Key takeaways

  • From October 1, 2026, companies designated as critical infrastructure operators in 15 sectors must notify the government when they introduce key computer systems and report cyber incidents affecting those systems "promptly".
  • The same day, police gain a legal power to access and neutralize computers used in attacks, for example by deleting malicious data from them over the network. The SDF can be ordered to act against highly organized attacks from abroad. Police action normally needs prior approval from an independent oversight commission.
  • Japanese media often describe the law as a way to "counterattack" (反撃) hackers. That framing is misleading. The law is mostly about reporting, information sharing and removing malicious code from compromised machines, not about attacking back.
  • The government's analysis of cross-border internet traffic, the most privacy-sensitive part, comes later, by November 2027 at the latest.
  • Foreign companies are affected as Japanese subsidiaries of designated operators, as vendors whose products run in covered systems, and as managed security providers whose Japanese customers now face a reporting clock.

What the law is#

The law is widely called Japan's "Active Cyber Defense" law (能動的サイバー防御). Japanese media usually call it the サイバー対処能力強化法. Japan's National Cybersecurity Office calls it the "Cybersecurity Capability Enhancement Act" in English. Its formal title is 重要電子計算機に対する不正な行為による被害の防止に関する法律, roughly the Act on the Prevention of Damage Caused by Unauthorized Acts Against Critical Computers (Act No. 42 of 2025, promulgated May 23, 2025).

A companion act, passed together with it, amends 15 other laws. The most important amendments are to the Police Duties Execution Act and the Self-Defense Forces Act. They give the police and the SDF the power to act against attack infrastructure.

Taken together, the package does five things:

  1. It creates a mandatory incident reporting system for designated critical infrastructure operators.
  2. It lets the government share analyzed threat information with agencies, operators, vendors and foreign partners, and sets up a public–private council.
  3. It allows police access and neutralization measures against computers used in attacks, and SDF communications protection measures against highly organized attacks from abroad.
  4. It allows the government to acquire and analyze communications data, mainly traffic crossing Japan's borders.
  5. It creates an independent oversight commission to approve and inspect the use of these powers.

Items 1 to 3 take effect on October 1, 2026. The commission was set up earlier, and item 4 comes later.

How the law is being read in Japan#

Ask people in Japan what "active cyber defense" means and many will say it lets the government hack back at attackers. That impression comes largely from how the law has been covered. Headlines and commentary have repeatedly described it in terms of 反撃 ("counterattack"). Critics on the left have gone further and called it a pretext for preemptive attacks. Supporters have also used the counterattack language, as shorthand for Japan finally being able to act.

Working in security in Japan, we think both readings miss what the law actually contains:

  • Most of the law is about reporting and information sharing. The provisions that will affect the most organizations are the notification and reporting duties for critical infrastructure. They look more like the incident reporting rules the US and the EU already have than like offensive cyber operations.
  • The "neutralization" power is narrow and defensive in design. The police provision is triggered by an urgent risk of serious harm. It allows measures that are "normally necessary to prevent harm", such as deleting malicious data from a computer being used in an attack, or ordering the machine's administrator to do so. It is not a mandate to disrupt attackers' operations in general.
  • Many of the machines involved will be victims, not attackers. Much attack traffic comes from compromised routers, cameras and servers belonging to ordinary people and companies. In practice, "neutralizing" an attack computer will often mean cleaning up someone else's infected device.

This matters beyond semantics. If the public believes the law is about striking back, the debate becomes about escalation risk. It then misses the questions that will decide whether the law works: whether operators report quickly and honestly, whether the government shares useful information back, and whether the police use their new powers against the right targets.

Why Japan passed it#

Japan's 2022 National Security Strategy committed the government to introduce "active cyber defense" and bring its capabilities up to the level of major Western countries. Until now, Japan had no general legal duty for critical infrastructure operators to report cyber incidents to a central authority. The government also had limited legal room to act against attack infrastructure before damage occurred, partly because of the constitutional protection of the secrecy of communications.

High-profile incidents added pressure. One example is the 2023 ransomware attack that halted container operations at the Port of Nagoya, which later led the government to add port operations to its critical infrastructure regime.

The rollout, step by step#

The dates below come from the official revision history of the laws on e-Gov.

Date What took effect
May 23, 2025 Law and companion act promulgated
July 1, 2025 General provisions, including the basis for a government basic policy. NISC reorganized into the National Cybersecurity Office (NCO), headed by a National Cyber Director
December 23, 2025 Cabinet approves the basic policy under the law
April 1, 2026 Provisions establishing the Cyber Communications Information Oversight Commission (サイバー通信情報監理委員会)
October 1, 2026 Main provisions: system notification and incident reporting, information sharing, public–private council. Police access and neutralization (Police Duties Execution Act Art. 6-2) and SDF communications protection (SDF Act Art. 81-3)
By November 22, 2027 Communications-data acquisition and handling, and the commission's inspection powers. The exact date is to be set by cabinet order

Who has to comply#

The reporting duties apply to special social infrastructure operators (特別社会基盤事業者). In practice, these are companies that:

  1. Have already been designated under Japan's Economic Security Promotion Act as operators of critical infrastructure services (特定社会基盤事業者), and
  2. Use computers that could, if compromised, stop or degrade the critical equipment that designation covers. The law calls these specified critical computers (特定重要電子計算機).

The Economic Security Promotion Act covers 15 sectors:

Energy and utilities Transport Communications Finance
Electricity Railways Telecommunications Banking and finance
Gas Trucking Broadcasting Credit cards
Oil International shipping Postal services
Water Aviation
Airports
Port operations

Designation is by name: each ministry lists the specific companies it has designated. A company in one of these sectors is not covered unless it has been designated.

The implementing order defines "specified critical computers" in technical terms. They include computers that send data directly to the critical equipment, the routers and firewalls immediately in front of those systems, and systems that store data or programs for them. The scope goes beyond the core control system to its nearby network perimeter.

Obligation 1: Tell the government what you run#

When an operator introduces a specified critical computer, it must notify the minister responsible for its sector. The notice includes the product name, the manufacturer and other details. Under the implementing order, the deadline is four months from introduction. The notice covers appliance hardware, and the operating system, middleware and applications running on other covered computers. Changes must be notified within four months as well.

The minister passes the information on to the Prime Minister, which in practice means the NCO. As a result, the government will build a picture of which products are running in Japan's most critical systems. When a vulnerability is disclosed in a specific product, the government will be able to tell which operators are exposed.

Obligation 2: Report incidents promptly#

Operators must report to both the sector minister and the Prime Minister when they become aware of a "specified infringement event" (特定侵害事象) affecting a specified critical computer. They must also report certain events that could lead to one.

Timing. The implementing order requires reports to be made "promptly" (速やかに) after the operator becomes aware of the event. It does not set a fixed number of hours. The initial report only needs to include what the operator knows at that point, so operators are expected to report early and update later.

What must be reported. For the most critical systems, the reportable events include:

  • Receipt of malware or other malicious instructions
  • Logins using someone else's credentials
  • Bypassing access controls
  • Theft of credentials for later unauthorized access
  • Traces of any of the above found in logs

The report covers seven categories: the type of report, an overview of the operator, an overview of the event, the affected computers, technical details, the response, and other notes.

There are limited carve-outs, including events within six months of an operator's initial designation for the newly covered systems.

Enforcement. A minister can order an operator that fails to notify or report to do so, or to correct its report. Violating such an order carries a fine of up to ¥2 million. Failing to respond to a ministry's request for information, or giving false information, carries a fine of up to ¥300,000. Both penalties can apply to the company as well as to the individual responsible.

What the government gives back#

The law lets the Prime Minister, through the NCO, analyze reports and other information and share the results with:

  • Government agencies, including the police and the Ministry of Defense
  • Designated operators, through their sector ministries
  • Anyone using critical computers, through public alerts
  • Vendors of affected products, including vulnerability information
  • Foreign governments and international organizations that protect the information to an equivalent standard

A public–private council provides a standing channel for this exchange.

Police and SDF: the "neutralization" powers#

Police. The National Police Agency designates specially qualified officers as cyber harm prevention officers (サイバー危害防止措置執行官). When they find traffic or data used in an attack, and leaving it alone would risk serious harm to life, body or property, they can:

  • Order the administrator of the computer involved to take measures, or
  • Take those measures themselves over the network. Examples include deleting malicious data, and connecting to the computer to check its records as far as necessary.

The safeguards are built into the article:

  • Prior approval from the Cyber Communications Information Oversight Commission is required. The exception is when an attack causing serious damage to critical computers is already under way, or there is otherwise no time. In that case the police must notify the commission promptly afterward, and the commission can review the action and issue recommendations.
  • If there is no good reason to believe the computer is in Japan, only National Police Agency officers can act, and they must consult the Minister for Foreign Affairs in advance.
  • Officers must not unduly obstruct legitimate business. They must also notify the computer's administrator afterward, unless doing so would undermine the response or the administrator cannot be found.

SDF. The Prime Minister can order SDF units to take communications protection measures (通信防護措置) against attacks on critical computers. These must be attacks by actors outside Japan that are particularly highly organized and planned. Three further conditions apply: serious disruption must be likely, the SDF's special technology or information must be indispensable, and the National Public Safety Commission must request or consent. SDF units carry out these measures jointly with the police.

What it means for foreign companies#

If your Japanese subsidiary is a designated operator, the reporting clock starts when the subsidiary becomes aware of an event. Group-level security operations centers and incident response processes may need a Japan-specific path. This matters when detection happens outside Japan, so that the subsidiary can report "promptly" in Japanese to two authorities.

If you provide managed security, SOC or cloud services to a Japanese operator, expect your customer to ask for notification commitments beyond your standard SLA. The operator can only report promptly if its providers tell it promptly. Standard contracts often give providers hours or days to notify customers, and often only for confirmed incidents. Japanese customers may now ask for:

  • Near-immediate notice of suspicious events, including traces found in logs
  • Evidence that supports the government report
  • Japanese-language communication

Overseas MSS providers without a Japan-based incident desk should prepare for these requests. (This is our assessment, not a requirement in the law itself.)

If you sell technology used in Japanese critical infrastructure, Article 42 is the provision to read. Ministers who learn of a vulnerability in a product used in covered systems can:

  • Share information with the vendor
  • Publicize the vulnerability and how to address it
  • Request that the vendor take measures to prevent damage
  • Ask the vendor for reports and materials, which the vendor must make efforts to provide

The law states that these provisions apply to suppliers located outside Japan that supply products to users in Japan.

Privacy safeguards and criticism#

The most privacy-sensitive part of the package is the government's acquisition of communications data. Critics, including privacy advocates and opposition lawmakers, raised concerns about the secrecy of communications guaranteed by Article 21 of Japan's Constitution.

The government's answer is the Cyber Communications Information Oversight Commission, an independent body established in April 2026. It approves police neutralization measures from October 2026. It will also inspect how communications data is acquired and handled once those provisions take effect, by November 2027 at the latest. How strictly the commission works in practice will be the real test of these safeguards.

Our view: the test is whether Japan can take down botnets#

The most useful thing this law could do is let Japan do what US and European authorities have been doing for years. They have been dismantling botnets by working from the inside, not just arresting operators or seizing domains:

  • Qakbot (2023). The FBI redirected infected computers to servers it controlled and pushed an uninstaller to remove the malware.
  • KV-botnet (2024). The US removed malware from hundreds of small-office routers that a China-linked group had been using to hide its operations.
  • Operation Endgame (2024 onward). Europol coordinated takedowns of the infrastructure behind major malware loaders.

Japan's police have taken part in international operations before. They helped in Operation Cronos against LockBit in 2024 and developed a decryption tool for victims. But inside Japan, the response to infected devices has largely relied on notifying owners and asking them to fix their devices, with limited effect. Large numbers of home routers, network cameras and small-business devices in Japan remain vulnerable and are used as stepping stones for attacks.

The new police power is the first clear legal basis in Japan for removing malicious code from those devices over the network. Whether it gets used that way is an open question. The trigger requires an urgent risk of serious harm, and it is not yet clear how the police and the commission will read that requirement. Botnets are a steady, long-term threat rather than a sudden emergency. We hope to see the first operations under Article 6-2 target this kind of infrastructure, carried out transparently and in coordination with international partners. That would do more to change how the law is understood in Japan than any explanation.

Japanese terms at a glance#

Japanese Reading Our translation
能動的サイバー防御 nōdōteki saibā bōgyo Active cyber defense
サイバー対処能力強化法 saibā taisho nōryoku kyōka-hō Cyber response capability enhancement act (common name)
反撃 hangeki Counterattack (common, misleading media framing)
国家サイバー統括室 kokka saibā tōkatsu-shitsu National Cybersecurity Office (NCO)
特定社会基盤事業者 tokutei shakai kiban jigyōsha Designated critical infrastructure operator (Economic Security Promotion Act)
特別社会基盤事業者 tokubetsu shakai kiban jigyōsha Special social infrastructure operator (operators subject to the new duties)
特定重要電子計算機 tokutei jūyō denshi keisanki Specified critical computer
特定侵害事象 tokutei shingai jishō Specified infringement event (reportable incident)
アクセス・無害化措置 akusesu mugaika sochi Access and neutralization measures
サイバー危害防止措置執行官 saibā kigai bōshi sochi shikkōkan Cyber harm prevention officer
通信防護措置 tsūshin bōgo sochi Communications protection measures (SDF)
サイバー通信情報監理委員会 saibā tsūshin jōhō kanri iinkai Cyber Communications Information Oversight Commission

What to watch next#

  • The first months of reporting. Whether the NCO publishes aggregate statistics, and how "promptly" is interpreted in practice.
  • The first use of police neutralization powers. What they target, whether the commission approved in advance, and how much is disclosed.
  • Contract changes between operators and their IT and security providers. This is especially relevant for foreign providers.
  • The cabinet order for the next phase. It will set the date for the communications-data provisions, no later than November 22, 2027.

We will update this article as implementation proceeds.