Starting your own CA would be pointless for those outside of the DPRK. It would get labeled as being used by "authoritarian regimes", the technical people for Chrome, Firefox, Edge would ask why they should add it and act like it's going to be used for nefarious ends and probably refuse to add it to their certificate stores.
Without that and without a state-distributed operating system or state-browser bundle you can distribute to people with it pre-installed everyone would have to install the CA root, trust it in their browser, etc. And most people aren't going to do that they're just going to see the scary untrusted cert warning and back away from the website. Them adding untrusted CA generated certificates would literally hurt their ability to get people to look at them.