/보안/CSAP Certification 2026 Guide: Low, Medium, and High Grade Differences and a Complete Application Process
SecurityCSAP인증CSAP등급차이

CSAP Certification 2026 Guide: Low, Medium, and High Grade Differences and a Complete Application Process

A practical 2026 guide to CSAP certification, which is required for public-sector cloud bids in Korea. It covers IaaS, SaaS (standard/simplified), and DaaS types; differences among low, medium, and high grades; the application process; a su

CSAP Certification 2026 Guide: Low, Medium, and High Grade Differences and a Complete Application Process

CSAP Certification 2026 Complete Guide: From Low, Medium, and High Grade Differences to the Application Process

"Without CSAP, you cannot even bid on this project"

When preparing proposals for public-sector cloud projects, you often see this at the top of the RFP eligibility requirements: "Limited to businesses that have obtained CSAP (Cloud Security Assurance Program) certification." No matter how strong your technology is, without the certificate you cannot even submit a proposal. CSAP is operated by the Korea Internet & Security Agency (KISA) under a notice from the Digital Platform Government Committee, and it is effectively the entry permit for public cloud procurement.

The problem for PMs and security officers preparing for the first time is that they get stuck at the very first question: which type and grade does my service need? Choosing the wrong track can waste months of preparation and a non-trivial amount of money. This article minimizes conceptual explanation and focuses on what to prepare and how.

CSAP Certification Types at a Glance: IaaS / SaaS / DaaS

The first decision is the certification track. The type you need depends on your service delivery model.

Certification TypeApplicable ToControl Item ScaleAssessment MethodTypical Suitable Services
IaaSProviding infrastructure (compute, storage, network)Largest (100+ items)Documents + on-site (including data center physical review)Public cloud CSPs
SaaS StandardApplication services provided to public agenciesMedium scaleDocuments + on-siteGroupware, ERP, security monitoring SaaS
SaaS SimplifiedRelatively lower-importance SaaS; supports faster entrySignificantly reduced vs. standard (~30 items)Simplified assessmentCollaboration tools, surveys/reservations, simple business SaaS
DaaSVirtual desktop servicesMedium to largeDocuments + on-siteVDI-based work environments

Practical tip: Due to the Digital Platform Government’s “SaaS-first adoption in the public sector” policy, demand for SaaS Simplified grade is rising sharply. For SaaS providers entering for the first time, a realistic strategy is to quickly secure references with Simplified grade, then expand to Standard. However, the scope of information that can be handled under Simplified is limited, so first check the data sensitivity of your target customers.

The Real Differences Between Low, Medium, and High Grades

This is the most confusing part after the shift to a grade system. Grades are divided based on the importance of the information handled in the cloud.

CategoryLow GradeMedium GradeHigh Grade
Information handledPublic / non-sensitive work materialsNon-public work materials, general personal informationSensitive information / nationally important work
Applicable systemsLow-impact systemsMost general public workNational security / confidentiality-related systems
Number of control itemsFewestMediumMost
Management/physical assessment intensityRelaxedStandardStrengthened (strict evidence requirements)
Network separation requirementsRelaxed application such as logical separationMix of logical/physicalStrong requirements such as physical network separation

The key is that you must match the grade required by the contracting agency for the project you want to bid on. Raising the grade too high causes cost and timeline to explode because of network separation and physical security requirements; lowering it means you cannot participate in that bid. In 2025–2026, discussions on relaxing network separation for SaaS are underway, somewhat lowering the entry burden for Low and Medium grades, so be sure to check the latest notice revisions.

From Application to Certificate Issuance: Step-by-Step Flow

The overall process typically takes 4–8 months. The step-by-step flow and realistic timeframes are as follows.

CODE
1. Application submission            (1–2 weeks)
       ↓
2. Evaluation/certification contract (1–2 weeks)
       ↓
3. Preparation / self-assessment     (1–3 months)  ← Most variable stage
       ↓
4. Document review                   (3–4 weeks)
       ↓
5. On-site assessment                (1–2 weeks)
       ↓
6. Defect remediation                (2–6 weeks)  ← Can spike depending on number of findings
       ↓
7. Certification committee review    (2–4 weeks)
       ↓
8. Certificate issuance

Most delays occur at step 3 (self-assessment) and step 6 (defect remediation). If you apply for assessment without enough accumulated evidence, you get stuck at remediation with “insufficient evidence period.”

Document Submission Checklist

  • Information security policy and guidelines (including latest revision history)
  • System and network diagrams (explicitly showing network separation architecture)
  • Risk analysis and assessment report
  • Access control policy and account/privilege management evidence
  • Log collection, retention, and inspection evidence
  • Security patch and vulnerability assessment history
  • Physical security (data center access control) evidence
  • Incident response procedures and tabletop/drill records

Common Defect Cases That Get You Stuck

  1. Insufficient evidence period — Logs and inspection history need several months accumulated, but you only started just before assessment
  2. Inadequate network separation — Diagrams do not match the actual environment; insufficient justification for logical separation
  3. Missing security patch history — No records of patch application or verification evidence
  4. Poor privilege management — Departed employee accounts not revoked; privilege review cycle not followed

Managing Renewal and Surveillance Assessment Cycles

Certification is not a one-and-done. Put maintenance and renewal cycles on the calendar in advance.

CategoryTimingPreparation Points
Certification validity5 years from issuance dateBased on the initial certificate
Surveillance (maintenance) assessmentOnce per yearContinuously accumulate operational evidence; reflect changes
Renewal assessmentBefore validity expiresFull re-assessment at initial assessment level

The most common mistake is taking surveillance assessments lightly. If evidence is empty for a year, it all blows up at renewal. Accumulating evidence as you go is the cheapest path.

Conclusion & ISMS-P vs CSAP FAQ

In my practical experience, the most costly pattern in CSAP preparation is starting only after you see the RFP. Self-assessment and evidence accumulation alone take 1–3 months, so as soon as you recognize a business opportunity, decide the track and grade and start collecting evidence.

Frequently Asked Questions (FAQ)

Q. If we have ISMS-P, are we exempt from CSAP? A. No. The two certifications have different purposes and scopes. ISMS-P covers the overall information security and personal information protection management system, while CSAP assesses the security of public cloud services and is a mandatory requirement for participating in public procurement. However, some control items are mutually recognized, so if you hold ISMS-P you can reuse some evidence for overlapping items. CSAP-specific requirements such as network separation and physical security still need separate preparation.

Q. Can we participate in all public bids with SaaS Simplified grade? A. No. Simplified grade is limited to services with lower information sensitivity. If the contracting agency requires Medium/High grade or SaaS Standard, participation is restricted, so check the eligibility requirements of your target projects first.

Q. How long should we plan for the entire process through certification? A. It varies by self-assessment maturity and number of findings, but typically 4–8 months is recommended. New providers with insufficient evidence may take longer, so build in buffer.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.