Information Security Consulting & ISMS Preparation Total Cost Calculator

Combine the current KISA single-certification fee formula with actual consulting, security-control, testing, internal-time, annual maintenance, surveillance, and renewal costs.

Step 1

Certification scope and official fee reference

This reproduces the single-certification formula in KISA fee workbook v1.9. The audit body’s confirmed scope and contract fee take precedence.

Step 2

Initial consulting, remediation, and internal preparation

If the consulting quote already includes testing, training, or documentation, set the separate item to zero to avoid double counting.

Step 3

Annual maintenance and available budget

Recurring maintenance excludes the official surveillance fee and direct expenses; it covers risk work, internal review, tools, and training.

ISMS preparation total-cost summary

Cash outlay is separated from internal-time economic cost and extended through annual maintenance, two surveillance audits, and renewal.

Initial cash outlay
KRW 92,050,000

After confirmed grant

Initial economic cost
KRW 122,050,000

Includes internal preparation time

Cash cost through renewal
KRW 187,500,000

Includes maintenance, two surveillance audits, and renewal

Economic cost through renewal
KRW 253,500,000

Includes annual internal maintenance time

KISA v1.9

Official certification-fee reference

Sources checked 2026-08-06

Certification scale
2,000 (50 × 40)
Initial/renewal audit days
25 days
v1.9 day-rate reference
KRW 390,000
ISMS base fee
KRW 9,750,000
Pre-discount initial/renewal
KRW 9,750,000
Selected discount
0%
Final initial/renewal fee
KRW 9,750,000
Final surveillance fee
KRW 5,850,000

This is a reference from the official workbook. It excludes direct expenses, VAT, scope adjustments, and contract terms. Compare it with the audit body’s confirmed quote.

Budget and monthly funding

Monthly funding amount
KRW 11,506,250
Budget shortfall
KRW 12,050,000
Official initial-fee share
7.99%
Internal preparation share
24.58%

Annual maintenance

Annual maintenance cash
KRW 23,000,000
Annual internal maintenance
KRW 12,000,000
Annual maintenance economic cost
KRW 35,000,000

Initial cost breakdown

Information-security consulting and ISMS initial cost breakdown
ItemAmount
Information-security consultingKRW 20,000,000
Security-control implementationKRW 30,000,000
Vulnerability and penetration testingKRW 8,000,000
Training and documentationKRW 3,000,000
Corrective-action reserveKRW 10,000,000
Other initial costsKRW 2,000,000
Initial contingencyKRW 7,300,000
Official initial feeKRW 9,750,000
Initial-audit direct expensesKRW 2,000,000
Non-recoverable VAT and taxesKRW 0
Internal preparation costKRW 30,000,000
Confirmed grant deductionKRW 0

Fixed sensitivity comparison

Each row changes one input only. Scope growth changes the official fee only when it crosses an audit-day bracket.

ISMS preparation fixed sensitivity scenarios
ScenarioScaleAudit daysInitial feeInitial cashInitial economicLifecycle cashLifecycle economic
Base2,00025KRW 9,750,000KRW 92,050,000KRW 122,050,000KRW 187,500,000KRW 253,500,000
Consulting fee +20%2,00025KRW 9,750,000KRW 96,450,000KRW 126,450,000KRW 191,900,000KRW 257,900,000
Security implementation +20%2,00025KRW 9,750,000KRW 98,650,000KRW 128,650,000KRW 194,100,000KRW 260,100,000
Internal hours +20%2,00025KRW 9,750,000KRW 92,050,000KRW 128,050,000KRW 187,500,000KRW 266,700,000
Scope personnel +20%2,40025KRW 9,750,000KRW 92,050,000KRW 122,050,000KRW 187,500,000KRW 253,500,000
Information systems +20%2,40025KRW 9,750,000KRW 92,050,000KRW 122,050,000KRW 187,500,000KRW 253,500,000

Items to verify

  • The available budget is below initial cash outlay. Review the shortfall and monthly funding amount.

Calculation boundary

This tool combines the KISA v1.9 fee reference with user-entered quotes. It does not determine mandatory status, scope, discount eligibility, certification outcome, or tax treatment. Manage the minimum two-month operating evidence, at least annual surveillance, three-year validity, and renewal application three months before expiry separately.

Related calculators

An ISMS audit fee is not the total preparation cost

A consulting quote or certification audit fee is often the first number in a Korean ISMS budget.
The complete project can also require scope confirmation, gap analysis, risk assessment, policies and procedures, security controls, infrastructure changes, vulnerability testing, training, internal staff time, and corrective action after the audit.
Certification also creates recurring work: the management system must keep operating, surveillance is required at least once each year during the validity period, and renewal must be prepared before the three-year certificate expires.

This calculator reproduces the single-certification formulas in the current KISA fee workbook v1.9 and then combines the reference fee with quotes and internal resource estimates entered by the user.
It keeps the official fee reference, initial cash outlay, internal-time economic cost, annual maintenance, two surveillance events, and renewal separate so that omissions and duplicated quote items are easier to find.
Every non-official default is an illustrative planning input, not a Korean market benchmark or recommended security budget.

Official fee reference

Use personnel multiplied by information systems to select audit days and estimate an ISMS or ISMS-P fee.

Initial preparation

Put consulting, controls, testing, training, internal time, and corrective-action reserves inside one cost boundary.

Maintenance and renewal

Separate annual operations, two surveillance audits, and renewal into cash and economic cost views.

Timeline boundaries checked on August 6, 2026

Article 47 of the current Network Act gives ISMS certification a three-year validity period and requires follow-up management at least once each year.
Article 17 of the current ISMS-P Certification Notice requires an applicant to establish and operate the management system for a minimum of two months before applying, except where the separate preliminary-certification rule applies.
Article 27 requires surveillance at least once each year during the validity period, and Article 28 requires the renewal application three months before expiry.
The July 2024 KISA certification guide also advises applying at least eight weeks before the desired audit date.

Official timing boundaries for Korean ISMS preparation and maintenance
StageChecked boundaryBudget implication
Before applicationOperate the management system for at least two monthsBudget staff time to create real operating evidence, not merely policy documents
Before the desired auditKISA guide advises applying at least eight weeks in advanceAllow time for preliminary review, contracting, and audit-team scheduling
After the auditCorrective-action period can be up to 100 daysKeep a reserve without pretending to predict the number of findings
During validitySurveillance at least once each yearKeep recurring operations separate from surveillance fees and direct expenses
Certificate validityThree yearsEvaluate preparation and the full three-year lifecycle together
RenewalApply three months before expiryReserve the renewal fee and related direct expenses before the deadline

Establish scope personnel and information systems first

KISA fee workbook v1.9 defines certification scale as personnel in scope multiplied by information systems in scope.
The workbook guidance includes internal employees and in-scope external personnel such as system-management and system-integration staff.
Its information-system count covers servers, L4-or-higher switches, routers, and security systems such as firewalls, IPS, IDS, web application firewalls, DLP, DRM, and database access-control systems.
For ISMS-P, the count of personal-data entrustees and personal-data processing services also affects the fee surcharge.

Personnel checklist

  • Include service operations, development, administration, information security, and privacy roles inside the proposed scope.
  • Review both resident and non-resident contractors who perform work within that scope.
  • Reconcile the organization chart, operating descriptions, account inventory, and access-control records.

System checklist

  • Compare the asset register, network diagrams, cloud accounts, and security-system administration list.
  • When consolidating redundant or load-balanced equipment into one count, verify the KISA conditions concerning purpose, operating system, version, and administrator.
  • Do not reduce scope merely to obtain a lower fee bracket; use the audit organization review as the controlling input.

Cloud services still require a responsibility review

Using IaaS, PaaS, or SaaS does not automatically remove related systems from the certification scope.
The KISA guide explains that scope depends on the responsibility split for the service type and the areas that the applicant can directly manage.
Before counting cloud assets, verify contractual responsibility and who operates accounts, networks, logs, and access controls.

KISA fee workbook v1.9 formulas

The current single-certification workbook uses KRW 300,000 of direct labor, KRW 60,000 of overhead equal to 20% of direct labor, and KRW 36,000 of technical fee equal to 10% of the first two amounts.
It floors the KRW 396,000 subtotal to KRW 10,000 and therefore uses a reference audit-day rate of KRW 390,000.
Annex 6 of the Notice defines fee components and limits, while the workbook supplies the operational percentages.
Treat KRW 390,000 as the current official workbook reference, not as an eternal statutory day rate for every audit organization.

ISMS

Audit days × KRW 390,000

ISMS-P

ISMS base × 120% + entrustee surcharge + service surcharge

Surveillance

60% of the pre-discount initial or renewal fee, then the same selected discount

KISA v1.9 initial and renewal audit days by certification scale
Certification scaleInitial or renewal daysISMS fee before discount
1–80023 daysKRW 8,970,000
801–4,00025 daysKRW 9,750,000
4,001–10,00028 daysKRW 10,920,000
10,001–20,00031 daysKRW 12,090,000
20,001–35,00033 daysKRW 12,870,000
35,001–65,00035 daysKRW 13,650,000
65,001–150,00039 daysKRW 15,210,000
150,001–300,00042 daysKRW 16,380,000
300,001–900,00046 daysKRW 17,940,000
900,001–1,600,00050 daysKRW 19,500,000
1,600,001–30,000,00051 daysKRW 19,890,000
30,000,001 or more52 daysKRW 20,280,000
ISMS-P surcharge rates by personal-data entrustee count
EntrusteesSurcharge
0–40%
5–145%
15–2910%
30–4920%
50 or more30%
ISMS-P surcharge rates by personal-data processing service count
ServicesSurcharge
0–20%
3–45%
5–910%
10–1920%
20 or more30%

Normalize consulting quotes into the same cost boundary

Providers do not always include the same work under an information-security consulting label.
One quote may cover only gap analysis and risk assessment, while another includes policies, training, vulnerability testing, internal-audit support, or corrective-action assistance.
Comparing only headline totals can hide omitted work or count the same service twice, so build an inclusion-and-exclusion matrix before entering amounts.

Consulting

Confirm deliverables and iterations for scoping, current-state review, gap analysis, risk assessment, policy structure, internal audit, and audit response.

Security controls

Enter only approved quotes arising from the risk-treatment plan for access, logging, encryption, backup, network, endpoint, and physical controls.

Vulnerability and penetration testing

Confirm target systems, methods, retesting, reports, and remediation verification in the contract.

Training and documentation

Check whether workforce, developer, and administrator training, document tools, translation, and separate drafting are already included.

Internal preparation time

Include meetings and evidence work by security, engineering, infrastructure, HR, procurement, legal, business units, and management.

Corrective-action reserve

Keep a controlled reserve for unresolved technical and procedural work instead of inventing an expected number of findings.

Keep internal time separate from cash outlay

Setting preparation time to zero because employees already receive salaries hides resource consumption and makes alternatives difficult to compare.
The calculator multiplies internal hours by an employer-loaded labor value or opportunity cost and includes the result in economic cost, while keeping it outside payments to external vendors.
Cash outlay matters for funding approval; economic cost matters for staffing and scheduling.
Review both rather than adding an internal-time amount to a vendor invoice.

Step-by-step use

  1. Select ISMS or ISMS-P. ISMS-P adds privacy requirements and activates entrustee and personal-data service inputs in the fee model.
  2. Count personnel and systems from preliminary scope records. Label estimates separately and recalculate when the audit organization changes the scope.
  3. Select only a discount that has credible evidence. If applicability is unclear, use no discount and preserve a conservative budget baseline.
  4. Break consulting and technical quotes into components. Set a separate field to zero when the same testing, training, or documentation work is already included elsewhere.
  5. Add internal time and a corrective-action reserve. Include interviews, asset reconciliation, account and log review, training, internal audit, and audit response.
  6. Enter annual maintenance. Keep security tools, external support, testing, training, and internal maintenance time separate from the official surveillance fee.
  7. Review initial cash and three-year economic cost together. Share the funding gap, monthly preparation amount, cost composition, and fixed sensitivity cases with security, procurement, and finance teams.

Worked example using the defaults

These values explain the formulas; they are not average Korean fees or a recommended project budget.
Fifty personnel multiplied by forty information systems gives a scale of 2,000, which falls in the 25-day bracket.
The ISMS initial or renewal reference fee is KRW 9,750,000, and one surveillance reference fee is 60% of that amount, or KRW 5,850,000.

Default Korean ISMS preparation cost example
ResultAmountComposition
Initial external preparation baseKRW 73,000,000Consulting 20m, controls 30m, testing 8m, training and documents 3m, remediation reserve 10m, other 2m
Initial contingencyKRW 7,300,00010% of the external preparation base
Initial cash outlayKRW 92,050,000External preparation, contingency, initial fee, and direct expenses
Initial total economic costKRW 122,050,000Initial cash plus 600 internal hours × KRW 50,000
Annual maintenance economic costKRW 35,000,000Annual cash maintenance of 23m plus internal maintenance value of 12m
Three-year cash through renewalKRW 187,500,000Initial cash, three years of maintenance, two surveillance events, and renewal
Three-year economic cost through renewalKRW 253,500,000Lifecycle cash plus initial and annual internal-time value
Monthly amount over eight monthsKRW 11,506,250Initial cash outlay divided by eight months

ISMS-P surcharge and discount example

At the same scale of 2,000, fifteen entrustees and five personal-data processing services add 10% each.
Applying the 120% ISMS-P base plus both 10% surcharges to the KRW 9,750,000 ISMS base gives KRW 13,650,000 before discount.
A selected 30% information-security disclosure scenario gives KRW 9,555,000 before final rounding, then KRW 9,550,000 after flooring to KRW 10,000.
The corresponding surveillance reference is KRW 5,730,000 after the 60% factor, the same selected discount, and final flooring.
Do not commit either discounted amount until actual disclosure eligibility and audit-organization treatment are confirmed.

How to interpret sensitivity results

The calculator compares the baseline with a 20% increase in consulting cost, control-implementation cost, internal preparation and maintenance time, scope personnel, or information systems.
Quote changes normally move the total continuously, but personnel and system changes affect the official fee only when their product crosses an audit-day bracket.
If the current scale is near 800, 4,000, 10,000, or another upper boundary, one additional person or system can move the fee to the next step.
Save both the preliminary and confirmed scope results so that the budget change has an auditable explanation.

Quote variation

See whether a consulting or control-scope change creates a funding shortfall against the approved cash budget.

Internal workload

See how higher staff time changes economic cost and operational sustainability even when vendor payments stay unchanged.

Scope boundary

Check whether more personnel or systems crosses a KISA audit-day bracket, then replace estimates after preliminary review.

Practical planning scenarios

Before budget approval

Separate the official fee, consulting, controls, and internal time so one-time cash funding and staffing can be approved on their own terms.

Comparing multiple consulting quotes

Move every inclusion and exclusion into the same fields to reveal whether a price difference comes from scope or unit cost.

After preliminary scope review

Replace estimated personnel and systems, recalculate the fee and lifecycle cost, and record the change from the original baseline.

Comparing ISMS and ISMS-P

Measure the fee effect of privacy entrustees and services without treating the result as advice about which certification to choose.

Building an annual operating budget

Separate tools, support, testing, training, internal time, and surveillance so funding does not disappear immediately after certification.

Preparing for renewal

Include the renewal fee and direct expenses in the three-year lifecycle before the application point three months ahead of expiry.

Tips and cautions

  • Replace every non-official example amount with an actual quote or an internally approved estimate.
  • If one contract already includes testing, training, or documentation, leave the duplicated field at zero and record the inclusion evidence.
  • Direct expenses can be billed separately from the displayed official fee; enter only confirmed travel, lodging, meal, VAT, and tax cash outflows.
  • Do not stack small-enterprise, disclosure, or partial-audit discounts, and verify both evidence and the applied rate.
  • Buying a security product does not establish compliance or effective risk reduction; prioritize controls through risk assessment and operating evidence.
  • Treat the minimum two-month operation period as time to perform controls and preserve evidence, not merely the age of a policy file.
  • A corrective-action reserve is not a forecast of audit findings, and an unused reserve is not evidence of control effectiveness.
  • Split certification scopes may require separate contracts and extra fees, so do not divide the scale product and claim automatic savings.
  • Do not translate certification into guaranteed revenue, procurement access, customer approval, or incident reduction.
  • When KISA publishes a workbook newer than v1.9, recheck KRW 390,000, every bracket, surcharge, discount, and the 60% surveillance rule.

Frequently asked questions

Is KRW 390,000 a statutory audit-day rate for every organization?

No. Annex 6 of the current Notice defines fee components and limits, while the current KISA v1.9 workbook calculates direct labor, overhead, and technical fee and uses KRW 390,000 after flooring. A newer official workbook and the actual audit contract take priority.

Does hiring a consultant guarantee certification?

No. Consulting can support preparation, but it does not determine the certification result. The audit examines documented and actual operation, technical and physical safeguards, and evidence; conflict-of-interest rules also apply to auditors.

Why does ISMS-P ask for entrustees and services?

Workbook v1.9 adds bracketed surcharges for personal-data entrustees and personal-data processing services on top of the 120% ISMS-P base. The applicant and audit organization must confirm the actual counts and scope.

How many surveillance audits are included?

For a planning horizon through first renewal, the model includes two surveillance events, generally associated with the first and second years, followed by renewal before expiry. Actual certificate and audit dates control.

Are direct expenses already inside the displayed fee?

Annex 6 treats travel, lodging, and meals as direct expenses and allows separate payment depending on the audit situation. Enter the amount separately from the v1.9 final-fee display.

Can an expected subsidy be entered?

Use only an awarded, usable grant or reimbursement. The calculator does not roll an amount above initial cash outlay into annual maintenance automatically.

Does ISO/IEC 27001 automatically create a 20% discount?

No. Confirm validity, scope coverage, the Article 20 partial-audit application, the v1.9 treatment, and the audit organization adjustment. The calculator value is only a scenario.

What is an appropriate security-control budget?

There is no official universal average because assets, threats, current controls, cloud responsibilities, and quotes differ. Enter the approved risk-treatment amount and assess certification adequacy separately.

Official sources and update boundary

The law identifiers, effective dates, notice serial, and workbook formulas below were checked directly on August 6, 2026 and aligned across requirements, code, and tests.
The Network Act source was current MST 282481 and the Enforcement Decree source was current MST 288033, both effective July 7, 2026.
The ISMS-P Certification Notice was administrative-rule serial 2100000244750, effective July 24, 2024.
Recheck every item before an actual application if the law, Notice, KISA guide, or fee workbook changes.

Build a budget baseline from real scope and quotes

Replace examples with the actual personnel and system inventory, consulting proposal, risk-treatment plan, direct expenses, and internal hours.
Identify which costs exceed the official audit fee, test whether approved funding covers both preparation and continued operation, and then reconcile the result with the scope and fee confirmed by the audit organization.