TRAFEED

Japan's Local-Government IT Procurement Shift (2027) — What Global Vendors Need on JC-STAR, ISMAP, and Supply Chains

Published2026-04-24Updated2026-08-09Ryuta Hamamoto

Japan's 2027 local-government IT procurement shift is certification-led, not a simple name ban. What global vendors need on JC-STAR, ISMAP, and RFPs.

Japan's Local-Government IT Procurement Shift (2027) — What Global Vendors Need on JC-STAR, ISMAP, and Supply Chains
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

In April 2026, Japan's Takaichi administration announced a policy that will limit local-government IT procurement to government-certified products12. A Ministry of Internal Affairs and Communications (MIC) ordinance is expected in June 2026; operations start in summer 2027.

On paper it is an administrative rule about PCs, servers, and cloud. In practice it redraws who can sell into one of Japan's largest distributed public IT markets — about 1,700 local governments — and it does so through certification design rather than a country-name ban. Because JC-STAR and ISMAP do not currently certify Chinese vendors, products associated with makers such as Huawei and ZTE effectively leave that procurement network.

The same week, Tokyo issued an order to stop the Makino Milling Machine acquisition (22 April) and the National Security Information Council bill cleared the Lower House (23 April). Lined up together, the three moves show economic security policy accelerating under this administration.

I walk through what was decided, why local government, the intent stack, and — for global vendors, integrators, and compliance teams — how to read the supply-chain impact. If you want a quick read on export-control and procurement readiness, use our free export-control readiness check.


What was actually decided

Key points134:

Item Content
Scope All local governments in Japan
Target equipment PCs, tablets, communications equipment, servers, cloud services
Mechanism Procurement limited to government-certified products (JC-STAR / ISMAP)
Ordinance revision June 2026 (planned)
Operation start Summer 2027
Existing equipment Switch to certified products at renewal

Two certification tracks matter. JC-STAR (Japan Cybersecurity Star), under METI, assesses security conformity for IoT and similar devices. ISMAP (Information System Security Management and Assessment Program), under the Cybersecurity Strategic Headquarters, covers cloud security assessment. For how JC-STAR is already used as an economic-security instrument, see JC-STAR and Chinese storage batteries.

Neither scheme currently certifies Chinese vendors. The legal shape is not "we ban Chinese products by name." It is "you may only buy certified products — and those products are not on the list." Certification as regulation; exclusion as operational result.


Why local governments, not another central-ministry memo?

Central ministries have run similar guidance since 20181. This step finally pushes a working pattern down to municipalities.

Why the gap lasted: scale and fragmentation. Roughly 1,700 local governments run their own tenders. A uniform security baseline is hard. Chinese-made equipment that left central ministries often remained in local environments.

Those environments hold resident information, My Number records, local tax data, and medical and long-term care data. Security practitioners have argued for years that Japan's soft underbelly sits at local government. This policy is Tokyo closing that gap from the top.


Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Three layers of intent

1) Response to Chinese economic statecraft

In February 2026, China published an export-control list covering 40 Japanese entities, including Mitsubishi Heavy Industries, SUBARU, TDK, and JAXA. That is economic statecraft using trade tools to pressure policy. Details: China's export controls on Japan.

From Tokyo's seat, dependence on Chinese IT in government systems is harder to leave open. The local-government rule encodes that judgment in procurement law.

2) Paired with the National Security Information Council

The National Security Information Council bill creates an intelligence-policy apex body chaired by the Prime Minister. A top-level decision body without a better government and local IT baseline is incomplete. Policy layer (Council), execution layer (national intelligence architecture), field layer (IT equipment certification) — moving together is the real story of that announcement week.

3) A domestic market for certified kit

Certification also guarantees demand. Domestic manufacturers, data-center operators, and cloud providers gain a clearer path to public share. Security-framed industrial preference is not unique to Japan; the US Buy American tradition is the familiar comparison. In Japan, the tailwind lands with players such as NEC, Fujitsu, Sakura Internet, and NTT Communications.


One continuous arc, not a one-off ban

Standalone, the story is easy to misread as ad hoc China politics. Chronology shows a long net:

Year Event
2018 Central-ministry IT procurement effectively excludes Chinese products (government guidance)
2020 Government drone procurement effectively excludes Chinese makers such as DJI
2022 Economic Security Promotion Act enacted
2023 14 critical infrastructure sectors designated
2024 Pre-notification and review for critical infrastructure fully operational
Feb 2026 China's export-control list targeting 40 Japanese entities
22 Apr 2026 Makino Milling acquisition blocked (first use of FEFTA block power in that form)
23 Apr 2026 National Security Information Council bill clears Lower House
Apr 2026 Local-government IT certification policy

Read in order: central ministries → drones → critical infrastructure → individual acquisitions → intelligence architecture → local governments.

List placement and certification outcomes are regulatory designations. They are not a moral verdict on any named firm. Write and brief them as control categories, not as character judgments — especially when those firms may sit in your own customer or partner set.


Why "we're not a Japanese local government" fails

The ordinance hits local governments. Private and foreign companies still feel it through three channels.

Under the Economic Security Promotion Act, 14 sectors are "specified social infrastructure"5:

  • Electricity, gas, oil
  • Water
  • Railways, trucking, international shipping, aviation, airports
  • Telecommunications, broadcasting
  • Finance, credit cards

Operators must notify and obtain review before introducing or outsourcing maintenance of "specified critical equipment." In practice, Chinese-origin specified equipment is hard to adopt there as well.

Channel 1 — You sell into the public or critical-infrastructure chain. Local governments and designated operators will demand security explanations you can document: origin, certification status, firmware lineage, cloud region, subcontractors.

Channel 2 — Overseas counterparties, especially US buyers, already ask. Questionnaires increasingly include "any Chinese IT equipment or components in use." An empty answer when systems still run uncertified Chinese kit is a deal risk, not a paperwork quirk.

Channel 3 — Deemed export and technical access. Foreign-national engineers and shared design environments now sit next to the same supply-chain questions.

"We don't sell to cities, so this is irrelevant" breaks the day a customer or US partner sends a due-diligence pack you cannot complete. The US debate over Chinese-made devices now reaches well beyond federal procurement — including consumer devices. Background: US campaign on Chinese-made devices.


Open operational issues

Cost and schedule. Replacing installed base is heavy. Smaller municipalities may struggle to finish by summer 2027.

Certification transparency. JC-STAR and ISMAP do not publish a country-exclusion list. Criteria clarity remains an open governance task — similar transparency debates appeared after the Makino Milling block.

Competition effects. If certification becomes a soft guarantee of wins, domestic vendors may under-invest in competition. Oversight on that line will matter.

Chinese countermeasures. Further regulation or retaliatory export controls aimed at Japanese companies are plausible. The February 40-entity list is best read as an opening move, not a one-time event.


What global vendors and procurement teams should do

If you sell to Japanese local governments, SI partners, or critical infrastructure operators

  • Map country-of-origin for every IT product, major component, and software package in the offered stack
  • Confirm JC-STAR / ISMAP status for target SKUs, or a migration plan to certified alternatives
  • Prepare Japanese-language and English evidence packs (BOM origin, firmware provenance, cloud regions, support centers)
  • Build renewal timelines that match the 2027 operational start and existing-equipment replacement cycles

If your Japan entity or partner is in the supply chain only

  • Expect questionnaires from integrators who are bidding
  • Treat Chinese-origin silicon, radios, and cloud sub-services as disclosure items, not footnotes
  • Align answers with Entity List, Foreign User List, and sanctions screening so trade compliance and procurement tell the same story

If you are US- or EU-facing with Japan content

  • Inventory Chinese IT exposure the same way you already inventory EAR / de minimis content
  • Manual Excel screening of counterparties and components does not scale for 2026 volumes

Our AI export-control agent TRAFEED is built for that last problem: multi-list counterparty screening and AI-assisted first-pass controlled-goods work with audit trails that map to METI-style expectations. Final decisions stay with your compliance officer; the tool compresses research and documentation.

Export and procurement teams still running on tribal knowledge are out of step with the 2026 environment. Using this policy as a forcing function to operationalize origin and certification data is, in my view, the cheapest insurance available.


If you are reviewing export-control or supplier-screening workflows, download the TRAFEED product catalog (PDF) or contact us.

Summary

  • What: Local-government PCs, communications gear, servers, and cloud limited to certified products from summer 2027
  • How: JC-STAR and ISMAP — Chinese products effectively excluded without a country-name ban statute
  • Why: Sensitive resident and My Number data; response to Chinese economic coercion; industrial policy for certified domestic capacity
  • Arc: Central ministries (2018) → drones (2020) → critical infrastructure (2023–24) → local governments (2026–27)
  • Vendor impact: Public and critical-infrastructure sales, US-facing questionnaires, and multi-tier supply-chain transparency

Even if you believe this "has nothing to do with us," walk two or three steps up your customer chain. The odds you touch this net are higher than most sales decks admit. Audit Chinese IT exposure and certification status before your next RFP, not after the award is lost.

For TRAFEED details, materials, or a demo, see the product page. To talk through your company, book a consultation.


References

Footnotes

  1. Local governments to exclude Chinese products in IT procurement — Nikkei (2026-04-17) 2 3

  2. Government to limit local IT procurement to certified products — Business+IT

  3. MIC to revise ordinance to exclude Chinese IT in local procurement — Fukushima Minpo

  4. MIC to limit local IT procurement to certified products — Epoch Times Japan

  5. Critical infrastructure regime under the Economic Security Promotion Act — Cabinet Office

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Supply-Chain Due Diligence (Human Rights, Forced Labour, Conflict Minerals) Self-Check Sheet (2026)

A fill-in self-check from the UNGP/OECD six steps to the US UFLPA, EU CSDDD and German LkSG obligations, conflict minerals (3TG) and Japan's guideline — with a plain-language intro. Based on each issuer's primary sources and reflecting the EU CSDDD's 2025–2026 Omnibus changes (thresholds; application in 2029) and the LkSG's operational change. A starting point for procurement, legal and sustainability staff (final decisions rest with each authority's latest guidance and your own officer).

China Business Travel: Technology Pre-Departure Worksheet (fill-in, 2026)

A fill-in worksheet for engineers, sales and researchers travelling to China, and for the teams that send them. Under Japan's Foreign Exchange and Foreign Trade Act, taking technical information on a trip can amount to providing technology in a foreign country (Art. 25(1)), and carrying it on a laptop or opening it from abroad can fall within Art. 25(3)(i). Most trips stay within the exemptions in Article 9 of the Ordinance on Trade Relations Invisible Trade (publicly available technology, basic scientific research, patent filings, technology incidental to exported goods). This worksheet shows where the line sits, situation by situation, with fill-in sections for before, during and after the trip. The China side reflects State Council Order No. 841 (in force 15 September 2026) Arts. 3 and 5, the Exit and Entry Administration Law Art. 28, and Japan's MOFA overseas safety advisory. Classification and licensing decisions rest with your export-control officer.

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles