Global cloud companies have obtained the low-tier grade of South Korea's Cloud Service Security Assurance Program, or CSAP, and moved to target the domestic public-sector market. But they still appear to have produced no notable results.
Amazon Web Services, Microsoft and Google Cloud, the global top 3 cloud providers, all secured the low-tier CSAP grade in 2024 and 2025 and entered the public cloud market.
Microsoft received CSAP certification in December 2024. Google Cloud was certified in February last year and AWS in March.
The CSAP grading system, managed by the Ministry of Science and ICT, was introduced to promote the use of private-sector cloud services in the public sector. It classifies services into high, mid and low grades based on the characteristics of user institutions and system criticality, and applies different security assessment criteria. A low-grade certification can be used for systems that operate public data that do not include personal information.
But the market accessible with a low-grade certification is relatively less attractive for global companies, and their services are seen as expensive for low-grade systems. As a result, an assessment says there has been no major change in a public cloud landscape led by domestic providers.
Industry sources say there are still not many public institutions using global clouds, apart from some research institutes.
One industry official said, "It is expensive to deploy AWS in a low-grade system. To use AWS, you need to use many advanced features, but with only low-grade certification the reality is that there is still limited room to operate."
Budget execution practices for public projects are also cited as an obstacle for global companies. Public projects often proceed with costs set in advance, while global cloud companies focus on pay-as-you-go models. Some large-scale customers get flexible terms, but that is not easy in the public market.
With growth in the domestic private cloud market not as fast as it used to be, the public market is seen as having significant potential for global companies. They could seek higher-grade certification after the low grade, but for now there appears to be no concrete move, industry sources say.
Changes to the public cloud security certification system itself could be a major variable going forward.
The government is pursuing a policy centered on bringing public-sector cloud security certification under a single verification framework run by the National Intelligence Service, while converting the CSAP system into a voluntary security certification for private companies.
To provide cloud services to public institutions, cloud providers had to first obtain CSAP and then undergo a security review by the intelligence agency. The government aims to improve what it calls double regulation through the overhaul.
The National Intelligence Service plans to establish a new security certification framework reflecting this. It plans to implement the new system from the second half of next year, but details have not yet been released. Some see that once the government's direction is set, global providers could seek new opportunities. Some in the industry also believe the overhaul will, in the long run, have a positive effect on expanding global providers' entry into the public market.