[{"data":1,"prerenderedAt":54},["ShallowReactive",2],{"tool-wss-2568-en":3},{"doc":4},{"title":5,"description":6,"link":7,"published":8,"lastReviewed":9,"lede":10,"faq":11,"handoff":21,"body":28},"Website Security Standard B.E. 2568: Practical Guide","A step-by-step guide and self-assessment tool for the NCSA Website Security Standard B.E. 2568 (2025), with forms ค1\u002Fค2 you can fill in and print. Everything you enter stays in your browser.","wss-2568","2026-09-10","2026-09-21","The National Cyber Security Agency (NCSA) notification sets the minimum website security requirements that Thai government agencies, regulators and critical information infrastructure operators must meet. The guide and self-assessment are in Thai, the language the standard is written in and the forms are filed in.",[12,15,18],{"q":13,"a":14},"How often must a covered organisation complete the self-assessment?","At least once a year, using form ค1. Any requirement assessed as not yet met must also be documented on form ค2, with a cause, an interim mitigation, the fix required, the responsible owner and a target date, before it goes to the organisation's top executive.",{"q":16,"a":17},"Does every organisation have to send its results to the NCSA?","No, only websites rated at high impact must send a copy of forms ค1 and ค2 to the National Cyber Security Agency (NCSA, สกมช.), after the results have gone to the organisation’s top executive and to its regulator where one applies. Low- and mid-impact results stay with the organisation for the NCSA to inspect on request, not filed proactively.",{"q":19,"a":20},"We already hold ISO\u002FIEC 27001 certification. Do we still need this assessment?","If the certification scope covers the assessed website, you may limit the extra work to requirements not already met under ISO\u002FIEC 27001. If certification does not exist yet, or its scope does not cover the website, the full set of requirements in the standard applies as normal.",{"title":22,"time":23,"autosave":24,"privacy":25,"cta":26,"resume":27},"Start the self-assessment","About 20–30 minutes","Saved automatically in your browser. Close and come back any time","What you enter stays on your device. We never store it.","Open the Thai guide","Continue",{"type":29,"value":30,"toc":50},"minimark",[31,35,38,41],[32,33,34],"p",{},"The Website Security Standard B.E. 2568 was published in the Royal Gazette on 16 September 2025 and comes into force on 16 September 2026. Organisations in scope must self-assess each website with form ค1 at least once a year and file form ค2 for any requirement not yet met.",[32,36,37],{},"The Thai guide walks through the standard in the order the work actually happens: whether your organisation is in the mandatory or the encouraged group, the yearly compliance cycle, how the website's impact level sets the scope, and then every requirement clause by clause. The self-assessment is a separate page that moves one section at a time and can be paused and resumed.",[32,39,40],{},"Nothing you type in the assessment is sent anywhere. Answers, organisation details and evidence notes live in your browser only; we keep no copy. The only signal we receive is anonymous usage (how many people start, which impact level they select, how far they get) with no form content attached.",[32,42,43,44,49],{},"If your team would rather have the assessment done with you, or needs the gaps closed, ",[45,46,48],"a",{"href":47},"\u002Fcontact","talk to us",".",{"title":51,"searchDepth":52,"depth":52,"links":53},"",2,[],1790565613354]