/보안/2026 CSAP Simplified Grade Prep Checklist — A Practical Guide for Public SaaS
SecurityCSAPCSAP간편등급

2026 CSAP Simplified Grade Prep Checklist — A Practical Guide for Public SaaS

A 2026 CSAP Simplified Grade preparation guide for SaaS sold to public institutions. It covers Standard vs. Simplified Grade, the application process and costs, frequently failed controls, and a copy-paste-ready deliverables checklist.

2026 CSAP Simplified Grade Prep Checklist — A Practical Guide for Public SaaS

2026 CSAP Simplified Grade Prep Checklist — A Practical Guide for SaaS Providers

If you found this article after hearing that “you cannot even bid on public-institution SaaS without CSAP,” you are in the right place. As Digital Platform Government accelerates public SaaS adoption, CSAP (Cloud Security Certification) is no longer a nice-to-have — without it, you cannot even get started.

The first place security and infrastructure owners get stuck is surprisingly simple: “Is our service Standard Grade or Simplified Grade?” Get that wrong and your quotes, timeline, and deliverables all go off track. This article walks through that first decision, then the application process and costs, frequently failed controls, and a copy-paste-ready list of artifacts.

⚠️ Disclaimer: The number of assessment items, detailed costs, and lead times change with the latest KISA and assessment-body (certification body) notices and quotes. Figures below are a rough guide for practical prep. Always confirm against official KISA CSAP guidance and a consultation with an assessment body.

Standard Grade vs. Simplified Grade: Which applies to our service?

As of 2026, CSAP is operated as a grade system (Low / Medium / High) based on the criticality of the information processed. For SaaS providers, the practical split that matters most is “non-critical information → Simplified Grade (Low-grade track)” vs. “critical information → Standard Grade.” Most general business SaaS — collaboration tools, scheduling, CRM, and the like — falls under Simplified Grade.

CategorySimplified GradeStandard Grade
ScopeSaaS that processes non-critical informationSystems that process critical information (resident registration numbers, sensitive data, etc.)
Number of assessment itemsRelatively few (streamlined)Many items (full control set)
On-site assessmentPrimarily document-based in principle (streamlined)Document review + on-site assessment
Multi-tenancy isolationBroader allowance for logical isolationStricter isolation requirements
Typical servicesGeneral business SaaS, non-critical collaboration toolsAdministrative information and high-volume personal-data processing services
Prep burdenMediumHigh

Decision tip: Start by asking whether a leak of the information your service processes would have only limited impact on citizens or public administration. If so, prepare on the Simplified Grade track — but always confirm the grade the contracting agency (demanding institution) actually requires. If the agency requires Medium and you prepared Low, the certification is useless in the bid.

Application process, timeline, and cost roadmap

From application to certificate issuance takes as little as 4 months, and 6 months or more if remediation drags on. Work backward from the bid date and start at least 6 months ahead.

StageOwnerCumulative estimated durationCost (quote-dependent, approximate)
1. Application and pre-consultationProvider → assessment body~0.5 monthsConsultation stage
2. ContractProvider and assessment body~1 monthAssessment-fee contract signed
3. Assessment prep (writing artifacts)Provider~2 monthsInternal labor / consulting cost
4. Document and (on-site) assessmentAssessment body~3.5 monthsIncluded in assessment fees
5. RemediationProvider~4.5 monthsRemediation work cost
6. Certification committee reviewKISA / certification body~5 months
7. Certificate issuanceCertification body~5–6 months

Costs vary widely, up into the tens of millions of KRW, depending on system scale and assessment scope. The assessment body’s quote is the only reliable figure.

Frequently flagged controls checklist (copy-paste ready)

Start your internal review by copying this table as-is. These are the controls most often cited when teams prepare for the first time.

Control areaPass criteriaEvidenceCheck
Account and privilege separationLeast privilege by role, no shared accounts, grant/revoke procedures in operationAccess-privilege register, approval history
Administrator access controlMFA on the admin console, source-IP restriction, activity loggingMFA configuration screens, access-control policy
Encryption in transitTLS 1.2 or higher enforced on all external communicationsSSL configuration, scan results
Encryption at restEncryption applied to DB and storageEncryption settings, list of in-scope assets
Key managementKeys stored separately, rotated periodically, access controlledKey-management policy, KMS configuration
Log retention periodMeets statutory/baseline retention (typically 1 year or more), tamper protectionLog-management register, retention policy
Physical and logical isolationPublic-sector zone isolation, multi-tenant isolationSystem architecture diagram, isolation design
Backup and recoveryRegular backups, recovery procedures, and recovery tests performedBackup policy, recovery-test records
Security patch managementDefined OS/middleware patch cycle and actual executionPatch-management register, change records

Pre-assessment deliverables list

Assessment is ultimately a process of proving things in writing. The most common delay is operations that work well but have no documents, which then get pushed into remediation. Fill these artifacts in advance.

ArtifactPurposePrep difficulty
Information security policy and guidelinesFoundational documents for how controls are operatedMedium
System architecture diagramEvidence of infrastructure, network, and isolation designMedium
Asset inventoryIdentification of hardware, software, and dataLow
Access-privilege registerHistory of account and privilege grant/revokeMedium
Encryption policyStated standards for transit, rest, and key managementMedium
Log-management registerRetention period, in-scope logs, and review cycleLow
Change-management recordsTraceability of patches and configuration changesMedium
Outsourced CSP evidenceCSAP certificate and contract for the IaaS in useHigh

Common fail and remediation reasons — avoid these in advance

These remediation findings show up repeatedly in practice. Checking them before you start can save an entire round.

  • Log retention too short: Settings such as “we only keep 30 days for operational convenience” are the most common finding. Configure retention to meet the baseline in advance.
  • No MFA on admin accounts: MFA is on for end users, but the admin console is still ID/password only. Apply MFA to administrator accounts without exception.
  • IaaS CSAP certification not verified: Cases where nobody checked whether the cloud infrastructure (IaaS) the SaaS runs on is itself CSAP-certified. SaaS certification only means something on certified IaaS. Always verify the CSP’s certification scope.
  • Misreading physical-isolation requirements: Over-interpreting Simplified Grade as needing Standard Grade–level physical isolation, or claiming logical isolation with no evidence. Map requirements accurately to the grade.
  • Policy documents vs. actual operations: The document says “quarterly patches” but there is no patch history — instant remediation. Documents must reflect operations, and operations must follow the documents.

One lesson from the field

Looking at first-time CSAP preparations, teams burn more time on document–operations alignment than on technical controls. TLS, encryption, and MFA are a setting or two. If the cycle written in the policy does not match actual operations logs, remediation rounds repeat and a month or two disappears. That is why I recommend not starting with artifacts: first record how you actually operate, then align the policy language to that. Write an idealized policy first and operations will never catch up.

Conclusion: three-step prep priority

  1. Lock the grade: Confirm Simplified vs. Standard from the demanding institution’s required grade plus the criticality of the information you process.
  2. Verify the infrastructure prerequisite: Validate the CSAP certification scope of the IaaS you run on, and configure the high-fail items first — MFA, log retention, encryption.
  3. Align documents and operations: Write the eight artifacts against actual operations, and remove mismatches between policy and real history.

Finish these three steps and you are ready to walk into an assessment-body consultation. Copy the tables above into your internal wiki and split the checkboxes across owners.

Frequently asked questions (FAQ)

Q. We are non-critical SaaS — can we always go Simplified Grade? A. Even if the information you process would put you on Simplified Grade, the grade the public institution you sell to requires takes priority. Confirm the required grade in the bid notice or in pre-discussions first.

Q. Does our IaaS (cloud infrastructure) also need its own CSAP? A. The SaaS provider does not need to certify the IaaS itself, but the service must run on CSAP-certified IaaS. Obtain the CSP’s certification scope and certificate as evidence.

Q. What are the exact prep time and cost? A. Typically 4–6 months from application to issuance; cost varies widely with scale. The only accurate way to lock item counts, fees, and duration is official KISA CSAP guidance plus an assessment-body quote.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.