Hello, this is Ryuta Hamamoto from TIMEWELL.
On September 30, I published a two-part series on the run of data breaches in Japan, written from the personal data side (Part 1, Part 2). If you handle export controls at a manufacturer, though, I suspect customer lists are not what worries you most. Drawings and technical documents are.
Around the same time, Ikegami Tsushinki, a Japanese maker of broadcast equipment and surveillance cameras, disclosed an incident in stages. On September 24 it announced a possible cyberattack. On September 30 it reported that files on some servers had been encrypted and that information provided to it from outside included what appeared to be company documents. In a third update on October 2, it said it had confirmed that information it appears to have held had been posted on an attacker's leak site on the dark web123. What was posted is still being examined, and the company has not said what kind of documents they are. I mention the company not to judge its response. Disclosing what you know, step by step, gives everyone else something to learn from, and I think that deserves credit.
Also in September, Japan's National Police Agency (NPA) and National Cybersecurity Office (NCO), together with agencies in the United States, Australia and Germany, published a joint alert on a North Korean cyber actor group and on the activities of North Korean IT workers4. On October 1, Japan's Active Cyber Defense legislation took effect5. Put those three events side by side and the old split, where IT owns cybersecurity and the compliance office owns export controls, starts to look outdated. The person who knows best which technologies are controlled, where they sit and who receives them is usually the export control officer.
Let me be clear about where I stand. This article does not blame any company that disclosed an incident. The North Korean IT worker material is about a specific revenue-generation scheme that governments have warned about. It is not a reason to treat the people of any country with blanket suspicion. If you want a quick read on where your own export control program stands first, the three-minute export compliance self-check will make the rest of this article easier to apply.
Key points (as of October 4, 2026)
- Japan's export control law requires a license to provide controlled technology. Even so, METI's guidance for universities and research institutions asks for access control so that controlled technology does not leak "through theft or unauthorized access"
- METI's Technology Leakage Prevention Guidance (2nd edition) lists cyberattacks as one leakage route and gives the example of leaving an overseas subsidiary's IT management entirely to local staff
- The Japanese government warns that ordering work from North Korean IT workers and paying them "may violate" domestic laws, including the Foreign Exchange and Foreign Trade Act
- For companies that receive customers' important technical information, the design policy for Japan's new SCS supply chain security ratings gives "TICS or 4-star" as an example. 3-star and 4-star ratings are expected to launch around March 2027
- The compliance items for the internal compliance program (CP) filed with METI contain no separate item on information security or access control. Where to write technical data access rules is each company's design choice
Why a cyberattack becomes an export control issue
Start with what Japan's Foreign Exchange and Foreign Trade Act (FEFTA) actually controls. It requires a license from the Minister of Economy, Trade and Industry for transactions that provide list-controlled technology in a foreign country, or to a non-resident even inside Japan6. The trigger is the act of providing. METI's Guidance on Sensitive Technology Management for Security Export Control (for universities and research institutions, 5th edition, September 2025) gives an example in a footnote: a domestic research partner happens to be on a business trip abroad, and you email them by chance. In that case, it says, where "the provider has no intention of conducting a cross-border transaction, it is not subject to the controls" (my translation)7.
So what happens when an attacker steals the data? As far as I could find, no primary source addresses theft through unauthorized access head-on. Given that unintentional transmission falls outside the controls, it seems hard to treat a theft as the company "providing" the technology. That is my reading, though, and I would not state it as settled.
What matters is the next part. Under "Information management," the same guidance says (my translation): "List-controlled technical information in particular should be access-controlled. Everyday information management is important so that controlled technology does not leak in unexpected ways through theft, unauthorized access and the like"7. It then recommends applying any existing information security rules to technical data, and lists practical measures for organizations that have none: user authentication and USB restrictions on PCs holding controlled technology, limits on who can reach shared databases, keeping access logs (which it says are "necessary for identifying the leakage route"), and restricting or prohibiting access to the intranet "from outside (such as overseas offices)." The document is written for universities, but any company holding controlled technology could adopt these measures as they are.
I think the view that "theft isn't a violation, so it's outside export control" is risky, for two reasons. First, leaked technology does not come back. By the time anyone settles whether a violation occurred, the technology is long gone. If it was a drawing a customer entrusted to you, your credibility goes with it. Second, the export control side is the one holding the list of what to protect. Technologies you classified as controlled, drawings received from customers, specifications from joint research. That list doubles as a priority list for cyber defense. It is exactly the information IT wants and usually does not have, and the export control team already has it.
Four routes technology takes out of the company
METI's Technology Leakage Prevention Guidance (2nd edition), published in April 2026, opens with blunt language (my translation): "Companies that think 'it is enough to comply with the rules the government sets' must abandon that view immediately and strengthen their own efforts to protect their interests and credibility"8. It also states that its measures are not obligations, that no countermeasure is perfect, and that small and medium-sized firms should "reliably carry out the measures they can"8. In a reference page on cybersecurity, it notes that cyberattacks targeting companies' important technical information are "on the rise, and their methods are becoming more sophisticated"8. The NPA likewise sorts the risk of technology being targeted from abroad into three patterns and puts "technology leakage through cyberattacks" first9.
The chapter on overseas operations includes a diagram of leakage routes. Two of the four examples go straight to the subject of this article. One is a case where "IT management at an overseas subsidiary was left to local staff, and technical information leaked after a cyberattack." The other is a case where "design drawings and other necessary technical information were provided to a foreign company for contract manufacturing, and leaked because the contractor's information management was sloppy"8. The same chapter suggests that when sending design drawings to an overseas site, you create a version with highly confidential information removed and manage the two separately8. It is part of what the guidance calls black-boxing information, giving local sites only what they need, and a small company could start doing it tomorrow.
Combining these public documents with the September NPA alert, I sorted the cyber-related routes into four.
| Route | What happens | What the government documents say | What the export control side already has |
|---|---|---|---|
| Unauthorized access (own servers, cloud) | Drawings and technical documents are stolen directly | University guidance: "through theft, unauthorized access"7; first of the NPA's three patterns9 | The classification ledger (which technologies are controlled) |
| Overseas sites | Locally managed systems are attacked and technical data leaks | Leakage guidance: "IT management left to local staff"8 | Guidance to subsidiaries and affiliates (CP compliance item 7)10 |
| Contractors and subcontractors | Entrusted drawings leak from the contractor | Leakage guidance: "contractor's information management was sloppy"8 | Records of technology provided (when, to whom, what) |
| Fake IT workers (hiring, outsourcing) | Accounts you issued are used to get inside; source code is published | NPA, NCO and partner agencies (September 18, 2026)11 | Procedures to confirm end use and end user |
Look at the right-hand column. Every route maps to something the export control officer already holds. When cybersecurity is planned by IT alone, that material goes unused, nobody knows what to protect first, and the budget gets spread thin across everything. I mapped the full set of leakage routes into seven in Where does technology leakage happen?. Think of this article as a close-up of the parts where cyberattacks are involved. The old-fashioned route, a person walking out with a storage device, is covered in my piece on the Asahi Kasei arrest. Money spent on stopping cyberattacks and money spent on closing that route are two different investments.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Fake IT workers are an extension of knowing your counterparty
On September 18, 2026, the NPA and the NCO, together with the FBI, the US Department of Defense Cyber Crime Center (DC3), Australia's ASD's ACSC, and Germany's BND and BfV, published a joint alert on the North Korean cyber actor group "WaterPlum" (also known as "Contagious Interview") and on North Korean IT workers411. WaterPlum targets IT professionals. According to the alert, from around December 2025 through July 2026 it infected at least 30,000 devices in more than 100 countries and regions, including Japan, and transferred 1.7 billion yen (about 10.71 million USD) in crypto assets. Japanese authorities identified and dismantled a "laptop farm" run by an enabler in Japan for the first time, and found evidence of several hundred million yen sent abroad. The NPA and the FBI assess that WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department of the Workers' Party of Korea Central Committee411.
The methods look nothing like the spy story an export control officer might picture. The workers use identity document images supplied by enablers living in Japan to pose as those enablers and take on work. They have enablers set up remotely operated PCs at home, or use virtual private servers (VPS) rented by enablers, to hide where they actually are. In one case, someone believed to be a North Korean IT worker applied for an engineering job at a Japanese crypto exchange. The applicant used commercial VPN services to reach the application form. In the interview, they refused to relocate to Japan or said "maybe in six months," insisted on being paid in crypto, and kept glancing at another monitor as if reading from it. The company spotted the red flags and handled the situation properly, and the alert states that no hiring or damage resulted11.
The damage on the client side is concrete too. In one case, a company that outsourced part of a software project, not knowing the contractor was a North Korean IT worker, had its proprietary source code published online after a payment dispute. In another, a website the worker had helped build was later defaced and taken offline. The alert also warns that such workers could misuse the credentials they were given to steal sensitive information from the client, or try to infect the client with malware through ordinary work exchanges11. Of all the leakage routes, this is the one closest to the export control officer's own job.
The alerts also spell out the legal risk. The September 18 document says that paying North Korean IT workers for commissioned work, or facilitating their revenue generation, may constitute violations of domestic laws and sanctions against the DPRK11. An earlier Japanese government alert, dated August 27, 2025, goes further. It says that ordering work from North Korean IT workers and paying for their services "may violate domestic laws, including the Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949)" (my translation), and lists the Ministry of Finance's foreign transactions office and METI among the contacts12. On July 31, 2026, the NPA, the NCO, the Ministry of Foreign Affairs, the Ministry of Finance and METI updated the alert jointly with partners including the United States and South Korea13.
Export control officers already have a routine for confirming who the counterparty is and what they will use the goods or technology for. The CP compliance items require companies to "establish procedures to confirm end use and end user" (my translation)10. My recommendation is to extend that habit to outsourcing, freelance contracts and remote hiring. The limits are obvious, though. Someone using a false identity or another person's name will not show up in restricted party screening. What you look for is behavior, not names. The July alert lists red flags for employers and clients: profiles with errors that suggest machine translation and a weak command of the language of the claimed home country, inconsistencies during video calls (including mismatches with photo ID and video that looks altered or AI-generated), refusing video meetings, rates well below market, signs that several people share one account (the person you talk to changes with the time of day), and requests for payment in crypto13. The September alert asks clients to limit the information (source code, credentials and so on) and access rights given to contractors to the minimum necessary, to set clear contract terms on outsourcing and subcontracting, and to revoke accounts and sessions promptly once a contractor looks suspicious11.
One more point. None of this means sorting people by nationality. The scheme runs on borrowed IDs and impersonation, so checking the nationality on a document will not stop it, and judging people by nationality alone creates other problems. What you need to confirm before sharing technology is residency status under FEFTA and whether the person falls into one of the "specified categories" under Japan's deemed export rules. The Technology Leakage Prevention Guidance also lists confirming "residency status under FEFTA" as a hiring step8. I explain the specified categories in Building a people-centered defense against technology leakage.
What the government documents actually ask for
The documents above differ in legal weight and in who they apply to. Mixing up which one is a law, which is guidance and which is an alert leads to wrong explanations to customers. Here they are side by side.
| Document | Issuer and date | Status | What it says about technical information |
|---|---|---|---|
| Guidance on Sensitive Technology Management (universities and research institutions), 5th ed. | METI, September 2025 | Guidance | Access control for list-controlled technology, log retention, restricting access from outside (such as overseas offices)7 |
| Technology Leakage Prevention Guidance, 2nd ed. | METI, April 2026 | Not an obligation | Measures by route: leakage through cyberattacks, through contractors, separate drawings for overseas sites8 |
| Alerts on North Korean IT workers | Government (August 2025); five agencies with partner countries (July 2026); NPA, NCO and partners (September 2026) | Alert | Ordering and paying may violate FEFTA and other laws; give contractors minimum data and access111213 |
| SCS rating scheme design policy | METI and the NCO, March 2026 | Voluntary scheme | "TICS or 4-star" when receiving customers' important technical information (an example of how to choose)14 |
| Active Cyber Defense legislation | In force October 1, 2026 | Law (applies to critical infrastructure operators) | Incident reporting; compromise of covered equipment managed by a contractor is also reportable1516 |
| CP compliance items under FEFTA | METI | Filing standard | No separate item on information security or access control10 |
The last row corrects a common assumption. You sometimes hear that a CP "covers technical information management." The compliance items attached to a CP filed with METI are a basic policy, the export control organization, transaction screening (classification and end use and end user checks), shipping control, audits, training, record keeping, guidance to subsidiaries and affiliates, and reporting and prevention of recurrence. There is no separate item on information security or access control10. Whether to build technical data access rules into the CP is up to each company. The university guidance itself recommends applying existing information security rules to technical data7. In my view, rather than writing a new chapter into the CP, it is more practical to add a section to the information security rules covering "where technologies classified as controlled are stored and who can access them," and have the CP refer to it. Even when the two documents are revised by different departments, the cross-reference is less likely to break.
A word on the Active Cyber Defense legislation. Since October 1, critical infrastructure operators, 258 of them across 15 sectors including electricity, finance and railways, must report cyber incidents. Product names of covered equipment already in use must be filed by March next year, and the use of communications information to detect attack servers is scheduled to take effect next autumn15. It may look irrelevant to small manufacturers. But the government's explanatory guide states that compromise of covered equipment managed by a contractor is also reportable, and that the operator decides whether an event is reportable "as soon as it receives notice of the compromise from the contractor"16. I expect companies that do business with critical infrastructure operators to see more contract clauses asking them to report compromises promptly. The guide even reminds operators to respect Japan's subcontracting fairness law when they ask suppliers for information, which suggests the government expects those requests to reach suppliers. I wrote about how the critical infrastructure regime reaches vendors in Japan's critical infrastructure regime and security clearance.
Ten things to check in your own company
Read the documents together and the core demands are not many. Decide what to protect. Narrow where it lives and who can touch it. Keep records. Confirm the recipient and the content before anything goes out. That is about it. I think the fastest way forward is for the export control officer and the IT lead to work from the same table.
| # | What to check | Usually owned by | Basis |
|---|---|---|---|
| 1 | Is there a list of what to protect (technologies classified as controlled, drawings received from customers, materials from joint research)? | Export control, R&D | University guidance7, leakage guidance8, TICS "decide what to protect"14 |
| 2 | Where is that technology stored (file servers, cloud, personal PCs, overseas sites)? | IT | University guidance7 |
| 3 | Is access limited to the right people and reviewed regularly? | IT, export control | University guidance7 |
| 4 | Are access logs kept (needed to trace a leak)? | IT | University guidance7 |
| 5 | Is access from outside and from overseas sites prohibited or restricted? | IT | University guidance7 |
| 6 | Is an overseas subsidiary's IT management left entirely to local staff? | IT, international operations | Leakage guidance8 |
| 7 | Are drawings sent to overseas sites or contractors kept separate from versions with sensitive details removed? | R&D, export control | Leakage guidance8 |
| 8 | Is the data and access given to contractors minimal, and do contracts prohibit unapproved subcontracting and require notice of compromise? | Procurement, legal | NPA, NCO and partners11; Active Cyber Defense guide16 |
| 9 | Do outsourcing and remote hiring include identity checks and a look for red flags? | HR, ordering departments | Alerts on North Korean IT workers1113 |
| 10 | Is it decided whom to contact if a leak is suspected (police, customers, the export control officer)? | Management, export control | NPA, "Preventing Technology Leakage"9 |
You do not have to do all ten at once. The Technology Leakage Prevention Guidance itself says to reliably carry out the measures you can8. If I had to pick, I would have the export control officer and the IT lead fill in items 1 and 2 together this month, looking at the same table. Once you know what you have and where it is, items 3 to 5 turn into concrete tasks about which settings go where. Skip item 1 and jump to 3 through 5, and you usually end up either locking every folder so tightly that work stops, or protecting nothing well enough.
Our TRAFEED can help with building the list in item 1 and with checking counterparties in item 8. TRAFEED supports Japan export classification under Japan's security export controls with AI, screens the names of customers and contractors against the US Consolidated Screening List and sanctions lists from other jurisdictions, and keeps the evidence behind each decision on file. Your export control officer makes the final call; TRAFEED is built on that premise. To be honest, preventing cyberattacks is outside TRAFEED's scope, and someone using a false identity will not be caught by list screening. What it covers is identifying the technology to protect, confirming who receives it, and keeping a record. One more note: a listing on a restricted party list is a regulatory designation, not a judgment on the company. A match is a signal to run your review process, not a verdict on the counterparty.
Spotting the red flags in item 9 and preparing staff for impersonated applications and interviews takes training. If running that in-house is hard, our WARP SECURITY program may be worth a look. It spends less time on attack techniques and more on everyday preparation: internal rules, approval design and how to decide when something goes wrong.
When a customer asks for an SCS rating or TICS
The SCS rating scheme (Japan's supply chain security evaluation scheme) is a voluntary scheme run by the Information-technology Promotion Agency (IPA) under the supervision of METI and the NCO14. A 3-star rating is a self-assessment checked by a qualified security professional, with 26 requirements and a one-year validity. A 4-star rating is a third-party assessment that adds an on-site audit and technical testing to the document review, with 43 requirements and a three-year validity14. According to IPA's FAQ, 3-star and 4-star ratings are expected to launch around March 202717. The scope is a company's IT infrastructure (including cloud environments). Operational technology (OT) in factories and products supplied to customers are not directly covered14. An explanatory guide to the requirements and assessment criteria is scheduled for around October 202618. I covered the overall scheme in ISMAP and SCS explained from scratch, so here I will stick to where it meets technical information.
That meeting point is TICS, Japan's technical information management certification. It is based on the Industrial Competitiveness Enhancement Act and audits and certifies a company's information security arrangements; according to the SCS design policy, seven certification bodies are accredited14. Its requirements cover deciding what information to protect, identifying that information and sorting out measures, appointing a manager, setting up information management processes, informing and training employees, rules for reporting incidents, access rights to managed information, physical control such as safes, and electronic control such as ID settings. As an example of how to use the two schemes, the design policy says that "when receiving a customer's important technical information for product planning, design, manufacturing and the like, work toward TICS or 4-star under this scheme," and that "where third-party certification is not needed, 3-star is recommended" (my translation)14. A small manufacturer that receives drawings for machining or assembly is exactly who that sentence is about.
| Point | SCS 3-star | SCS 4-star | TICS |
|---|---|---|---|
| Basis | Design policy (voluntary scheme) | Same | Industrial Competitiveness Enhancement Act |
| Assessment | Self-assessment checked by a security professional | Third-party assessment (documents, on-site audit, technical testing) | Third-party certification (seven certification bodies) |
| Requirements | 26 | 43 | From deciding what to protect to electronic control by ID settings |
| Validity | 1 year | 3 years (annual self-assessment submitted to the assessor) | Not stated in the comparison table |
| Suggested use (design policy example) | When third-party certification is not needed | When receiving customers' important technical information | When receiving customers' important technical information |
Source: METI, design policy for the SCS rating scheme, pp. 13, 24 and 3114
Whether to make a rating a contract condition is for the two parties to agree on. METI and the Japan Fair Trade Commission have prepared example scenarios showing requests for SCS-based measures that would not be a problem under the Antimonopoly Act or the subcontracting fairness law19. Ahead of the launch, authorities have also warned about inappropriate sales pitches pushing companies to get rated in a hurry; I covered that in Part 2.
Here is my view. A company that nobody has asked yet does not need to rush into an expensive support contract before the scheme even starts. The first job is "deciding what information to protect," the first item in the TICS requirements. The SCS side has a "risk identification" category as well, and neither scheme gets far until you know what you are protecting. That is item 1 on the checklist above. If your company has an export control officer, the classification ledger is probably already there. Add the drawings you have received from customers, note where they are stored and who can access them, and you have taken the first step whichever scheme you are asked for. Then, when a customer actually asks, talk with them about TICS or 4-star based on how sensitive the technical information you hold is.
Summary
- Japan's export control law requires a license to provide technology. No primary source I found directly addresses theft, but METI's university guidance asks for access control so that controlled technology does not leak through theft or unauthorized access
- The Technology Leakage Prevention Guidance (2nd edition) names cyberattacks as a leakage route, with examples of overseas subsidiaries left to manage their own IT and drawings leaking from contractors
- The government warns that ordering work from and paying North Korean IT workers may violate FEFTA and other laws. Extend counterparty checks to outsourcing and hiring, look for red flags rather than names, and give contractors minimal data and access
- The CP compliance items have no separate item on information security. Cross-referencing the information security rules and the CP is the practical design
- For companies receiving customers' important technical information, the SCS design policy gives TICS or 4-star as an example. Whichever you are asked for, start by deciding what to protect
Articles about cyberattacks tend to drift toward entry points and security products. Deciding what to protect is a job no product can do for you, and the export control officer already holds a draft of the answer. Next week, try showing your classification ledger to your IT lead. If you would like to talk through how your technologies are classified or how to run counterparty and contractor checks, reach out through a TRAFEED consultation.
References
Footnotes
-
Notice regarding a possible cyberattack on the company (Ikegami Tsushinki Co., Ltd., September 24, 2026, in Japanese) ↩
-
Notice regarding a cyberattack on the company (Ikegami Tsushinki Co., Ltd., September 30, 2026, in Japanese). Encryption of files on some servers, the continued disconnection of the internal network, and information containing what appeared to be company documents are from this release ↩
-
Notice regarding a cyberattack on the company, third update (Ikegami Tsushinki Co., Ltd., October 2, 2026, in Japanese). The content and scope of the posted information are under examination ↩
-
Public attribution by Japan, the United States, Australia and Germany regarding the North Korean cyber actor group "WaterPlum" and North Korean IT workers (NPA and NCO press material, September 18, 2026, in Japanese) ↩ ↩2 ↩3
-
Cabinet Order No. 46 setting the effective date of the Act on the Prevention of Damage from Unauthorized Acts against Important Computers (in Japanese). Effective October 1, 2026 ↩
-
Foreign Exchange and Foreign Trade Act (Act No. 228 of 1949, e-Gov, in Japanese). Article 25 ↩
-
Guidance on Sensitive Technology Management for Security Export Control, for universities and research institutions, 5th edition (METI, September 2025, in Japanese). "Information management" and the example measures are on pp. 72–73; the explanation of transmissions without intent is in footnote 96 on p. 78 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Technology Leakage Prevention Guidance, 2nd edition (METI Trade and Economic Security Bureau, April 2026, in Japanese). The quote on complying with government rules is on p. 4, rising cyberattacks on p. 13, the leakage route diagram on p. 24, separate drawings on p. 46, and the residency check at hiring on p. 68 (PDF page numbers) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13
-
Preventing technology leakage (NPA, in Japanese). The three risk patterns (cyberattacks, espionage, and economic and academic activities) are from this page ↩ ↩2 ↩3
-
Compliance items under the Foreign Exchange Act, Attachment 1 to the internal compliance program filing (METI, in Japanese). See also METI's CP and checklist page ↩ ↩2 ↩3 ↩4
-
North Korean "WaterPlum," commonly referred to as "Contagious Interview," Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe (NPA, NCO, FBI, DC3, ASD's ACSC, BND and BfV, September 18, 2026). The Japanese version is here. Methods, damage to clients, legal risk, mitigations for outsourcing and the job application case are from this document ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Alert to companies regarding North Korean IT workers (Japanese government, August 27, 2025, in Japanese) ↩ ↩2
-
Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers (July 31, 2026). The issuing agencies are listed on the NPA page ↩ ↩2 ↩3 ↩4
-
Design policy for the security measures evaluation scheme for strengthening supply chains (METI and NCO, March 27, 2026, in Japanese). IPA's copy is here. Scope (treatment of OT systems) on pp. 8–9, the voluntary nature and operating structure on p. 11, the 3-star and 4-star comparison on p. 13, the 4-star annual self-assessment on p. 24, and the relationship with TICS on p. 31 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
On the entry into force of the Cyber Response Capability Enhancement Act and related legislation (Cabinet Secretariat National Cybersecurity Office and Cabinet Office, September 2026, in Japanese). The 258 operators in 15 sectors, the asset filing deadline and the start of communications information use next autumn are from this document ↩ ↩2
-
Explanatory guide to the reporting regime for specified compromise events under the Cyber Response Capability Enhancement Act (Cabinet Office and others, October 1, 2026, in Japanese). Q2 on equipment managed by contractors and the treatment of equipment owned by other organizations are from this document ↩ ↩2 ↩3
-
SCS rating scheme requirements and assessment criteria (IPA, in Japanese) ↩
-
SCS rating scheme related programs and policies (IPA, in Japanese). The example scenarios for building partnerships with business partners are introduced on this page ↩






