Website Security Standard B.E. 2568 (2025)

The National Cyber Security Agency (NCSA) notification sets the minimum website security requirements that Thai government agencies, regulators and critical information infrastructure operators must meet. The guide and self-assessment are in Thai, the language the standard is written in and the forms are filed in.

Open the Thai guide

The Website Security Standard B.E. 2568 was published in the Royal Gazette on 16 September 2025 and comes into force on 16 September 2026. Organisations in scope must self-assess each website with form ค1 at least once a year and file form ค2 for any requirement not yet met.

The Thai guide walks through the standard in the order the work actually happens: whether your organisation is in the mandatory or the encouraged group, the yearly compliance cycle, how the website's impact level sets the scope, and then every requirement clause by clause. The self-assessment is a separate page that moves one section at a time and can be paused and resumed.

Nothing you type in the assessment is sent anywhere. Answers, organisation details and evidence notes live in your browser only; we keep no copy. The only signal we receive is anonymous usage — how many people start, which impact level they select, how far they get — with no form content attached.

If your team would rather have the assessment done with you, or needs the gaps closed, talk to us.

Frequently asked questions

How often must a covered organisation complete the self-assessment?

At least once a year, using form ค1. Any requirement assessed as not yet met must also be documented on form ค2, with a cause, an interim mitigation, the fix required, the responsible owner and a target date, before it goes to the organisation's top executive.

Does every organisation have to send its results to the NCSA?

No — only websites rated at high impact must send a copy of forms ค1 and ค2 to the National Cyber Security Agency (NCSA, สกมช.), after the results have gone to the organisation’s top executive and to its regulator where one applies. Low- and mid-impact results stay with the organisation for the NCSA to inspect on request, not filed proactively.

We already hold ISO/IEC 27001 certification — do we still need this assessment?

If the certification scope covers the assessed website, you may limit the extra work to requirements not already met under ISO/IEC 27001. If certification does not exist yet, or its scope does not cover the website, the full set of requirements in the standard applies as normal.

logologo

INCOGNITO LAB CO., LTD.

38 Soi Petchakasem 30, Pak Khlong Phasi Charoen, Phasi Charoen, Bangkok 10160

©2026 Incognito Lab Co., Ltd. All rights reserved

Terms & ConditionsPrivacy Policy