Republic of Korea: Information Security Level Evaluation obligations in Act on Promotion of Information and Communications Network Utilization and Information Protection (Law No. 21500) enter into force

Description

Information Security Level Evaluation obligations in Act on Promotion of Information and Communications Network Utilization and Information Protection (Law No. 21500) enter into force

On 1 April 2027, the Information Security Level Evaluation obligations in the Act on Promotion of Information and Communications Network Utilization and Information Protection (Law No. 21500) enter into force. The Korea Ministry of Science and ICT must conduct an annual evaluation of qualifying information and communications service providers to assess their compliance with statutory obligations and the stability and reliability of their information and communications networks. Qualifying providers are determined by Presidential Decree on the basis of business type, revenue scale, and number of users. The Korea Ministry of Science and ICT may publish evaluation results. Qualifying providers must submit relevant data to the Minister upon request and must not refuse or submit false information. Where the evaluation finds that a provider's information security level is insufficient, the Korea Ministry of Science and ICT may issue improvement recommendations, and providers must make sincere efforts to implement those recommendations and submit a report on measures taken to the Minister.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2025-11-24
under deliberation

On 24 November 2025, a Bill amending the Network Act was introduced to the National Assembly. The B…

2026-03-20
adopted

On 20 March 2026, the Bill amending the Network Act, including incident response obligations and en…

2026-03-31
adopted

On 31 March 2026, the President of Korea promulgated the Act on Promotion of Information and Commun…

2026-10-01
in grace period

On 1 October 2026, the incident response, user notification, and organisational obligations in the …

2027-04-01
in force

On 1 April 2027, the Information Security Level Evaluation obligations in the Act on Promotion of I…