/보안/ISMS-P Certification: Mandatory Scope, Application Process, and Costs — Complete 2026 Guide
Security국내보안규제컴플라이언스실무

ISMS-P Certification: Mandatory Scope, Application Process, and Costs — Complete 2026 Guide

Is your company required to obtain ISMS-P certification? This practitioner guide covers eligibility by revenue and user counts, the application timeline, 101 certification criteria, how to prepare for common findings, plus duration and cost

ISMS-P Certification: Mandatory Scope, Application Process, and Costs — Complete 2026 Guide

ISMS-P Certification: Mandatory Scope, Application Process, and Costs — Complete 2026 Guide

Every year at the start of the year, one question never fails to land in an information security officer’s inbox: “The CEO is asking—do we need ISMS-P too?” And surprisingly few practitioners can answer that with a straight yes or no. Revenue, user counts, and industry conditions are intertwined, and failing to certify doesn’t just mean a fine of up to KRW 30 million—in large-enterprise and public-sector bids, not holding the certification often means losing the contract.

📌 For item-by-item checks, evidence, and responses to frequently cited findings across all 102 criteria, see ISMS-P 102-Item Practical Checklist. This article focuses on determining mandatory status, the application process, timeline, and cost.

This article aims to give immediate answers—from “are we in scope?” to “what to prepare, when, and at what cost”—using tables, a timeline, and checklists. Even scanning the tables should give you a clear direction.

⚠️ Don’t confuse this with CSAP

  • ISMS-P: Certifies an organization’s information security and personal information protection management system (KISA / Korea Internet & Security Agency)
  • CSAP: Certifies the security level of the cloud service itself (a condition for using public-sector cloud) The two differ in both scope and legal basis. “We use the cloud, so isn’t CSAP enough?” is a misconception.

📌 Figures below are general 2026 baselines. Always confirm actual applicability against the latest notices and KISA guidance (isms.kisa.or.kr).

1. Are We in Scope? — Decision Criteria Table

Mandatory ISMS certification under the Information and Communications Network Act can be summarized as follows.

CategoryMandatory conditionDecision point
ISPInformation and communications network service provider under the Telecommunications Business Act (owns circuit facilities)Provides service in Seoul and all metropolitan cities
IDCIntegrated information and communications facility (data center) operatorOperates facilities for others to provide information and communications services
Revenue thresholdKRW 10 billion or more in prior-year revenue from the information and communications services segmentSegment revenue, not total company revenue
User thresholdDaily average of 1 million or more users over the three months immediately preceding the prior year-endDAU basis; confirm how unique visitors are counted
HospitalsTertiary general hospitals with annual revenue of KRW 150 billion or moreSpecial rule for medical institutions
UniversitiesUniversities with 10,000 or more enrolled studentsSchools under the Higher Education Act

If any one of the above applies, you are an ISMS mandatory subject. If you also process personal information (most organizations do), obtaining ISMS-P, which includes the personal information protection domain, is the more practical choice.

ISMS vs. ISMS-P — how to choose

  • ISMS: Information security management system only. Meets the minimum mandatory requirement.
  • ISMS-P: Information security plus personal information processing stages. Recommended for organizations that handle large volumes of personal information or face elevated personal-data risk (MyData, AI training data, etc.).

Even if you are not in mandatory scope, voluntary application is allowed, and organizations increasingly pursue it for bid scoring, customer requirements, and external trust.

2. From Application to Certificate Issuance — Stage-by-Stage Timeline

Including preparation, plan for at least 6 months, typically 8–12 months.

Week (cumulative)StageWhat practitioners need to do
0–12 weeksGap analysis and management system build-outUpdate policies and guidelines, perform risk assessment, collect evidence per control
12–20 weeksOperations and evidence accumulationAccumulate at least 2 months of actual operating logs and records (paper-only setups get findings)
Week 20Submit applicationFinalize certification scope, submit official letter, pay fees
Weeks 21–22Preliminary reviewAudit team checks readiness and gives advance feedback on gaps
Weeks 23–24Audit team formation and initial audit (document + on-site)Staff interviews, system walkthroughs, on-site inspection response
Weeks 25–29Remediation of findings (up to 100 days)Remediate against the findings report, then submit a remediation report
Weeks 30–33Certification committee reviewPrepare additional supporting materials
Week 34 onwardCertificate issued3-year validity begins; register follow-up audit schedule

The critical piece is the “operating period.” Writing policies is not enough—you need at least 2–3 months of logs, meeting minutes, and inspection records showing those policies actually ran.

3. Three-Domain Checklist — Structure of the 101 Certification Criteria

As of 2026, ISMS-P criteria fall into three domains.

DomainNumber of controlsKey inspection items
1. Establishment and operation of the management system16Policy establishment, designation of senior officer (CISO/CPO), risk management, internal audit and improvement
2. Protection measure requirements64Access control, encryption, authentication and authorization, physical security, incident response, backup, vulnerability assessment
3. Requirements by personal information processing stage21Collection, use, provision, outsourcing, destruction; data subject rights
Total101ISMS covers domains 1 and 2 (80 items); ISMS-P covers all three

Practitioner tip: Most actual findings come from the 64 protection measure requirements. Concentrate your preparation resources there.

4. Recurring Audit Findings TOP — Causes Matched 1:1 with Countermeasures

Knowing why something becomes a finding makes it easier to prepare.

Recurring findingWhy it is a findingHow to prepare in advance
Inadequate access-rights reviewTerminated-employee accounts and excessive privileges left in placeKeep records of quarterly access-rights recertification
Log review not performedLogs are collected but there is no evidence they were reviewedProduce periodic log-review meeting minutes and checklists
Personal information not destroyedData past its retention period not deletedMaintain destruction target lists and destruction confirmation records
Risk assessment done as a formalitySame assets and same risks copied year after yearReflect actual asset changes; document DoA rationale
CISO/CPO designation or filing missingStatutory filing obligation not metAfter designation, confirm filing with the competent authority is complete
Weak third-party / processor managementOutsourcing contracts lack security clauses; no inspectionsAnnual processor status review; control of sub-processing
Vulnerability findings not remediatedAssessment done, remediation not doneEvidence a closed loop: assess → remediate → re-assess

Especially during cloud migrations, outsourcing/processor management findings are surging. Moving infrastructure to AWS or Azure does not transfer responsibility—the audit team will always check that outsourcing management accountability remains with your organization.

5. Duration and Cost Estimates, and In-House vs. Consulting

Audit fees are calculated from the size of the criteria set and auditor person-days (staff × days). Depending on organization size, they typically fall in the several million to tens of millions of KRW range, per KISA’s fee schedule. Adding consulting typically adds another tens of millions of KRW.

Self-check: do you need consulting? (2 or more Yes → consulting recommended)

  • Dedicated information security staff of 1 or fewer
  • No prior ISMS/ISMS-P experience in the organization
  • Never drawn a personal information processing flow diagram
  • Difficult to establish a risk assessment methodology in-house

💬 A note from the field: For the first certification, use consulting—but switch to internal capability from the follow-up audits onward. That is more cost-efficient. When everything is handed to consultants, we have repeatedly seen the in-house owner unable to explain their own system in the audit room and pick up findings. You can outsource the documents; you must internalize the operations.

6. If You Already Hold ISMS — Expanding to ISMS-P

If you already hold ISMS, you do not need to start over.

  • You can expand to ISMS-P by adding an audit of the personal information processing stage (21 criteria) only
  • Aligning the expansion audit with re-audit or renewal reduces audit burden and cost
  • Validity remains 3 years, maintained with one follow-up audit per year
  • Follow-up audits check whether prior findings remain remediated, so findings history management is critical

In 2026, with Personal Information Protection Act amendments and the spread of MyData, domain 3 audits are tightening—so even ISMS-only organizations should start considering a P expansion.

Kickoff Checklist

  • Determine mandatory status using information and communications services segment revenue and user counts
  • Decide ISMS vs. ISMS-P (consider volume of personal information processed)
  • Confirm certification scope and CISO/CPO designation and filing
  • Run a gap analysis and identify deficient controls
  • Plan 2–3 months of operating evidence accumulation
  • Use the consulting self-check to decide in-house vs. external

Frequently Asked Questions (FAQ)

Q. How long does ISMS-P preparation actually take? A. Building the management system and accumulating at least 2–3 months of operating evidence typically takes 3–6 months for preparation alone. Including the audit, remediation, and certification committee, 8–12 months total is realistic.

Q. If we only have ISMS, is personal information not certified? A. Correct. ISMS covers only the information security management system. To certify collection, use, provision, destruction, and other processing stages, you need ISMS-P, which adds the 21 personal information criteria. If you already hold ISMS, you can convert via an expansion audit.

Q. If we use the cloud, is CSAP enough? A. No. CSAP certifies the cloud service itself; ISMS-P certifies the organization’s information security and personal information protection management system. Purpose and scope are different. If you are a mandatory subject, you need ISMS-P (or ISMS) regardless of whether you use the cloud.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.