing](https://www.etda.or.th/getattachment/Regulator/DigitalID/law/ETS-DID-Part2-IdentityProofing_V01-22F.pdf.aspx?lang=th-TH)
- [ETS 11-2566 Part 3: authentication](https://www.etda.or.th/getattachment/Regulator/DigitalID/law/ETS-DID-Part3-Authentication_V01-22F.pdf.aspx?lang=th-TH)
- [ETDA withdrawn recommendations](https://www.etda.or.th/th/Our-Service/Standard/Withdrawn-Rec.aspx)
- [DGA government Digital ID standards](https://standard.dga.or.th/news/3728/)
- [ETDA electronic signature guidance](https://www.etda.or.th/th/contact/faq/e-Signature.aspx)
- [ETDA Digital Platform Services regulation](https://www.etda.or.th/th/regulator/Digitalplatform/index.aspx)

## Need a pentest that satisfies these requirements?

Tell us about your systems and the requirements you must meet. The STH team will assess the approach and prepare a quotation.

[Request a Pentest quote](/en/#contact)

Last updated 6 October 2026
