CSAP Certification 2026 Complete Guide: From Low, Medium, and High Grade Differences to the Application Process
"Without CSAP, you cannot even bid on this project"
When preparing proposals for public-sector cloud projects, you often see this at the top of the RFP eligibility requirements: "Limited to businesses that have obtained CSAP (Cloud Security Assurance Program) certification." No matter how strong your technology is, without the certificate you cannot even submit a proposal. CSAP is operated by the Korea Internet & Security Agency (KISA) under a notice from the Digital Platform Government Committee, and it is effectively the entry permit for public cloud procurement.
The problem for PMs and security officers preparing for the first time is that they get stuck at the very first question: which type and grade does my service need? Choosing the wrong track can waste months of preparation and a non-trivial amount of money. This article minimizes conceptual explanation and focuses on what to prepare and how.
CSAP Certification Types at a Glance: IaaS / SaaS / DaaS
The first decision is the certification track. The type you need depends on your service delivery model.
| Certification Type | Applicable To | Control Item Scale | Assessment Method | Typical Suitable Services |
|---|---|---|---|---|
| IaaS | Providing infrastructure (compute, storage, network) | Largest (100+ items) | Documents + on-site (including data center physical review) | Public cloud CSPs |
| SaaS Standard | Application services provided to public agencies | Medium scale | Documents + on-site | Groupware, ERP, security monitoring SaaS |
| SaaS Simplified | Relatively lower-importance SaaS; supports faster entry | Significantly reduced vs. standard (~30 items) | Simplified assessment | Collaboration tools, surveys/reservations, simple business SaaS |
| DaaS | Virtual desktop services | Medium to large | Documents + on-site | VDI-based work environments |
Practical tip: Due to the Digital Platform Government’s “SaaS-first adoption in the public sector” policy, demand for SaaS Simplified grade is rising sharply. For SaaS providers entering for the first time, a realistic strategy is to quickly secure references with Simplified grade, then expand to Standard. However, the scope of information that can be handled under Simplified is limited, so first check the data sensitivity of your target customers.
The Real Differences Between Low, Medium, and High Grades
This is the most confusing part after the shift to a grade system. Grades are divided based on the importance of the information handled in the cloud.
| Category | Low Grade | Medium Grade | High Grade |
|---|---|---|---|
| Information handled | Public / non-sensitive work materials | Non-public work materials, general personal information | Sensitive information / nationally important work |
| Applicable systems | Low-impact systems | Most general public work | National security / confidentiality-related systems |
| Number of control items | Fewest | Medium | Most |
| Management/physical assessment intensity | Relaxed | Standard | Strengthened (strict evidence requirements) |
| Network separation requirements | Relaxed application such as logical separation | Mix of logical/physical | Strong requirements such as physical network separation |
The key is that you must match the grade required by the contracting agency for the project you want to bid on. Raising the grade too high causes cost and timeline to explode because of network separation and physical security requirements; lowering it means you cannot participate in that bid. In 2025–2026, discussions on relaxing network separation for SaaS are underway, somewhat lowering the entry burden for Low and Medium grades, so be sure to check the latest notice revisions.
From Application to Certificate Issuance: Step-by-Step Flow
The overall process typically takes 4–8 months. The step-by-step flow and realistic timeframes are as follows.
1. Application submission (1–2 weeks)
↓
2. Evaluation/certification contract (1–2 weeks)
↓
3. Preparation / self-assessment (1–3 months) ← Most variable stage
↓
4. Document review (3–4 weeks)
↓
5. On-site assessment (1–2 weeks)
↓
6. Defect remediation (2–6 weeks) ← Can spike depending on number of findings
↓
7. Certification committee review (2–4 weeks)
↓
8. Certificate issuanceMost delays occur at step 3 (self-assessment) and step 6 (defect remediation). If you apply for assessment without enough accumulated evidence, you get stuck at remediation with “insufficient evidence period.”
Document Submission Checklist
- Information security policy and guidelines (including latest revision history)
- System and network diagrams (explicitly showing network separation architecture)
- Risk analysis and assessment report
- Access control policy and account/privilege management evidence
- Log collection, retention, and inspection evidence
- Security patch and vulnerability assessment history
- Physical security (data center access control) evidence
- Incident response procedures and tabletop/drill records
Common Defect Cases That Get You Stuck
- Insufficient evidence period — Logs and inspection history need several months accumulated, but you only started just before assessment
- Inadequate network separation — Diagrams do not match the actual environment; insufficient justification for logical separation
- Missing security patch history — No records of patch application or verification evidence
- Poor privilege management — Departed employee accounts not revoked; privilege review cycle not followed
Managing Renewal and Surveillance Assessment Cycles
Certification is not a one-and-done. Put maintenance and renewal cycles on the calendar in advance.
| Category | Timing | Preparation Points |
|---|---|---|
| Certification validity | 5 years from issuance date | Based on the initial certificate |
| Surveillance (maintenance) assessment | Once per year | Continuously accumulate operational evidence; reflect changes |
| Renewal assessment | Before validity expires | Full re-assessment at initial assessment level |
The most common mistake is taking surveillance assessments lightly. If evidence is empty for a year, it all blows up at renewal. Accumulating evidence as you go is the cheapest path.
Conclusion & ISMS-P vs CSAP FAQ
In my practical experience, the most costly pattern in CSAP preparation is starting only after you see the RFP. Self-assessment and evidence accumulation alone take 1–3 months, so as soon as you recognize a business opportunity, decide the track and grade and start collecting evidence.
Frequently Asked Questions (FAQ)
Q. If we have ISMS-P, are we exempt from CSAP? A. No. The two certifications have different purposes and scopes. ISMS-P covers the overall information security and personal information protection management system, while CSAP assesses the security of public cloud services and is a mandatory requirement for participating in public procurement. However, some control items are mutually recognized, so if you hold ISMS-P you can reuse some evidence for overlapping items. CSAP-specific requirements such as network separation and physical security still need separate preparation.
Q. Can we participate in all public bids with SaaS Simplified grade? A. No. Simplified grade is limited to services with lower information sensitivity. If the contracting agency requires Medium/High grade or SaaS Standard, participation is restricted, so check the eligibility requirements of your target projects first.
Q. How long should we plan for the entire process through certification? A. It varies by self-assessment maturity and number of findings, but typically 4–8 months is recommended. New providers with insufficient evidence may take longer, so build in buffer.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.