2026 CSAP Simplified Grade Prep Checklist — A Practical Guide for SaaS Providers
If you found this article after hearing that “you cannot even bid on public-institution SaaS without CSAP,” you are in the right place. As Digital Platform Government accelerates public SaaS adoption, CSAP (Cloud Security Certification) is no longer a nice-to-have — without it, you cannot even get started.
The first place security and infrastructure owners get stuck is surprisingly simple: “Is our service Standard Grade or Simplified Grade?” Get that wrong and your quotes, timeline, and deliverables all go off track. This article walks through that first decision, then the application process and costs, frequently failed controls, and a copy-paste-ready list of artifacts.
⚠️ Disclaimer: The number of assessment items, detailed costs, and lead times change with the latest KISA and assessment-body (certification body) notices and quotes. Figures below are a rough guide for practical prep. Always confirm against official KISA CSAP guidance and a consultation with an assessment body.
Standard Grade vs. Simplified Grade: Which applies to our service?
As of 2026, CSAP is operated as a grade system (Low / Medium / High) based on the criticality of the information processed. For SaaS providers, the practical split that matters most is “non-critical information → Simplified Grade (Low-grade track)” vs. “critical information → Standard Grade.” Most general business SaaS — collaboration tools, scheduling, CRM, and the like — falls under Simplified Grade.
| Category | Simplified Grade | Standard Grade |
|---|---|---|
| Scope | SaaS that processes non-critical information | Systems that process critical information (resident registration numbers, sensitive data, etc.) |
| Number of assessment items | Relatively few (streamlined) | Many items (full control set) |
| On-site assessment | Primarily document-based in principle (streamlined) | Document review + on-site assessment |
| Multi-tenancy isolation | Broader allowance for logical isolation | Stricter isolation requirements |
| Typical services | General business SaaS, non-critical collaboration tools | Administrative information and high-volume personal-data processing services |
| Prep burden | Medium | High |
Decision tip: Start by asking whether a leak of the information your service processes would have only limited impact on citizens or public administration. If so, prepare on the Simplified Grade track — but always confirm the grade the contracting agency (demanding institution) actually requires. If the agency requires Medium and you prepared Low, the certification is useless in the bid.
Application process, timeline, and cost roadmap
From application to certificate issuance takes as little as 4 months, and 6 months or more if remediation drags on. Work backward from the bid date and start at least 6 months ahead.
| Stage | Owner | Cumulative estimated duration | Cost (quote-dependent, approximate) |
|---|---|---|---|
| 1. Application and pre-consultation | Provider → assessment body | ~0.5 months | Consultation stage |
| 2. Contract | Provider and assessment body | ~1 month | Assessment-fee contract signed |
| 3. Assessment prep (writing artifacts) | Provider | ~2 months | Internal labor / consulting cost |
| 4. Document and (on-site) assessment | Assessment body | ~3.5 months | Included in assessment fees |
| 5. Remediation | Provider | ~4.5 months | Remediation work cost |
| 6. Certification committee review | KISA / certification body | ~5 months | — |
| 7. Certificate issuance | Certification body | ~5–6 months | — |
Costs vary widely, up into the tens of millions of KRW, depending on system scale and assessment scope. The assessment body’s quote is the only reliable figure.
Frequently flagged controls checklist (copy-paste ready)
Start your internal review by copying this table as-is. These are the controls most often cited when teams prepare for the first time.
| Control area | Pass criteria | Evidence | Check |
|---|---|---|---|
| Account and privilege separation | Least privilege by role, no shared accounts, grant/revoke procedures in operation | Access-privilege register, approval history | ☐ |
| Administrator access control | MFA on the admin console, source-IP restriction, activity logging | MFA configuration screens, access-control policy | ☐ |
| Encryption in transit | TLS 1.2 or higher enforced on all external communications | SSL configuration, scan results | ☐ |
| Encryption at rest | Encryption applied to DB and storage | Encryption settings, list of in-scope assets | ☐ |
| Key management | Keys stored separately, rotated periodically, access controlled | Key-management policy, KMS configuration | ☐ |
| Log retention period | Meets statutory/baseline retention (typically 1 year or more), tamper protection | Log-management register, retention policy | ☐ |
| Physical and logical isolation | Public-sector zone isolation, multi-tenant isolation | System architecture diagram, isolation design | ☐ |
| Backup and recovery | Regular backups, recovery procedures, and recovery tests performed | Backup policy, recovery-test records | ☐ |
| Security patch management | Defined OS/middleware patch cycle and actual execution | Patch-management register, change records | ☐ |
Pre-assessment deliverables list
Assessment is ultimately a process of proving things in writing. The most common delay is operations that work well but have no documents, which then get pushed into remediation. Fill these artifacts in advance.
| Artifact | Purpose | Prep difficulty |
|---|---|---|
| Information security policy and guidelines | Foundational documents for how controls are operated | Medium |
| System architecture diagram | Evidence of infrastructure, network, and isolation design | Medium |
| Asset inventory | Identification of hardware, software, and data | Low |
| Access-privilege register | History of account and privilege grant/revoke | Medium |
| Encryption policy | Stated standards for transit, rest, and key management | Medium |
| Log-management register | Retention period, in-scope logs, and review cycle | Low |
| Change-management records | Traceability of patches and configuration changes | Medium |
| Outsourced CSP evidence | CSAP certificate and contract for the IaaS in use | High |
Common fail and remediation reasons — avoid these in advance
These remediation findings show up repeatedly in practice. Checking them before you start can save an entire round.
- Log retention too short: Settings such as “we only keep 30 days for operational convenience” are the most common finding. Configure retention to meet the baseline in advance.
- No MFA on admin accounts: MFA is on for end users, but the admin console is still ID/password only. Apply MFA to administrator accounts without exception.
- IaaS CSAP certification not verified: Cases where nobody checked whether the cloud infrastructure (IaaS) the SaaS runs on is itself CSAP-certified. SaaS certification only means something on certified IaaS. Always verify the CSP’s certification scope.
- Misreading physical-isolation requirements: Over-interpreting Simplified Grade as needing Standard Grade–level physical isolation, or claiming logical isolation with no evidence. Map requirements accurately to the grade.
- Policy documents vs. actual operations: The document says “quarterly patches” but there is no patch history — instant remediation. Documents must reflect operations, and operations must follow the documents.
One lesson from the field
Looking at first-time CSAP preparations, teams burn more time on document–operations alignment than on technical controls. TLS, encryption, and MFA are a setting or two. If the cycle written in the policy does not match actual operations logs, remediation rounds repeat and a month or two disappears. That is why I recommend not starting with artifacts: first record how you actually operate, then align the policy language to that. Write an idealized policy first and operations will never catch up.
Conclusion: three-step prep priority
- Lock the grade: Confirm Simplified vs. Standard from the demanding institution’s required grade plus the criticality of the information you process.
- Verify the infrastructure prerequisite: Validate the CSAP certification scope of the IaaS you run on, and configure the high-fail items first — MFA, log retention, encryption.
- Align documents and operations: Write the eight artifacts against actual operations, and remove mismatches between policy and real history.
Finish these three steps and you are ready to walk into an assessment-body consultation. Copy the tables above into your internal wiki and split the checkboxes across owners.
Frequently asked questions (FAQ)
Q. We are non-critical SaaS — can we always go Simplified Grade? A. Even if the information you process would put you on Simplified Grade, the grade the public institution you sell to requires takes priority. Confirm the required grade in the bid notice or in pre-discussions first.
Q. Does our IaaS (cloud infrastructure) also need its own CSAP? A. The SaaS provider does not need to certify the IaaS itself, but the service must run on CSAP-certified IaaS. Obtain the CSP’s certification scope and certificate as evidence.
Q. What are the exact prep time and cost? A. Typically 4–6 months from application to issuance; cost varies widely with scale. The only accurate way to lock item counts, fees, and duration is official KISA CSAP guidance plus an assessment-body quote.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.