Digital Badge Adoption Checklist | 7 Things to Verify Before Signing in 2026
From the version and roles of 1EdTech certification to the ISO 27001 edition number, personal data processing consignment, the amended privacy law effective September 2026, and public procurement requirements - seven things to verify before signing a digital badge solution contract.
Three of the items to verify before signing a digital badge solution contract changed in 2026. All ISO/IEC 27001 certificates based on the 2013 edition lapsed as of 31 October 2025, the amended Personal Information Protection Act takes effect on 11 September 2026, and public cloud security certification (CSAP) is set to be absorbed into a single National Intelligence Service verification system in July 2027. This article sets out the seven things to verify before contracting, as of August 2026, together with the legal provisions and official certification directories behind them.
Checklists are also going stale faster. Article 31 of the Network Act, still cited by many adoption guides today, was deleted on 4 February 2020. Leaving in a question whose legal basis has disappeared means revisiting it at the legal review stage.
Three verification items that changed in 2026
The items in a 2026 checklist that need updating are three: the security certification edition number, the amendment to the Personal Information Protection Act, and the public cloud certification framework. In all three cases, leaving the question as it stood through 2025 means either that verifying it is meaningless, or that the requirement changes during the contract period. The table below sets out how each item changed, along with its basis.
| Verification item | The question through 2025 | The question as of August 2026 | Basis |
|---|---|---|---|
| Security certification | Do you hold ISO 27001 certification? | Is it a valid certificate transitioned to the ISO/IEC 27001:2022 edition? | IAF MD 26 Issue 2 (2023) |
| Personal data | Do you comply with the current Personal Information Protection Act? | Does the contract reflect the requirements of the amendment effective 11 September 2026? | Amendment to the Personal Information Protection Act (promulgated 10 March 2026) |
| Public procurement | Do you hold CSAP certification? | Check the CSAP grade and expiry date together with the July 2027 transition plan | Ministry of Science and ICT / National Intelligence Service announcement (20 April 2026) |
The security certification row and the public procurement row in the table are only settled once you receive a copy of the certificate, and the personal data row is only settled once you look at the contract wording. None of the three can be determined from a proposal alone.

For 1EdTech certification, verify the version and the role
For 1EdTech Open Badges certification, look at the combination of version and role rather than whether it is held. As of August 2026, many major Korean platforms hold Open Badges 3.0 certification, so holding the certification itself does not distinguish much. Even within 3.0, a provider certified for the Issuer role alone and one certified across all three roles - Issuer, Displayer, and Host - differ in external wallet integration and the scope of badge display.
What each of the three roles validates is defined in the 1EdTech official certification guide.
| Role | Scope of validation |
|---|---|
| Issuer | Creating standards-compliant badges and delivering them to recipients, revocation procedures, cryptographic signature support |
| Displayer | Displaying badge metadata and verifying expiry and revocation status, supporting verification by the viewer |
| Host | Storing and publicly hosting badges for recipients, exporting with metadata preserved and exchanging with other hosts |
Also note that the axis of certification splits by version. Open Badges 2.0 and 3.0 certify against the three roles above, but 2.1 (Badge Connect API) certifies against a different framework of Service Provider and Service Consumer. If you plan to connect institutional systems and the badge platform by API, it is more accurate to check separately whether 2.1 certification is held.
3.0 is not an upper version of 2.0 but a specification with a different data model. Badges in 3.0 are issued as credentials following the W3C Verifiable Credentials data model, and revisions to the context of the standards document continued through June 2026. The differences between the two specifications are set out separately in Open Badges 3.0 compared with W3C Verifiable Credentials.
The certification records of major Korean platforms as confirmed in the official directory are below (confirmed August 2026).

| Platform | Open Badges 3.0 | Open Badges 2.0 | 2.1 (Badge Connect API) | CASE |
|---|---|---|---|---|
| Kolleges | Issuer, Displayer, Host | Issuer, Displayer, Host | Service Consumer, Provider | None |
| LecoS | Issuer, Displayer, Host | Issuer, Displayer, Host | Not shown in directory | None |
| K-OpenBadge | Issuer, Displayer, Host | Issuer, Displayer, Host | Service Provider | 1.0, 1.1 |
| Certi | Issuer | Issuer, Displayer, Host | Not shown in directory | None |
| OmniOne Badge | No registration confirmed | No registration confirmed | No registration confirmed | None |
In the table, only the CASE column of the K-OpenBadge row is filled in. CASE is a specification for exchanging competency and academic standards between institutions, and it is worth checking for institutions that plan to exchange competency frameworks externally. Certifications are renewed and expire, so at the final review stage check the certification date and status (Active / Out of Date) directly in the directory.
Differences in features and operating approach by platform are set out along the same axes in a comparison of digital badge providers in Korea.
For ISO 27001, look at the edition number and the expiry date together
For ISO/IEC 27001 certification, checking the edition number is essential in 2026. IAF MD 26 Issue 2, a mandatory document of the International Accreditation Forum (IAF), provides that certifications based on the 2013 edition expire or are withdrawn when the transition period ends, and that deadline was 31 October 2025. So as of August 2026, the notation “holds ISO 27001 certification” alone cannot establish validity.
There are three things to check on the copy of the certificate.
- Standard notation - whether it reads ISO/IEC 27001:2022, and whether any 2013 edition notation remains
- Scope of certification - whether badge issuance and storage services fall within the certified scope, and whether only head office administrative areas were certified
- Validity period - whether the expiry date covers the contract period, and whether a renewal audit is scheduled mid-contract
For Korean institutions, look at ISMS-P certification as well. Unlike ISO 27001, an international private-sector standard, ISMS-P is a statutory certification grounded in Article 47 of the Network Act and Article 32-2 of the Personal Information Protection Act, and operators above a certain threshold are subject to it as an obligation. Among universities too, those above the thresholds for enrolled student numbers and revenue fall within the obligation, so it is the right order to first check whether your own institution is subject to it, not just the solution vendor. The relationship between ISO 27001 and digital badge security is covered in more detail in a separate article.
For personal data, separate it into the consignment agreement, the amended law, and the storage location
A digital badge SaaS is a structure in which an institution entrusts the personal data of its recipients to an outside party. So the starting point for verification is not the service’s features but Article 26 of the Personal Information Protection Act (restrictions on the processing of personal information under consignment of work). Adding the requirements of the amendment taking effect in September 2026 and the data storage location completes the review of the personal data items.
The processing consignment agreement is the actual legal basis
Article 26 of the Personal Information Protection Act requires that, when consigning, the purpose and scope of processing, restrictions on sub-consignment, safety measures, and the supervision of the consignee be set out in a document, and that the fact of consignment be disclosed in the privacy policy. In a contract review, check whether the consignment document specifies the items processed and the retention period, whether there is a prior consent clause where sub-processors are used, and whether records of consignee training and inspections can be obtained.
Article 31 of the Network Act, frequently cited in past adoption guides, is not used as a basis. As the personal data provisions of the Network Act were transferred to the Personal Information Protection Act under the Data 3 Acts amendment, it was deleted on 4 February 2020. That said, Article 50 of the Network Act, which covers the transmission of advertising information for marketing purposes, remains in force, so where badge issuance notifications and marketing sends are handled through the same channel, consent needs to be separated.
Check whether the contract reflects the amendment effective 11 September 2026
The amended Personal Information Protection Act was promulgated on 10 March 2026 and takes effect on 11 September of the same year. The breach notification obligation moves earlier, from the point a breach is confirmed to the point a breach is possible, and the content of the notification must include remedies and dispute resolution procedures. The ceiling on administrative fines rises from 3% to 10% of revenue, with repeat violations within three years and failure to comply with corrective orders among the conditions for application. Mandatory ISMS-P certification for large-scale personal information controllers begins on 1 July 2027.
What changes in practice for an institution is the incident notification clause in the contract. Unless it is set out that the vendor must inform the institution within a given number of hours of becoming aware of a breach, the institution will struggle to meet the notification deadline under the amended law. Check three things in the contract: the notification deadline, the duty to cooperate, and the scope of liability.

Verify the data storage location and cross-border transfers
Get the server location and whether data is transferred abroad in writing before contracting. Where personal data is transferred outside the country, the requirements under Article 28-8 of the Personal Information Protection Act must be met, and the Personal Information Protection Commission signaled in its 2026 work plan that management of cross-border transfers would be strengthened, including the introduction of standard contractual clauses and binding corporate rules. If you are considering an overseas platform, this item becomes a condition to verify ahead of anything you would check for a Korean provider.
For public institutions, look at the procurement route and the certification transition plan
Public institutions settle the contracting route first, separately from the feature review. Using the specialized contracting system for digital services, introduced in October 2020, cloud services can be contracted through a negotiated contract or a catalog contract. Because the structure is one of contracting for services selected by a Ministry of Science and ICT review committee through the Public Procurement Service’s digital service mall, the first verification item is whether the service is on that list.
Cloud security certification has entered a transitional phase. On 20 April 2026, the Ministry of Science and ICT and the National Intelligence Service announced that the structure - split between CSAP and National Intelligence Service verification - would be unified into a single National Intelligence Service verification system. Administrative, physical, and technical safeguard items will be consolidated into ISMS, and public-sector-specific requirements will move to a newly established National Intelligence Service cloud security verification. It takes effect in July 2027, and existing CSAP certifications obtained before then are recognized for their validity period.
For this reason, it is more accurate for the certification question in a public institution’s checklist to be asked in three parts: whether CSAP certification is currently held and at what grade, the certificate expiry date, and the plan for handling the transition after July 2027.
Items that are not in the contract but determine operational workload
Once the standards and security questions are passed, the remaining differences come down to post-issuance operations. Most platforms provide the ability to create a badge, but the process of issuing to several hundred people in a cohort, reissuing for errors, and turning verification page views into performance reporting is structured differently from product to product. This is what actually determines your staff’s working hours.
Verifying the following four in a live demo at the review stage gives you a sense of the workload after adoption.
- Bulk issuance - how many steps from roster upload to send, and how error cases are displayed
- Reissuance and revocation - the reissuance procedure and handling of the existing badge when a name is misspelled or a program changes
- Verification page - how the screens seen by the recipient and by a third party each appear, and whether co-issuing organizations are shown
- Aggregation - whether issuance, view, and share data comes out in report form, and whether it can be exported
Kolleges places post-issuance usage and aggregation among these as its operational axis. That said, priorities differ by institution, so an institution that urgently needs bulk issuance automation and one that urgently needs performance reporting will evaluate the same product differently. When requesting a demo, it helps your judgment to give the actual roster size and number of programs at your institution and receive the demo under those conditions.
Summary: the seven things to verify before contracting
All seven items below are things confirmed through a document or a screen, not a proposal. Requesting the materials from the vendor ahead of the review meeting lets you reach a decision within the meeting itself.
| # | Verification item | How to verify |
|---|---|---|
| 1 | The version and role combination of 1EdTech certification | Look up the certification date, roles, and status directly in the 1EdTech official directory |
| 2 | A valid ISO/IEC 27001:2022 certificate | Check the edition number, scope of certification, and expiry date on the copy of the certificate |
| 3 | Personal data processing consignment agreement (Article 26) | The items processed, sub-consignment clauses, and supervision records in the consignment document |
| 4 | Clauses responding to the September 2026 amendment | The incident notification deadline, duty to cooperate, and scope of liability in the contract |
| 5 | Data storage location and cross-border transfer | Documentation of server location, and whether Article 28-8 requirements are met for transfers abroad |
| 6 | (Public) Procurement route and certification transition plan | Whether listed on the digital services list, the CSAP grade and expiry date, and the 2027 transition plan |
| 7 | Post-issuance operations | A live demo of bulk issuance, reissuance, the verification page, and aggregation |

Of the seven items, 1 through 5 apply the same way to any institution, 6 applies only to public institutions, and the weight of 7 varies with an institution’s issuance volume. If annual issuance is in the tens, item 7 does not carry much weight, but in a structure where several departments each issue hundreds, the final decision often comes down to item 7 after items 1 through 6 have been passed.
Certification and statutory requirements keep changing. The content of this article is as of August 2026, and at the time of contracting it is accurate to check the 1EdTech directory, the original certificates, and the statutory provisions in force again.
Frequently asked questions
Want to turn learning outcomes into verifiable assets?
From issuing to verifying and amplifying, see it for yourself with Kolleges.
Request a Kolleges demoRelated posts
Top 5 Digital Badge Providers in Korea | 2026 Comparison Guide
We compare five major digital badge platforms in Korea along two axes - their 1EdTech certification records and what happens after issuance - and lay out selection criteria by institutional situation.
Why ISO 27001 (Information Security) Certification Is Essential for Digital Badge Platforms
Digital badge platforms must hold ISO 27001 certification because learner credentials are lifelong career assets - any forgery, leakage, or outage directly harms individuals, not just institutions.
The complete Open Badges 3.0 guide: how it differs from W3C Verifiable Credentials
Open Badges 3.0 wraps W3C Verifiable Credentials with an education-specific metadata layer, replacing platform-dependent verification with cryptographic signatures that let learners own and selectively disclose their credentials.