Every year, KISA notifies select companies in South Korea that they must obtain ISMS-P certification, setting a 30 June deadline to appeal. If you sell online services in Korea and haven't received a notice, it is easy to assume compliance is someone else's problem. However, KISA's letter is merely administrative outreach. Under Article 47(2) of the Network Act (정보통신망법 제47조제2항), compliance attaches automatically as soon as your metrics cross statutory thresholds. Five criteria trigger this obligation, two of which apply regardless of company size.

Compliance is required. No opt-in, no opt-out
Most security certifications are voluntary business decisions. For example, if a client requests SOC 2, you pursue it on your own schedule. Article 47(2), however, operates strictly by statute:
정보통신망법 제47조제2항 — 「전기통신사업법」 제2조제8호에 따른 전기통신사업자와 전기통신사업자의 전기통신역무를 이용하여 정보를 제공하거나 정보의 제공을 매개하는 자로서 다음 각 호의 어느 하나에 해당하는 자는 제1항에 따른 인증을 받아야 한다.
(A telecommunications business operator, and a person who provides information — or intermediates its provision — using such an operator's service, who falls under any of the following, shall obtain the certification under paragraph 1.)
The statutory verb is 받아야 한다 (shall obtain). Compliance is legally required whether a company wants it or received prior notification.
When is it required?
ISMS-P is NOT required for every company. Most small business are excluded from the requirement.
To understand if you must be ISMS-P compliant, focus on two things: what type of company you are, and then your financial metrics.
Certification becomes mandatory if you meet any of the following five criteria:
- Major Information and Communications Service Providers (주요정보통신서비스 제공자): Per KISA guidelines, this includes facilities-based operators serving Seoul and all metropolitan cities, plus mobile resellers. No size threshold.
- Internet Data Center Operators (집적정보통신시설 사업자): No size threshold.
- Previous-Year Revenue or Budget Receipts of KRW 150bn+ (전년도 매출액 또는 세입 1,500억원 이상): The Enforcement Decree (시행령) restricts this to tertiary general hospitals (상급종합병원) and higher-education institutions with 10,000+ enrolled students (재학생 1만명 이상).
- Previous-Year ICT Revenue of KRW 10bn+ (정보통신서비스 부문 전년도 매출액 100억원 이상).
- Previous-Year Daily Average Users of 1,000,000+ (전년도 일일평균 이용자수 100만명 이상): The same million-user benchmark that governs Korea's "personal-data safety-measures notice".
Foreign companies routinely miscalculate criterion number four.
Kim & Chang, 22 August 2024: "As to the first criterion, e-commerce sales would include B2B sales, not only sales to end customers." The same note puts "both domestic and overseas companies providing online services in Korea" inside the requirement.
You do not necessarily need to have physical Korean presence to trigger compliance, much like how an EU obligation reaches companies without an EU office.

Notification letter is a privilege
Don't wait until you receive a letter to prepare for ISMS-P. It's best to be proactive. The reality is that it's not guaranteed that you will be notified by a letter before the requirement starts applying to your company.
KISA builds its outreach list using visible market data (Kim & Chang noted that 2023 notices were sent sequentially starting in April). KISA's official lookup tool explicitly acknowledges its own limitations:
KISA, ISMS-P 인증대상 page — 과기정통부 및 KISA가 당해 안내한 자에 한하여 조회 가능하며, 별도 안내를 받지 않은 의무대상자는 조회되지 않을 수 있음
(Only parties that MSIT or KISA notified in the current year can be looked up; an 의무대상자 — a party under the certification obligation — that received no separate notice may not appear.)
The regulator openly admits its list is incomplete. Because notifications can also be issued in error, KISA provides an exclusion submission process (제외의견 제출). Companies that believe they were incorrectly designated can submit financial statements and traffic analytics by 30 June of the notification year to request an exemption.

The deadline is 31 August of the following year
The ISMS-P Notification sets a fixed deadline independent of formal notice:
ISMS-P 고시 제19조제4항 — 의무대상자에 해당하는 자는 다음 해 8월 31일까지 인증을 받아야 한다.
(A party under the certification obligation shall obtain certification by 31 August of the following year.)
KISA measures compliance against the certification committee's official decision date (인증 결정일), not the date the physical certificate is issued. Under Article 19(5), the Certification Council (협의회) may grant extensions only under recognized "unavoidable circumstances" (불가피한 사유), such as a natural disaster (재난).
Failing to obtain certification violates Article 47(2), triggering Article 76(1)(6-5) penalties of up to KRW 30 million (3천만원) in administrative fines (과태료). Operating above a threshold in any given year establishes a distinct obligation for that year, each with its own 31 August deadline. However, we found no public record of this fine being enforced to date.
An amendment effective 1 October 2026 adds a KRW 50 million tier under Article 76 for unreported breaches and unfulfilled corrective orders, while reclassifying non-certification under Article 76(2) without changing the fine amount, one of several key statutory dates to mark on your calendar.
Proactively seeking compliance
- Confirm last year's ICT revenue with finance (정보통신서비스 부문 매출액): B2B sales count toward the KRW 10 billion threshold.
- Verify your Telecommunications Business Act registration (전기통신사업법): Major ICT provider and internet data center statuses apply based on registration category, regardless of revenue.
- Mark 30 June on your calendar: This is the deadline to file an exclusion opinion (제외의견 제출) accompanied by financial statements.
- Treat 31 August of the following year as binding: Because compliance is measured by the certification decision date, all audit work must conclude well in advance.
As of 25 August 2026, KISA's registry showed 1,254 active ISMS-P certificates. For help on which South Korean regulations impact your business, use our two-minute Korea Digital Regulation Scoper.
Which criterion would your company cross first, and do you know your previous year's ICT revenue without checking?
References
- 국가법령정보센터 — 정보통신망 이용촉진 및 정보보호 등에 관한 법률, 제47조 · 제76조
- 과학기술정보통신부 — 정보보호 및 개인정보보호 관리체계 인증 등에 관한 고시, 제19조
- KISA — ISMS-P 인증대상
- KISA — 의무대상자 제외의견 제출
- KISA — ISMS-P 인증서 발급 현황
- Kim & Chang — Information Security-Related Certification Requirement for Companies Doing On-Line Business in Korea
- Kim & Chang — 한국인터넷진흥원(KISA)의 ISMS 인증 의무대상자 지정 통보
