TRAFEED

Data Centers, Cloud, and IoT in Japan's Economic Security, from Primary Sources

Published2026-07-19Ryuta Hamamoto

Data centers, cloud, and IoT devices now sit at the core of economic security. Drawing only on Japanese government primary sources, this guide walks through the designation of cloud programs as a specified critical material, ISMAP and the Government Cloud, prior review for critical infrastructure, and IoT security obligations under NOTICE, then lays out what companies should actually do.

Data Centers, Cloud, and IoT in Japan's Economic Security, from Primary Sources
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Which country's company operates the cloud your organization runs on? Who makes the network cameras sitting in your office, and are any of them still running on their default passwords? Surprisingly few IT managers can answer all three off the top of their heads. Yet these seemingly mundane questions have moved to the very center of economic security. Data centers, cloud, and the countless IoT devices around us are no longer just convenient tools. They are core infrastructure that keeps society running. That is precisely why the government has begun measuring them against a security yardstick: who controls them, and can an attack shut them down?

To be honest, this field is hard to see whole, because responsibility is split across several ministries and agencies. The Cabinet Office, the Ministry of Economy, Trade and Industry (METI), the Ministry of Internal Affairs and Communications (MIC), the Digital Agency, NICT, and even the National center of Incident readiness (the National Cyber Office) all have a hand in it. This article is written for business people encountering the topic for the first time. Relying only on Japanese government primary sources, it reconnects a single thread running from the designation of cloud as a critical material, through government procurement standards, prior review for critical infrastructure, the siting of data centers, and the supply chain for IoT devices. If you want to check up front whether your own equipment or software might be caught in the export-control net, spending 30 seconds on our export compliance check before you read on will make the rest of this feel a lot more personal.

This article is a deep-dive on digital infrastructure, branched from our hub article on the broader picture of economic security. If you have not yet grasped the four pillars of the law itself, it will be quicker to read the basics of the Economic Security Promotion Act first and then come back.

Cloud was designated a "specified critical material"

Let me start with the single most symbolic fact. The Economic Security Promotion Act (formally, the Act on the Promotion of Ensuring Security by Taking Integrated Economic Measures / 経済施策を一体的に講ずることによる安全保障の確保の推進に関する法律, Act No. 43 of 2022) has a pillar called the "system for ensuring the stable supply of critical materials." Under it, the state designates as "specified critical materials" those goods whose disruption would paralyze citizens' daily lives or economic activity, and then backs up domestic supply capacity for them. In December 2022, eleven items were designated as specified critical materials by cabinet order. One of them was "cloud programs."12

Look at the company that cloud keeps and the weight of the designation becomes clear. Antimicrobial agents, fertilizer, permanent magnets, machine tools and industrial robots, aircraft parts, semiconductors, storage batteries, natural gas, critical minerals, ship components. Cloud, a piece of software, was placed on this list of goods "whose supply the state should protect," shoulder to shoulder with pharmaceuticals, semiconductors, and rare metals. An invisible program is being treated on equal footing with visible strategic materials. That single fact tells you how the government positions digital infrastructure. The list of specified critical materials has kept expanding since: in February 2024, advanced electronic components (capacitors and filters) were added, and in December 2025, ventilators, unmanned aerial vehicles (drones), satellites, and rocket components were designated.2 For the full picture of the designated items, see our detailed guide to specified critical materials.

The competent minister for cloud programs is the Minister of Economy, Trade and Industry. The Cabinet Office (the Minister in charge of Economic Security) oversees the system as a whole, but strengthening cloud supply capacity is the province of METI. "Cloud programs" here refers to the software that underpins cloud services such as IaaS and PaaS. Lifting Japan from a state of near-total dependence on foreign hyperscale clouds to one where it holds its own domestic infrastructure software: that is the policy aim. The support comes in four forms: grants, long-term low-interest two-step loans (fiscal loans), subscription of shares and the like, and credit guarantees.2

The numbers show this is no paper promise. As of July 14, 2026, certified supply-assurance plans totaled 151 across all materials, with roughly 2.56 trillion yen in budget secured and a combined maximum grant amount of about 1.68 trillion yen.2 Cloud programs are part of this framework, targeted for shoring up the domestic supply of cloud infrastructure software. The scale of that budget tells you the state is seriously committing capital to bring the digital foundation back home.

The standards the government uses to buy cloud (ISMAP and the Government Cloud)

While protecting supply, the government has also built a rule that it will "use only secure cloud services itself." At its core is ISMAP, the Information system Security Management and Assessment Program. When the government procures cloud services, only services that meet predefined standards and have been evaluated and registered are published on the "ISMAP Cloud Service List," and, as a rule, procurement must be from that list.34 Turn that around, and a service not on the list cannot even step into the ring for a government bid, no matter how capable it is.

ISMAP also includes ISMAP-LIU (ISMAP for Low-Impact Use), a track with lighter screening for SaaS used in low-risk operations. Imposing the full screening on every service would slow registration to a crawl, so lower-risk areas are simplified. The Digital Agency has also run special measures to encourage ISMAP-LIU registration.3 Above ISMAP sits the Cybersecurity Strategy adopted by the Cabinet on September 28, 2021, from which the government's overall security policy for information systems flows down.3

The other thing to grasp is the Government Cloud maintained by the Digital Agency. It is a common cloud environment for government, aimed at building systems that are fast, flexible, secure, and cost-effective. What stands out is how demanding the procurement is. In the FY2023 procurement, the highest and most current level of information security and the assured safety of stored data were set as mandatory criteria, with technical requirements laid out across 305 items.5 Alongside foreign providers such as AWS, the selected cloud operators include the domestic "Sakura no Cloud" (SAKURA internet), which began providing its production environment on March 27, 2026.5 It is a milestone: a domestic cloud has come to hold a place in the common government platform. The Government Cloud is also being extended as the foundation for standardizing local governments' information systems, so municipal systems will progressively run on top of it.5

Why should a private company care about any of this? Because government procurement standards flow straight through into private transactions. Even if you do not deal directly with public agencies, if you supply parts or services to a prime contractor serving those agencies, the 305 requirements and the ISMAP standards reach your company indirectly. The Digital Agency has drawn up Security-by-Design guidelines for government information systems and is promoting the adoption of zero-trust architecture and Continuous Risk Scoring and Action (CRSA).3 That kind of thinking will, in time, be built into private-sector procurement specifications as standard. Standards the government creates become, with a lag, the rules of the whole market. Working from that assumption tends to make the practical work easier, in my experience.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Prior review for critical infrastructure now covers telecommunications and critical equipment

Another pillar of the Economic Security Promotion Act is the system for ensuring the stable provision of critical infrastructure services, which came into operation on May 17, 2024.6 It designates the businesses that underpin society as "specified critical infrastructure operations," and requires their operators, the "specified critical infrastructure operators," to file an "introduction plan" with the state in advance and undergo review before installing critical equipment or outsourcing its maintenance and management. The state uses that step to screen, ahead of time, the risk of interference such as cyberattacks.6

The specified critical infrastructure operations initially covered fourteen sectors: electricity, gas, oil, water, railways, freight trucking, ocean shipping, aviation, airports, telecommunications, broadcasting, postal services, finance, and credit cards. Since then, sectors such as port transport and healthcare have been added in stages, and the scope has widened incrementally.6 The inclusion of "telecommunications" among these fourteen sectors connects directly to the topic at hand: when a telecom operator installs critical equipment such as switches, routers, or transmission systems, the review reaches all the way to who manufactures the equipment, where the parts come from, and to whom maintenance is outsourced.

There is, however, an important line to note. Cloud and data centers themselves are not spelled out as independent target sectors.6 For now, they enter the picture only within the "telecommunications" bracket, as part of critical equipment. That said, the boundary between telecommunications and cloud is blurring year by year, and it is worth watching how the system is adjusted going forward. We dig into the practicalities of prior review, and what kinds of equipment can fall within scope, in our explainer on the critical-infrastructure prior-review system.

Here is where the position of the equipment supplier comes into play. It is the telecom or power company itself that bears the obligation to file and be reviewed, but the vendors that supply equipment and systems to those operators cannot stay out of it. When an operator files with the state, it is asked for information on suppliers and subcontractors, so the supplier effectively shares part of the review burden. In other words, the more a manufacturer handles sensitive communications equipment or servers, the more it needs to be in a position to explain the integrity of its own supply chain.

Domestic siting of data centers and the new constraint of electricity

After the software comes the "box" that carries it. The MIC is pursuing a policy of building digital infrastructure by regionally consolidating data centers and AI/cloud facilities, and it explicitly frames the aim of that policy as "the security of data and servers and economic security."7 The government is stating, head-on, that where data centers sit is itself a security issue. This is not widely known.

Behind it lies a vulnerability: overconcentration around the Tokyo area. When the country's major data centers cluster in the Tokyo region, a large-scale disaster or cyberattack could knock out their functions all at once. So the MIC has set areas such as Ishikari and Tomakomai in Hokkaido and the Kansai region as targets for development, seeking to disperse hubs to the regions.7 Together with that, it is advancing the development of submarine cables that support international communications, and the regional dispersion of internet exchanges (IXs, the hubs where telecom operators interconnect), and it has convened an experts' meeting on digital infrastructure development to build the discussion.7 Keep data within the country and make routes redundant. This can be read as a way of securing data sovereignty from a different direction than export control.

There is one more thing in this field you cannot ignore: electricity. Data centers are power-hungry facilities, and the spread of AI is swelling that demand further. Where in Japan you can build a data center depends on whether you can secure grid power and use renewable energy. Part of why Ishikari has become a candidate site is its favorable conditions for renewables. Data centers are tightly bound up with energy-conservation policy, decarbonization, and the broader GX (green transformation) agenda, and we have entered a phase where building out the power infrastructure holds the key to industrial siting and economic security alike. Note that future forecasts of data-center power demand and specific figures for energy-efficiency regulation are matters to confirm against the competent ministries' primary materials, so I will avoid asserting them here. What is certain is that we have entered an era in which a physical constraint, electricity, shapes the domestic siting of digital infrastructure.

Supply-chain risk in surveillance cameras and IoT devices

From here we descend to more everyday equipment. Network cameras in offices and factories, routers, and various IoT devices. The recognition that these can become holes in economic security has worked its way into the rules. Japan has no law that, as in the United States, shuts specific brands out of government procurement by name. Instead, it addresses the risk by layering several mechanisms.

The first is NOTICE (National Operation Towards IoT Clean Environment). Launched on February 20, 2019 by the MIC, NICT (the National Institute of Information and Communications Technology), the ICT-ISAC, and telecom operators, it targets IoT devices connected via global IP addresses. It surveys devices that can be broken into with easily guessed IDs and passwords and, via internet service providers, alerts the affected users.8 The targets explicitly include network cameras, that is, surveillance cameras, alongside routers. A camera left on its default password gets hijacked and turned into a springboard for a large-scale cyberattack. NOTICE is a nationwide countermeasure to that real-world threat. Its legal basis was put in place through a revision to the NICT Act (the Act on the National Institute of Information and Communications Technology).8

The second is mandatory IoT-device security via a revision to the Terminal Equipment Rules. The MIC revised these rules to require, as a technical standard, that IoT devices and the like connected to networks be equipped with functions such as access control, a function that forces the initial default password to be changed, and a function to update firmware. The basis is conformity to the technical standards under Article 52 of the Telecommunications Business Act.9 These technical standards are generally understood to have taken effect in 2020. Do not let devices be used on their factory-set passwords; do not let devices that cannot be updated be sold. The rules draw that minimum line. It makes sense once you understand it as nipping vulnerabilities in the bud from the hardware side.

The third is supply-chain risk handling in government procurement itself. Through an interagency agreement of December 10, 2018, "the agreement on the procurement policy and procedures for the state's goods and services relating to IT procurement," the government is understood to have set up a framework that factors supply-chain risks, such as the insertion of malicious functions, into procurement of government IT equipment and services. It is not run by naming specific companies or countries, but it has been reflected in procurement policy for communications equipment and, working in tandem with the later 305-item Government Cloud requirements, ISMAP, and the critical-infrastructure prior review, has shaped the government's procurement security standards. Government-wide cybersecurity and procurement supply-chain risk are now handled by the National Cyber Office (NCO, the former NISC).10 The exact title of this agreement and its current validity should be confirmed against the original text, so I touch on it cautiously here.

What companies should do right now

Having laid out the rules, what should a private company tackle first? Pushed to its essence, I believe the work in this field comes down to one thing: judging, against the rules' yardstick, "who you buy equipment and software from, and to whom you provide or export what," and keeping a continuous record of it. It sounds unglamorous, but if this crumbles, every other measure loses its footing.

The work sorts into three broad tasks. The first is counterparty screening. Check the sources of servers, network equipment, surveillance cameras, and high-performance GPUs, as well as data-center and cloud-service partners, against denied-party lists such as the U.S. Entity List, and from the standpoint of de facto control that reaches into indirect ownership relationships. The integrity of that supply chain is exactly what the government-procurement supply-chain agreement and critical-infrastructure prior review ask about. Our complete guide to sanctions and denied-party lists lays out how to approach the checking.

The second is export classification (gaihi hantei). Semiconductors, servers, high-performance GPUs, communications equipment, and cryptographic products used in data centers, cloud, and AI infrastructure are items that readily fall under Japan's Foreign Exchange and Foreign Trade Act (FEFTA / 外為法) and the U.S. Export Administration Regulations (EAR). Classification is needed not only when exporting abroad, but also for "deemed exports," where a foreign engineer inside Japan is given access to technical information. For the basics of classification, see our explainer on METI's classification guidelines; for the pitfalls of deemed exports, see our deemed-export risk guide. The third is visibility and record-keeping across the supply chain. Only once you can leave an auditable trail of who you bought from and to whom you handed things over can you withstand review or audit.

Running these three by hand is, frankly, a heavy burden. The rules expand almost every year, with new additions to specified critical materials and new critical-infrastructure sectors. Manual work cannot keep up. TRAFEED, the service we provide, was built to lighten this counterparty-screening and classification burden with AI. It automatically checks against denied-party lists and de facto control relationships, accelerates classification aligned with METI's standards, and reflects each country's legal amendments the same day. In a joint demonstration with Okayama University we confirmed classification accuracy of 95% or higher (per our own study based on past review data); we hold Japanese Patent No. 7862062 and have been adopted by more than 20 organizations. Of course, the final classification is made by the customer's own export-control officer, and the AI is merely a tool to make that judgment faster and more accurate. I have no intention of hard-selling, but the ability to bring screening, classification, and continuous monitoring into a single workflow should be a realistic option for procurement and export-control teams handling digital infrastructure.

Conclusion

Economic security for data centers, cloud, and IoT devices is an area where three things overlap: procurement, export control, and cyber. To close, here are the points I want you to hold on to.

  • Cloud programs were designated a specified critical material in December 2022, with METI as the competent ministry. As of July 2026, there were 151 certifications, with roughly 2.56 trillion yen in budget secured.
  • Government procurement is, as a rule, from the ISMAP Cloud Service List, and the Government Cloud set 305 technical requirements. The domestic Sakura no Cloud was selected as well.
  • Under the critical-infrastructure system, telecommunications is a target sector, and the introduction and outsourcing of critical equipment is subject to prior review. Vendors who deliver equipment are also asked to explain their supply chains.
  • The domestic siting of data centers is framed as "the security of data and servers and economic security," with regional dispersion and securing power supply as the key issues.
  • IoT devices are covered in layers by NOTICE, the Terminal Equipment Rules, and the 2018 government-procurement agreement, and surveillance cameras are an explicit target.

Responsibility is scattered, and the whole picture is genuinely hard to grasp. Even so, the core of what companies must do converges on a single point: judge who you buy from and to whom you hand things over, against the yardstick of the rules, and keep recording it. For the companies that turn this into a system, the demands of economic security shift from a "heavy burden" to a "matter of course." If you are unsure where in your own organization to start, feel free to reach out through our consultation on economic security and export control. It looks distant while it stays abstract, but the moment you bring it down to a single item in your own catalog, all of this becomes personal in a hurry.


Footnotes

  1. Cabinet Office, "Economic Security (Economic Security Promotion Act)" https://www.cao.go.jp/keizai_anzen_hosho/index.html

  2. Cabinet Office, "System for Ensuring the Stable Supply of Critical Materials (Supply Chain Resilience)" https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/supply_chain/supply_chain.html 2 3 4

  3. Digital Agency, "Cybersecurity" https://www.digital.go.jp/policies/security 2 3 4

  4. ISMAP Portal, "Information system Security Management and Assessment Program" https://www.ismap.go.jp/csm

  5. Digital Agency, "Government Cloud" https://www.digital.go.jp/policies/gov_cloud 2 3

  6. Cabinet Office, "System for Ensuring the Stable Provision of Critical Infrastructure Services" https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/infra.html 2 3 4

  7. Ministry of Internal Affairs and Communications, "Digital Infrastructure Development through Regional Consolidation of Data Centers and AI/Cloud" https://www.soumu.go.jp/menu_seisaku/ictseisaku/digital_infrastructure/index.html 2 3

  8. NOTICE, "Survey and Alerts for IoT Devices at Risk of Being Abused in Cyberattacks" (MIC and NICT) https://notice.go.jp/ 2

  9. Ministry of Internal Affairs and Communications, "Terminal Equipment Rules (IoT device security technical standards / Article 52 of the Telecommunications Business Act)" https://www.soumu.go.jp/main_sosiki/joho_tsusin/tanmatu/index.html

  10. National Cyber Office (NCO, formerly NISC) https://www.cyber.go.jp/

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles