The security certificate that shaped Korea's public cloud market

Korea told its agencies to move to the cloud, then routed them through a domestic security certification that global providers could not easily meet, and the supplier market grew accordingly.

Korea passed a dedicated cloud computing act in 2015, among the first countries to legislate specifically for the technology, and paired it with an ambition that public institutions should move their systems off their own racks. A decade of transition plans followed, each setting targets for how many government information systems would run on commercial infrastructure by a given year. Progress has been slower than every one of those plans assumed, and the reasons are more institutional than technical.

The most consequential of them is a certification. Any provider selling cloud services to Korean public institutions must hold the Cloud Security Assurance Programme certification, administered by the Korea Internet and Security Agency. In its original form the standard required that infrastructure serving public customers be physically separated from infrastructure serving everyone else — not logically partitioned, but running on distinct hardware in distinct space. For a hyperscale provider whose economics rest on shared capacity across a region, building a physically segregated Korean estate to serve a single class of customer is an expensive proposition, and for years the global platforms largely did not.

The predictable result was a public cloud market supplied by domestic firms. Korean providers built certified environments dedicated to the public sector and took the great majority of government workloads. Whether this counted as industrial policy depended on who was describing it; the certification was written as a security measure and functioned as a market boundary, and both descriptions are accurate. Domestic providers gained a protected base of demand at the moment their commercial businesses needed one, and public institutions gained suppliers who understood Korean procurement.

That structure was loosened in 2023, when the certification was restructured into tiers. Systems handling the most sensitive data remain subject to the strictest requirements, while a lower tier permits logical separation for workloads assessed as low sensitivity — public-facing websites, information services, systems holding no personal data. The reform opened a portion of public demand to providers that had been effectively excluded, and it did so without abandoning the principle that sensitive government data sits on infrastructure the state can inspect. The tiering is the more defensible design, since the previous regime applied the same physical-separation requirement to a ministry’s payroll database and to a municipal tourism site.

Certification was never the only brake. Public budgeting in Korea, as in most countries, is structured around capital purchases rather than recurring service charges, so an agency that buys servers spends once from a line item designed for the purpose while an agency that rents capacity must defend an operating cost every year. Procurement rules and evaluation criteria were written for hardware. Auditors, and the officials who anticipate them, have a well-founded instinct that a machine in a room the institution controls is easier to account for than a workload in a shared region. And the specialised staff required to run systems on cloud infrastructure are scarce inside government and expensive outside it.

The trade-off that remains is not really about security. A domestic supplier base gives Korea providers subject to its own law, staffed by people it can regulate, and resilient to decisions made in other jurisdictions — a genuine sovereignty argument that other countries are increasingly making in their own terms. The cost is that the frontier of cloud capability, particularly in machine learning tooling and managed data services, is developed by a handful of global platforms and arrives in domestic environments later and in reduced form. Korea has chosen, deliberately and through a technical standard rather than an announced policy, to accept the second cost in exchange for the first.