Launches

Thailand's Cloud Security Standard Now Mandatory: What Organizations Must Do

Thailand's Cloud Security Standard became enforceable on September 10, 2026, ending a two-year transition period. Government agencies, critical infrastructure operators, and their cloud providers must now comply with new security classifications and certification requirements.

·3 min read
Thailand’s Cloud Security Standard Is Now in Force: What Providers and CII Operators Must Review
Thailand’s Cloud Security Standard Is Now in Force: What Providers and CII Operators Must Review

The compliance deadline has arrived in Thailand. After two years following its publication in the Royal Gazette, the nation's Cloud Security Standard entered into effect on Sept. 10, 2026.

The standard applies to government agencies, regulatory and supervisory bodies, critical information infrastructure organizations, and public-cloud providers operating under contract with these entities. Affected organizations must now categorize their cloud systems by impact level, examine existing security controls and agreements, and gather documentation needed for compliance verification and certification.

According to Thailand's National Cyber Security Agency, the standard aligns with the government's Cloud First Policy and establishes baseline security measures for cloud environments within its scope. The timing coincides with increased attention to Thailand's digital infrastructure: on Sept. 4, officials requested that operators of 49 data centers halt construction efforts while new regulations covering power supply, water resources, safety protocols, and approval procedures are being drafted.

Impact levels shape the compliance burden

The framework distinguishes between cloud service customers (CSCs) and cloud service providers (CSPs). Covered customers encompass government agencies, CII organizations, and regulatory or supervisory bodies that have formal cloud-service contracts in place.

Cloud systems receive classifications of low, moderate, or high impact based on what damage could result from compromised confidentiality, integrity, or availability. The NCSA's guidance for cloud customer certification requires organizations to maintain asset inventories, define system boundaries, conduct risk assessments, establish security policies, categorize data, and maintain contracts or service-level agreements.

Cloud service providers must specify service scope and architecture, document relevant controls, perform risk evaluations, and establish business continuity and disaster recovery strategies. The NCSA's CSP certification requirements similarly mandate SLAs and documented clarification of shared security responsibilities between the provider and its customers.

The Cloud Security Standard itself adjusts security controls and assurance expectations based on the assigned impact level. Thailand has also been strengthening its ability to assess compliance. On Sept. 1, the NCSA designated NECTEC's Digital Technology Evaluation and Certification Institute as its inaugural cloud-security certification body.

Contracts move to the center of cloud compliance

Organizations should begin by identifying which systems require compliance, what data they process, and which impact classification is appropriate. Security teams should then evaluate access control mechanisms, risk assessment procedures, incident-response protocols, business continuity and recovery arrangements, and certification documentation. The ownCloud incident in the Philippines, which resulted in data theft from internet-accessible systems and exposed sensitive government and research information, illustrates the risks posed by inadequately protected systems.

Agreements deserve equal attention. Both customers and providers must verify how SLAs allocate security responsibilities, handle instances of non-compliance, and facilitate service transitions or terminations. The same principles guide how UK regulators oversee major cloud providers, with regulated financial institutions remaining accountable for outsourcing decisions, system resilience, risk management, and contingency arrangements.

Thailand may strengthen its approach to vendor management further. A proposed amendment to the Cybersecurity Act would obligate CII organizations to supervise external service providers and could grant regulators authority to instruct customers to discontinue services if a provider does not correct violations within 60 days.

This amendment has not yet taken effect. According to a Baker McKenzie analysis published Aug. 13, the proposal still requires Cabinet approval, parliamentary passage, Royal Assent, and publication in the Government Gazette.

With the Cloud Security Standard now active, covered organizations must address its control requirements and certification processes while tracking developments regarding the proposed amendment and any resulting additional vendor oversight obligations.