You're Subject to Korea's Mandatory ISMS — The First 90 Days, Counted Backward from August 31
Under South Korea's Network Act, companies that cross certain revenue or user thresholds must obtain ISMS certification by August 31 of the following year. Here is how to count the schedule backward from that deadline, what to do in the first 90 days, and what changed in the 2026 reform.

🇰🇷 This article is about South Korean law. ISMS (Information Security Management System) certification here refers to the mandatory scheme under Korea's Act on Promotion of Information and Communications Network Utilization and Information Protection ("Network Act"), Article 47(2) and Enforcement Decree Article 49 — not ISO 27001 or any other country's framework. If you operate an online service in Korea, or your company is expanding into the Korean market, this applies to you.
The moment your company becomes subject to mandatory ISMS, a clock starts. Whether you received a designation notice from the Ministry of Science and ICT / KISA, or discovered during year-end closing that your information-and-communications-service revenue crossed KRW 10 billion, the rule is the same: newly designated companies must obtain certification by August 31 of the following year, and missing that date carries an administrative fine of up to KRW 30 million (Network Act, Article 76). This article walks through the schedule counted backward from that deadline, and what to do in the first 90 days.
If you first want to check whether your company is subject at all, our ISMS obligation checker runs the revenue and user-count tests (Korean interface).
Step 0 — Make sure you are actually subject
The thresholds are set by Enforcement Decree Article 49. The most common misreading is treating the revenue test as total company revenue. It is not — the test is revenue from the information and communications service segment. A manufacturer with enormous offline revenue but a small online segment does not meet this test; conversely, e-commerce, platform, and app revenue can count toward it. If you are near the line, start with how your accounting classifies segment revenue.
If you believe a designation is wrong — segment classification, or how daily users were counted — KISA's certification portal has a formal objection procedure for designated companies. File that before you spend a single week on certification prep.
Count backward from the deadline
August 31 is not the application deadline — it is the acquisition deadline. The certification committee's decision must be complete by that date. Counting backward:
- August 31 — certification committee decision complete
- 2–3 months before — application, document and on-site audit, remediation of findings. Audit agencies get crowded in the second half of the year
- At least 2 months before that — the management system must have an operating history. Auditors read operating records, not just documents; a minimum of two months of operation is required at application
- 3–6 months before that — building the system: scoping, gap analysis, policies, technical controls
Add it up: twelve months comfortably, six months compressed. Starting in the autumn of the year you were designated is a normal schedule; starting the following spring is already a compressed one.
The first 90 days — do exactly three things
Month 1: fix the scope, appoint the officers
Certification scope drives audit duration and cost. The center of the scope is the service that made you subject — plus the infrastructure and personal-data flows connected to it. Resist the urge to include the entire corporate IT estate; start with what the law actually requires.
In the same month, appoint a Chief Information Security Officer (CISO). Under the 2026 reform, the preliminary check now verifies the CISO's and CPO's authority up front — a name-only concurrent appointment fails at the door.
Month 2: gap analysis — measure the distance between the standard and reality
The ISMS standard has 80 control items (ISMS-P, which adds the personal-data track, has 101). Gap analysis scores each item against where you are today. Two deliverables must come out of this month:
- An asset inventory — servers, databases, network equipment, software, personal-data processing. The preliminary check starts with asset identification
- A vulnerability assessment — especially end-of-life software, unapplied security patches, and missing logs. The 2026 reform names these three as critical defects: unresolved past a 100-day remediation window, they can lead to revocation. Find them first
Month 3: write the documents — and start the records the same day
Establish security policies and procedures, and start operating them as they are approved. The common mistake is sequencing: finish all documents, then begin operation. The two-month operating history required at application is counted from the day records begin — training completions, access-right reviews, backup checks, meeting minutes.
What the 2026 reform changed
The reform announced in April 2026 shifted the weight from "the moment you get the certificate" to "the entire period you hold it." Four changes reach newly designated companies directly:
- The preliminary check became a gate — core items (CISO/CPO authority, asset identification, vulnerability management) are verified before the main audit; failing them can get an application returned
- Continuous inspection — moving from one annual follow-up audit toward ongoing checks across the whole 3-year validity period
- Three named critical defects — EOL software, missing patches, missing logs; 100 days to fix or revocation proceedings begin
- ISMS-P becoming mandatory — the reform plan makes ISMS-P (the version covering personal data) mandatory for designated companies from 2027 (final notice still to be confirmed). If you are starting now, building to the ISMS-P standard from day one avoids doing the work twice
Three common failure modes
- Over-scoping — putting the whole company in scope doubles audit cost and preparation time. Scope what the law requires first
- Documents without records — hundreds of pages of consultant-written policy with no operating history passes "established" and fails "operated"
- Outsourcing everything — the certificate may arrive, but you pay the same consulting bill again at renewal. With continuous inspection arriving, certification without internalization got riskier
Summary
If you have been designated: ① confirm you are actually subject (checker, objection procedure), ② count the schedule backward from August 31 of next year, ③ spend the first 90 days on scope, officers, gap analysis, and operating records. Certification is an accumulation of operating records, not a paperwork sprint — and the 2026 reform made that direction explicit. The earlier you start, the less you pay for a compressed schedule.
References
- Act on Promotion of Information and Communications Network Utilization and Information Protection Art. 47, 76; Enforcement Decree Art. 49 — Korean Law Information Center (Korean)
- ISMS-P certification targets · objection procedure — KISA certification portal (Korean)
- Government overhauls ISMS·ISMS-P certification — Byline Network, April 2026 (Korean)