ISMS-P Certification Prep Checklist 2026 — Start with the Findings That Come Up Most
"We got the certificate, but the same findings keep coming up at every surveillance audit."
If you've been through ISMS-P even once, you'll nod at that. The problem isn't the findings themselves—it's that the cost of fixing them (re-audits, consulting, overtime) often exceeds the original consulting fee. That's even more true for SMEs and startups where a single security person, or an infra/dev lead wearing two hats, is carrying the whole load.
This post is a practical checklist. It starts with whether your company is a mandatory subject, then walks through the items that most often produce nonconformities (findings) in real audits, in symptom → checkpoint → how to prepare order. The tables are built so you can self-assess just by reading them—copy and use them if you're already in prep.
⚠️ Revenue, timeline, and fee figures in this article are reference values to aid understanding. Mandatory-subject criteria and fees change when notices are revised, so always check the latest KISA announcements and notices.
1. Is Our Company a Mandatory Subject? ISMS vs. ISMS-P
Let's start with the terms.
- ISMS (Information Security Management System): certifies the information security domain only
- ISMS-P (Information Security and Personal Information Protection Management System): information security plus protection at each stage of personal information processing
In other words, if your service actually handles personal information—sign-up, payments, marketing consent, and so on—ISMS-P is the right fit. Conversely, if personal information is a small share of what you do (for example, B2B infrastructure services), ISMS alone may be enough.
2026 ISMS Mandatory-Subject Decision Table
| Category | Subject criteria (examples) | When ISMS alone may suffice | When ISMS-P is the better fit |
|---|---|---|---|
| ISP (telecommunications network service provider) | Operators with nationwide circuit facilities | Low share of personal information processing | Directly processes subscriber personal information |
| IDC (internet data center) | Operates facilities for others' information and communications services | Simple colocation/hosting | Processes tenant personal information under consignment |
| Revenue/income scale | Annual revenue/income of KRW 150 billion or more, among other size thresholds | Low volume of personal information processing | Holds a large member database |
| Number of users | Daily average of 1 million or more users as of the end of the previous year | Mostly de-identified/anonymous | Processes large volumes of real-name/identifying information |
| Information and communications service revenue | Revenue from information and communications services of KRW 10 billion or more | Almost no personal information | Member- and payment-based services |
The figures above are examples of representative criteria. Many companies also obtain certification voluntarily (even when not mandatory) to build trust or score points in bids. The trend of obtaining ISMS-P voluntarily even when it is not required has been especially clear among AI and SaaS startups in 2026.
2. Process, Timeline, and Cost at a Glance
From prep to certificate issuance typically takes 4–6 months. Larger scope or a first-time certification takes longer.
[Stage 1] Prep & gap analysis (4–8 weeks) Current-state assessment, policy setup, asset identification
↓
[Stage 2] Application & contract (1–2 weeks) Apply to the certification body, schedule audit dates
↓
[Stage 3] Pre-check (optional) (1–2 weeks) Mock audit to clear findings in advance
↓
[Stage 4] Main audit (desk + on-site) (1–2 weeks) Document & operational evidence review, interviews
↓
[Stage 5] Finding remediation (2–6 weeks) Address findings + submit evidence
↓
[Stage 6] Certification committee & issue (2–4 weeks) Deliberation/decision, then certificate issuedCost Structure (scope and structure, not exact numbers)
| Item | What it covers | What drives variance by size |
|---|---|---|
| Audit fees | Paid to the certification body; calculated from certification scope and headcount | Scope of application (number of services/systems) and employee count |
| Consulting fees | Gap analysis, documentation, mock-audit support | Internal capability; whether you prepare in-house |
| Solution costs | Log management, access control, encryption, backup, etc. | Maturity of existing infrastructure |
| Internal effort | Time the owner spends (the most underestimated line) | Dual-role load; state of existing documentation |
💡 A note from the field: The line that most often goes missing from cost estimates is "internal effort." Consulting fees show up on the quote; the cost of your owner spending half of three months on certification does not. Securing the owner's available time when you set the schedule matters more than picking a consulting firm.
3. Checklist of Items That Frequently Produce Audit Findings (the core)
This is the main event. These are the items that repeatedly come back as nonconformities in real audits.
| Area | Symptom (how it usually gets called out) | Checkpoint | How to prepare |
|---|---|---|---|
| Access control & account management | Terminated/unused accounts still active; shared admin accounts in use | Reconcile account issuance/revocation logs with actual system accounts; privilege review cycle | Quarterly privilege re-review records, one person, one account, keep access-approval evidence |
| Log & access-record retention | Access logs for personal information processing systems don't meet the retention period; weak anti-tampering | Log retention period (access records at least 6 months; downloads and similar have separate requirements) and integrity | Store logs separately with access control; write regular inspection logs |
| Risk assessment documents | Risks identified but no DoA (acceptable risk level) rationale or treatment plan | Traceability: asset ID → threats/vulnerabilities → risk scoring → treatment plan | Annual risk assessment records; residual risk approved by management |
| Encryption | Passwords/unique identifiers stored or transmitted unencrypted; no key management | Scope of encryption in storage and transit; key generation, storage, and destruction procedures | Document encryption policy and key-management procedures, plus evidence of application |
| Personal information flow diagram | Collection-to-destruction flow doesn't match actual processing; consignment/third-party provision missing | Flow diagram ↔ personal information processing policy ↔ actual system behavior must match | Set a refresh cycle for the flow diagram (update immediately on change) |
If You Use Cloud (AWS, etc.) — Watch the Shared Responsibility Model
As more SaaS and cloud-based startups have appeared in 2026, questions about shared-responsibility findings have spiked. The key point: "our cloud provider is certified, so we're done" is not true.
- Cloud provider responsibility: physical security, hypervisor, underlying infrastructure
- Customer responsibility: OS and above, access permissions (IAM), security groups, encryption settings, log collection
Auditors look at configuration and operational evidence in the customer-responsibility zone. Document and evidence least-privilege IAM, S3 bucket public-access blocks, CloudTrail log retention, and similar controls.
4. The Real Game Is Maintenance — Preparing for Surveillance and Recertification Audits
An ISMS-P certificate is valid for 3 years. The structure in between looks like this:
- Year 1: issuance
- Years 2 and 3: annual surveillance audit (confirms you are maintaining the system)
- After 3 years: recertification audit (essentially a full re-audit)
The most common failure pattern is "cramming operational evidence together right before the audit." Six months of inspection records all created on the same day—auditors spot that immediately. The right answer is to accumulate evidence in the ordinary course of work, which is why you need an annual routine calendar.
Annual Operational-Evidence Calendar Template
| Cadence | Recurring activity | Evidence to keep |
|---|---|---|
| Monthly | Backup health check, security-patch status | Backup inspection logs, patch application records |
| Quarterly | Access-privilege re-review, unused-account revocation | Privilege review results, account revocation log |
| Semi-annual | Drills (phishing, incident response), vulnerability assessment | Drill after-action reports, remediation records |
| Annual | Risk assessment, information security training, internal audit | Risk assessment report, training completion roster, audit results |
Just putting this table on the calendar cuts the surveillance-audit burden roughly in half. The core idea: evidence is not something you manufacture—it's something you let accumulate.
Frequently Asked Questions (FAQ)
Q1. Should we get ISMS or ISMS-P? A. If you actually process personal information—members, payments, marketing, and so on—ISMS-P is the right fit. Infrastructure-style services with a low share of personal information may be fine with ISMS alone. Whether you are a mandatory subject is a separate call based on revenue and user counts.
Q2. Can we prepare in-house without consulting? A. Yes. For a first time, though, getting outside help at least for gap analysis and a mock audit usually costs less than a re-audit later. From the second recertification onward, many companies run it with internal capability.
Q3. What's the minimum prep time? A. Even if documentation and operations are reasonably in place, application to issuance is typically 4–6 months. If you're starting from a blank page, budget an extra 2–3 months just to close gaps.
Q4. Can the certificate be revoked at a surveillance audit? A. Yes—if you fail to remediate material findings by the deadline, or the management system is effectively not operating, the certificate can be revoked or suspended. That's why day-to-day operational evidence matters.
Q5. If we use cloud (AWS, etc.), how far does our responsibility go? A. Under the shared responsibility model, underlying infrastructure is the cloud provider's; OS and above (IAM, encryption, logs, security configuration) is yours. Auditors check configuration and operational evidence in the customer-responsibility zone.
Q6. The numeric thresholds keep changing—where do we check? A. Mandatory-subject criteria, audit fees, access-record retention requirements, and similar items change when notices are revised. Use KISA (Korea Internet & Security Agency) ISMS-P scheme announcements and the latest notices as the source of truth.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.