ISMS-P Certification: Mandatory Scope, Application Process, and Costs — Complete 2026 Guide
Every year at the start of the year, one question never fails to land in an information security officer’s inbox: “The CEO is asking—do we need ISMS-P too?” And surprisingly few practitioners can answer that with a straight yes or no. Revenue, user counts, and industry conditions are intertwined, and failing to certify doesn’t just mean a fine of up to KRW 30 million—in large-enterprise and public-sector bids, not holding the certification often means losing the contract.
📌 For item-by-item checks, evidence, and responses to frequently cited findings across all 102 criteria, see ISMS-P 102-Item Practical Checklist. This article focuses on determining mandatory status, the application process, timeline, and cost.
This article aims to give immediate answers—from “are we in scope?” to “what to prepare, when, and at what cost”—using tables, a timeline, and checklists. Even scanning the tables should give you a clear direction.
⚠️ Don’t confuse this with CSAP
- ISMS-P: Certifies an organization’s information security and personal information protection management system (KISA / Korea Internet & Security Agency)
- CSAP: Certifies the security level of the cloud service itself (a condition for using public-sector cloud) The two differ in both scope and legal basis. “We use the cloud, so isn’t CSAP enough?” is a misconception.
📌 Figures below are general 2026 baselines. Always confirm actual applicability against the latest notices and KISA guidance (isms.kisa.or.kr).
1. Are We in Scope? — Decision Criteria Table
Mandatory ISMS certification under the Information and Communications Network Act can be summarized as follows.
| Category | Mandatory condition | Decision point |
|---|---|---|
| ISP | Information and communications network service provider under the Telecommunications Business Act (owns circuit facilities) | Provides service in Seoul and all metropolitan cities |
| IDC | Integrated information and communications facility (data center) operator | Operates facilities for others to provide information and communications services |
| Revenue threshold | KRW 10 billion or more in prior-year revenue from the information and communications services segment | Segment revenue, not total company revenue |
| User threshold | Daily average of 1 million or more users over the three months immediately preceding the prior year-end | DAU basis; confirm how unique visitors are counted |
| Hospitals | Tertiary general hospitals with annual revenue of KRW 150 billion or more | Special rule for medical institutions |
| Universities | Universities with 10,000 or more enrolled students | Schools under the Higher Education Act |
If any one of the above applies, you are an ISMS mandatory subject. If you also process personal information (most organizations do), obtaining ISMS-P, which includes the personal information protection domain, is the more practical choice.
ISMS vs. ISMS-P — how to choose
- ISMS: Information security management system only. Meets the minimum mandatory requirement.
- ISMS-P: Information security plus personal information processing stages. Recommended for organizations that handle large volumes of personal information or face elevated personal-data risk (MyData, AI training data, etc.).
Even if you are not in mandatory scope, voluntary application is allowed, and organizations increasingly pursue it for bid scoring, customer requirements, and external trust.
2. From Application to Certificate Issuance — Stage-by-Stage Timeline
Including preparation, plan for at least 6 months, typically 8–12 months.
| Week (cumulative) | Stage | What practitioners need to do |
|---|---|---|
| 0–12 weeks | Gap analysis and management system build-out | Update policies and guidelines, perform risk assessment, collect evidence per control |
| 12–20 weeks | Operations and evidence accumulation | Accumulate at least 2 months of actual operating logs and records (paper-only setups get findings) |
| Week 20 | Submit application | Finalize certification scope, submit official letter, pay fees |
| Weeks 21–22 | Preliminary review | Audit team checks readiness and gives advance feedback on gaps |
| Weeks 23–24 | Audit team formation and initial audit (document + on-site) | Staff interviews, system walkthroughs, on-site inspection response |
| Weeks 25–29 | Remediation of findings (up to 100 days) | Remediate against the findings report, then submit a remediation report |
| Weeks 30–33 | Certification committee review | Prepare additional supporting materials |
| Week 34 onward | Certificate issued | 3-year validity begins; register follow-up audit schedule |
The critical piece is the “operating period.” Writing policies is not enough—you need at least 2–3 months of logs, meeting minutes, and inspection records showing those policies actually ran.
3. Three-Domain Checklist — Structure of the 101 Certification Criteria
As of 2026, ISMS-P criteria fall into three domains.
| Domain | Number of controls | Key inspection items |
|---|---|---|
| 1. Establishment and operation of the management system | 16 | Policy establishment, designation of senior officer (CISO/CPO), risk management, internal audit and improvement |
| 2. Protection measure requirements | 64 | Access control, encryption, authentication and authorization, physical security, incident response, backup, vulnerability assessment |
| 3. Requirements by personal information processing stage | 21 | Collection, use, provision, outsourcing, destruction; data subject rights |
| Total | 101 | ISMS covers domains 1 and 2 (80 items); ISMS-P covers all three |
Practitioner tip: Most actual findings come from the 64 protection measure requirements. Concentrate your preparation resources there.
4. Recurring Audit Findings TOP — Causes Matched 1:1 with Countermeasures
Knowing why something becomes a finding makes it easier to prepare.
| Recurring finding | Why it is a finding | How to prepare in advance |
|---|---|---|
| Inadequate access-rights review | Terminated-employee accounts and excessive privileges left in place | Keep records of quarterly access-rights recertification |
| Log review not performed | Logs are collected but there is no evidence they were reviewed | Produce periodic log-review meeting minutes and checklists |
| Personal information not destroyed | Data past its retention period not deleted | Maintain destruction target lists and destruction confirmation records |
| Risk assessment done as a formality | Same assets and same risks copied year after year | Reflect actual asset changes; document DoA rationale |
| CISO/CPO designation or filing missing | Statutory filing obligation not met | After designation, confirm filing with the competent authority is complete |
| Weak third-party / processor management | Outsourcing contracts lack security clauses; no inspections | Annual processor status review; control of sub-processing |
| Vulnerability findings not remediated | Assessment done, remediation not done | Evidence a closed loop: assess → remediate → re-assess |
Especially during cloud migrations, outsourcing/processor management findings are surging. Moving infrastructure to AWS or Azure does not transfer responsibility—the audit team will always check that outsourcing management accountability remains with your organization.
5. Duration and Cost Estimates, and In-House vs. Consulting
Audit fees are calculated from the size of the criteria set and auditor person-days (staff × days). Depending on organization size, they typically fall in the several million to tens of millions of KRW range, per KISA’s fee schedule. Adding consulting typically adds another tens of millions of KRW.
Self-check: do you need consulting? (2 or more Yes → consulting recommended)
- Dedicated information security staff of 1 or fewer
- No prior ISMS/ISMS-P experience in the organization
- Never drawn a personal information processing flow diagram
- Difficult to establish a risk assessment methodology in-house
💬 A note from the field: For the first certification, use consulting—but switch to internal capability from the follow-up audits onward. That is more cost-efficient. When everything is handed to consultants, we have repeatedly seen the in-house owner unable to explain their own system in the audit room and pick up findings. You can outsource the documents; you must internalize the operations.
6. If You Already Hold ISMS — Expanding to ISMS-P
If you already hold ISMS, you do not need to start over.
- You can expand to ISMS-P by adding an audit of the personal information processing stage (21 criteria) only
- Aligning the expansion audit with re-audit or renewal reduces audit burden and cost
- Validity remains 3 years, maintained with one follow-up audit per year
- Follow-up audits check whether prior findings remain remediated, so findings history management is critical
In 2026, with Personal Information Protection Act amendments and the spread of MyData, domain 3 audits are tightening—so even ISMS-only organizations should start considering a P expansion.
Kickoff Checklist
- Determine mandatory status using information and communications services segment revenue and user counts
- Decide ISMS vs. ISMS-P (consider volume of personal information processed)
- Confirm certification scope and CISO/CPO designation and filing
- Run a gap analysis and identify deficient controls
- Plan 2–3 months of operating evidence accumulation
- Use the consulting self-check to decide in-house vs. external
Frequently Asked Questions (FAQ)
Q. How long does ISMS-P preparation actually take? A. Building the management system and accumulating at least 2–3 months of operating evidence typically takes 3–6 months for preparation alone. Including the audit, remediation, and certification committee, 8–12 months total is realistic.
Q. If we only have ISMS, is personal information not certified? A. Correct. ISMS covers only the information security management system. To certify collection, use, provision, destruction, and other processing stages, you need ISMS-P, which adds the 21 personal information criteria. If you already hold ISMS, you can convert via an expansion audit.
Q. If we use the cloud, is CSAP enough? A. No. CSAP certifies the cloud service itself; ISMS-P certifies the organization’s information security and personal information protection management system. Purpose and scope are different. If you are a mandatory subject, you need ISMS-P (or ISMS) regardless of whether you use the cloud.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.