September 11, 2026: The Penalty Base Shifts to 10% of Total Revenue
When the amended Personal Information Protection Act takes effect on September 11, 2026, the basis for calculating administrative fines changes. Previously, fines were capped at 3% of revenue tied to the violation. Under the amendment, repeated violations involving intent or gross negligence can draw fines of up to 10% of total company revenue. Because both the base amount and the rate expand at once, the practical risk grows by far more than a simple multiple.
Simulated caps by revenue size
Actual fines are reduced based on severity and cooperation after the fact. What matters is that the starting point for that negotiation has moved, and that the "repeated intent or gross negligence" test is effectively met the moment an absent management system is demonstrated. Certification history and internal audit records are the most practical defense available.
Three Pillars of the ISMS/ISMS-P Overhaul
First, from snapshot audits to continuous verification. The overhaul was driven by data showing that 179 certified companies — about 14% of the total — still experienced security incidents. Paper evidence assembled only for audit day does not guarantee real security posture. Going forward, logs and vulnerability remediation records maintained throughout the certification period become subject to ongoing review.
Second, penetration testing for enhanced certification. Defenses are validated against real attack scenarios, so polished policy documents alone will not pass. If you operate web or mobile services, budget at least two to three months for pre-assessment and remediation.
Third, board resolution and explicit CEO accountability. Key information security matters are elevated to board-level resolutions, with the CEO holding final oversight responsibility. Security moves from an IT staff task to an executive decision.
Will the July 2027 Mandate Apply to Us?
The mandate targets "significant personal data controllers," currently identified as roughly 57 public institutions and around 50 private companies. By the numbers, most SMEs are not directly covered.
The real pressure is indirect. ISMS certification increasingly appears as a scored or mandatory item in public procurement proposals, large-enterprise supplier registration reviews, and e-commerce or fintech platform onboarding requirements. Even without a legal obligation, companies must prepare to protect revenue opportunities. Note that information security disclosure obligations are a separate regime based on total assets and revenue thresholds — assess disclosure scope and certification scope independently.
Reducing Duplication If You Already Hold ISO 27001
ISO 27001 is an international standard; ISMS-P is a domestic statutory certification. They rest on different laws and are audited by different bodies, so neither replaces the other. Because their controls overlap substantially, however, the following design reduces the burden.
Controls unique to ISMS-P — the personal data lifecycle of collection, use, provision, and destruction — still require separate work.
A 12-Month Roadmap
Months 0–3: Assessment
Map personal data flows (collection channels, storage locations, third-party provision, outsourcing) and run a gap analysis against the certification criteria. Sub-processing clauses in outsourcing contracts and vendor inspection records are the most frequently cited gaps.
Months 4–9: Build and Verify
Implement technical safeguards — access control, encryption, log retention, backup — and accumulate at least three months of operating evidence. Conduct at least one internal audit, and if you fall under enhanced certification, schedule the penetration test pre-assessment in this window.
Months 10–12: Audit and Institutionalize
Submit the application, remediate findings, and formalize regular reporting of security matters to executives and the board.
If cost is a constraint, look first at public programs such as SME information security consulting support, security solution adoption vouchers, and free diagnostics from regional information security support centers. Budgets are exhausted at different times, so catching announcements early in the year matters.
Talk to KITIM
KITIM supports each stage — gap analysis, policy and guideline frameworks, technical safeguard design, penetration test readiness, audit response, and post-certification maintenance. We also design integrated operations for companies already holding ISO 27001 and connect clients to relevant government support programs. If you want clarity on whether the mandate applies to you and how ready you are today, please request a consultation.
