Operations

Digital Badge Adoption Checklist | 7 Things to Verify Before Signing in 2026

A Amy Kim · Education Innovation Team Published Updated
UniversitiesPublic SectorDigital Badge AdoptionDigital Badges
Digital Badge Adoption Checklist | 7 Things to Verify Before Signing in 2026
Key points

From the version and roles of 1EdTech certification to the ISO 27001 edition number, personal data processing consignment, the amended privacy law effective September 2026, and public procurement requirements - seven things to verify before signing a digital badge solution contract.

Three of the items to verify before signing a digital badge solution contract changed in 2026. All ISO/IEC 27001 certificates based on the 2013 edition lapsed as of 31 October 2025, the amended Personal Information Protection Act takes effect on 11 September 2026, and public cloud security certification (CSAP) is set to be absorbed into a single National Intelligence Service verification system in July 2027. This article sets out the seven things to verify before contracting, as of August 2026, together with the legal provisions and official certification directories behind them.

Checklists are also going stale faster. Article 31 of the Network Act, still cited by many adoption guides today, was deleted on 4 February 2020. Leaving in a question whose legal basis has disappeared means revisiting it at the legal review stage.

Three verification items that changed in 2026

The items in a 2026 checklist that need updating are three: the security certification edition number, the amendment to the Personal Information Protection Act, and the public cloud certification framework. In all three cases, leaving the question as it stood through 2025 means either that verifying it is meaningless, or that the requirement changes during the contract period. The table below sets out how each item changed, along with its basis.

Verification itemThe question through 2025The question as of August 2026Basis
Security certificationDo you hold ISO 27001 certification?Is it a valid certificate transitioned to the ISO/IEC 27001:2022 edition?IAF MD 26 Issue 2 (2023)
Personal dataDo you comply with the current Personal Information Protection Act?Does the contract reflect the requirements of the amendment effective 11 September 2026?Amendment to the Personal Information Protection Act (promulgated 10 March 2026)
Public procurementDo you hold CSAP certification?Check the CSAP grade and expiry date together with the July 2027 transition planMinistry of Science and ICT / National Intelligence Service announcement (20 April 2026)

The security certification row and the public procurement row in the table are only settled once you receive a copy of the certificate, and the personal data row is only settled once you look at the contract wording. None of the three can be determined from a proposal alone.

A chart of the three items needing renewal in 2026 - the ISO 27001 edition number, the Personal Information Protection Act amended in September 2026, and the public cloud certification transition

For 1EdTech certification, verify the version and the role

For 1EdTech Open Badges certification, look at the combination of version and role rather than whether it is held. As of August 2026, many major Korean platforms hold Open Badges 3.0 certification, so holding the certification itself does not distinguish much. Even within 3.0, a provider certified for the Issuer role alone and one certified across all three roles - Issuer, Displayer, and Host - differ in external wallet integration and the scope of badge display.

What each of the three roles validates is defined in the 1EdTech official certification guide.

RoleScope of validation
IssuerCreating standards-compliant badges and delivering them to recipients, revocation procedures, cryptographic signature support
DisplayerDisplaying badge metadata and verifying expiry and revocation status, supporting verification by the viewer
HostStoring and publicly hosting badges for recipients, exporting with metadata preserved and exchanging with other hosts

Also note that the axis of certification splits by version. Open Badges 2.0 and 3.0 certify against the three roles above, but 2.1 (Badge Connect API) certifies against a different framework of Service Provider and Service Consumer. If you plan to connect institutional systems and the badge platform by API, it is more accurate to check separately whether 2.1 certification is held.

3.0 is not an upper version of 2.0 but a specification with a different data model. Badges in 3.0 are issued as credentials following the W3C Verifiable Credentials data model, and revisions to the context of the standards document continued through June 2026. The differences between the two specifications are set out separately in Open Badges 3.0 compared with W3C Verifiable Credentials.

The certification records of major Korean platforms as confirmed in the official directory are below (confirmed August 2026).

The 1EdTech official certification directory screen - a list showing certification dates and registration numbers for Open Badges 3.0, 2.0, and 2.1 along with the Issuer, Displayer, and Host roles

PlatformOpen Badges 3.0Open Badges 2.02.1 (Badge Connect API)CASE
KollegesIssuer, Displayer, HostIssuer, Displayer, HostService Consumer, ProviderNone
LecoSIssuer, Displayer, HostIssuer, Displayer, HostNot shown in directoryNone
K-OpenBadgeIssuer, Displayer, HostIssuer, Displayer, HostService Provider1.0, 1.1
CertiIssuerIssuer, Displayer, HostNot shown in directoryNone
OmniOne BadgeNo registration confirmedNo registration confirmedNo registration confirmedNone

In the table, only the CASE column of the K-OpenBadge row is filled in. CASE is a specification for exchanging competency and academic standards between institutions, and it is worth checking for institutions that plan to exchange competency frameworks externally. Certifications are renewed and expire, so at the final review stage check the certification date and status (Active / Out of Date) directly in the directory.

Differences in features and operating approach by platform are set out along the same axes in a comparison of digital badge providers in Korea.

For ISO 27001, look at the edition number and the expiry date together

For ISO/IEC 27001 certification, checking the edition number is essential in 2026. IAF MD 26 Issue 2, a mandatory document of the International Accreditation Forum (IAF), provides that certifications based on the 2013 edition expire or are withdrawn when the transition period ends, and that deadline was 31 October 2025. So as of August 2026, the notation “holds ISO 27001 certification” alone cannot establish validity.

There are three things to check on the copy of the certificate.

  1. Standard notation - whether it reads ISO/IEC 27001:2022, and whether any 2013 edition notation remains
  2. Scope of certification - whether badge issuance and storage services fall within the certified scope, and whether only head office administrative areas were certified
  3. Validity period - whether the expiry date covers the contract period, and whether a renewal audit is scheduled mid-contract

For Korean institutions, look at ISMS-P certification as well. Unlike ISO 27001, an international private-sector standard, ISMS-P is a statutory certification grounded in Article 47 of the Network Act and Article 32-2 of the Personal Information Protection Act, and operators above a certain threshold are subject to it as an obligation. Among universities too, those above the thresholds for enrolled student numbers and revenue fall within the obligation, so it is the right order to first check whether your own institution is subject to it, not just the solution vendor. The relationship between ISO 27001 and digital badge security is covered in more detail in a separate article.

For personal data, separate it into the consignment agreement, the amended law, and the storage location

A digital badge SaaS is a structure in which an institution entrusts the personal data of its recipients to an outside party. So the starting point for verification is not the service’s features but Article 26 of the Personal Information Protection Act (restrictions on the processing of personal information under consignment of work). Adding the requirements of the amendment taking effect in September 2026 and the data storage location completes the review of the personal data items.

Article 26 of the Personal Information Protection Act requires that, when consigning, the purpose and scope of processing, restrictions on sub-consignment, safety measures, and the supervision of the consignee be set out in a document, and that the fact of consignment be disclosed in the privacy policy. In a contract review, check whether the consignment document specifies the items processed and the retention period, whether there is a prior consent clause where sub-processors are used, and whether records of consignee training and inspections can be obtained.

Article 31 of the Network Act, frequently cited in past adoption guides, is not used as a basis. As the personal data provisions of the Network Act were transferred to the Personal Information Protection Act under the Data 3 Acts amendment, it was deleted on 4 February 2020. That said, Article 50 of the Network Act, which covers the transmission of advertising information for marketing purposes, remains in force, so where badge issuance notifications and marketing sends are handled through the same channel, consent needs to be separated.

Check whether the contract reflects the amendment effective 11 September 2026

The amended Personal Information Protection Act was promulgated on 10 March 2026 and takes effect on 11 September of the same year. The breach notification obligation moves earlier, from the point a breach is confirmed to the point a breach is possible, and the content of the notification must include remedies and dispute resolution procedures. The ceiling on administrative fines rises from 3% to 10% of revenue, with repeat violations within three years and failure to comply with corrective orders among the conditions for application. Mandatory ISMS-P certification for large-scale personal information controllers begins on 1 July 2027.

What changes in practice for an institution is the incident notification clause in the contract. Unless it is set out that the vendor must inform the institution within a given number of hours of becoming aware of a breach, the institution will struggle to meet the notification deadline under the amended law. Check three things in the contract: the notification deadline, the duty to cooperate, and the scope of liability.

A timeline of changes to personal data regulations - the end of the ISO 27001 transition in October 2025, the amended law taking effect in September 2026, and mandatory ISMS-P certification and the cloud certification transition in July 2027

Verify the data storage location and cross-border transfers

Get the server location and whether data is transferred abroad in writing before contracting. Where personal data is transferred outside the country, the requirements under Article 28-8 of the Personal Information Protection Act must be met, and the Personal Information Protection Commission signaled in its 2026 work plan that management of cross-border transfers would be strengthened, including the introduction of standard contractual clauses and binding corporate rules. If you are considering an overseas platform, this item becomes a condition to verify ahead of anything you would check for a Korean provider.

For public institutions, look at the procurement route and the certification transition plan

Public institutions settle the contracting route first, separately from the feature review. Using the specialized contracting system for digital services, introduced in October 2020, cloud services can be contracted through a negotiated contract or a catalog contract. Because the structure is one of contracting for services selected by a Ministry of Science and ICT review committee through the Public Procurement Service’s digital service mall, the first verification item is whether the service is on that list.

Cloud security certification has entered a transitional phase. On 20 April 2026, the Ministry of Science and ICT and the National Intelligence Service announced that the structure - split between CSAP and National Intelligence Service verification - would be unified into a single National Intelligence Service verification system. Administrative, physical, and technical safeguard items will be consolidated into ISMS, and public-sector-specific requirements will move to a newly established National Intelligence Service cloud security verification. It takes effect in July 2027, and existing CSAP certifications obtained before then are recognized for their validity period.

For this reason, it is more accurate for the certification question in a public institution’s checklist to be asked in three parts: whether CSAP certification is currently held and at what grade, the certificate expiry date, and the plan for handling the transition after July 2027.

Items that are not in the contract but determine operational workload

Once the standards and security questions are passed, the remaining differences come down to post-issuance operations. Most platforms provide the ability to create a badge, but the process of issuing to several hundred people in a cohort, reissuing for errors, and turning verification page views into performance reporting is structured differently from product to product. This is what actually determines your staff’s working hours.

Verifying the following four in a live demo at the review stage gives you a sense of the workload after adoption.

  1. Bulk issuance - how many steps from roster upload to send, and how error cases are displayed
  2. Reissuance and revocation - the reissuance procedure and handling of the existing badge when a name is misspelled or a program changes
  3. Verification page - how the screens seen by the recipient and by a third party each appear, and whether co-issuing organizations are shown
  4. Aggregation - whether issuance, view, and share data comes out in report form, and whether it can be exported

Kolleges places post-issuance usage and aggregation among these as its operational axis. That said, priorities differ by institution, so an institution that urgently needs bulk issuance automation and one that urgently needs performance reporting will evaluate the same product differently. When requesting a demo, it helps your judgment to give the actual roster size and number of programs at your institution and receive the demo under those conditions.

Summary: the seven things to verify before contracting

All seven items below are things confirmed through a document or a screen, not a proposal. Requesting the materials from the vendor ahead of the review meeting lets you reach a decision within the meeting itself.

#Verification itemHow to verify
1The version and role combination of 1EdTech certificationLook up the certification date, roles, and status directly in the 1EdTech official directory
2A valid ISO/IEC 27001:2022 certificateCheck the edition number, scope of certification, and expiry date on the copy of the certificate
3Personal data processing consignment agreement (Article 26)The items processed, sub-consignment clauses, and supervision records in the consignment document
4Clauses responding to the September 2026 amendmentThe incident notification deadline, duty to cooperate, and scope of liability in the contract
5Data storage location and cross-border transferDocumentation of server location, and whether Article 28-8 requirements are met for transfers abroad
6(Public) Procurement route and certification transition planWhether listed on the digital services list, the CSAP grade and expiry date, and the 2027 transition plan
7Post-issuance operationsA live demo of bulk issuance, reissuance, the verification page, and aggregation

A summary checklist presenting the seven items to verify before contracting as cards

Of the seven items, 1 through 5 apply the same way to any institution, 6 applies only to public institutions, and the weight of 7 varies with an institution’s issuance volume. If annual issuance is in the tens, item 7 does not carry much weight, but in a structure where several departments each issue hundreds, the final decision often comes down to item 7 after items 1 through 6 have been passed.

Certification and statutory requirements keep changing. The content of this article is as of August 2026, and at the time of contracting it is accurate to check the 1EdTech directory, the original certificates, and the statutory provisions in force again.

Frequently asked questions

Verify standards certification and security certification not by whether they are held, but by their detailed conditions. For 1EdTech Open Badges certification, look at the combination of version (2.0 / 2.1 / 3.0) and role (Issuer, Displayer, Host); for ISO/IEC 27001, check whether the edition number is the 2022 version and when it expires. Adding the personal data processing consignment agreement and data storage location to that gives you the basic frame of a contract review.
No. As of August 2026, many major Korean platforms hold Open Badges 3.0 certification in the official 1EdTech directory, so holding the certification itself does not distinguish much. Even within 3.0, a provider certified for the Issuer role alone and one certified across all three roles - Issuer, Displayer, and Host - differ in external wallet integration and the scope of badge display.
First look at whether the standard is written as ISO/IEC 27001:2022. Under IAF MD 26 Issue 2, a mandatory document of the International Accreditation Forum (IAF), certifications based on the 2013 edition expired or were withdrawn when the transition period ended on 31 October 2025. On the copy of the certificate, check three things: the edition number, the scope of certification, and whether the expiry date covers the contract period.
Under Article 26 of the Personal Information Protection Act, the purpose and scope of processing, restrictions on sub-consignment, safety measures, and the supervision of the consignee must be set out in a document. The fact of consignment is disclosed in the privacy policy. Article 31 of the Network Act, which adoption guides used to cite frequently, was deleted on 4 February 2020 and is no longer a legal basis.
Breach response requirements get stricter. The notification obligation moves earlier, from the point a breach is confirmed to the point a breach is possible, and notifications must include remedies and dispute resolution procedures. The ceiling on administrative fines also rises from 3% to 10% of revenue. It is safer to revisit the incident notification deadline and scope of liability in your contract against this standard.
Under the specialized contracting system for digital services, a negotiated contract or catalog contract can be concluded. Introduced in October 2020, the system lets institutions contract for services selected by a Ministry of Science and ICT review committee through the Public Procurement Service's digital service mall. Cloud security certification is scheduled to move to a single National Intelligence Service verification system in July 2027, so check the certification grade and expiry date together.

Want to turn learning outcomes into verifiable assets?

From issuing to verifying and amplifying, see it for yourself with Kolleges.

Request a Kolleges demo
A
Amy Kim
Education Innovation Team
From the fundamentals of digital badges to adoption guides and education trends, I share insights you can put to work right away.
More from this author