South Korea's product-security and cyber-resilience duties for the private sector sit inside the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (the Network Act, an official English translation current through Act No. 20069, effective Jan. 23, 2024) and the Personal Information Protection Act (PIPA), rather than in a dedicated cyber-resilience code.
Network Act Article 45(1) directs both a provider of information and communications services and a manufacturer or importer of a connected device a Presidential Decree designates to take protective measures securing the network's stability, but the specific content of those measures is left to guidelines the Minister of Science and ICT (MSIT) may issue and may only recommend a bound person observe, backed by MSIT's own power to order corrective measures under Article 64; no provision sets a binding technical standard, a pre-market compliance gate, or a mandatory vulnerability-disclosure channel a manufacturer must meet before placing a device on the market, so the product-requirements research dimension is a researched absence.
Article 48-3 requires a provider of information and communications services to report a computer security incident to MSIT or the Korea Internet and Security Agency (KISA) immediately on discovering it, with no revenue or user threshold gating the reporting duty itself, and Article 48-4 requires the same broad class to analyze the incident's cause, respond to it, and preserve or submit the data MSIT or KISA demands for that analysis; failing either duty is an administrative fine of up to KRW 30,000,000 under Article 76(1).
Because that reporting duty binds a provider of information and communications services in the Act's own broad for-profit online-service sense rather than a licensed or government-designated status, it is flagged here rather than deferred, the same posture this profile gives India's CERT-In Directions.
A separate, higher bar inside the same Act binds only a class of information and communications service provider a Presidential Decree designates: mandatory designation of a Chief Information Security Officer under Article 45-3, and mandatory certification of an information security management system under Article 47 (ISMS, since consolidated with the former personal-information management system certification into a single ISMS-P scheme KISA and the Personal Information Protection Commission run jointly), with the certification duty's own qualifying class set at an annual sales or tax revenue of at least KRW 150,000,000,000, an information-and-communications-service sales of at least KRW 10,000,000,000, or an average of at least one million daily users over the preceding year.
No declared activity in this corpus's vocabulary expresses that threshold class, so this regime is recorded here rather than raised against a guess, the same treatment this profile gives DORA's financial entities and New York's Department of Financial Services Part 500 covered entities.
The Act on the Protection of Information and Communications Infrastructure separately binds the operator of a critical information and communications infrastructure facility the government designates case by case, sector by sector, under its own Article 8, with a vulnerability-analysis and protection-plan duty and an incident-notification duty, and it carries criminal exposure of up to ten years' imprisonment or a fine of up to KRW 100,000,000 for disturbing, paralyzing, or destroying such infrastructure; its bound party is likewise a government-designated status no declared activity can express, so it too is deferred rather than flagged.
PIPA Article 29 (Duty of Safeguards) belongs to the privacy topic rather than here, as one article of the comprehensive regime addressed to a personal information controller, the same place the General Data Protection Regulation's Article 32 sits.
It requires every personal information controller, with no sector or size gate, to take the technical, managerial, and physical measures a Presidential Decree prescribes, including an internal management plan and preservation of access records, so that personal information is not lost, stolen, divulged, forged, altered, or damaged; a controller who breaches that duty and thereby causes a data subject to suffer exactly that kind of harm exposes itself to up to five times the subject's actual damages under Article 39(3), or to statutory damages of up to KRW 3,000,000 under Article 39-2 without proof of actual loss, the same general civil remedy this jurisdiction's own privacy enforcement row already records.
Korea has no enacted product-security law with a market-placement gate; the nearest instrument is KISA's IoT Security Certification System, a voluntary programme that evaluates a product against Lite and Standard assurance tiers and carries no legal force of its own beyond a public-procurement preference for a certified product, so it is named here rather than filed as an instrument.
Two further amendments are not coded as instruments because the primary text is not yet available through a reachable source and the finding rests only on secondary legal commentary: a PIPA amendment (Act No. 21445, promulgated Mar. 10, 2026) is reported to take effect Sept. 11, 2026 and to make ISMS-P certification mandatory from Jul. 1, 2027, and a Network Act amendment (Bill No. 14896, promulgated Mar. 31, 2026) is reported to take effect Oct.
1, 2026 (except a new information-security-level assessment system, Apr. 1, 2027) and to expand the Chief Information Security Officer's staffing, budget, and board-reporting duties. This jurisdiction's own privacy row already records PIPA's breach-notification duty to the Personal Information Protection Commission and to an affected individual (Article 34); it is not repeated here.