A bill amending the Network Act (정보통신망 이용촉진 및 정보보호 등에 관한 법률) has moved from committee referral to committee review as of 8 September 2026. As introduced, the bill would write a formal breach-information-sharing system into law and require any information-and-communications service provider that has designated and reported a Chief Information Security Officer (CISO) to join that sharing system on a mandatory basis; providers that have not designated a CISO would be invited to join voluntarily (proposed Article 48-2, paragraphs 10–13). This is a pending bill, not current law — no effective date or penalty has been set.

What this means for you

  • Check your CISO status first. The mandatory-join duty as drafted attaches specifically to providers that have designated and reported a CISO under the existing rule. If your Korean operation already meets the CISO-designation threshold and has filed that designation, you are the group this bill is aimed at.
  • No effective date or penalty is set yet. The bill is only at the committee-review stage; treat this as a signal to watch, not an obligation to act on today.
  • If you have not designated a CISO but are near the threshold, confirm your current designation status now — the bill's voluntary-participation track for non-CISO providers suggests the regulator's direction of travel is toward broader participation over time.
  • Track the bill through committee. A breach-information-sharing duty tied to an existing designation (rather than a new standalone threshold) is the kind of change that can move quickly once it clears committee; re-check status before assuming the current voluntary/no-duty position will hold.

Source: (no source URL was provided with this update)