Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
Cybersecurity Act and NCSA Thailand: CII Registration, Reporting, and Compliance
The Cybersecurity Act B.E. 2562 (2019) requires Critical Information Infrastructure (CII) organisations to register with the National Cybersecurity Agency (NCSA), implement security standards, and report incidents within statutory deadlines. This guide covers who counts as CII, reporting obligations, and penalties.
TL;DR
The Cybersecurity Act B.E. 2562 (2019) (พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562) — enacted on 27 May 2019 and operating under the National Cybersecurity Agency (NCSA / สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ) — imposes a tiered regulatory regime on Critical Information Infrastructure (CII) organisations across eight designated sectors. CII operators must register with NCSA, adopt minimum cybersecurity standards (broadly aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework), maintain a Cybersecurity Risk Management Plan (CRMP) and an Incident Response Plan (IRP), conduct annual audits, and report cyber threats and incidents within deadlines that range from 24 hours for severe events to 72 hours for less serious incidents. Non-compliance with NCSA orders attracts administrative penalties and, in defined cases, criminal liability. The regime sits alongside — not instead of — the PDPA's 72-hour breach notification, the Computer-related Crime Act B.E. 2550 (2007) as amended 2017, and sector regulators such as the BOT and SEC.
The Statutory Architecture
The Cybersecurity Act B.E. 2562 (2019) creates three institutional layers:
- National Cybersecurity Committee — policy body chaired by the Prime Minister.
- Cybersecurity Regulating Committee — executive supervisory committee.
- NCSA Office — operational regulator and CERT coordinator, headed by the Secretary-General.
The Act distinguishes between three categories of cyber threat by severity — non-critical, critical, and crisis — and confers escalating powers on NCSA. At the highest category, the NCSA can issue binding orders to CII operators and, with judicial confirmation, take control of compromised systems.
The Eight CII Sectors
| # | Sector | Primary regulator |
|---|---|---|
| 1 | National Security | Ministry of Defence / Council of National Security |
| 2 | Important Public Services | Ministry of Interior |
| 3 | Banking & Finance | BOT / SEC / OIC |
| 4 | ICT Infrastructure | NBTC / MDES |
| 5 | Transportation & Logistics | Ministry of Transport |
| 6 | Energy & Public Utilities | ERC / DEDE |
| 7 | Public Health | Ministry of Public Health |
| 8 | Other sectors designated by NCSA | NCSA + relevant ministry |
Each sector regulator works with NCSA to designate specific organisations as CII operators based on systemic impact, dependency analysis, and infrastructure interconnection.
CII Designation Criteria
NCSA assesses candidate organisations on:
- Number of dependent users or beneficiaries affected by service disruption.
- Economic impact of disruption (THB threshold benchmarks).
- Public-safety and national-security implications.
- Cross-sector cascading effect (e.g., an electricity grid failure on hospital operations).
- Time sensitivity of service restoration.
Designation is published in the Royal Gazette. Operators receive formal notification and have a transition period to register and submit baseline documents.
Registration with NCSA
Following designation, the CII operator must register on the NCSA portal and submit:
- Organisation profile and ownership.
- Critical systems inventory and dependency map.
- Designated cybersecurity officer / CISO equivalent with contact details for 24/7 incident liaison.
- Baseline Cybersecurity Risk Management Plan (CRMP).
- Baseline Incident Response Plan (IRP).
NCSA may request supplementary information, audit results, or evidence of standard certification. Failure to register triggers administrative orders and, on continued non-compliance, monetary penalties.
Minimum Security Standards
The NCSA-issued Notification on Minimum Cybersecurity Standards requires CII operators to implement controls aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover). Specific controls include:
- Asset and risk inventory, annually reviewed.
- Access control, MFA for privileged accounts.
- Secure software development lifecycle (S-SDLC) and patch management.
- 24/7 security operations or contracted MSSP equivalent.
- Penetration testing and vulnerability assessment annually.
- Business continuity and disaster recovery testing.
- Third-party / supply-chain risk management.
Incident Reporting Deadlines
| Threat level | NCSA notification deadline | Typical examples |
|---|---|---|
| Crisis | Immediate / 24 hours | Active control-system compromise; national-impact ransomware |
| Critical | 24-48 hours | Confirmed intrusion with data exfiltration risk |
| Non-critical but reportable | 72 hours | Defaced public-facing site; targeted phishing succeeding on single account |
| Post-incident report | 30 days | Root cause, scope, remediation, lessons learnt |
Where the incident also involves personal data, the PDPA Section 37 72-hour clock runs in parallel — the two regimes intersect but do not substitute for one another.
Audit and Compliance Verification
CII operators must undergo periodic independent audits (typically annual) by NCSA-approved auditors. The audit covers the CRMP, IRP, control implementation, training, and prior-incident remediation. Audit reports are filed with NCSA; deficiencies attract corrective orders.
CERT and CSIRT Ecosystem
- ThaiCERT (operated under NCSA) is the national CERT; coordinates cross-sector incidents.
- Sector CSIRTs — TB-CERT (Thai Banking), TCSIRT (Telecom), etc. — operate as front-line responders within sector.
- CII operators are expected to have an internal CSIRT or a contracted equivalent capable of 24/7 response.
Penalties
| Conduct | Penalty | Source |
|---|---|---|
| Failure to comply with NCSA orders | Administrative fine + escalating measures; criminal liability for wilful obstruction | Cybersecurity Act, Sections 70-77 |
| Obstruction of NCSA investigation | Up to 1 year imprisonment and/or fines | Cybersecurity Act, Section 74 |
| False reporting | Criminal penalties under Cybersecurity Act and Criminal Code B.E. 2499 (1956) | Cybersecurity Act, Section 76 |
| Concurrent PDPA breach | Up to THB 5M administrative fine | PDPA Section 78 |
Intersection with Other Statutes
- Computer-related Crime Act B.E. 2550 (2007) as amended B.E. 2560 (2017) — substantive offences (unauthorised access, system damage, illegal content).
- PDPA B.E. 2562 (2019) — personal data breach notification (separate 72-hour clock to PDPC).
- Anti-Money Laundering Act B.E. 2542 (1999) — for financial CII, fraud-loss reporting overlaps.
- Sector regulator rules — BOT cyber resilience standards for banks; SEC for capital markets; ERC for energy; OIC for insurers.
Common Mistakes
Avoid these traps:
- Assuming "not a tech company" means not CII. Hospitals, ports, water utilities, and large retailers handling payment infrastructure can all be designated.
- One IRP for both NCSA and PDPC. The two regimes share facts but have different audiences, deadlines, and content requirements.
- No after-hours contact roster. A 24-hour notification deadline is impossible without a duty officer schedule.
- Forgetting supply-chain risk. CII auditors increasingly assess major vendors as part of the operator's risk profile.
- Treating ISO 27001 certification as a finish line. The NCSA standard goes beyond ISO 27001 in operational specificity; certification helps but does not exempt.
- Late post-incident report. The 30-day reflective report is often missed even when the initial notification was timely.
FAQs
1. Who designates a CII operator?
The Cybersecurity Regulating Committee, on recommendation from the sector regulator and NCSA, with publication in the Royal Gazette.
2. Is the Cybersecurity Act extraterritorial?
It applies to organisations operating CII in Thailand, regardless of nationality of ownership. Foreign companies running Thai data centres or critical services are within scope.
3. Does NCSA share data with foreign CERTs?
Yes, under cooperation arrangements with APCERT, FIRST, and bilateral MOUs. Sensitive operational data is handled under confidentiality agreements.
4. Can a CII operator outsource its CSIRT?
Yes, to a qualified MSSP, but accountability for compliance with the Cybersecurity Act remains with the operator.
5. What is the relationship between the 72-hour PDPA clock and the 72-hour cybersecurity clock?
They run in parallel. A single incident affecting personal data and CII triggers separate notifications to PDPC and NCSA, even if the underlying facts are identical.
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful