Thailand’s Cloud Security Standard Is Now in Force: What Providers and CII Operators Must Review

Thailand’s Cloud Security Standard Is Now in Force: What Providers and CII Operators Must Review

Thailand’s new Cloud Security Standard is now in force as NCSA builds out the certification system for covered cloud providers and customers. Image: NECTEC / National Electronics and Computer Technology Center

Thailand’s Cloud Security Standard took effect Sept. 10, 2026, raising compliance requirements for government, CII organizations, and cloud providers.

Sep 11, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

Thailand’s two-year runway for cloud security compliance has ended. The country’s Cloud Security Standard took effect Sept. 10, 2026, two years after its publication in the Royal Gazette.

The rules cover government agencies, regulatory and supervisory bodies, critical information infrastructure organizations, and public-cloud providers serving those entities under contract. Organizations in scope now need to classify cloud systems by impact, review security controls and contracts, and prepare the evidence required for compliance and certification.

Thailand’s National Cyber Security Agency says the standard supports the government’s Cloud First Policy and sets minimum controls for covered cloud environments. The change comes amid broader scrutiny of Thailand’s digital infrastructure: On Sept. 4, operators of 49 data centers were asked to pause construction voluntarily while officials develop new power, water, safety, and approval rules.

Impact levels shape the compliance burden

The framework separates cloud service customers, or CSCs, from cloud service providers, or CSPs. Covered customers include government agencies, CII organizations, and regulatory or supervisory bodies with formal cloud-service agreements.

Systems are classified as low, moderate, or high impact based on the potential consequences of losing confidentiality, integrity, or availability. NCSA’s cloud customer certification guidance calls for asset inventories, system scope, risk assessments, security policies, data classifications, and contracts or service-level agreements.

Providers must define service scope and architecture, document applicable controls, assess risks, and prepare business continuity and disaster recovery plans. The agency’s CSP certification requirements also call for SLAs and documented shared responsibilities with customers.

The official Cloud Security Standard scales security controls and assurance requirements according to impact level. Thailand has also begun expanding its compliance-assessment capacity. On Sept. 1, NCSA recognized NECTEC’s Digital Technology Evaluation and Certification Institute as its first cloud-security certification body.

Advertisement

Contracts move to the center of cloud compliance

Organizations should first determine which systems fall within scope, what information they handle, and which impact level applies. Security teams can then review access controls, risk assessments, incident-response procedures, continuity and recovery plans, and certification evidence. The Philippine ownCloud data-theft case showed how vulnerable internet-facing systems can expose sensitive government and research data.

Contracts require the same scrutiny. Customers and providers should confirm how SLAs divide security duties, address nonconformities, and support recovery or exit from a service. Similar concerns underpin direct oversight of major cloud providers in the UK, where regulated financial firms remain responsible for outsourcing, resilience, risk management, and contingency planning.

Thailand could tighten vendor oversight further. A proposed Cybersecurity Act amendment would require CII organizations to monitor external providers and could allow regulators to direct customers to consider ending services if a provider fails to remedy noncompliance within 60 days.

The proposal is not in force. Baker McKenzie said in an Aug. 13 analysis that it would still require Cabinet and parliamentary consideration, Royal Assent, and publication in the Government Gazette.

The Cloud Security Standard is now in force, leaving covered organizations to address its controls and certification requirements while monitoring the amendment for additional vendor obligations.

Let us teach you How to Talk to AI for free! Try our six-minute course at The Neuron Academy and learn a few simple ways to write better prompts and get more useful results from AI, or browse our other AI course for free for seven days. Check out all the lessons here →