Back to Columns
ISMS & Certification12 min read

ISMS vs Privacy Mark: Which One Should You Take?

September 14, 2026

ISMS vs Privacy Mark: Which One Should You Take?
Share this article

When a company decides to "get a security certification," the first fork in the road is usually ISO/IEC 27001 (ISMS) versus Japan's Privacy Mark. Both are third-party certifications about how information is handled, and from the outside they look similar. But what they protect, how scope is defined, and how they are maintained all differ.

The common mistake is treating them as interchangeable and choosing whichever looks easier. Take the Privacy Mark when your client wanted evidence of an information security framework generally, and you will be asked for ISO/IEC 27001 later anyway. Conversely, if you handle almost nothing but personal data and want to signal trust to Japanese consumers, ISO certification may not be the best answer.

This article compares the two across what they protect, scope, audit frequency, and recognition, and offers a decision framework for healthcare companies. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. For ISMS, the authoritative sources are ISO/IEC 27001 (JIS Q 27001) and the publications of accreditation and certification bodies; for the Privacy Mark, those of the granting body (JIPDEC) and its designated assessment bodies. Scheme details change; verify against primary sources.

They Are Different Kinds of Scheme

ISO/IEC 27001 is certification against an international standard. A third-party body confirms that an organisation has established and operates an information security management system. The Japanese edition is JIS Q 27001, and the domestic accreditation body is ISMS-AC. Being international, it travels to overseas counterparties.

The Privacy Mark is a domestic Japanese scheme. It assesses conformity with JIS Q 15001, the standard for personal information protection management systems, and permits conforming businesses to display the mark. The granting body is JIPDEC, with assessments performed by designated bodies. Its distinguishing feature is high recognition within Japan and the ability to display a visual mark on consumer-facing sites and materials.

Already the difference in use emerges: ISO certification is for explaining a framework; the Privacy Mark is for displaying a signal.

What Each Protects

The most fundamental difference.

ISO/IEC 27001 (ISMS)Privacy Mark
ProtectsInformation assets generally, personal data includedPersonal information
CoversCustomer data, technical information, source code, contracts, management information, system availabilityAcquisition, use, provision, storage, and disposal of identifiable personal data
Central ideaBalancing confidentiality, integrity, and availability through riskManaging personal data properly across its whole lifecycle
Typical topicsAccess control, logging, vulnerability management, supplier management, business continuitySpecifying and notifying purpose of use, obtaining consent, handling disclosure requests, supervising processors

Note the treatment of availability. An ISMS treats "the information becomes unusable" as a risk. Ransomware halting a system, a cloud outage stopping a service — these sit squarely inside ISMS scope but are not naturally derived from a personal-data protection framework.

For a vendor of medical information systems, that gap is not small. An electronic medical record or PHR service going down is itself an event affecting care delivery. You need a framework that can account for availability. For how hospitals evaluate vendors, see Security Check Sheets for Vendors and Demarcating Responsibility.

Also worth stating: compliance with Japan's personal information protection law is required regardless. The Privacy Mark assesses a management system that includes legal compliance; it is not a licence without which you may not handle personal data.

Scope: Can You Certify a Single Division?

In practice, this is the difference that most often decides the question.

An ISMS scope can be drawn organisationally. You can define it as, say, "development and operation of service X provided by division Y at the head office" and certify exactly that. So you can:

  • Certify only the team building and running your flagship service, then widen later
  • Certify only the business line serving hospitals
  • Include or exclude particular sites or data centres

Because scope breadth drives auditor-days and documentation volume — and therefore cost — being able to fit scope to what clients actually require is a substantial practical advantage. See Defining ISMS Scope and Scope Design for Healthcare Companies.

The Privacy Mark, by contrast, is granted at the level of the business entity. Certifying a single division is not the intent of the scheme — reasonably so, since displaying a mark that says "this company handles personal data properly" would mean little if only one department conformed.

SituationISMSPrivacy Mark
Only one of several business lines needs certificationCertify that line aloneCompany-wide effort required
Only part of a group is in viewPossible, depending on entity and scope definitionGranted per entity
Want to start small and quicklyAdjustable by narrowing scopeHard to compress, being company-wide
Want to signal a company-wide standard for personal dataRequires explaining what is out of scopeMatches the scheme's purpose

"Can we mobilise the whole company?" is frequently the real deciding question.

Audit Frequency and Maintenance

ISMSPrivacy Mark
InitialStage 1 (documentation) → Stage 2 (on-site)Document review → on-site assessment
MaintenanceAnnual surveillance auditNo routine interim audit during the validity period
RenewalRecertification every three yearsRenewal every two years
ValidityThree years, conditional on annual surveillanceTwo years

(Validity periods and audit practice can change with scheme revisions and the practice of granting and assessment bodies. Verify against primary sources.)

Annual for ISMS, biennial for the Privacy Mark. The yearly load looks heavier for ISMS — but seen differently, ISMS forces an internal audit and management review every year, which makes the practice harder to abandon. The Privacy Mark's longer interval leaves more room for operations to drift in year two.

See Preparing for Surveillance Audits, Preparing for the Year-Three Recertification Audit, and The Full Cost of ISMS Certification.

Recognition: Who Are You Showing It To?

The Privacy Mark's strength is visibility to consumers. It is a mark you can display, and it is widely recognised in Japan — useful in a B2C service footer, in recruiting, in PR.

ISO certification's strength is currency in business-to-business procurement. As an international standard it explains itself abroad, and the certificate plus your scope statement and Statement of Applicability let you say concretely what is covered, which controls you adopted, and why. B2B procurement asks for that substance rather than a logo.

A frequent practical problem is vague wording in a client's requirement. Where it says only "must hold a security certification," confirm:

  • Where the requirement comes from (their own procurement policy, or their customer's demand)
  • Whether they want evidence about personal data or about information security generally
  • Whether they will also ask for the scope statement and SoA
  • Whether a completed security questionnaire would substitute for certification

That last point matters: certification is not always mandatory. See Choosing Not to Certify: Certification vs. Security Questionnaires and When ISMS Becomes a Condition of Trade.

A Decision Table for Healthcare Companies

AxisFavours ISMSFavours Privacy Mark
Main counterpartiesHospitals, pharma, government, enterprises (B2B)Consumers (B2C)
Evidence being asked forInformation security framework generallyProper handling of personal data
Information handledClinical data, systems, technical information — broadLargely personal data only
Importance of availabilityHigh — outages affect the business and care deliveryComparatively lower
ScopeWant to limit to a business or divisionCan, and want to, act company-wide
Overseas activityYes — an international standardPrimarily domestic
Industry guidelinesWant a base for three-ministry guideline workLimited direct connection
Maintenance capacityCan run an internal audit and review every yearOperate around a two-year renewal

For a B2B healthcare company, ISMS is the baseline, for three reasons:

  1. It is what gets specified. Hospitals must satisfy the three-ministry guidelines and are therefore pushed to require an equivalent standard of suppliers
  2. What needs protecting is not limited to personal data — system availability, technical information, and supplier management are all in play
  3. It is the foundation for other schemes. ISO 27017 (cloud) and ISO 27701 (privacy information) both build on an ISMS, and three-ministry guideline documentation is most efficiently derived from ISMS documents

Where the business is B2C and personal data is the core — a PHR operator, for instance — the calculus can differ. That domain needs the relationship with personal data law settled first: see ISMS for PHR Operators.

Before You Decide to Take Both

Some companies hold both. But the maintenance burden simply adds up: two document hierarchies, two audit calendars.

It is worth considering when:

  • You run both B2C and B2B lines with genuinely different evidentiary demands
  • You want a company-wide consumer signal and a detailed framework explanation for a specific business

Even then, take one, stabilise the operation, then consider the other. Building both at once spikes the internal load sharply.

And if the real goal is simply to strengthen personal data protection within an ISMS, ISO 27701 (PIMS) is an alternative — an extension that stacks onto ISMS documentation. See ISO 27701 (PIMS): Connecting Privacy to Your ISMS. Cloud providers should also weigh ISO 27017 and 27018.

For US counterparties and overseas SaaS expansion, the requirement may be neither of these but SOC 2, a fundamentally different instrument: see ISMS vs SOC 2.

Conclusion

  1. ISMS certifies management of information assets generally under an international standard; the Privacy Mark addresses personal data under a domestic scheme
  2. ISMS scope can be drawn per business or division; the Privacy Mark is granted per entity. Whether you can mobilise the whole company is often the real decider
  3. Maintenance differs: annual surveillance plus three-year recertification for ISMS; two-year renewal for the Privacy Mark (verify current practice). ISMS is harder to let lapse but heavier annually
  4. Recognition differs: the Privacy Mark is visible to consumers; ISMS carries weight in B2B procurement. When a requirement is vaguely worded, ask whether it concerns personal data or the framework as a whole
  5. For B2B healthcare, ISMS is the baseline — it accounts for availability and underpins guideline compliance and further certifications
  6. Holding both is possible but the burden is additive; if the goal is only privacy, ISO 27701 may serve better

Pottech supports ISO/IEC 27001 certification with a focus on healthcare, and we are glad to be involved at the "which one, and what is the client actually asking for" stage. We cover scope design, templates for procedures, registers and training, project management, and internal audit.

See ISMS Certification Support for scope and pricing, or contact us to talk through the choice.

References and Sources

Note: requirements, validity periods, and assessment practice for both schemes are governed by the standards themselves and the publications of the accreditation, granting, and assessment bodies, and are subject to revision. Verify the validity and frequency figures here against primary sources.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.