
Short answer: ISMS-P certification is South Korea's national certification for information security and personal information management, operated by the Korea Internet & Security Agency (KISA). It is voluntary for most foreign SaaS and HealthTech vendors, but Korean enterprise and healthcare buyers often prefer it. If you already hold ISO 27001 or SOC 2, you can reuse much of that work.
Related guides:
- ISO 27001 Certification Steps Explained
- SOC 2 vs ISO 27001: Which Framework is Right for You?
- How GDPR, ISO 27001, and SOC 2 can level up your selling game
Key takeaways
- ISMS-P combines two earlier Korean schemes, ISMS and PIMS, into one certification covering both information security and personal information processing.
- There are two certification types: ISMS (security only, 80 criteria) and ISMS-P (security plus personal information, 101 criteria). ISMS is mandatory for certain organizations that meet legal thresholds, including some large hospitals and universities. ISMS-P is currently voluntary, but Korea announced plans in April 2026 to make ISMS-P mandatory for certain large personal data processors, with a planned start in 2027 that is not yet final.
- ISMS-P is not a substitute for ISO 27001, and ISO 27001 is not a substitute for ISMS-P. They overlap heavily, but ISMS-P is far more specific about how personal information is collected, used, shared and destroyed under Korea's Personal Information Protection Act (PIPA).
- Certificates are valid for three years, with annual surveillance audits in between.
- Teams with a working ISO 27001 or SOC 2 program should treat ISMS-P as a gap exercise focused on PIPA, data lifecycle controls and Korean-language documentation.
What is ISMS-P certification?
ISMS-P (Personal Information and Information Security Management System) is South Korea's government-backed certification that confirms an organization runs a sound security and privacy management system. It has been in force since November 7, 2018, when the older ISMS certification was merged with the PIMS (Personal Information Management System) scheme, so organizations no longer had to pursue two separate programs.
The scheme is operated by KISA under the Ministry of Science and ICT and the Personal Information Protection Commission (PIPC), Korea's data protection authority. ISMS-P rests on Article 32-2 of PIPA, while ISMS rests on Article 47 of the Information and Communications Network Act (the Network Act). Official criteria, notices and the list of certified organizations are on the ISMS-P portal run by KISA, and the PIPC publishes an English overview of the scheme.
The current criteria, 101 in total, are grouped into three areas:
- Management system establishment and operation (16 criteria). Leadership commitment, scope, risk management, and the ongoing operation and improvement of the program. This will feel familiar to anyone who has implemented ISO 27001 clauses 4 to 10.
- Protection measures (64 criteria). Technical, physical and administrative safeguards such as access control, encryption, logging, vulnerability management, incident response and supplier management.
- Requirements for each stage of personal information processing (21 criteria). Controls for collection, use, provision to third parties, retention and destruction of personal information, plus the protection of data subject rights. This area applies only to the ISMS-P certification type, so ISMS uses 80 criteria and ISMS-P uses all 101.
The third area is what makes ISMS-P distinct: you must prove that each step of handling personal information follows Korean privacy law.
ISMS or ISMS-P: which certification type applies to you?
Choose ISMS if you only need to demonstrate information security, and ISMS-P if you process personal information of Korean users and want to show privacy compliance too. Both types share the same management system and protection measures criteria. ISMS-P adds the personal information processing requirements on top.
| ISMS | ISMS-P | |
|---|---|---|
| What it covers | Information security management | Information security plus personal information processing |
| Criteria areas | Management system and protection measures (80 criteria) | All three areas, including each stage of personal information processing (101 criteria) |
| Mandatory? | Yes, for certain organizations that meet legal thresholds | Voluntary today; mandatory certification is planned for certain large processors (planned for 2027, not yet final) |
| Typical candidates | Major telecom and internet service providers, data center operators, larger online service providers, and some large hospitals and universities | Organizations that process significant volumes of personal information |
| Best fit for SaaS and HealthTech | Infrastructure or B2B services that hold little personal data | Products that store patient, user or employee personal information |
For most HealthTech vendors, ISMS-P is the more useful certificate because Korean healthcare customers care about how patient and user data is handled, not just how servers are secured.
Does a foreign SaaS or HealthTech vendor need ISMS-P?
Usually not by law today, but often by market expectation. The mandatory obligation currently attaches to ISMS, under Article 47 of the Network Act and its Enforcement Decree. The categories include, among others:
- Major telecommunications and internet service providers and integrated data center operators.
- Information and communications service providers above revenue or daily user thresholds (for example, prior-year information and communications service revenue of KRW 10 billion or more, or an average of 1 million or more daily users).
- Some large hospitals (tertiary general hospitals above a revenue threshold) and universities above an enrollment threshold.
This list is not exhaustive and thresholds change through amendments, so check the current Enforcement Decree on law.go.kr or confirm with Korean counsel. A foreign startup selling into Korea is unlikely to cross these thresholds early on, but do not assume.
ISMS-P is becoming mandatory for some organizations. In April 2026, the PIPC and the Ministry of Science and ICT announced a reform of the scheme. According to a Yulchon summary of the announcement, ISMS-P is planned to become mandatory for key public and private personal data controllers, such as major public system operators, telecom carriers, identity verification agencies and large-scale processors, with a planned start in the second half of 2027 through amendments to the PIPA Enforcement Decree. The reform also plans tiered certification levels, more technical audits such as penetration testing, and stricter post-certification monitoring and revocation. The details depend on regulations that are not yet final, so track PIPC announcements.
Even when voluntary, it can matter commercially:
- Korean enterprise procurement. Large Korean buyers often list ISMS or ISMS-P in security requirements, the same way US buyers ask for a SOC 2 report.
- Healthcare and public sector buyers. Organizations handling sensitive data look for a recognized local certification that shows PIPA compliance. Large hospitals that are themselves subject to mandatory ISMS may also scrutinize the security of vendors inside their certified scope.
Separately from certification, PIPA applies whenever you process personal information of people in Korea. PIPA has its own requirements around consent, notices, overseas transfers and, for some foreign businesses, designating a domestic representative. PIPA has been amended in recent years, so confirm the current text and guidance with the PIPC before finalizing your approach.
ISMS-P vs ISO 27001: what is different?
ISO 27001 is an international, risk-based standard for an information security management system, while ISMS-P is a Korean national certification with prescriptive privacy criteria tied to Korean law. Both certify a management system, and both run on three-year cycles with annual surveillance audits. The differences are in scope, prescriptiveness and recognition.
| ISMS-P | ISO 27001 | |
|---|---|---|
| Owner | Korean government, operated by KISA | International standard published by ISO and IEC |
| Legal basis | Tied to Korean law, including PIPA | Voluntary standard with no single legal basis |
| Privacy coverage | Detailed criteria for each stage of personal information processing | Limited, privacy extension available through ISO 27701 |
| Control approach | Defined set of 101 criteria (80 for ISMS) that auditors check | 93 Annex A controls selected through risk assessment and a Statement of Applicability |
| Recognition | Strongest inside South Korea | Recognized worldwide |
| Audit language | Expect Korean-language documentation and interviews | Usually your working language |
| Certificate validity | Three years with annual surveillance audits | Three years with annual surveillance audits |
| Can replace the other? | No | No |
In short, ISO 27001 gives you the structure and most technical safeguards, and ISMS-P adds detail on personal information and Korean law. If you need a refresher on Annex A, our ISO 27001 checklist lists every control.
How does the ISMS-P certification process work?
The process moves from preparation through application, audit, corrective action, committee review and issuance, followed by annual surveillance. Exact timelines and fees depend on your scope and the certification body, so get a current quote from KISA or a designated body before planning a budget.
- Define scope. Decide which services, systems, locations and personal information flows are in scope. For ISMS-P, the scope must include the personal information processing for the services you certify.
- Build and operate the management system. Run the program for a period before applying so auditors can see evidence of operation, not just documents. Check the current minimum operating period in KISA guidance.
- Apply to the certification body. Submit the application and scope documents. The body reviews eligibility and agrees on audit scope and effort.
- Certification audit. A team of qualified auditors reviews documentation and conducts on-site checks and interviews against the criteria.
- Corrective actions. Auditors issue findings for any criteria not met. You fix them and submit evidence within the deadline set by the certification body.
- Certification committee review. A committee reviews the audit results and corrective actions and decides whether to grant certification.
- Certificate issued. The certificate is valid for three years.
- Annual surveillance (post) audits. Each year, auditors confirm the program is still operating. At the end of the three years, a renewal audit starts the next cycle.
If you have been through ISO 27001, this sequence will look familiar. One common mistake is applying too early: auditors want to see the program running, so leave time to generate records first.
How do you get ready if you already have ISO 27001 or SOC 2?
Start with a gap assessment against the ISMS-P criteria, then focus your effort on personal information lifecycle controls, PIPA alignment and Korean documentation. Most of your existing security controls will map across. The plan below assumes a SaaS or HealthTech team with a working ISO 27001 certificate or SOC 2 report.
Phase 1: Scope and gap assessment
- Map every Korean customer and user data flow, including which systems store personal information and which subprocessors receive it.
- Compare your current control set to all three ISMS-P areas and tag each criterion as covered, partially covered or missing.
- Decide between ISMS and ISMS-P based on whether personal information processing is central to the service.
Phase 2: Close privacy and lifecycle gaps
- Document lawful collection and consent practices that match PIPA, including privacy notices in Korean.
- Define retention periods and secure destruction procedures for each category of personal information.
- Record every third-party provision and overseas transfer, and confirm the legal basis for each.
- Set up processes to handle data subject requests such as access, correction and deletion.
Phase 3: Strengthen management system evidence
- Extend your risk assessment to include Korea-specific legal and privacy risks.
- Add Korean legal requirements to your register of legal and contractual obligations.
Phase 4: Prepare for the audit
- Translate or prepare Korean versions of core policies, procedures and records, and line up a Korean-speaking point of contact for interviews.
- Run a mock audit against the criteria, ideally with an advisor who has ISMS-P experience.
- Collect evidence that the program has been operating, such as access reviews, training records and incident logs.
What carries over and what does not
| Existing control area | Carries over from ISO 27001 or SOC 2? | ISMS-P gap to watch |
|---|---|---|
| Risk assessment and treatment | Mostly | Add Korean legal and privacy risks |
| Access control and MFA | Yes | Evidence of access limits on personal information systems |
| Logging and monitoring | Mostly | Access logs for personal information and log review records |
| Vendor management | Mostly | Third-party provision and outsourcing disclosures under PIPA |
| Incident response | Mostly | Korean breach notification duties to PIPC and data subjects |
| Privacy notices and consent | Rarely | PIPA-aligned notices and consent records |
| Retention and destruction | Partly | Defined periods and documented destruction per data type |
If you are still building your first certification, our guide for startups on achieving ISO 27001 certification is a good foundation before taking on ISMS-P.
How SecureSlate helps
SecureSlate helps SMB, SaaS and HealthTech teams run several frameworks from one program. Multi-framework mapping lets you reuse ISO 27001 and SOC 2 controls as the base for a new framework gap assessment, while policy templates give you a starting point for the additional privacy and lifecycle procedures. Continuous control monitoring and automated evidence collection keep audit records current between surveillance audits, vendor risk management tracks the subprocessors that receive personal information, and a trust center lets you share your security posture with prospective Korean buyers.
Start your free SecureSlate trial
FAQ
Is ISMS-P certification mandatory for foreign companies?
Generally no, at least today. The mandatory obligation currently applies to ISMS, and only for organizations that meet legal thresholds, such as major telecom and internet service providers, data center operators, larger online service providers, and some large hospitals and universities. That list is not exhaustive. ISMS-P is voluntary for now, but Korea has announced plans to make it mandatory for certain large personal data processors, with a planned 2027 start that is not yet final, and Korean buyers may request it regardless. Confirm your specific position with Korean counsel.
Does ISO 27001 certification count toward ISMS-P?
Only in limited cases. Article 47(3) of the Network Act lets the government omit part of the ISMS audit for organizations that are required to obtain ISMS and already hold an international-standard information security certification, with the omitted scope set by ministerial notice. Outside that rule there is no automatic recognition, and the personal information criteria are always audited. In practice, an ISO 27001 program still shortens preparation because the management system, risk process and many protection measures already exist.
How long is an ISMS-P certificate valid?
Three years. You must pass annual surveillance audits during that period, and a renewal audit at the end of the cycle.
What is the difference between ISMS-P and PIPA?
PIPA is the law that governs personal information in South Korea. ISMS-P is a certification that shows your management system and processing practices meet a defined set of security and privacy criteria aligned with that law. Holding ISMS-P does not replace PIPA compliance.
Can SOC 2 help with ISMS-P readiness?
Yes. Many SOC 2 controls, such as access reviews, change management, logging and incident response, map to the ISMS-P protection measures. You will still need to add the management system elements and the personal information processing requirements.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds