Educational Information Only — Not Legal Advice

    This site provides educational information only and is not a substitute for professional legal advice. Consult a qualified Thai lawyer for personalized guidance. Laws may change. Full DisclaimerPrivacy Policy

    Skip to main content
    Last updated:
    Share:

    Educational Information Only

    The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.

    Back to Legal News
    Regulatory Updates

    Cybersecurity Act and NCSA Thailand: CII Registration, Reporting, and Compliance

    The Cybersecurity Act B.E. 2562 (2019) requires Critical Information Infrastructure (CII) organisations to register with the National Cybersecurity Agency (NCSA), implement security standards, and report incidents within statutory deadlines. This guide covers who counts as CII, reporting obligations, and penalties.

    5/19/202612 min read read
    Cybersecurity-Act
    NCSA
    CII
    incident-response
    ISO-27001
    ThaiCERT
    compliance

    TL;DR

    The Cybersecurity Act B.E. 2562 (2019) (พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์ พ.ศ. 2562) — enacted on 27 May 2019 and operating under the National Cybersecurity Agency (NCSA / สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ) — imposes a tiered regulatory regime on Critical Information Infrastructure (CII) organisations across eight designated sectors. CII operators must register with NCSA, adopt minimum cybersecurity standards (broadly aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework), maintain a Cybersecurity Risk Management Plan (CRMP) and an Incident Response Plan (IRP), conduct annual audits, and report cyber threats and incidents within deadlines that range from 24 hours for severe events to 72 hours for less serious incidents. Non-compliance with NCSA orders attracts administrative penalties and, in defined cases, criminal liability. The regime sits alongside — not instead of — the PDPA's 72-hour breach notification, the Computer-related Crime Act B.E. 2550 (2007) as amended 2017, and sector regulators such as the BOT and SEC.

    The Statutory Architecture

    The Cybersecurity Act B.E. 2562 (2019) creates three institutional layers:

    • National Cybersecurity Committee — policy body chaired by the Prime Minister.
    • Cybersecurity Regulating Committee — executive supervisory committee.
    • NCSA Office — operational regulator and CERT coordinator, headed by the Secretary-General.

    The Act distinguishes between three categories of cyber threat by severity — non-critical, critical, and crisis — and confers escalating powers on NCSA. At the highest category, the NCSA can issue binding orders to CII operators and, with judicial confirmation, take control of compromised systems.

    The Eight CII Sectors

    #SectorPrimary regulator
    1National SecurityMinistry of Defence / Council of National Security
    2Important Public ServicesMinistry of Interior
    3Banking & FinanceBOT / SEC / OIC
    4ICT InfrastructureNBTC / MDES
    5Transportation & LogisticsMinistry of Transport
    6Energy & Public UtilitiesERC / DEDE
    7Public HealthMinistry of Public Health
    8Other sectors designated by NCSANCSA + relevant ministry

    Each sector regulator works with NCSA to designate specific organisations as CII operators based on systemic impact, dependency analysis, and infrastructure interconnection.

    CII Designation Criteria

    NCSA assesses candidate organisations on:

    • Number of dependent users or beneficiaries affected by service disruption.
    • Economic impact of disruption (THB threshold benchmarks).
    • Public-safety and national-security implications.
    • Cross-sector cascading effect (e.g., an electricity grid failure on hospital operations).
    • Time sensitivity of service restoration.

    Designation is published in the Royal Gazette. Operators receive formal notification and have a transition period to register and submit baseline documents.

    Registration with NCSA

    Following designation, the CII operator must register on the NCSA portal and submit:

    • Organisation profile and ownership.
    • Critical systems inventory and dependency map.
    • Designated cybersecurity officer / CISO equivalent with contact details for 24/7 incident liaison.
    • Baseline Cybersecurity Risk Management Plan (CRMP).
    • Baseline Incident Response Plan (IRP).

    NCSA may request supplementary information, audit results, or evidence of standard certification. Failure to register triggers administrative orders and, on continued non-compliance, monetary penalties.

    Minimum Security Standards

    The NCSA-issued Notification on Minimum Cybersecurity Standards requires CII operators to implement controls aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover). Specific controls include:

    • Asset and risk inventory, annually reviewed.
    • Access control, MFA for privileged accounts.
    • Secure software development lifecycle (S-SDLC) and patch management.
    • 24/7 security operations or contracted MSSP equivalent.
    • Penetration testing and vulnerability assessment annually.
    • Business continuity and disaster recovery testing.
    • Third-party / supply-chain risk management.

    Incident Reporting Deadlines

    Threat levelNCSA notification deadlineTypical examples
    CrisisImmediate / 24 hoursActive control-system compromise; national-impact ransomware
    Critical24-48 hoursConfirmed intrusion with data exfiltration risk
    Non-critical but reportable72 hoursDefaced public-facing site; targeted phishing succeeding on single account
    Post-incident report30 daysRoot cause, scope, remediation, lessons learnt

    Where the incident also involves personal data, the PDPA Section 37 72-hour clock runs in parallel — the two regimes intersect but do not substitute for one another.

    Audit and Compliance Verification

    CII operators must undergo periodic independent audits (typically annual) by NCSA-approved auditors. The audit covers the CRMP, IRP, control implementation, training, and prior-incident remediation. Audit reports are filed with NCSA; deficiencies attract corrective orders.

    CERT and CSIRT Ecosystem

    • ThaiCERT (operated under NCSA) is the national CERT; coordinates cross-sector incidents.
    • Sector CSIRTs — TB-CERT (Thai Banking), TCSIRT (Telecom), etc. — operate as front-line responders within sector.
    • CII operators are expected to have an internal CSIRT or a contracted equivalent capable of 24/7 response.

    Penalties

    ConductPenaltySource
    Failure to comply with NCSA ordersAdministrative fine + escalating measures; criminal liability for wilful obstructionCybersecurity Act, Sections 70-77
    Obstruction of NCSA investigationUp to 1 year imprisonment and/or finesCybersecurity Act, Section 74
    False reportingCriminal penalties under Cybersecurity Act and Criminal Code B.E. 2499 (1956)Cybersecurity Act, Section 76
    Concurrent PDPA breachUp to THB 5M administrative finePDPA Section 78

    Intersection with Other Statutes

    • Computer-related Crime Act B.E. 2550 (2007) as amended B.E. 2560 (2017) — substantive offences (unauthorised access, system damage, illegal content).
    • PDPA B.E. 2562 (2019) — personal data breach notification (separate 72-hour clock to PDPC).
    • Anti-Money Laundering Act B.E. 2542 (1999) — for financial CII, fraud-loss reporting overlaps.
    • Sector regulator rules — BOT cyber resilience standards for banks; SEC for capital markets; ERC for energy; OIC for insurers.

    Common Mistakes

    Avoid these traps:
    • Assuming "not a tech company" means not CII. Hospitals, ports, water utilities, and large retailers handling payment infrastructure can all be designated.
    • One IRP for both NCSA and PDPC. The two regimes share facts but have different audiences, deadlines, and content requirements.
    • No after-hours contact roster. A 24-hour notification deadline is impossible without a duty officer schedule.
    • Forgetting supply-chain risk. CII auditors increasingly assess major vendors as part of the operator's risk profile.
    • Treating ISO 27001 certification as a finish line. The NCSA standard goes beyond ISO 27001 in operational specificity; certification helps but does not exempt.
    • Late post-incident report. The 30-day reflective report is often missed even when the initial notification was timely.

    FAQs

    1. Who designates a CII operator?

    The Cybersecurity Regulating Committee, on recommendation from the sector regulator and NCSA, with publication in the Royal Gazette.

    2. Is the Cybersecurity Act extraterritorial?

    It applies to organisations operating CII in Thailand, regardless of nationality of ownership. Foreign companies running Thai data centres or critical services are within scope.

    3. Does NCSA share data with foreign CERTs?

    Yes, under cooperation arrangements with APCERT, FIRST, and bilateral MOUs. Sensitive operational data is handled under confidentiality agreements.

    4. Can a CII operator outsource its CSIRT?

    Yes, to a qualified MSSP, but accountability for compliance with the Cybersecurity Act remains with the operator.

    5. What is the relationship between the 72-hour PDPA clock and the 72-hour cybersecurity clock?

    They run in parallel. A single incident affecting personal data and CII triggers separate notifications to PDPC and NCSA, even if the underlying facts are identical.

    Related Reading

    Professional Legal Assistance

    blog.ctaContext

    Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.

    blog.templatePromo.title

    blog.templatePromo.description

    blog.templatePromo.cta

    Stay Informed

    Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.

    Subscribing does not create a lawyer-client relationship. Please don't include confidential information. Anglo Siam Law is an educational platform — for representation, contact Anglo Siam Legal.

    Topics you're interested in (optional)

    We respect your privacy. Unsubscribe anytime.

    feedback.wasThisHelpful