Educational Information Only
The content on this page is for general educational purposes and does not constitute legal advice. Every legal situation is unique. For matters involving investigation, arrest, litigation, or formal proceedings, consult a qualified legal professional.
Cybersecurity Act B.E. 2562 (2019): NCSA, CII, and Sector Obligations
The Cybersecurity Act B.E. 2562 (2019) established the National Cyber Security Agency (NCSA) and the Critical Information Infrastructure (CII) framework. Designated CII organisations must register with NCSA, implement controls, and report incidents. This guide covers designation thresholds, obligations, and penalties.
TL;DR
The Cybersecurity Act B.E. 2562 (2019) (พระราชบัญญัติการรักษาความมั่นคงปลอดภัยไซเบอร์) established the National Cyber Security Agency (NCSA / สกมช.) and a tiered regulatory framework. Organisations designated as Critical Information Infrastructure (CII) across 8 sectors must register with NCSA, implement minimum controls, report incidents, and submit to NCSA inspection. Non-designated organisations have lighter obligations but may still be subject to incident reporting via the sectoral regulator. Penalties under Sections 70+ reach THB 200,000 per violation plus directors' personal liability.
Eight CII Sectors
- National security
- Public services (utilities, water, electricity)
- Banking and finance
- Information technology and telecommunications
- Transportation and logistics
- Energy and natural resources
- Public health
- Other sectors designated by NCSA Notification
CII Designation Criteria
| Factor | Indicator |
|---|---|
| Service significance | Impact on national security, economy, public services |
| Customer / user base | Scale of dependency |
| System interconnection | Cascade effect on other CII |
| Sector concentration | Limited alternative providers |
Obligations of Designated CII Organisations
- Register with NCSA and designate a Chief Information Security Officer (CISO).
- Implement information security management system aligned with NCSA standards (commonly ISO/IEC 27001 family + sectoral overlays).
- Maintain incident response capability and tested business continuity plans.
- Annual risk assessment and reporting.
- Incident reporting to NCSA within prescribed timelines (typically rapid — hours to days).
- Submit to NCSA inspection and audit.
- Cybersecurity awareness training for staff.
Incident Reporting Timelines
| Severity | Examples | Action |
|---|---|---|
| Critical | Service disruption, data exfiltration affecting national security | Immediate notification; full report within 24 hours |
| High | Significant breach, ransomware | Notification within 24-72 hours per NCSA guidance |
| Medium / Low | Contained incidents | Periodic reporting via NCSA dashboard |
NCSA Powers
- Inspect CII organisations.
- Issue directives in major incidents.
- Require remediation timelines.
- Coordinate sector-wide response to systemic threats.
- Cross-border cooperation with foreign cybersecurity agencies.
Penalties
- Administrative fines up to THB 200,000 per violation.
- Director liability for failure to implement controls.
- Compounding penalties for ongoing non-compliance.
- Reputational and regulatory consequences in regulated sectors.
Common Mistakes
Avoid these traps:
- Assuming non-designation now means non-applicability forever — NCSA can designate based on evolving criteria.
- Treating cybersecurity as IT-only — Cybersecurity Act expects board-level governance.
- Inadequate incident response — generic plans without tested playbooks fail under NCSA review.
- Conflicts with PDPA obligations — breach notification may have different timelines under Cybersecurity Act vs PDPA.
- Underestimating supply-chain risk — CII organisations are accountable for vendor security postures.
FAQs
1. How do I know if my organisation is designated CII?
NCSA publishes designations sectorally. Confirm with NCSA or sectoral regulator. Designation can change.
2. Is voluntary registration possible?Some sectoral regulators encourage voluntary disclosure or registration. NCSA cooperation programmes exist for non-designated entities.
3. How does the Cybersecurity Act interact with PDPA?Both apply concurrently. Personal data breach reporting under PDPA (72 hours to PDPC) is separate from cybersecurity incident reporting under Cybersecurity Act (NCSA). Both may be triggered by the same incident.
4. Are foreign-owned CII organisations subject to the same rules?Yes — application is jurisdictional, not nationality-based. Foreign-owned banks, telecoms, etc. operating in Thailand are within scope if designated.
5. What standards does NCSA reference?ISO/IEC 27001/27002, NIST Cybersecurity Framework, sectoral standards (Bank of Thailand cybersecurity standards for banking; SEC for capital markets; etc.). NCSA also issues Thai-specific notifications.
Related Reading
Professional Legal Assistance
blog.ctaContext
Anglo Siam Legal provides experienced legal services across Thailand for both Thai nationals and foreigners.
Stay Informed
Get the latest updates on Thai law changes, new guides, and legal resources delivered to your inbox.
We respect your privacy. Unsubscribe anytime.
feedback.wasThisHelpful