Hello, this is Ryuta Hamamoto from TIMEWELL.
In April 2026, Japan's Takaichi administration announced a policy that will limit local-government IT procurement to government-certified products12. A Ministry of Internal Affairs and Communications (MIC) ordinance is expected in June 2026; operations start in summer 2027.
On paper it is an administrative rule about PCs, servers, and cloud. In practice it redraws who can sell into one of Japan's largest distributed public IT markets — about 1,700 local governments — and it does so through certification design rather than a country-name ban. Because JC-STAR and ISMAP do not currently certify Chinese vendors, products associated with makers such as Huawei and ZTE effectively leave that procurement network.
The same week, Tokyo issued an order to stop the Makino Milling Machine acquisition (22 April) and the National Security Information Council bill cleared the Lower House (23 April). Lined up together, the three moves show economic security policy accelerating under this administration.
I walk through what was decided, why local government, the intent stack, and — for global vendors, integrators, and compliance teams — how to read the supply-chain impact. If you want a quick read on export-control and procurement readiness, use our free export-control readiness check.
What was actually decided
| Item | Content |
|---|---|
| Scope | All local governments in Japan |
| Target equipment | PCs, tablets, communications equipment, servers, cloud services |
| Mechanism | Procurement limited to government-certified products (JC-STAR / ISMAP) |
| Ordinance revision | June 2026 (planned) |
| Operation start | Summer 2027 |
| Existing equipment | Switch to certified products at renewal |
Two certification tracks matter. JC-STAR (Japan Cybersecurity Star), under METI, assesses security conformity for IoT and similar devices. ISMAP (Information System Security Management and Assessment Program), under the Cybersecurity Strategic Headquarters, covers cloud security assessment. For how JC-STAR is already used as an economic-security instrument, see JC-STAR and Chinese storage batteries.
Neither scheme currently certifies Chinese vendors. The legal shape is not "we ban Chinese products by name." It is "you may only buy certified products — and those products are not on the list." Certification as regulation; exclusion as operational result.
Why local governments, not another central-ministry memo?
Central ministries have run similar guidance since 20181. This step finally pushes a working pattern down to municipalities.
Why the gap lasted: scale and fragmentation. Roughly 1,700 local governments run their own tenders. A uniform security baseline is hard. Chinese-made equipment that left central ministries often remained in local environments.
Those environments hold resident information, My Number records, local tax data, and medical and long-term care data. Security practitioners have argued for years that Japan's soft underbelly sits at local government. This policy is Tokyo closing that gap from the top.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Three layers of intent
1) Response to Chinese economic statecraft
In February 2026, China published an export-control list covering 40 Japanese entities, including Mitsubishi Heavy Industries, SUBARU, TDK, and JAXA. That is economic statecraft using trade tools to pressure policy. Details: China's export controls on Japan.
From Tokyo's seat, dependence on Chinese IT in government systems is harder to leave open. The local-government rule encodes that judgment in procurement law.
2) Paired with the National Security Information Council
The National Security Information Council bill creates an intelligence-policy apex body chaired by the Prime Minister. A top-level decision body without a better government and local IT baseline is incomplete. Policy layer (Council), execution layer (national intelligence architecture), field layer (IT equipment certification) — moving together is the real story of that announcement week.
3) A domestic market for certified kit
Certification also guarantees demand. Domestic manufacturers, data-center operators, and cloud providers gain a clearer path to public share. Security-framed industrial preference is not unique to Japan; the US Buy American tradition is the familiar comparison. In Japan, the tailwind lands with players such as NEC, Fujitsu, Sakura Internet, and NTT Communications.
One continuous arc, not a one-off ban
Standalone, the story is easy to misread as ad hoc China politics. Chronology shows a long net:
| Year | Event |
|---|---|
| 2018 | Central-ministry IT procurement effectively excludes Chinese products (government guidance) |
| 2020 | Government drone procurement effectively excludes Chinese makers such as DJI |
| 2022 | Economic Security Promotion Act enacted |
| 2023 | 14 critical infrastructure sectors designated |
| 2024 | Pre-notification and review for critical infrastructure fully operational |
| Feb 2026 | China's export-control list targeting 40 Japanese entities |
| 22 Apr 2026 | Makino Milling acquisition blocked (first use of FEFTA block power in that form) |
| 23 Apr 2026 | National Security Information Council bill clears Lower House |
| Apr 2026 | Local-government IT certification policy |
Read in order: central ministries → drones → critical infrastructure → individual acquisitions → intelligence architecture → local governments.
List placement and certification outcomes are regulatory designations. They are not a moral verdict on any named firm. Write and brief them as control categories, not as character judgments — especially when those firms may sit in your own customer or partner set.
Why "we're not a Japanese local government" fails
The ordinance hits local governments. Private and foreign companies still feel it through three channels.
Under the Economic Security Promotion Act, 14 sectors are "specified social infrastructure"5:
- Electricity, gas, oil
- Water
- Railways, trucking, international shipping, aviation, airports
- Telecommunications, broadcasting
- Finance, credit cards
Operators must notify and obtain review before introducing or outsourcing maintenance of "specified critical equipment." In practice, Chinese-origin specified equipment is hard to adopt there as well.
Channel 1 — You sell into the public or critical-infrastructure chain. Local governments and designated operators will demand security explanations you can document: origin, certification status, firmware lineage, cloud region, subcontractors.
Channel 2 — Overseas counterparties, especially US buyers, already ask. Questionnaires increasingly include "any Chinese IT equipment or components in use." An empty answer when systems still run uncertified Chinese kit is a deal risk, not a paperwork quirk.
Channel 3 — Deemed export and technical access. Foreign-national engineers and shared design environments now sit next to the same supply-chain questions.
"We don't sell to cities, so this is irrelevant" breaks the day a customer or US partner sends a due-diligence pack you cannot complete. The US debate over Chinese-made devices now reaches well beyond federal procurement — including consumer devices. Background: US campaign on Chinese-made devices.
Open operational issues
Cost and schedule. Replacing installed base is heavy. Smaller municipalities may struggle to finish by summer 2027.
Certification transparency. JC-STAR and ISMAP do not publish a country-exclusion list. Criteria clarity remains an open governance task — similar transparency debates appeared after the Makino Milling block.
Competition effects. If certification becomes a soft guarantee of wins, domestic vendors may under-invest in competition. Oversight on that line will matter.
Chinese countermeasures. Further regulation or retaliatory export controls aimed at Japanese companies are plausible. The February 40-entity list is best read as an opening move, not a one-time event.
What global vendors and procurement teams should do
If you sell to Japanese local governments, SI partners, or critical infrastructure operators
- Map country-of-origin for every IT product, major component, and software package in the offered stack
- Confirm JC-STAR / ISMAP status for target SKUs, or a migration plan to certified alternatives
- Prepare Japanese-language and English evidence packs (BOM origin, firmware provenance, cloud regions, support centers)
- Build renewal timelines that match the 2027 operational start and existing-equipment replacement cycles
If your Japan entity or partner is in the supply chain only
- Expect questionnaires from integrators who are bidding
- Treat Chinese-origin silicon, radios, and cloud sub-services as disclosure items, not footnotes
- Align answers with Entity List, Foreign User List, and sanctions screening so trade compliance and procurement tell the same story
If you are US- or EU-facing with Japan content
- Inventory Chinese IT exposure the same way you already inventory EAR / de minimis content
- Manual Excel screening of counterparties and components does not scale for 2026 volumes
Our AI export-control agent TRAFEED is built for that last problem: multi-list counterparty screening and AI-assisted first-pass controlled-goods work with audit trails that map to METI-style expectations. Final decisions stay with your compliance officer; the tool compresses research and documentation.
Export and procurement teams still running on tribal knowledge are out of step with the 2026 environment. Using this policy as a forcing function to operationalize origin and certification data is, in my view, the cheapest insurance available.
If you are reviewing export-control or supplier-screening workflows, download the TRAFEED product catalog (PDF) or contact us.
Summary
- What: Local-government PCs, communications gear, servers, and cloud limited to certified products from summer 2027
- How: JC-STAR and ISMAP — Chinese products effectively excluded without a country-name ban statute
- Why: Sensitive resident and My Number data; response to Chinese economic coercion; industrial policy for certified domestic capacity
- Arc: Central ministries (2018) → drones (2020) → critical infrastructure (2023–24) → local governments (2026–27)
- Vendor impact: Public and critical-infrastructure sales, US-facing questionnaires, and multi-tier supply-chain transparency
Even if you believe this "has nothing to do with us," walk two or three steps up your customer chain. The odds you touch this net are higher than most sales decks admit. Audit Chinese IT exposure and certification status before your next RFP, not after the award is lost.
For TRAFEED details, materials, or a demo, see the product page. To talk through your company, book a consultation.
References
Footnotes
-
Local governments to exclude Chinese products in IT procurement — Nikkei (2026-04-17) ↩ ↩2 ↩3
-
Government to limit local IT procurement to certified products — Business+IT ↩
-
MIC to revise ordinance to exclude Chinese IT in local procurement — Fukushima Minpo ↩
-
MIC to limit local IT procurement to certified products — Epoch Times Japan ↩
-
Critical infrastructure regime under the Economic Security Promotion Act — Cabinet Office ↩


![JC-STAR and Chinese Storage Batteries: Japan's IoT Cyber Label, Economic Security, and the "De Facto Exclusion" Dispute [2026 Edition]](/images/columns/jc-star-china-battery-economic-security-2026/cover.png)



