Information Security Consulting & ISMS Preparation Total Cost Calculator
Combine the current KISA single-certification fee formula with actual consulting, security-control, testing, internal-time, annual maintenance, surveillance, and renewal costs.
Step 1
Certification scope and official fee reference
This reproduces the single-certification formula in KISA fee workbook v1.9. The audit body’s confirmed scope and contract fee take precedence.
Step 2
Initial consulting, remediation, and internal preparation
If the consulting quote already includes testing, training, or documentation, set the separate item to zero to avoid double counting.
Step 3
Annual maintenance and available budget
Recurring maintenance excludes the official surveillance fee and direct expenses; it covers risk work, internal review, tools, and training.
ISMS preparation total-cost summary
Cash outlay is separated from internal-time economic cost and extended through annual maintenance, two surveillance audits, and renewal.
Initial cash outlay
KRW 92,050,000
After confirmed grant
Initial economic cost
KRW 122,050,000
Includes internal preparation time
Cash cost through renewal
KRW 187,500,000
Includes maintenance, two surveillance audits, and renewal
Economic cost through renewal
KRW 253,500,000
Includes annual internal maintenance time
KISA v1.9
Official certification-fee reference
Sources checked 2026-08-06
Certification scale
2,000 (50 × 40)
Initial/renewal audit days
25 days
v1.9 day-rate reference
KRW 390,000
ISMS base fee
KRW 9,750,000
Pre-discount initial/renewal
KRW 9,750,000
Selected discount
0%
Final initial/renewal fee
KRW 9,750,000
Final surveillance fee
KRW 5,850,000
This is a reference from the official workbook. It excludes direct expenses, VAT, scope adjustments, and contract terms. Compare it with the audit body’s confirmed quote.
Budget and monthly funding
Monthly funding amount
KRW 11,506,250
Budget shortfall
KRW 12,050,000
Official initial-fee share
7.99%
Internal preparation share
24.58%
Annual maintenance
Annual maintenance cash
KRW 23,000,000
Annual internal maintenance
KRW 12,000,000
Annual maintenance economic cost
KRW 35,000,000
Initial cost breakdown
Information-security consulting and ISMS initial cost breakdown
Item
Amount
Information-security consulting
KRW 20,000,000
Security-control implementation
KRW 30,000,000
Vulnerability and penetration testing
KRW 8,000,000
Training and documentation
KRW 3,000,000
Corrective-action reserve
KRW 10,000,000
Other initial costs
KRW 2,000,000
Initial contingency
KRW 7,300,000
Official initial fee
KRW 9,750,000
Initial-audit direct expenses
KRW 2,000,000
Non-recoverable VAT and taxes
KRW 0
Internal preparation cost
KRW 30,000,000
Confirmed grant deduction
KRW 0
Fixed sensitivity comparison
Each row changes one input only. Scope growth changes the official fee only when it crosses an audit-day bracket.
ISMS preparation fixed sensitivity scenarios
Scenario
Scale
Audit days
Initial fee
Initial cash
Initial economic
Lifecycle cash
Lifecycle economic
Base
2,000
25
KRW 9,750,000
KRW 92,050,000
KRW 122,050,000
KRW 187,500,000
KRW 253,500,000
Consulting fee +20%
2,000
25
KRW 9,750,000
KRW 96,450,000
KRW 126,450,000
KRW 191,900,000
KRW 257,900,000
Security implementation +20%
2,000
25
KRW 9,750,000
KRW 98,650,000
KRW 128,650,000
KRW 194,100,000
KRW 260,100,000
Internal hours +20%
2,000
25
KRW 9,750,000
KRW 92,050,000
KRW 128,050,000
KRW 187,500,000
KRW 266,700,000
Scope personnel +20%
2,400
25
KRW 9,750,000
KRW 92,050,000
KRW 122,050,000
KRW 187,500,000
KRW 253,500,000
Information systems +20%
2,400
25
KRW 9,750,000
KRW 92,050,000
KRW 122,050,000
KRW 187,500,000
KRW 253,500,000
Items to verify
The available budget is below initial cash outlay. Review the shortfall and monthly funding amount.
Calculation boundary
This tool combines the KISA v1.9 fee reference with user-entered quotes. It does not determine mandatory status, scope, discount eligibility, certification outcome, or tax treatment. Manage the minimum two-month operating evidence, at least annual surveillance, three-year validity, and renewal application three months before expiry separately.
An ISMS audit fee is not the total preparation cost
A consulting quote or certification audit fee is often the first number in a Korean ISMS budget. The complete project can also require scope confirmation, gap analysis, risk assessment, policies and procedures, security controls, infrastructure changes, vulnerability testing, training, internal staff time, and corrective action after the audit. Certification also creates recurring work: the management system must keep operating, surveillance is required at least once each year during the validity period, and renewal must be prepared before the three-year certificate expires.
This calculator reproduces the single-certification formulas in the current KISA fee workbook v1.9 and then combines the reference fee with quotes and internal resource estimates entered by the user. It keeps the official fee reference, initial cash outlay, internal-time economic cost, annual maintenance, two surveillance events, and renewal separate so that omissions and duplicated quote items are easier to find. Every non-official default is an illustrative planning input, not a Korean market benchmark or recommended security budget.
Official fee reference
Use personnel multiplied by information systems to select audit days and estimate an ISMS or ISMS-P fee.
Initial preparation
Put consulting, controls, testing, training, internal time, and corrective-action reserves inside one cost boundary.
Maintenance and renewal
Separate annual operations, two surveillance audits, and renewal into cash and economic cost views.
Timeline boundaries checked on August 6, 2026
Article 47 of the current Network Act gives ISMS certification a three-year validity period and requires follow-up management at least once each year. Article 17 of the current ISMS-P Certification Notice requires an applicant to establish and operate the management system for a minimum of two months before applying, except where the separate preliminary-certification rule applies. Article 27 requires surveillance at least once each year during the validity period, and Article 28 requires the renewal application three months before expiry. The July 2024 KISA certification guide also advises applying at least eight weeks before the desired audit date.
Official timing boundaries for Korean ISMS preparation and maintenance
Stage
Checked boundary
Budget implication
Before application
Operate the management system for at least two months
Budget staff time to create real operating evidence, not merely policy documents
Before the desired audit
KISA guide advises applying at least eight weeks in advance
Allow time for preliminary review, contracting, and audit-team scheduling
After the audit
Corrective-action period can be up to 100 days
Keep a reserve without pretending to predict the number of findings
During validity
Surveillance at least once each year
Keep recurring operations separate from surveillance fees and direct expenses
Certificate validity
Three years
Evaluate preparation and the full three-year lifecycle together
Renewal
Apply three months before expiry
Reserve the renewal fee and related direct expenses before the deadline
Establish scope personnel and information systems first
KISA fee workbook v1.9 defines certification scale as personnel in scope multiplied by information systems in scope. The workbook guidance includes internal employees and in-scope external personnel such as system-management and system-integration staff. Its information-system count covers servers, L4-or-higher switches, routers, and security systems such as firewalls, IPS, IDS, web application firewalls, DLP, DRM, and database access-control systems. For ISMS-P, the count of personal-data entrustees and personal-data processing services also affects the fee surcharge.
Personnel checklist
Include service operations, development, administration, information security, and privacy roles inside the proposed scope.
Review both resident and non-resident contractors who perform work within that scope.
Reconcile the organization chart, operating descriptions, account inventory, and access-control records.
System checklist
Compare the asset register, network diagrams, cloud accounts, and security-system administration list.
When consolidating redundant or load-balanced equipment into one count, verify the KISA conditions concerning purpose, operating system, version, and administrator.
Do not reduce scope merely to obtain a lower fee bracket; use the audit organization review as the controlling input.
Cloud services still require a responsibility review
Using IaaS, PaaS, or SaaS does not automatically remove related systems from the certification scope. The KISA guide explains that scope depends on the responsibility split for the service type and the areas that the applicant can directly manage. Before counting cloud assets, verify contractual responsibility and who operates accounts, networks, logs, and access controls.
KISA fee workbook v1.9 formulas
The current single-certification workbook uses KRW 300,000 of direct labor, KRW 60,000 of overhead equal to 20% of direct labor, and KRW 36,000 of technical fee equal to 10% of the first two amounts. It floors the KRW 396,000 subtotal to KRW 10,000 and therefore uses a reference audit-day rate of KRW 390,000. Annex 6 of the Notice defines fee components and limits, while the workbook supplies the operational percentages. Treat KRW 390,000 as the current official workbook reference, not as an eternal statutory day rate for every audit organization.
ISMS
Audit days × KRW 390,000
ISMS-P
ISMS base × 120% + entrustee surcharge + service surcharge
Surveillance
60% of the pre-discount initial or renewal fee, then the same selected discount
KISA v1.9 initial and renewal audit days by certification scale
Certification scale
Initial or renewal days
ISMS fee before discount
1–800
23 days
KRW 8,970,000
801–4,000
25 days
KRW 9,750,000
4,001–10,000
28 days
KRW 10,920,000
10,001–20,000
31 days
KRW 12,090,000
20,001–35,000
33 days
KRW 12,870,000
35,001–65,000
35 days
KRW 13,650,000
65,001–150,000
39 days
KRW 15,210,000
150,001–300,000
42 days
KRW 16,380,000
300,001–900,000
46 days
KRW 17,940,000
900,001–1,600,000
50 days
KRW 19,500,000
1,600,001–30,000,000
51 days
KRW 19,890,000
30,000,001 or more
52 days
KRW 20,280,000
ISMS-P surcharge rates by personal-data entrustee count
Entrustees
Surcharge
0–4
0%
5–14
5%
15–29
10%
30–49
20%
50 or more
30%
ISMS-P surcharge rates by personal-data processing service count
Services
Surcharge
0–2
0%
3–4
5%
5–9
10%
10–19
20%
20 or more
30%
Normalize consulting quotes into the same cost boundary
Providers do not always include the same work under an information-security consulting label. One quote may cover only gap analysis and risk assessment, while another includes policies, training, vulnerability testing, internal-audit support, or corrective-action assistance. Comparing only headline totals can hide omitted work or count the same service twice, so build an inclusion-and-exclusion matrix before entering amounts.
Consulting
Confirm deliverables and iterations for scoping, current-state review, gap analysis, risk assessment, policy structure, internal audit, and audit response.
Security controls
Enter only approved quotes arising from the risk-treatment plan for access, logging, encryption, backup, network, endpoint, and physical controls.
Vulnerability and penetration testing
Confirm target systems, methods, retesting, reports, and remediation verification in the contract.
Training and documentation
Check whether workforce, developer, and administrator training, document tools, translation, and separate drafting are already included.
Internal preparation time
Include meetings and evidence work by security, engineering, infrastructure, HR, procurement, legal, business units, and management.
Corrective-action reserve
Keep a controlled reserve for unresolved technical and procedural work instead of inventing an expected number of findings.
Keep internal time separate from cash outlay
Setting preparation time to zero because employees already receive salaries hides resource consumption and makes alternatives difficult to compare. The calculator multiplies internal hours by an employer-loaded labor value or opportunity cost and includes the result in economic cost, while keeping it outside payments to external vendors. Cash outlay matters for funding approval; economic cost matters for staffing and scheduling. Review both rather than adding an internal-time amount to a vendor invoice.
Step-by-step use
Select ISMS or ISMS-P. ISMS-P adds privacy requirements and activates entrustee and personal-data service inputs in the fee model.
Count personnel and systems from preliminary scope records. Label estimates separately and recalculate when the audit organization changes the scope.
Select only a discount that has credible evidence. If applicability is unclear, use no discount and preserve a conservative budget baseline.
Break consulting and technical quotes into components. Set a separate field to zero when the same testing, training, or documentation work is already included elsewhere.
Add internal time and a corrective-action reserve. Include interviews, asset reconciliation, account and log review, training, internal audit, and audit response.
Enter annual maintenance. Keep security tools, external support, testing, training, and internal maintenance time separate from the official surveillance fee.
Review initial cash and three-year economic cost together. Share the funding gap, monthly preparation amount, cost composition, and fixed sensitivity cases with security, procurement, and finance teams.
Worked example using the defaults
These values explain the formulas; they are not average Korean fees or a recommended project budget. Fifty personnel multiplied by forty information systems gives a scale of 2,000, which falls in the 25-day bracket. The ISMS initial or renewal reference fee is KRW 9,750,000, and one surveillance reference fee is 60% of that amount, or KRW 5,850,000.
Default Korean ISMS preparation cost example
Result
Amount
Composition
Initial external preparation base
KRW 73,000,000
Consulting 20m, controls 30m, testing 8m, training and documents 3m, remediation reserve 10m, other 2m
Initial contingency
KRW 7,300,000
10% of the external preparation base
Initial cash outlay
KRW 92,050,000
External preparation, contingency, initial fee, and direct expenses
Initial total economic cost
KRW 122,050,000
Initial cash plus 600 internal hours × KRW 50,000
Annual maintenance economic cost
KRW 35,000,000
Annual cash maintenance of 23m plus internal maintenance value of 12m
Three-year cash through renewal
KRW 187,500,000
Initial cash, three years of maintenance, two surveillance events, and renewal
Three-year economic cost through renewal
KRW 253,500,000
Lifecycle cash plus initial and annual internal-time value
Monthly amount over eight months
KRW 11,506,250
Initial cash outlay divided by eight months
ISMS-P surcharge and discount example
At the same scale of 2,000, fifteen entrustees and five personal-data processing services add 10% each. Applying the 120% ISMS-P base plus both 10% surcharges to the KRW 9,750,000 ISMS base gives KRW 13,650,000 before discount. A selected 30% information-security disclosure scenario gives KRW 9,555,000 before final rounding, then KRW 9,550,000 after flooring to KRW 10,000. The corresponding surveillance reference is KRW 5,730,000 after the 60% factor, the same selected discount, and final flooring. Do not commit either discounted amount until actual disclosure eligibility and audit-organization treatment are confirmed.
How to interpret sensitivity results
The calculator compares the baseline with a 20% increase in consulting cost, control-implementation cost, internal preparation and maintenance time, scope personnel, or information systems. Quote changes normally move the total continuously, but personnel and system changes affect the official fee only when their product crosses an audit-day bracket. If the current scale is near 800, 4,000, 10,000, or another upper boundary, one additional person or system can move the fee to the next step. Save both the preliminary and confirmed scope results so that the budget change has an auditable explanation.
Quote variation
See whether a consulting or control-scope change creates a funding shortfall against the approved cash budget.
Internal workload
See how higher staff time changes economic cost and operational sustainability even when vendor payments stay unchanged.
Scope boundary
Check whether more personnel or systems crosses a KISA audit-day bracket, then replace estimates after preliminary review.
Practical planning scenarios
Before budget approval
Separate the official fee, consulting, controls, and internal time so one-time cash funding and staffing can be approved on their own terms.
Comparing multiple consulting quotes
Move every inclusion and exclusion into the same fields to reveal whether a price difference comes from scope or unit cost.
After preliminary scope review
Replace estimated personnel and systems, recalculate the fee and lifecycle cost, and record the change from the original baseline.
Comparing ISMS and ISMS-P
Measure the fee effect of privacy entrustees and services without treating the result as advice about which certification to choose.
Building an annual operating budget
Separate tools, support, testing, training, internal time, and surveillance so funding does not disappear immediately after certification.
Preparing for renewal
Include the renewal fee and direct expenses in the three-year lifecycle before the application point three months ahead of expiry.
Tips and cautions
Replace every non-official example amount with an actual quote or an internally approved estimate.
If one contract already includes testing, training, or documentation, leave the duplicated field at zero and record the inclusion evidence.
Direct expenses can be billed separately from the displayed official fee; enter only confirmed travel, lodging, meal, VAT, and tax cash outflows.
Do not stack small-enterprise, disclosure, or partial-audit discounts, and verify both evidence and the applied rate.
Buying a security product does not establish compliance or effective risk reduction; prioritize controls through risk assessment and operating evidence.
Treat the minimum two-month operation period as time to perform controls and preserve evidence, not merely the age of a policy file.
A corrective-action reserve is not a forecast of audit findings, and an unused reserve is not evidence of control effectiveness.
Split certification scopes may require separate contracts and extra fees, so do not divide the scale product and claim automatic savings.
Do not translate certification into guaranteed revenue, procurement access, customer approval, or incident reduction.
When KISA publishes a workbook newer than v1.9, recheck KRW 390,000, every bracket, surcharge, discount, and the 60% surveillance rule.
Frequently asked questions
Is KRW 390,000 a statutory audit-day rate for every organization?
No. Annex 6 of the current Notice defines fee components and limits, while the current KISA v1.9 workbook calculates direct labor, overhead, and technical fee and uses KRW 390,000 after flooring. A newer official workbook and the actual audit contract take priority.
Does hiring a consultant guarantee certification?
No. Consulting can support preparation, but it does not determine the certification result. The audit examines documented and actual operation, technical and physical safeguards, and evidence; conflict-of-interest rules also apply to auditors.
Why does ISMS-P ask for entrustees and services?
Workbook v1.9 adds bracketed surcharges for personal-data entrustees and personal-data processing services on top of the 120% ISMS-P base. The applicant and audit organization must confirm the actual counts and scope.
How many surveillance audits are included?
For a planning horizon through first renewal, the model includes two surveillance events, generally associated with the first and second years, followed by renewal before expiry. Actual certificate and audit dates control.
Are direct expenses already inside the displayed fee?
Annex 6 treats travel, lodging, and meals as direct expenses and allows separate payment depending on the audit situation. Enter the amount separately from the v1.9 final-fee display.
Can an expected subsidy be entered?
Use only an awarded, usable grant or reimbursement. The calculator does not roll an amount above initial cash outlay into annual maintenance automatically.
Does ISO/IEC 27001 automatically create a 20% discount?
No. Confirm validity, scope coverage, the Article 20 partial-audit application, the v1.9 treatment, and the audit organization adjustment. The calculator value is only a scenario.
What is an appropriate security-control budget?
There is no official universal average because assets, threats, current controls, cloud responsibilities, and quotes differ. Enter the approved risk-treatment amount and assess certification adequacy separately.
Official sources and update boundary
The law identifiers, effective dates, notice serial, and workbook formulas below were checked directly on August 6, 2026 and aligned across requirements, code, and tests. The Network Act source was current MST 282481 and the Enforcement Decree source was current MST 288033, both effective July 7, 2026. The ISMS-P Certification Notice was administrative-rule serial 2100000244750, effective July 24, 2024. Recheck every item before an actual application if the law, Notice, KISA guide, or fee workbook changes.
Build a budget baseline from real scope and quotes
Replace examples with the actual personnel and system inventory, consulting proposal, risk-treatment plan, direct expenses, and internal hours. Identify which costs exceed the official audit fee, test whether approved funding covers both preparation and continued operation, and then reconcile the result with the scope and fee confirmed by the audit organization.