In September 2025, the National Cyber Security Committee (NCSC) issued a new notification revising the country’s official list of Critical Information Infrastructure (CII) organizations under the Cybersecurity Act B.E. 2562 (2019).
Published in the Royal Gazette on 16 September 2025, the notification designates seven key sectors as “critical infrastructures” essential to Thailand’s security, economic stability, and public welfare. The update modernises the national cybersecurity regime by clarifying regulatory oversight and broadening the scope of obligations imposed on both public and private entities that provide or support vital services.
Policy Context: From Strategic Vision to Operational Enforcement
The Cybersecurity Act B.E. 2562 (2019) established Thailand’s foundational framework for safeguarding information systems that are integral to public security, essential services, and economic stability. However, practical enforcement depended on defining which sectors and operators fell within the scope of CII.
The 2025 notification replaces earlier classifications issued in 2023, expanding coverage to reflect emerging technological interdependencies. It positions the National Cyber Security Agency (NCSA) and its sectoral regulators as the core enforcers of Thailand’s cybersecurity standards, thereby moving the framework from policy aspiration to regulatory implementation.
By codifying which organisations are considered critical, Thailand aligns its approach more closely with international norms such as Singapore’s Cybersecurity Act and the European Union’s NIS2 Directive, both of which require sector-specific oversight, audit mechanisms, and coordinated incident reporting.
The Legal Framework
The notification was issued under Sections 9(8) and 45 of the Cybersecurity Act, empowering the NCSC to identify critical infrastructure and assign supervisory authorities. It defines CII as systems, networks, or operations whose disruption could severely impact national security, public safety, or economic activity.
Each CII sector is paired with a designated regulator responsible for supervising cybersecurity compliance and coordinating with the NCSA on standards, audits, and enforcement actions. Operators within these sectors are now subject to enhanced duties, including:
- Implementing cybersecurity measures consistent with NCSC-approved standards;
- Conducting periodic risk assessments and technical audits;
- Reporting cybersecurity incidents to both the regulator and NCSA within prescribed timeframes; and
- Cooperating with official investigations and mitigation directives.
These obligations extend not only to state entities but also to private operators and vendors providing supporting digital infrastructure, including cloud platforms, data centers, and managed IT services.
| Sector | Examples of Critical Services | Regulatory Authority |
| National Security | Defence, law enforcement, justice administration, national intelligence, and narcotics suppression | Ministry of Defence, Royal Thai Police, Office of Narcotics Control Board |
| Essential Government Services | Government financial systems, citizen registration, ID and household databases | Ministry of Finance, Department of Provincial Administration |
| Banking and Finance | Deposit and interbank payment systems, BAHTNET, ICS, PromptPay, and Single Payment System | Bank of Thailand |
| Communications and Technology | Fixed, mobile, and internet networks, international gateways, domain name management | National Broadcasting and Telecommunications Commission (NBTC), Thai Network Information Centre Foundation |
| Transport and Logistics | Air, sea, and land transport; traffic control; freight and logistics management | Royal Thai Police, Department of Land Transport, Marine Department, Civil Aviation Authority of Thailand |
| Energy and Utilities | Electricity generation and distribution; oil and gas production and supply; water and wastewater systems | Ministry of Energy, Ministry of Interior |
| Public Health | Hospital operations, pharmaceutical and medical device production, radiology and nuclear medicine, health data systems | Department of Health Service Support, Food and Drug Administration (FDA), Office of Atoms for Peach, Ministry of Public Health |
Regulatory Oversight and Compliance Requirements
Each designated regulator is responsible for developing or adopting cybersecurity standards within its jurisdiction in coordination with the NCSA. Operators classified as CII must maintain a Cybersecurity Readiness Plan, identify a responsible officer for incident response, and report significant threats through the national coordination mechanism.
Service providers that support these sectors, such as telecommunications carriers, data processors, or payment networks, may be indirectly regulated through procurement clauses or licensing conditions. This approach ensures that cybersecurity accountability flows through the entire supply chain, not only the primary operator.
The notification also provides for continuity of designation. If a listed operator transfers, merges, or dissolves, the successor entity automatically assumes its CII obligations unless the regulator determines otherwise.
The CII regime also operates alongside the Personal Data Protection Act B.E. 2562 (2019), creating dual obligations for operators managing sensitive personal or financial data. Breach notification and risk-management procedures must therefore be harmonised to satisfy both the PDPC and NCSA requirements.In sectors such as banking, healthcare, and telecommunications, where digital services depend on cross-border data exchanges, compliance now demands integrated governance that balances operational efficiency with statutory security controls.
Implications for Businesses and Technology Firms
The revised CII notification marks a decisive transition toward mandatory cybersecurity governance in Thailand. For private businesses, particularly those in fintech, telecommunications, logistics, or health-tech, the following implications are clear:
- Expanded Compliance Scope: Companies providing digital or operational infrastructure to CII sectors will be drawn into the regulatory perimeter through contracts or licences.
- Regulator Audits and Certification: Sectoral regulators may issue additional technical or procedural requirements, including periodic audits or certification obligations.
- Procurement and Partnership Impacts: Public-sector clients and financial institutions are expected to prioritise vendors with demonstrable compliance capabilities.
- Strategic Investment Considerations: Investors and acquirers must now include CII compliance and cyber-risk assessments in due diligence reviews.
Failure to comply may expose organisations to administrative orders, suspension of operations, or other penalties under the Cybersecurity Act.
By clearly defining its critical infrastructure sectors and assigning oversight responsibility, the Thai government is effectively institutionalising a sector-driven cybersecurity model that integrates public and private accountability.
For businesses, this evolution transforms cybersecurity from an IT function into a core element of legal and operational compliance. Firms operating within or supplying to CII sectors should therefore proactively align their governance, risk, and compliance systems with NCSA standards to remain competitive and resilient in Thailand’s rapidly evolving digital economy.
As Thailand transitions toward mandatory cybersecurity governance, businesses operating in or supporting critical infrastructure sectors must demonstrate readiness, accountability, and compliance. Silk Legal works to help firms design, implement, and audit cybersecurity and data governance programs aligned with national regulations.
To learn how your organization can prepare, contact us for a consultation at [email protected].
