Hello, this is Ryuta Hamamoto from TIMEWELL. "We don't export anything, so economic security has nothing to do with us, right?" I still hear this from people in charge at infrastructure companies in electricity, gas, railways, finance, and telecommunications. Yet the framework that has, over the past few years, most quietly and most surely begun to bind corporate procurement is aimed precisely at those infrastructure operators. It is the critical infrastructure prescreening system. Every overseas server, communication device, and maintenance contract must be notified to the government and reviewed before it is introduced. Violations can lead to imprisonment. In fiscal 2025 alone, 1,200 advance notifications piled up.
Let me give you the key points first. Under this framework, critical infrastructure operators designated by the government (designated critical infrastructure operators) must notify the government and undergo review before they introduce important equipment or outsource its maintenance and management. Fifteen sectors are covered at present, and 258 operators had been designated as of July 2026. After notification, there is a review period of 30 days as a rule during which the equipment cannot be introduced or outsourced, and if the risk is judged to be high, recommendations or orders may follow. Introducing equipment without notification, or during the review period, is punishable by imprisonment of up to two years or a fine of up to one million yen. This article organizes everything from the overall picture of the framework to what the notification forces you to disclose and what you should prepare in practice, following primary sources from the Cabinet Office and e-Gov statutes.
If you would first like to gauge where your company stands on how well you understand the capital ties of overseas vendors and contractors and any foreign government involvement, our free export control and business-partner screening check lets you review your current state in about three minutes. As I explain below, this notification is essentially business-partner due diligence in its own right.
What is the critical infrastructure prescreening system?
The formal name of this framework is "the system for ensuring the stable provision of specified critical infrastructure services" (特定社会基盤役務の安定的な提供の確保に関する制度). Because that is a mouthful, government materials abbreviate it as the "critical infrastructure system" or the "critical infrastructure service assurance system." Its legal basis is Chapter 3 of the Economic Security Promotion Act (formally the "Act on the Promotion of Ensuring Security by Taking Economic Measures in an Integrated Manner," Act No. 43 of 2022), specifically Articles 49 through 59. The Economic Security Promotion Act bundles four systems into a single law: strengthening the supply chains of critical materials, ensuring the stable provision of critical infrastructure, supporting the development of advanced critical technologies, and keeping certain patent applications confidential. The critical infrastructure system is the second of these. I have laid out the full map of the law in The Complete Guide to the Economic Security Promotion Act, so please read that alongside this piece.
Why should government review be required just to introduce equipment? Power control systems, telecom switching equipment, core financial systems: much of this equipment now runs on overseas hardware and software. If a device contains a mechanism that allows unauthorized external manipulation, interference from abroad could trigger blackouts, communication failures, or the halting of settlements. The law calls this "an act carried out from outside our country that interferes with the stable provision of infrastructure services" a specified act of interference. The purpose of the framework is to prevent, before introduction, in other words before an incident occurs, any situation in which equipment is used as a means for a specified act of interference. It is prescreening rather than after-the-fact enforcement because there is no undoing the damage once infrastructure has already gone down.
Three terms make the framework easy to follow. The first is specified critical infrastructure services (特定社会基盤役務), meaning the services themselves, such as electricity, telecommunications, and finance, on which people's lives and economic activity depend. The second is specified critical facilities (特定重要設備), meaning the equipment, devices, and programs that are indispensable for providing those services and whose loss of function risks disrupting their stable provision. The target is not ordinary PCs or general office equipment, but facilities that form the core of the service. The third is the specified act of interference described above. In a single sentence, the relationship among the three is this: the framework prevents the critical facilities that support a service from becoming an entry point for external interference.
Who is covered? Fifteen sectors, healthcare, and 258 operators
Covered operators are those, among the sectors the law defines as "specified critical infrastructure businesses," that have received a designation from the government. The law first sets out 15 sectors as the outer boundary, and then Cabinet orders and each ministry's ordinances narrow it down to the range that truly warrants regulation. The 15 sectors currently in force are as follows.
| Sector | Examples of covered businesses |
|---|---|
| Electricity | Electricity business |
| Gas | Gas business |
| Oil | Oil refining, LPG import |
| Water supply | Water supply, bulk water supply |
| Railways | Class 1 railway business |
| Trucking | General trucking |
| Ocean-going cargo | Scheduled and non-scheduled cargo shipping routes |
| Ports | General port transport |
| Aviation | International and domestic scheduled air transport |
| Airports | Establishment and management of airports |
| Telecommunications | Telecommunications business |
| Broadcasting | Core broadcasting |
| Postal services | Postal business |
| Finance | Banking, insurance, securities, trust, funds settlement, etc. |
| Credit cards | Comprehensive credit purchase intermediation under the Installment Sales Act |
An amendment promulgated on June 17, 2026, added the healthcare sector to this list. It is to take effect on a date set by Cabinet order within a period not exceeding one year and six months from the date of promulgation, so as of July 2026 it has not yet taken effect. The accurate way to put it, then, is that 15 sectors are covered right now, and it becomes 16 sectors including healthcare only after enforcement. The same thinking will reach the systems and medical-device supply chains of healthcare providers, widening the scope of impact still further. I plan to track the points at issue toward enforcement of the healthcare sector in a separate article.
Belonging to a covered sector does not mean every operator is designated. Ministerial ordinances set designation criteria such as the number of users or volume of supply, and only operators of a scale that meets those criteria are designated as designated critical infrastructure operators. The initial designation began on November 16, 2023, with 210 operators, and after subsequent increases and decreases, Cabinet Office materials show 258 operators as of July 1, 2026. This figure moves as the framework is applied, so when reading articles or materials, always check the point in time to which a number refers. Once designated, an operator bears the obligation to pass the prescreening described below each time it introduces or outsources a specified critical facility.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The prescreening flow: 30 days from notification, then recommendations and orders
The heart of the practical work is filing an "introduction plan" with the competent minister before introducing a specified critical facility or outsourcing its important maintenance and management to an outside party. Note that outsourcing important maintenance and management is also covered. A notification is required not only when you buy equipment, but also when you entrust its maintenance, updates, or operational monitoring to an outside party. The thinking is that the contractor with continuous access to the equipment is in fact a higher risk than the equipment itself.
For 30 days as a rule after the notification is accepted, the operator may not introduce the specified critical facility or outsource its important maintenance and management. These 30 days are both the review period and the prohibition period. If the review finds no problems, the competent minister may shorten the period, and conversely, if careful confirmation is needed, may extend it up to four months (Article 52, paragraphs 3 and 4). If the review concludes that there is a significant risk the facility could be used as a means for a specified act of interference, the competent minister may recommend that the operator "introduce the facility only after taking necessary measures" or "suspend the introduction." An operator that receives a recommendation must notify within 10 days whether it will comply, and if it does not comply without a legitimate reason, the minister may issue an order (Article 52, paragraphs 6 through 10). During the review, there is also a mechanism for the competent minister to hear the opinions of the Prime Minister and relevant administrative bodies. The design deliberately avoids letting a single ministry decide on its own.
That said, there are situations, such as disaster recovery, where waiting 30 days is not feasible. For those cases, an "emergency introduction notification" allows the operator to introduce or outsource first and file after the fact without delay in an emergency and unavoidable situation. This is not a loophole anyone can use, however. Ministerial ordinances require all four conditions to be met: urgency, unforeseeability, necessity, and non-substitutability. The strict conditions are that there is an urgent need to introduce, that it could not be foreseen in advance, that the introduction is indispensable, and that there is no alternative. "Important changes," such as switching suppliers or contractors during or after introduction, also require prior notification as a rule, and only minor changes are exempt from notification and reporting. It is easier to remember the notifications by organizing them into four types: "prior introduction plan," "emergency introduction notification," "prior notification of an important change," and "after-the-fact report of a change."
What the notification asks for: investigating the entire supply chain
What makes this framework heavy in practice is not the review period itself but the content you must put in the notification. In addition to an overview of the specified critical facility and its component equipment, the introduction plan asks for the name, address, and country of the law under which each entity was established for the supplier (the maker or other party delivering the equipment), the contractor, and even sub-contractors. For an introduction, the scope of investigation extends to the supplier and contractor; for outsourcing, it extends to all sub-contractors. Merely bringing in a single piece of equipment obliges you to explain to the government the backgrounds of the group of companies behind it.
Among the items you must disclose, the capital and personnel information carries particular weight. For the supplier and contractor, you need to identify anyone who directly holds 5% or more of the voting rights. The question is who effectively controls the company. For officers, you disclose their names, dates of birth, and even nationalities. Furthermore, if dealings with a foreign government, a foreign government agency, a local government, a central bank, or a political party accounted for 25% or more of sales in any of the past three fiscal years, you must disclose the counterpart country and the ratio. This is a mechanism for measuring how far foreign government influence reaches, weighted by monetary value. You also state the location where the equipment is manufactured and the risk management measures described below.
On top of this, you are required to confirm concrete risk management measures at the time of notification and attach documents that substantiate them. Alongside technical items such as acceptance inspection, vulnerability testing, applying security patches, access control, ransomware countermeasures, and ensuring redundancy, the items that dig into the "background" of the supplier and contractor are the ones worth noting. They include confirming whether there were any violations of domestic laws or international standards over the past three years, whether contracts secure against the risk that a foreign legal environment or the instructions of an external actor could cause a contract to be broken, and, when handling video equipment such as surveillance cameras or drones, whether the legal environment of the country where the supplier's headquarters is located has been checked. In short, you are told to consider even the possibility that a foreign law could compel a company to provide data or cooperate. Reading China's Anti-Espionage Law and National Intelligence Law makes it clear why so much care is warranted here.
In short, this notification is tantamount to demanding "supply-chain-wide business-partner due diligence" in legal language. From the supplier to the contractor to the sub-contractor, across multiple layers, you investigate capital ties, foreign government involvement, and any history of violations. This is structurally almost identical to the business-partner screening and end-user review done in export control. That is precisely why companies that run their economic security response and their export control separately, with different teams working in isolation, see their workload spike here.
Suppliers and contractors are not bystanders
An easily overlooked point is that it is not only the 258 designated operators who must deal with this framework. The suppliers, contractors, and sub-contractors named in the notification are precisely the companies that deliver the equipment and handle its maintenance. There is also a mechanism allowing part of the information required for the notification to be submitted directly to the competent minister by the supplier or contractor. In other words, if your company is on the side that provides equipment, software, or maintenance services to infrastructure operators, you may be asked by the 258 operators that are your customers to disclose your capital structure, the nationalities of your officers, and your dealings with foreign governments, and in some cases you may find yourself submitting information to the government yourself.
In terms of scale, the directly regulated operators number 258, but the vendors, contractors, and sub-contractors hanging off their procurement networks run into the thousands. If you assume "we're not designated, so this has nothing to do with us," you may one day be caught off guard when a detailed questionnaire arrives from a major customer. Conversely, for vendors doing business with infrastructure operators, being able to properly explain your own capital ties and compliance structure is becoming a precondition for continuing to do business. This breadth at the base is why the framework cannot be dismissed as "a matter for a handful of large companies."
What happens if you violate it? Penalties and the risk of recommendations and orders
The penalties are by no means light. Introducing or outsourcing a specified critical facility without notification or with a false notification, doing so during the review (prohibition) period, and violating an order to suspend or change are punishable by imprisonment of up to two years, a fine of up to one million yen, or both (Article 92, paragraph 1). "Imprisonment" (拘禁刑) is the term used after the Penal Code amendment unified imprisonment with and without labor; think of it as corresponding to the former "imprisonment with labor." The structure is such that not only the company but also the individual who handled the procedure can be held criminally liable.
Separately, failing to report or submit materials, refusing or obstructing an on-site inspection, or giving false answers is punishable by a fine of up to 300,000 yen (Article 96, in connection with Article 58). The amount may look small, but treating an on-site inspection lightly seriously damages the authorities' impression of you. And what must not be forgotten is the weight of the recommendations and orders themselves, quite apart from the penalties. If a suspension is recommended for equipment you planned to introduce, your procurement plan goes back to square one, and selecting alternative equipment and undergoing another review push the schedule far back. Infrastructure businesses are often tied to public-sector bids and licenses, and the fact of having received an economic security concern can cast a shadow over subsequent contract dealings. This should be understood not as a question of the size of a fine, but as the risk that the business plan itself grinds to a halt.
Where the framework stands now, and what to prepare in practice
Tracing the framework's history in order: the Economic Security Promotion Act was promulgated on May 18, 2022; the basic policy was decided by the Cabinet on April 28, 2023; provisions on the businesses and designation criteria took effect in November of that year; and 210 operators were designated on November 16, 2023. After a six-month transitional period, the notification obligation began in full on May 17, 2024.
The number of notifications since the framework began has risen steadily. According to Cabinet Office materials (as of July 1, 2026), advance notifications in fiscal 2025 reached 1,200, of which 167 were for equipment introductions and 1,033 were for outsourcing important maintenance and management. That outsourcing notifications exceed introductions by more than sixfold captures the center of gravity of this framework well. After-the-fact reports numbered 799. For reference, the previous fiscal 2024 saw 972 advance notifications and 195 after-the-fact reports, so after-the-fact reports have grown more than fourfold. Looking at advance notifications by ministry, the Ministry of Internal Affairs and Communications received 320, the Ministry of Land, Infrastructure, Transport and Tourism 203, the Ministry of Economy, Trade and Industry 173, and the Financial Services Agency and the Ministry of Agriculture, Forestry and Fisheries combined 504. This suggests that notifications in the finance sector are the most numerous. This is because each ministry, as the competent minister for the sector it oversees, handles everything from accepting notifications to reviews, recommendations, and orders. Overall coordination and the basic policy for the framework rest with the Cabinet Office (Director-General for Policy Planning, in charge of economic security).
So where should your company start? When people come to me for advice, the order I always recommend is the following.
- Confirm whether your company is designated as a designated critical infrastructure operator, or is at a scale close to the designation criteria
- Inventory which of the equipment you hold or plan to introduce could constitute a specified critical facility
- Screen suppliers, contractors, and sub-contractors for foreign involvement (capital, officer nationalities, dealings with foreign governments)
- Document risk management measures item by item, and link and retain the substantiating records
- Build an internal flow that can determine whether a prior notification is required when a supplier or contractor changes
Where many companies get stuck on this list is the third item, business-partner screening. Manually tracing a multilayered supply chain to investigate capital ties, foreign government involvement, and whether a party appears on a sanctions or concern list is, realistically, more than staff can keep up with.
The export control AI agent we provide, TRAFEED (formerly ZEROCK ExCHECK, aligned with the standards of the Ministry of Economy, Trade and Industry), was built precisely to streamline this business-partner screening and the mapping of effective control relationships. It cross-references a partner's capital structure, foreign government involvement, and whether they appear on sanctions lists or as a concern party, and it supports confirming risk management measures and documenting evidence. Whether it is a critical infrastructure notification or export control under the Foreign Exchange Act, at bottom both are the work of confirming who the counterpart is and who stands behind them. For companies that want to run export control classification and business-partner screening on the same foundation, TRAFEED's capabilities apply directly to the economic security response as well. For the entry points to export control itself, METI's classification (gaihi-hantei) guide, the risks of deemed exports, and an overview of the various sanctions lists are also worth consulting. To be clear, the final judgment on whether a notification is required, and any classification, should be made by your company's export control and legal leads. Think of the tool as support for quickly assembling the material for that judgment.
Conclusion
The critical infrastructure prescreening system may look unremarkable, but it is fundamentally changing corporate procurement. Here are the key points.
- Under Chapter 3 of the Economic Security Promotion Act, designated critical infrastructure operators must notify the government and undergo review before introducing or outsourcing a specified critical facility
- Fifteen sectors are covered at present, and an amendment promulgated on June 17, 2026, is set to add the healthcare sector. Designated operators numbered 258 as of July 2026
- After notification, there is a review (prohibition) period of 30 days as a rule, which can be extended up to four months. If the risk is high, recommendations and orders follow
- Introducing without notification, with a false notification, or during the review period is punishable by imprisonment of up to two years or a fine of up to one million yen
- The notification asks about the capital ties and dealings with foreign governments of suppliers, contractors, and sub-contractors, making it substantive business-partner due diligence
- Beyond the 258 designated operators, the vendors and contractors that provide equipment and maintenance are also involved in the practical work of disclosure
One last thing. If you frame the response to this framework only as "the cost of defense," the people in charge will burn out. But understanding the backgrounds of your business partners in ordinary times is effective not just for economic security, but also for avoiding supply-chain disruptions and reputational risk. What you investigate for the notification becomes, directly, an asset that strengthens your own procurement. Start with an inventory of your equipment and contractors. If you are unsure how to proceed with the response or how to build a business-partner screening structure, please feel free to reach out through a one-on-one consultation on TRAFEED.
References and primary sources
- Cabinet Office, Economic Security Promotion Act, portal for the system for ensuring the stable provision of specified critical infrastructure services (critical infrastructure system)1
- Cabinet Office, "On the System for Ensuring the Stable Provision of Specified Critical Infrastructure Services under the Economic Security Promotion Act" (framework overview, as of July 7, 2026)2
- Cabinet Office, "Number of Advance Notifications and After-the-Fact Reports in FY2025" (as of July 1, 2026)3
- Cabinet Office, "Explanation of the Critical Infrastructure System (technical explanation)" (as of March 31, 2026)4
- e-Gov Law Search, Act on the Promotion of Ensuring Security by Taking Economic Measures in an Integrated Manner (Act No. 43 of 2022)5
Footnotes
-
Cabinet Office https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/infra.html ↩
-
Cabinet Office (framework overview PDF) https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/doc/infra_gaiyou.pdf ↩
-
Cabinet Office (advance notification and after-the-fact report counts PDF) https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/doc/infra_kensu.pdf ↩
-
Cabinet Office (technical explanation PDF) https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/doc/infra_kaisetsu.pdf ↩
-
e-Gov Law Search https://laws.e-gov.go.jp/law/504AC0000000043 ↩
