When a company decides to "get a security certification," the first fork in the road is usually ISO/IEC 27001 (ISMS) versus Japan's Privacy Mark. Both are third-party certifications about how information is handled, and from the outside they look similar. But what they protect, how scope is defined, and how they are maintained all differ.
The common mistake is treating them as interchangeable and choosing whichever looks easier. Take the Privacy Mark when your client wanted evidence of an information security framework generally, and you will be asked for ISO/IEC 27001 later anyway. Conversely, if you handle almost nothing but personal data and want to signal trust to Japanese consumers, ISO certification may not be the best answer.
This article compares the two across what they protect, scope, audit frequency, and recognition, and offers a decision framework for healthcare companies. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. For ISMS, the authoritative sources are ISO/IEC 27001 (JIS Q 27001) and the publications of accreditation and certification bodies; for the Privacy Mark, those of the granting body (JIPDEC) and its designated assessment bodies. Scheme details change; verify against primary sources.
They Are Different Kinds of Scheme
ISO/IEC 27001 is certification against an international standard. A third-party body confirms that an organisation has established and operates an information security management system. The Japanese edition is JIS Q 27001, and the domestic accreditation body is ISMS-AC. Being international, it travels to overseas counterparties.
The Privacy Mark is a domestic Japanese scheme. It assesses conformity with JIS Q 15001, the standard for personal information protection management systems, and permits conforming businesses to display the mark. The granting body is JIPDEC, with assessments performed by designated bodies. Its distinguishing feature is high recognition within Japan and the ability to display a visual mark on consumer-facing sites and materials.
Already the difference in use emerges: ISO certification is for explaining a framework; the Privacy Mark is for displaying a signal.
What Each Protects
The most fundamental difference.
| ISO/IEC 27001 (ISMS) | Privacy Mark | |
|---|---|---|
| Protects | Information assets generally, personal data included | Personal information |
| Covers | Customer data, technical information, source code, contracts, management information, system availability | Acquisition, use, provision, storage, and disposal of identifiable personal data |
| Central idea | Balancing confidentiality, integrity, and availability through risk | Managing personal data properly across its whole lifecycle |
| Typical topics | Access control, logging, vulnerability management, supplier management, business continuity | Specifying and notifying purpose of use, obtaining consent, handling disclosure requests, supervising processors |
Note the treatment of availability. An ISMS treats "the information becomes unusable" as a risk. Ransomware halting a system, a cloud outage stopping a service — these sit squarely inside ISMS scope but are not naturally derived from a personal-data protection framework.
For a vendor of medical information systems, that gap is not small. An electronic medical record or PHR service going down is itself an event affecting care delivery. You need a framework that can account for availability. For how hospitals evaluate vendors, see Security Check Sheets for Vendors and Demarcating Responsibility.
Also worth stating: compliance with Japan's personal information protection law is required regardless. The Privacy Mark assesses a management system that includes legal compliance; it is not a licence without which you may not handle personal data.
Scope: Can You Certify a Single Division?
In practice, this is the difference that most often decides the question.
An ISMS scope can be drawn organisationally. You can define it as, say, "development and operation of service X provided by division Y at the head office" and certify exactly that. So you can:
- Certify only the team building and running your flagship service, then widen later
- Certify only the business line serving hospitals
- Include or exclude particular sites or data centres
Because scope breadth drives auditor-days and documentation volume — and therefore cost — being able to fit scope to what clients actually require is a substantial practical advantage. See Defining ISMS Scope and Scope Design for Healthcare Companies.
The Privacy Mark, by contrast, is granted at the level of the business entity. Certifying a single division is not the intent of the scheme — reasonably so, since displaying a mark that says "this company handles personal data properly" would mean little if only one department conformed.
| Situation | ISMS | Privacy Mark |
|---|---|---|
| Only one of several business lines needs certification | Certify that line alone | Company-wide effort required |
| Only part of a group is in view | Possible, depending on entity and scope definition | Granted per entity |
| Want to start small and quickly | Adjustable by narrowing scope | Hard to compress, being company-wide |
| Want to signal a company-wide standard for personal data | Requires explaining what is out of scope | Matches the scheme's purpose |
"Can we mobilise the whole company?" is frequently the real deciding question.
Audit Frequency and Maintenance
| ISMS | Privacy Mark | |
|---|---|---|
| Initial | Stage 1 (documentation) → Stage 2 (on-site) | Document review → on-site assessment |
| Maintenance | Annual surveillance audit | No routine interim audit during the validity period |
| Renewal | Recertification every three years | Renewal every two years |
| Validity | Three years, conditional on annual surveillance | Two years |
(Validity periods and audit practice can change with scheme revisions and the practice of granting and assessment bodies. Verify against primary sources.)
Annual for ISMS, biennial for the Privacy Mark. The yearly load looks heavier for ISMS — but seen differently, ISMS forces an internal audit and management review every year, which makes the practice harder to abandon. The Privacy Mark's longer interval leaves more room for operations to drift in year two.
See Preparing for Surveillance Audits, Preparing for the Year-Three Recertification Audit, and The Full Cost of ISMS Certification.
Recognition: Who Are You Showing It To?
The Privacy Mark's strength is visibility to consumers. It is a mark you can display, and it is widely recognised in Japan — useful in a B2C service footer, in recruiting, in PR.
ISO certification's strength is currency in business-to-business procurement. As an international standard it explains itself abroad, and the certificate plus your scope statement and Statement of Applicability let you say concretely what is covered, which controls you adopted, and why. B2B procurement asks for that substance rather than a logo.
A frequent practical problem is vague wording in a client's requirement. Where it says only "must hold a security certification," confirm:
- Where the requirement comes from (their own procurement policy, or their customer's demand)
- Whether they want evidence about personal data or about information security generally
- Whether they will also ask for the scope statement and SoA
- Whether a completed security questionnaire would substitute for certification
That last point matters: certification is not always mandatory. See Choosing Not to Certify: Certification vs. Security Questionnaires and When ISMS Becomes a Condition of Trade.
A Decision Table for Healthcare Companies
| Axis | Favours ISMS | Favours Privacy Mark |
|---|---|---|
| Main counterparties | Hospitals, pharma, government, enterprises (B2B) | Consumers (B2C) |
| Evidence being asked for | Information security framework generally | Proper handling of personal data |
| Information handled | Clinical data, systems, technical information — broad | Largely personal data only |
| Importance of availability | High — outages affect the business and care delivery | Comparatively lower |
| Scope | Want to limit to a business or division | Can, and want to, act company-wide |
| Overseas activity | Yes — an international standard | Primarily domestic |
| Industry guidelines | Want a base for three-ministry guideline work | Limited direct connection |
| Maintenance capacity | Can run an internal audit and review every year | Operate around a two-year renewal |
For a B2B healthcare company, ISMS is the baseline, for three reasons:
- It is what gets specified. Hospitals must satisfy the three-ministry guidelines and are therefore pushed to require an equivalent standard of suppliers
- What needs protecting is not limited to personal data — system availability, technical information, and supplier management are all in play
- It is the foundation for other schemes. ISO 27017 (cloud) and ISO 27701 (privacy information) both build on an ISMS, and three-ministry guideline documentation is most efficiently derived from ISMS documents
Where the business is B2C and personal data is the core — a PHR operator, for instance — the calculus can differ. That domain needs the relationship with personal data law settled first: see ISMS for PHR Operators.
Before You Decide to Take Both
Some companies hold both. But the maintenance burden simply adds up: two document hierarchies, two audit calendars.
It is worth considering when:
- You run both B2C and B2B lines with genuinely different evidentiary demands
- You want a company-wide consumer signal and a detailed framework explanation for a specific business
Even then, take one, stabilise the operation, then consider the other. Building both at once spikes the internal load sharply.
And if the real goal is simply to strengthen personal data protection within an ISMS, ISO 27701 (PIMS) is an alternative — an extension that stacks onto ISMS documentation. See ISO 27701 (PIMS): Connecting Privacy to Your ISMS. Cloud providers should also weigh ISO 27017 and 27018.
For US counterparties and overseas SaaS expansion, the requirement may be neither of these but SOC 2, a fundamentally different instrument: see ISMS vs SOC 2.
Conclusion
- ISMS certifies management of information assets generally under an international standard; the Privacy Mark addresses personal data under a domestic scheme
- ISMS scope can be drawn per business or division; the Privacy Mark is granted per entity. Whether you can mobilise the whole company is often the real decider
- Maintenance differs: annual surveillance plus three-year recertification for ISMS; two-year renewal for the Privacy Mark (verify current practice). ISMS is harder to let lapse but heavier annually
- Recognition differs: the Privacy Mark is visible to consumers; ISMS carries weight in B2B procurement. When a requirement is vaguely worded, ask whether it concerns personal data or the framework as a whole
- For B2B healthcare, ISMS is the baseline — it accounts for availability and underpins guideline compliance and further certifications
- Holding both is possible but the burden is additive; if the goal is only privacy, ISO 27701 may serve better
Pottech supports ISO/IEC 27001 certification with a focus on healthcare, and we are glad to be involved at the "which one, and what is the client actually asking for" stage. We cover scope design, templates for procedures, registers and training, project management, and internal audit.
See ISMS Certification Support for scope and pricing, or contact us to talk through the choice.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Privacy Mark System | JIPDEC
- Personal Information Protection Commission, Japan
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: requirements, validity periods, and assessment practice for both schemes are governed by the standards themselves and the publications of the accreditation, granting, and assessment bodies, and are subject to revision. Verify the validity and frequency figures here against primary sources.