Riscala AI for ISMS
FeaturesPricingGuideFAQView source on GitHubSend feedback
LoginDemo login
  1. Home
  2. /
  3. Guide
  4. /
  5. ISMS (ISO 27001) vs Privacy Mark: Which Certification Should a Japanese IT Company Choose?

Guide

ISMS (ISO 27001) vs Privacy Mark: Which Certification Should a Japanese IT Company Choose?

The core difference between ISMS (ISO/IEC 27001) and the Privacy Mark (P Mark), a Japanese certification based on JIS Q 15001, is what each one protects. ISMS covers information assets as a whole, including personal data, under an international standard. The Privacy Mark focuses specifically on how personal information is handled inside a Japanese company. B2B IT companies that hold client systems and data are more often asked for ISMS, while B2C businesses handling large volumes of consumer data more often pursue the Privacy Mark.

Published: 2026-09-10·Last updated: 2026-09-10

Table of contents

  1. The difference in one sentence
  2. What ISMS (ISO/IEC 27001) is
  3. What the Privacy Mark is
  4. ISMS and Privacy Mark side by side
  5. How to decide which one to pursue
  6. Holding both, and what can be shared
  7. Three common misconceptions
  8. Start by mapping where you stand

The difference in one sentence

The two are often lumped together as security certifications, but they protect different things. ISMS looks at information assets in general such as servers, source code, contracts and know-how, and audits the management system that keeps confidentiality, integrity and availability under control. The Privacy Mark narrows the target to personal information and audits how it is collected, used, stored and disposed of.

That single distinction produces most of the practical differences below. Neither is superior; the right choice depends on what information your business handles and what your customers are actually asking for.

  • ISMS lets you define the scope, so a single service or engineering unit can be certified
  • The Privacy Mark applies to the legal entity as a whole, with no partial-scope concept
  • ISMS is an international standard, so it can be presented to overseas customers as is
  • The Privacy Mark logo is widely recognised by Japanese consumers and signals trust domestically

What ISMS (ISO/IEC 27001) is

ISMS stands for Information Security Management System, and ISO/IEC 27001 is the international standard that sets out its requirements. The current edition is the 2022 revision, whose Annex A reorganises the controls into 93 items. Rather than checking whether individual security measures exist, the audit asks whether a cycle of selecting controls from a risk assessment, operating them and improving them is genuinely running.

In practice that means a policy, risk identification and evaluation, a Statement of Applicability, internal audits and management review, together with the records that evidence them. For what has to be written down, see the ISMS document list; for the path to certification, see how ISO 27001 certification works.

What the Privacy Mark is

The Privacy Mark (P Mark) is a Japanese third-party certification for the handling of personal information, operated by JIPDEC (Japan Institute for Promotion of Digital Economy and Community). Its basis is JIS Q 15001, the Japanese Industrial Standard for a personal information protection management system, which reflects the thinking of the Act on the Protection of Personal Information while setting its own management requirements.

An audit covers the inventory of personal information held, notification and publication of purposes of use, procedures for handling disclosure requests from individuals, supervision of subcontractors, and employee training. Because everything down to business cards and job applications is in scope, the entity-wide boundary is what makes this the heavier lift for many companies.

ISMS and Privacy Mark side by side

DimensionISMS (ISO/IEC 27001)Privacy Mark (P Mark)
StandardISO/IEC 27001:2022 (international)JIS Q 15001 (Japanese national standard)
What is protectedInformation assets in general, including personal data (confidentiality, integrity, availability)Personal information only
Certification boundaryScope can be set by department, site or serviceThe legal entity as a whole, as a rule
International reachRecognised internationally by overseas customersPrimarily a domestic Japanese scheme
Audit cycleInitial audit, annual surveillance, renewal every three yearsRenewal audit every two years
Cost rangeAudit plus support fees typically discussed in a range from the low hundreds of thousands to several million yenComparable, and sometimes somewhat lower depending on conditions
TimelineRoughly six months to a year from starting preparationRoughly six months to a year
Best suited toB2B IT firms, SaaS providers, contract development, companies with overseas businessB2C businesses handling large volumes of consumer data: recruitment, e-commerce, membership services

Cost and duration vary widely with headcount, number of sites, breadth of scope and how mature your existing rules are, so both are given as ranges. The breakdown and the factors that move it are covered in the ISMS certification cost guide.

Mind the audit cycle

ISMS runs on a three-year cycle with an annual surveillance audit in between. The Privacy Mark is renewed every two years with no interim audit. As a result, ISMS effort tends to be spread evenly across the years, while Privacy Mark work concentrates in the renewal year.

How to decide which one to pursue

Industry alone does not settle the question. Looking at your situation through these five lenses usually makes the priority obvious.

  • What customers ask for: which name appears on the security questionnaires and tender conditions you receive. This is the strongest signal
  • Type of information held: client systems, source code and trade secrets point to ISMS; consumer personal data points to the Privacy Mark
  • Overseas business: if you must explain your posture to non-Japanese customers or auditors, an international standard travels better
  • Internal structure: the Privacy Mark covers the whole entity, so more sites and business lines mean more work. ISMS can start narrow
  • Room to grow: if you plan to certify one service first and widen later, ISMS is built for that

Among Japanese B2B IT companies of up to about 100 people, customer security requirements frequently name ISO/IEC 27001 specifically, which is why ISMS often comes first. If personal data is the core of your product, that reasoning does not hold.

Holding both, and what can be shared

Some companies hold both. The usual reasons are a B2B SaaS that also holds end-user personal data, or enterprise customers asking for ISMS while public-sector work asks for the Privacy Mark. When that happens, building two separate systems from scratch is wasteful; the shared layer should be operated once.

  • Policies: keep the information security policy and the personal information protection policy consistent as one hierarchy
  • Employee training: merge annual materials and attendance records, with privacy protection as a module inside them
  • Incident response: unify reporting routes, first response and record formats, with a branch for personal data breaches
  • Document control: run versioning, approval, retention and disposal on one common framework
  • Internal audit: keep checklists separate but share the annual plan and auditor development

Risk assessment and the Statement of Applicability are distinctly ISMS, while the personal information inventory is distinctly Privacy Mark. Keeping those separate is usually easier to maintain than forcing them together.

Three common misconceptions

These three assumptions come up often, and each stems from misreading what a certification represents.

We have the Privacy Mark, so we do not need ISMS

The Privacy Mark covers personal information. Client source code, design documents and internal trade secrets are outside it, so when a customer asks how you manage information assets in general, the Privacy Mark alone may not answer the question they asked.

The second is the belief that certifying to ISMS automatically satisfies the Act on the Protection of Personal Information. ISMS examines a management system for information assets; it is not a determination of legal compliance. Specifying and notifying purposes of use, responding to requests from individuals, and reporting obligations after a breach still have to be handled separately. The third is reading certification as a promise that nothing will go wrong. It records that a third party confirmed the system was functioning, which is not the same as the absence of incidents.

Start by mapping where you stand

Whichever route you take, the decision rests on knowing what you already have and what is missing. Policies that exist only in part, an asset inventory with no risk evaluation behind it, training delivered but never recorded: the real starting point differs considerably from company to company.

The ISMS readiness self-check makes that visible by answering a short set of questions. Even while you are still weighing ISMS against the Privacy Mark, seeing which areas are thin makes the comparison a much easier conversation to have internally.

Frequently asked questions

Do we need both ISMS and the Privacy Mark?
Few companies genuinely need both. A B2B IT company whose customers name ISO/IEC 27001 is usually served by ISMS alone, while a business handling consumer personal data at scale, or bidding for work that requires the Privacy Mark, may reasonably hold both. Work backwards from the security requirements you actually receive rather than from the industry you are in.
If we can only do one first, which should it be?
As a general pattern, ISMS is easier to start because you can limit the scope, certify one service or engineering unit, and widen later once the routine is stable. That said, if a customer has named the Privacy Mark, their requirement wins. Deciding from the requests that cost you deals in the past year keeps the choice grounded.
Can Privacy Mark work be reused for ISMS?
A large share of it can. Policy hierarchy, employee training, incident response, document and record control, internal audit operation and subcontractor management are common ground. ISMS adds an information asset inventory, a risk assessment and a Statement of Applicability covering the Annex A controls. Plan it as filling gaps rather than starting over.
Is there a privacy extension to ISMS?
ISO/IEC 27701 exists as an extension that builds a privacy information management system (PIMS) on top of an ISO/IEC 27001 ISMS. It suits an organisation already running ISMS that wants to explain its handling of personal data internationally. Within Japan the Privacy Mark carries more name recognition, so the right choice depends on whether your audience is domestic or global.
How different are the cost and the timeline?
Both move so much with headcount, sites, scope and existing maturity that a direct comparison is unreliable. As a rough sense of scale, preparation to certification is often discussed as six months to a year, and audit plus support fees in a range from the low hundreds of thousands to several million yen. The meaningful difference is that ISMS scope can be narrowed to keep the first cycle smaller.

Check where your ISMS stands in 5 questions

Answers are processed only in your browser and are never sent from this app.

Start the self-check

This article is for general information only and does not guarantee any audit outcome or certification. Schemes and costs change, so confirm the latest details with certification bodies.

Related articles

ISO 27001 (ISMS) Certification Cost: Audit, Consulting and Maintenance Breakdown

ISO 27001 certification typically costs JPY 1.5M-7M in year one and JPY 400K-2M a year to maintain. See the breakdown by company size and 5 ways to cut it.

Last updated: 2026-09-10Read article →

The ISO 27001 (ISMS) Certification Process and Timeline: 8 Steps from Kickoff to Registration

ISO 27001 (ISMS) certification in eight steps from kickoff to registration, why it usually takes 6 to 12 months, and what Stage 1 and Stage 2 audits check.

Last updated: 2026-09-10Read article →

Required Documents for an ISMS (ISO 27001): Documented Information and Records, Organized

ISO/IEC 27001 documents in two layers: the documented information the standard explicitly requires, and the policies teams build around Annex A controls.

Last updated: 2026-09-10Read article →
I
Riscala AI for ISMS

Simplifying ISO27001 certification for growing businesses worldwide

Product

  • Features
  • Pricing
  • Guide
  • Public GitHub repository
  • Public overview

Company

  • About Us
  • Feedback and inquiries
  • Privacy Policy
  • Terms of Service

Support

  • Help Center
  • Documentation
  • System Status

© 2026 Riscala AI for ISMS. All rights reserved.

Privacy PolicyTerms of ServiceCookie Policy