Skip to main content
株式会社オブライト
Business DX2026-09-078 min read

Privacy Mark & ISMS Certification Costs for Japanese SMBs

Privacy Mark and ISMS (ISO 27001) differ in scope and cost, confusing SMB owners. This guide covers realistic certification costs and IT controls you need.


Privacy Mark and ISMS (ISO 27001) are different certifications with different scopes: Privacy Mark covers personal data handling, while ISMS covers an organization's overall information security management. Costs vary widely, but as a rough benchmark, new Privacy Mark certification typically runs 500,000–1,500,000 yen in total, and ISMS certification typically runs 800,000–3,000,000 yen. Understanding this distinction and rough cost range is the starting point for deciding whether your company needs either one.

Privacy Mark vs. ISMS: What's the Difference?

Both certifications signal to outside parties that a company manages information securely, but their purpose and scope differ considerably. Privacy Mark is a Japan-specific certification run by JIPDEC that assesses whether personal information protection practices are embedded across the whole organization. ISMS, based on the international standard ISO/IEC 27001, evaluates management of information assets more broadly — not just personal data, but technical information and client confidential data as well. Companies with overseas business or that take on outsourced system development tend to be asked for ISMS, while companies handling large volumes of personal data in consumer-facing (B2C) businesses tend to be asked for Privacy Mark. Some companies end up pursuing both.

ComparisonPrivacy MarkISMS (ISO 27001)
ScopeHandling of personal informationInformation assets broadly (technical & confidential data included)
Certification unitGenerally the whole legal entityCan be scoped to a business unit or site
Typical triggerB2C business handling large volumes of personal dataOutsourced system development, overseas trade, government contracts
Renewal cycleRenewal review every 2 yearsRenewal review every 3 years (plus annual surveillance audits)
Rough costRoughly 500,000–1,500,000 yen totalRoughly 800,000–3,000,000 yen total
Diagram comparing Japan's Privacy Mark and ISMS (ISO 27001) across what they protect, certification unit, main motivation, and cost, and showing the four IT measures — access control, multi-factor auth, vendor management, and logs and audit trail — required either way.

What the Certification Costs Actually Cover

Costs generally fall into two buckets: fees paid to outside parties, and the internal labor (staff time) it takes to get there. External fees mostly cover application and assessment fees paid to the certifying body, but because most small businesses struggle to prepare the required documentation on their own, many hire a consulting firm to guide the process — and that consulting fee often makes up the largest share of the total. Internal labor is easy to underestimate: drafting policies, training staff, and handling audits can easily add up to hundreds of hours, and many companies never account for this as a real cost.

Cost categoryWhat it coversRough range (company of 30-100 employees)
Application & assessment feesRegistration and review fees paid to the certifying bodyPrivacy Mark: roughly 200,000-400,000 yen / ISMS: roughly 300,000-600,000 yen
Consulting feesSupport drafting policies and preparing for the assessmentRoughly 500,000-1,500,000 yen (varies by scope)
Internal labor (in staff-time value)Drafting policies, training, internal audits, corrective actionsCan equate to several hundred thousand yen or more
Annual renewal/surveillance feesOngoing renewal or surveillance assessmentsRoughly 100,000-300,000 yen per year

Why Companies Pursue Certification: The Client-Requirement Reality

For most small businesses, the trigger for considering Privacy Mark or ISMS isn't an internal security initiative — it's a request from a client. Large enterprises and government agencies increasingly screen the security posture of their vendors, and companies that are repeatedly asked to complete security check sheets from business partners often start looking into certification as a result. Lacking certification doesn't necessarily rule out doing business, but the recurring burden of answering check sheets, or being disqualified outright from large new deals, is a real operational cost. It's worth treating certification as a means to smoother business dealings rather than a goal in itself, and deciding accordingly.

The Path to Certification and How Long It Takes

- Current-state assessment (1-2 months): Inventory personal data and information assets, and review current management practices
- Building policies and structure (2-4 months): Draft a personal information protection policy, information security policy, and related manuals, and appoint a responsible manager
- Employee training: Train all employees and keep records — assessors always check for this
- Internal audit and corrective action: Verify through an internal audit that the new practices are actually working, and correct any gaps found
- Formal assessment: Undergo document review and an on-site assessment by the certifying body
- Certification granted: Certification is issued once corrective items are addressed
- Overall, the process typically takes 6 months to a year from start to certification

The IT Work You'll Actually Have to Do

The most labor-intensive part of certification is often the actual IT implementation. Writing a policy isn't enough — assessors need evidence that it's actually being followed in daily operations. The following areas tend to trip up small businesses in particular.

- Access permission management: Map out who can access which information, and establish a process to promptly revoke access when someone leaves or changes roles
- Multi-factor authentication (MFA): Require MFA for email and cloud service logins, and eliminate password reuse
- Log collection and retention: Establish a way to record who accessed what information and when, over a defined retention period
- Device management: Track OS update status and antivirus coverage across company-issued PCs and smartphones
- Vendor management: If you outsource work externally, verify vendors' own information management practices and reflect that in contracts
- Backup practices: Regular backups of critical data and a documented recovery procedure

Much of this overlaps with the fundamentals covered in our SMB IT risk guide, regardless of whether you pursue certification. In practice, many companies use certification as the trigger to finally overhaul their IT setup, rather than the other way around.

Deciding Criteria — Including Choosing Not to Certify

- Low likelihood of a client requirement in the next 1-2 years: There's no need to rush — prioritizing basic IT security fundamentals first is a legitimate option
- Limited personal data handling and no outsourced system development: The case for either certification is relatively weak
- No dedicated IT or admin staff: Consider first whether you can sustain the ongoing operational effort certification maintenance requires
- What peers and key clients are doing: Whether certification is becoming a de facto standard in your industry is a useful signal
- Cost-benefit: Weigh the scale of new business the certification could unlock against its acquisition and maintenance costs

Common Mistakes

- Policies exist on paper but aren't actually followed: The most common failure mode — tidying things up right before the assessment while daily operations don't match the documented policy
- Leaving the consultant to handle everything, with no in-house knowledge retained: Consultants can carry the first certification, but renewal assessments and daily operations need to run in-house afterward
- Not budgeting for internal labor: Planning only around external fees, without accounting for staff time, leaves the operational burden far heavier than expected
- Treating it as an IT-department-only project: Information security is a company-wide effort, and assessors flag a lack of engagement from leadership and other departments
- Never revisiting it after certification: Certification isn't a one-time achievement — policies and IT controls need ongoing review as the business changes

FAQ

Should a small business get Privacy Mark or ISMS?

If a client is explicitly asking for one, start there. Absent a specific request, Privacy Mark tends to be the starting point for B2C businesses handling large amounts of personal data, while ISMS tends to fit businesses doing outsourced system development or overseas trade. Some companies end up needing both.

How long does certification take?

Typically 6 months to a year from the start of preparation to certification, depending on how much internal structure already exists and the certifying body's schedule.

Do we need to hire a consulting firm to get certified?

Some companies do it without one, but starting from scratch with no experience in policy drafting or assessment preparation puts a heavy burden on whoever is assigned. Most companies bring in outside support, especially for the first certification.

Are there ongoing costs after certification?

Yes. Privacy Mark requires renewal every 2 years and ISMS every 3 years, with ISMS also requiring annual surveillance audits in between — both involve recurring assessment fees. Factor in this ongoing cost when deciding.

Is certification worth it for a very small company (under 10 employees)?

It's worth it if a client is clearly asking for it; otherwise the cost-benefit often doesn't hold up. Starting with basics like access management and MFA before pursuing certification is a reasonable alternative.

Can a company fail the assessment?

Yes. Assessors will flag cases where policies exist but aren't actually followed in practice, or where gaps found during an internal audit haven't been corrected — this can require corrective action and a follow-up review.

Summary

Privacy Mark and ISMS are distinct certifications with different scopes and cost profiles, and the first step is figuring out which one, if either, your company actually needs right now. If you do decide to pursue one, budget for the real cost — including internal labor, not just external fees. And regardless of whether you certify, fundamentals like access permission management, multi-factor authentication, and log management are worth putting in place early, as the foundation of any real information security effort.

Feel free to contact us

Contact Us