Key takeaways
- Japan is creating a government-backed security rating for companies in supply chains, known as the SCS evaluation system (SCS評価制度). It is designed by the Ministry of Economy, Trade and Industry (METI) and the National Cybersecurity Office (NCO), and run by IPA, the Information-technology Promotion Agency.
- Companies can earn a ★3 mark through a self-assessment checked by a registered expert, or a ★4 mark through a third-party assessment that includes on-site review and vulnerability testing of internet-facing devices such as VPNs.
- Applications open in March 2027. Assessment guides are due in late October 2026, and the first assessment bodies are due to be named in late December.
- The system is voluntary, and built for buyers to ask suppliers for it. The government is considering referring to it in public procurement. Whether private companies will require it from their suppliers remains to be seen.
- Our view: The mark is unlikely to replace the security checklists it was created to eliminate, and risks becoming another formality like ISMS and the Privacy Mark, under which incidents keep happening at certified companies. Vendors are already presenting it as an opportunity to sell security products. As things stand, the likely result is more work for suppliers without more security.
What the system is for#
Japanese companies have repeatedly had operations disrupted or data exposed through attacks on their suppliers and contractors. The government's policy document names two problems:
- Buyers cannot easily see how well their suppliers are protected, and cannot be sure their own security checklists ask the right questions.
- Suppliers, especially small ones, receive different checklists from every customer, which is a heavy and duplicated burden.
The SCS system is meant to replace those one-off checklists with one common standard. A buyer tells a direct supplier which level it needs, ★3 or ★4, and checks whether the supplier holds it. The policy says the marks show that a company met the standard at the time of assessment. They are not a guarantee against incidents, and not a ranking for companies to compete on.
The star levels#
The numbering continues from SECURITY ACTION, IPA's existing self-declaration program for small businesses, which covers ★1 and ★2.
| ★3 | ★4 | ★5 | |
|---|---|---|---|
| Aimed at | The minimum every supplier should have | The standard target for suppliers that matter to a buyer's operations or hold its sensitive data | Advanced, risk-based security |
| Threats in mind | Common attacks exploiting widely known vulnerabilities | Attacks on companies whose disruption or data loss would badly affect the supply chain | Advanced attacks, including unknown ones |
| Requirements | 26 | 43 | Under discussion |
| Assessment | Self-assessment, checked and signed by a registered expert, plus a declaration by management | Third-party assessment: document review, on-site (or remote) review and technical verification | Third-party (planned) |
| Valid for | 1 year | 3 years, with an annual self-assessment | Not yet set |
| Benchmarks | Japan's auto industry guideline Level 1, UK Cyber Essentials | Auto industry guideline Level 2, sector guidelines | ISO/IEC 27001, auto industry guideline Level 3 |
A company does not need ★3 before applying for ★4. To pass either level, it must meet all of the criteria for that level.
What the requirements cover#
The requirements are grouped into seven categories. Six follow the functions of the NIST Cybersecurity Framework, and a seventh covers managing suppliers:
- Governance: a named security lead, a security policy, and at ★4, regular reporting to management
- Supplier management: clear rules for handling other companies' confidential data, and at ★4, checking the security of important suppliers at least once a year
- Identify: knowing your IT assets, networks and cloud services, and at ★4, a vulnerability management process
- Protect: account and password management, separating internal and external networks, timely patching, malware protection, and at ★4, encryption of important data, log analysis and blocking suspicious outbound traffic
- Detect: network monitoring, and at ★4, monitoring the behavior of devices
- Respond: a written incident response procedure
- Recover: recovery arrangements, and at ★4, procedures that meet set recovery point and recovery time targets
What is in scope#
The system covers a company's whole IT infrastructure, not just its perimeter:
- Servers that support the business as a whole, including internal ones. Internet-facing servers, such as web and mail servers, must always be included.
- Endpoints: PCs, smartphones and other devices people use
- Cloud services and shared networks, such as a group-wide network run by a parent company. The company must either secure these itself or check the provider's measures, for example through Japan's ISMAP government cloud registry or a SOC 2 report.
- The network devices that mark the edge of the scope, such as firewalls, routers and VPN devices, including those that connect to other organizations' systems
A company can set its own scope, for example its offices in Japan, but must keep traffic between systems inside and outside the scope to the minimum necessary.
Factory control systems (OT) and the products a company sells to its customers are out of scope. The policy says these call for different measures, to be handled under other programs and guidelines. IoT products, for example, have their own security labeling scheme in Japan, JC-STAR.
How assessment works#
★3: The company fills in a self-assessment against the ★3 criteria. A registered SCS security expert, from inside or outside the company, reviews it, advises on corrections and signs it. Management declares that the company conforms, and the company submits the result to IPA.
★4: The company fills in a self-assessment, then hires a designated assessment body. The assessor reviews documents, conducts an on-site or remote review, and runs a technical verification, a vulnerability test of internet-facing devices that could let an attacker into the network, such as VPN devices and routers. The technical test is limited to those internet-facing devices. The rest of the requirements, such as internal network separation, log analysis and endpoint protection, are checked through the document and on-site reviews. Problems found can be fixed within a set period, for example a month, and the company then applies to IPA.
Registered experts must hold one of these qualifications and complete training: Registered Information Security Specialist (情報処理安全確保支援士, Japan's national security qualification), Certified Information Security Auditor (Japan), CISSP, CISA, CISM, or ISO/IEC 27001 lead auditor.
Companies that earn a mark will be listed in a public registry with their name, address, the scope of the assessment and, for ★4, the assessment body.
Timeline#
| Date | Milestone |
|---|---|
| March 27, 2026 | METI and the NCO publish the policy for building the system |
| April 21, 2026 | IPA launches the SCS website, with ★3 and ★4 requirements and criteria |
| September 18 – October 26, 2026 | IPA accepts applications from would-be assessment bodies, technical verifiers and training providers |
| Late October 2026 | Assessment guides and an explanatory handbook are due |
| Late December 2026 | First assessment bodies are designated and published |
| January 2027 | Expert training begins, experts start registering, and the SCS online system goes live |
| February 2027 | ★4 assessments can begin |
| March 2027 | IPA starts accepting ★3 and ★4 applications |
IPA says the schedule may be revised if preparations fall behind. It also says English versions of the system documents and the requirements will be published before launch.
What it costs#
IPA's registration fees, announced on September 18, are low:
| Until March 31, 2028 | From April 1, 2028 | |
|---|---|---|
| ★3 registration | ¥10,000 per year | ¥20,000 per year |
| ★4 registration | ¥60,000 for 3 years | ¥60,000 for 3 years |
| SCS security expert registration | Free |
These are only IPA's fees. The real cost is in meeting the requirements, paying an outside expert for ★3 if there is none in-house, and paying an assessment body for ★4. Those fees are set by the market, not by IPA.
Our analysis#
Voluntary, but who will ask for it?#
The system is voluntary, and METI stresses it. But it is designed around buyers asking suppliers for a mark, so whether a supplier gets one will often be decided by its customers.
The most likely first demand is from the public sector. The policy says the government will consider referring to the marks in government procurement and recommending them to critical infrastructure operators. Nothing has been decided yet.
Whether private companies will require the marks from their suppliers is less clear. That depends on large buyers deciding to write ★3 or ★4 into their supplier requirements. Some already have their own yardsticks: automakers, for example, ask suppliers to assess themselves against the auto industry's guideline. It is too early to tell, and worth watching once applications open in 2027.
The checklists will not go away#
The problem the system was built to solve is the security checklist. Every buyer writes its own questionnaire for suppliers, and every supplier answers dozens of them. Both sides find it a heavy burden. A common mark was supposed to replace them.
We do not expect that to happen. A ★3 or ★4 mark shows that a supplier met a common baseline at the time of assessment. It does not show that the supplier meets what a particular buyer needs: how it handles that buyer's data, what its contract requires, or what the buyer's own industry guidelines demand. The system covers IT infrastructure, not everything that can go wrong at a supplier. The misdirected Sompo Japan data at TOPPAN this week came from a manual file-handling error, which no questions about firewalls and patching would have caught.
Existing certificates show why. In a 2024 interview published by JIPDEC, the Times Car operator said that even as a Privacy Mark holder, corporate customers often still ask it to fill in a checklist on how it handles personal data before signing up. The policy itself expects buyers to go further. It suggests they may ask for ★4 where ★3 falls short, or add their own measures on top of the requirements. It also suggests using the ★3 and ★4 criteria as a checklist for suppliers that do not hold a mark yet. And at the March working group meeting, one vendor said it was considering a feature to answer check sheets automatically, a sign that the industry expects the questionnaires to stay.
The most likely outcome is that checklists get a new first question, "Do you hold ★3 or ★4?", followed by the buyer's own questions as before. If that happens, suppliers will carry the cost of the mark and the checklists, and the burden the system was meant to reduce will grow. The system will only deliver on its purpose if buyers commit to accepting the mark in place of the questions it already covers, and ask only about what it does not.
Another certificate on the pile#
Japanese suppliers already live with several overlapping schemes. Many hold ISMS certification or the Privacy Mark. Small businesses can declare ★1 or ★2 under IPA's SECURITY ACTION. Auto parts makers assess themselves against the auto industry's own cybersecurity guideline, published by the Japan Automobile Manufacturers Association (JAMA) and the Japan Auto Parts Industries Association (JAPIA). There are separate schemes for protecting technical information (TICS) and for IoT products (JC-STAR).
On paper, the government has placed SCS among them. The policy calls it complementary to ISMS and the other schemes, and says ★3 and ★4 correspond to Levels 1 and 2 of the auto industry guideline. In practice, little is settled. Coordination with the auto industry is "still under consideration". Mutual recognition with UK Cyber Essentials is still being studied. At the March working group meeting, members raised the proliferation of schemes and "evaluation fatigue". Officials replied that SCS is a common baseline that does not overlap with other schemes, and said mapping it against them would be considered next fiscal year.
From a supplier's side, it does overlap. An auto parts maker that already holds ISMS and completes the auto industry self-assessment could be asked for ★4 as well, and nothing yet says that one counts toward the other. Until the schemes recognize each other, SCS does not replace any of them. It adds one more certificate to maintain, with its own assessments, renewal cycle and fees.
The ★4 test: the right target, checked once#
The most concrete part of ★4 is the technical verification: a vulnerability test of internet-facing devices that would put the internal network at risk if exploited, such as VPN devices and routers. The target is right. Over the past five years, VPN devices were the entry point in about 60% of Japanese ransomware cases where the victim could say how attackers got in. See our overview of ransomware in Japan.
But a single test for a certificate says little about how well those devices are protected. New vulnerabilities in VPN and other edge devices are disclosed all the time, and some are exploited soon after. A device that passes a test on the day of assessment can be exposed by an advisory published the following month. ★4 has a full third-party assessment once every three years, and the policy is considering accepting a recent vulnerability test report in place of the test itself.
What protects these devices is not the test but the routine behind it: knowing which devices are exposed, following vendor advisories, patching quickly, and replacing equipment that is no longer supported. ★4 does include requirements for vulnerability management and timely updates, but those are checked on paper. Buyers who want to know whether a supplier's VPN is safe should ask how it handled the last critical advisory, not whether it passed a test.
Will it go the way of ISMS and the Privacy Mark?#
Japan is a country of certificates. 8,701 organizations are registered for ISMS certification (ISO/IEC 27001) with Japan's accreditation body, ISMS-AC, and 17,695 companies hold the Privacy Mark (Pマーク), a Japanese certification for handling personal data. Many got them because customers, especially in outsourcing and public procurement, asked for them.
Yet incidents keep happening at certified companies. In fiscal 2025, 2,021 Privacy Mark holders reported 10,633 incidents to JIPDEC, which runs the scheme. Most were misdelivered mail and misdirected email, but 848 involved unauthorized access. The operator of Times Car, whose customers lost 1.6 million identity documents in September, has held the Privacy Mark since 2021.
In many organizations, the certificate has become something to maintain for customers rather than a way of running security: documents are updated for the annual audit, and little changes in practice. The Japanese word for this is 形骸化 (keigaika), when a rule survives only as an empty shell.
We expect the same risk with the SCS marks, and some of it is built into the design:
- ★3 is a self-assessment. Its value depends on the registered expert who signs it, and that expert can be an employee of the company being assessed.
- Assessments are snapshots. ★3 is checked once a year. ★4 has a full third-party assessment only once every three years, with self-assessments in between.
- On-site review is sampled. At the September committee meeting, a member warned that assessors may drift toward items that are easy to check, and proposed a list of items that must always be reviewed, updated every year.
- Even the technical test may become paperwork. The policy says a company may be allowed to submit the results of a recent vulnerability test instead, a point still under consideration.
- An incident does not cost a company its mark. The policy provides for suspending or withdrawing a mark over false statements or concealment, for example uncovered through whistleblowing. Being breached is not in itself a reason.
The government says SCS is different. ISMS certifies that a company runs a management system and leaves the choice of controls to each company, while SCS sets common measures for everyone.
Read the criteria, though, and the difference is smaller than it sounds. By our count, about two-thirds of the 153 evaluation criteria for ★3 and ★4 ask whether a rule, procedure, role, inventory or record exists, whether it has been communicated to staff, or whether it is reviewed once a year. There are some concrete technical requirements: multi-factor authentication for cloud services that hold important confidential data, installing critical and high-risk security updates within 14 days of release, and no vulnerabilities rated CVSS 7.0 or higher in the firmware of internet-facing network devices. But most of what an assessor checks is whether processes exist, which is much of what ISMS audits already look at. The ★4 technical test is the main exception, and it is a one-off snapshot.
Whether that difference survives depends mostly on buyers. If a buyer treats the registry as a box to tick, the mark will be maintained as one. If it treats the mark as a starting point, and still asks how the supplier patched its VPN last month, the system could avoid the fate of its predecessors. Buyers deciding between ★3 and ★4 should also keep the basic difference in mind: ★3 is checked, ★4 is tested.
Warning against the sales pitch, after hearing one#
Vendors, meanwhile, are not waiting to see who will ask for the marks. In April, METI and the NCO said they had received reports of sales pitches for products and services that used the system as a selling point, telling companies that their business dealings would be restricted without a rating, or that they would be "excluded from bids unless they get rated right away". The two issued a public warning that such pitches run against the purpose of the system: it is voluntary, it does not regulate business between companies, and no specific security product is needed to meet the criteria.
The warning does not settle the question of public bids. The system has not started, so no one can be excluded from anything because of it yet. But the same policy says the government will consider referring to the marks in government procurement. If it does, a rating could eventually matter for public-sector work. That open question is exactly what the sales pitches play on.
Seven weeks before that warning, on March 4, the METI sub-working group designing the system invited two companies to present, as "information provision" (情報提供). According to the published minutes and slides:
- SecureNavi, whose cloud service it says is used by about a third of organizations newly getting ISMS certification, presented StarQuest, a service for getting and maintaining ★ marks. It said the price for small businesses would be around ¥30,000 a month, a level it judged affordable based on its experience in the ISMS and Privacy Mark business. It said it would sell the service through security vendors as a way to win small businesses' trust and expand business opportunities, and was working with Ricoh Japan on showing Ricoh Japan products to users inside the service to help sell security products. One slide describes partners being able to see each company's progress and make sales proposals at the right time. It also presented a version for experts and assessment bodies, aimed at cutting assessment work to a tenth.
- NTT Data presented a plan, timed to the system's launch, in which regional banks would refer their business customers to NTT Data for ★ support, outsourced IT and managed security services.
It is normal for a government working group to hear from industry, the materials are public, and tools that cut paperwork may well help small companies. But the record shows the system being presented, in front of the officials designing it, as an opportunity to sell security products, weeks before the same officials warned the public against sales pitches built on it. It also shows the same software being offered both to the companies being assessed and to the people assessing them.
The policy says a single organization may provide ★4 assessments and other support, such as consulting and products, with requirements on neutrality and fairness "to be detailed". At the September committee meeting, members asked IPA to state clearly that assessors may give only general information when a company fails a criterion, and may not decide or carry out the fix for it, paid or unpaid, or require particular products. Given who is already lining up, those requirements will matter as much as the security criteria. It is also a reminder of where the ISMS and Privacy Mark business went: a large market for getting and keeping certificates, not necessarily for improving security.
Who pays#
Small suppliers carry the cost, and the benefit goes largely to their customers. METI and the Japan Fair Trade Commission have published guidance saying buyers that request security measures should respond positively to price negotiations over the cost. Whether that happens in practice will decide whether the system raises the level of the supply chain or just pushes costs down it.
Our view: more work, not more security#
Put together, the picture is not encouraging. The checklists the system was meant to replace are likely to stay. The marks risk being maintained for customers, as ISMS and the Privacy Mark often are, rather than changing how companies defend themselves. Suppliers will pay for the mark on top of the certificates and checklists they already maintain. And vendors were presenting the system as an opportunity to sell security products before the rules were even final.
If that is how it plays out, the result will be more work for suppliers, more business for vendors, and little change in how secure Japan's supply chains actually are.
The system has not started yet, and parts of it could prove us wrong. Assessments that check how suppliers manage vulnerabilities between tests, not just on test day, buyers who drop the questions the mark already covers, and neutrality rules that keep assessors from selling to the companies they assess would all make a difference. Those are the things to watch when applications open in March 2027.
What this means for foreign companies#
- If you supply Japanese companies, including through a Japanese subsidiary, customers may start asking about ★3 or ★4 from 2027, especially in the public sector and critical infrastructure. Be skeptical of anyone who says you must have one now. The policy is written for all companies in a supply chain, and a company can set the scope of its assessment, for example to its offices in Japan.
- If you hold UK Cyber Essentials, it is one of the benchmarks for ★3, and the Japanese government is studying mutual recognition. Nothing has been agreed.
- If you sell security services, IPA's designation for assessment bodies, technical verifiers and training providers is open until October 26, 2026. The next round is planned for the first half of fiscal 2027.
- If you are a buyer, the ★3 and ★4 requirements are already public. Consider which of your own questionnaire items they already cover, and drop those for suppliers that hold a mark.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| サプライチェーン強化に向けたセキュリティ対策評価制度 | sapurai chēn kyōka ni muketa sekyuriti taisaku hyōka seido | Security measures evaluation system for strengthening supply chains (SCS) |
| SCS評価制度 | esu-shī-esu hyōka seido | The SCS evaluation system |
| 専門家確認付き自己評価 | senmonka kakunin-tsuki jiko hyōka | Self-assessment checked by an expert (★3) |
| 第三者評価 | daisansha hyōka | Third-party assessment (★4) |
| 技術検証 | gijutsu kenshō | Technical verification (vulnerability testing, ★4) |
| 評価機関 | hyōka kikan | Assessment body |
| 形骸化 | keigaika | Becoming an empty formality |
| プライバシーマーク(Pマーク) | puraibashī māku (pī māku) | Privacy Mark, a Japanese certification for personal data handling |
| 情報処理安全確保支援士 | jōhō shori anzen kakuho shienshi | Registered Information Security Specialist |
| 国家サイバー統括室 | kokka saibā tōkatsu-shitsu | National Cybersecurity Office (NCO) |
The NCO also oversees Japan's new Active Cyber Defense law, whose main provisions take effect on October 1, 2026. We will update this article when IPA publishes the assessment guides and the first assessment bodies.