Hello, this is Hamamoto from TIMEWELL. Over the past year, I have heard the line "we're SaaS, so export control doesn't apply to us" more times than I can count. I understand the instinct. You don't ship physical goods, you have no warehouse, and there is no customs entry. In reality, though, SaaS and software sit deeper inside the export control net than almost any other field.
Working through this series on industry-specific export control has reminded me how unusual SaaS is. The goods don't move, but the technology does. An API with an embedded cryptographic algorithm crosses a border the moment its client sits overseas. Hire a remote engineer overseas, and the deemed export issue is triggered at the instant of onboarding. On top of that, Japan has its own government procurement gate — ISMAP — whose standards were substantially revised at the end of 2025. This article organizes what SaaS and software companies need to get right as of April 2026, in five practical topics.
Work through where your encryption-bearing SaaS lands under the EAR: A fill-in working sheet covering "subject to the EAR? -> ECCN on the CCL? -> EAR99?", the cases where an EAR99 item still needs a license (embargoed destinations, end-use, end-user), de minimis / FDP, counterparty screening, and the two-track cross-check with Japan's classification. You can keep it as a filled-in record for your own items and destinations rather than re-deriving the flow each time. → Download the EAR flow & EAR99 checklist (Free. Registration with your company name and work email address is required.)
SaaS is a party to export control even when it thinks it isn't
The first thing SaaS companies trip on is the definition of "export." Both Japan's Foreign Exchange and Foreign Trade Act and the U.S. EAR cover not only goods, but also technology and services. SaaS doesn't move goods, but delivering technology is its entire business, so it sits at the center of the control perimeter rather than outside it.
The U.S. EAR (Export Administration Regulations) sweeps a lot of encryption software into Category 5 Part 2, and if your product implements TLS, VPN, file-based encryption, or end-to-end messaging, it may qualify as 5D002 or 5A002. Integrate a U.S.-origin library or OSS, and the de minimis rule (25% U.S.-origin content — 10% for certain countries) extends U.S. re-export control to your Japanese entity. "We're fully domestic" is a harder claim than most SaaS companies realize.
Under domestic law, METI issued a notice in 2013 on cloud services and service transactions. The key point there was: "if data merely passes through or is stored in an encrypted state on overseas servers, it does not qualify as a service transaction." But that concerns data transit. If you provide the encryption technology itself to an overseas base, or if decryption keys are handled outside Japan, it is a different analysis.
SaaS often blurs the line between "provision of services" and "provision of a program." Monthly subscription API access tends toward a service transaction; distributing an on-premises installer or virtual appliance tilts toward a program. Companies that offer both models need to run classification per service. In practice, many teams try to manage this in a single spreadsheet and end up with inconsistent granularity. Japanese SaaS companies have not yet matured their export control operations to the level of manufacturing, and viewed through METI's security trade control lens, SaaS feels about a decade behind manufacturing.
ISMAP's 2026 revision reshapes government procurement and cloud provider response
For domestic SaaS operators, ISMAP (Information System Security Management and Assessment Program) is just as unavoidable as export control. The program is meant to assure the security level of cloud services in government procurement, and since its launch in 2020, the major CSPs — AWS, Microsoft Azure, Google Cloud, IIJ, Sakura Internet — have registered.
Without a listing on the ISMAP Cloud Service List, you cannot even enter the bidding round for government platform systems, and some local government procurements are also locked. That has been a meaningful barrier to entry for Japanese SaaS companies, especially mid-sized ones. The cost of acquisition and maintenance has long been called excessive, and on September 18, 2025 the government published a proposal for a broad revision of the control baseline and put it out for public comment through October 17. The results were published on December 25, 2025, with 60 submissions and revisions made to the draft12.
The revision has two main points. First, it imports the governance, management, and control baselines from the Information Security Management Standard (2025 revision), which reflects updates to the international standards, and adds the cloud-specific controls from the Cloud Information Security Management Standard (2016 edition) plus controls drawn from the Common Standards for Government Agencies and NIST SP 800-53 rev.5. Second, the detailed control items are compressed from 1,163 to 322 — roughly a 70% cut3. This reduction is less a lightening of the checklist and more a change of granularity: the detailed controls are pared back to "the minimum description needed to achieve the control objective," and the concrete how-to moves into a newly created implementation guide. The correct reading is that quality was not cut — the granularity changed.
In January 2026, IIJ announced the additional registration of its cloud-based authentication service (IIJ ID Service / Identity Management Option) and its cloud-based web security service4. When the revised baseline will actually apply, and what transitional treatment already-registered providers will receive, was still described in the December 25, 2025 comment response as something the government "will continue to consider carefully, taking into account the views of the parties involved"2. The guidelines and other regulations are also still being drafted. It is a good moment for mid-sized SaaS providers that had passed on ISMAP to revisit the question, but plan on tracking official announcements for the schedule. Honestly, 322 items is still not a low bar. Rather than tackling it solo, a realistic path for SaaS built on AWS is to rely on AWS's ISMAP registration and focus on the controls you actually own.
On a side note, I get occasional questions that conflate ISMAP with JC-STAR (IPA's IoT security labeling scheme). JC-STAR targets IoT products; ISMAP targets cloud services — they cover different things. JC-STAR's Level 1 and Level 2 both run on vendor self-declaration and are currently accepting new applications. For Level 3, which requires third-party evaluation, IPA published the security requirements for communication equipment and network cameras on February 6, 2026, and the conformance requirements for those same two product types on June 12, 20265. Pure SaaS is outside JC-STAR's scope, but B2B SaaS vendors whose products pair with hardware should watch both.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The deemed export trap: hiring overseas engineers pulls the trigger
SaaS lives or dies by its engineers. Almost no company can staff entirely from domestic talent anymore, and fully remote hiring from India, Vietnam, or Ukraine is now routine. This is where deemed export steps in.
Article 25(1) of the Foreign Exchange and Foreign Trade Act treats the provision of technology by a resident in Japan to a non-resident as an "export" of controlled technology, and the May 1, 2022 amendment clarified operations6. The key point of the amendment: even a person who is formally a resident, if judged to be under the strong influence of a foreign government or foreign company, is treated in substance the same as a non-resident for technology transfer. Typical indicators include strong ties to foreign governments or militaries, being under the direction of a foreign company, and receiving non-refundable scholarships from foreign governments (under certain conditions).
Here is what SaaS HR actually encounters. You want to hire a strong backend engineer who holds Chinese nationality. The individual has lived in Japan for a long time and is treated as a resident. But if they earned a doctorate on their home country's scholarship and continue to receive conditional support from that fund, after the 2022 amendment they may fall within deemed export control. Hiring is not prohibited. What you need is a design that controls access to relevant technology (encryption, AI, defense-related functionality) and a mechanism to assess whether prior METI licensing is required.
On January 31, 2025, METI published a draft amendment to the ministerial ordinance, and the revised supplementary export controls took effect on October 9, 20257. The catch-all controls were tightened there, which also affects deemed export decisions. What SaaS companies should do now is add "relationship with foreign governments, militaries, and foreign companies," "source of funding," and "current residence and travel history" to the hiring checklist, and formalize consents and declarations. Beyond paperwork, you need a design that scopes access by attribute — GitHub branch permissions, Snowflake roles, Kubernetes namespaces — so that scope can be narrowed by candidate profile.
I wrote more detail in A Practical Guide to Deemed Export Risk, but the scariest deemed export pattern is the one you notice after the hire. By the time you realize, the person has already touched the source repository, the audit trail is there, and you cannot walk it back. Whether HR, engineering, and legal can sit at the same table and discuss cases together is the real firewall.
The data residency, encryption, and API-delivery trio
When you talk about SaaS export control, data residency, encryption, and API delivery are inseparable. Each gets discussed on its own, but in operation they must be designed as a set — otherwise you will leave gaps.
On data residency, Japan has no restriction on the storage location itself under the Act on the Protection of Personal Information. But when personal data is stored overseas, you must check the destination country's data protection regime and implement safety management measures (Article 28). Note that an act amending the APPI and related laws passed the Diet on July 10, 2026 and was promulgated on July 17, 2026; apart from certain provisions it takes effect on a date to be fixed by cabinet order within two years of promulgation, so cross-border transfer practice will need to track the forthcoming cabinet orders, commission rules, and guidelines8. For government information systems, Digital Society Promotion Standard Guideline DS-310 (September 2023) applies, and the government cloud assumes closed domestic use9. Interestingly, even for information requiring protection, the guideline allows non-domestic data centers if the data is encrypted with an algorithm on the CRYPTREC cipher list (e-Government recommended ciphers) and the keys are managed by the user side or a tamper-resistant device. In other words, if you do encryption and key management properly, AWS's overseas regions can be on the table.
Next, encryption. EAR Category 5 Part 2 covers encryption software that meets criteria such as symmetric keys over 128 bits or asymmetric keys over 2048 bits. Modern algorithms like AES-256, RSA-4096, and ECC almost all cross that line. Japanese SaaS companies rarely implement these themselves; in practice they use AWS KMS, Azure Key Vault, or Google Cloud KMS. In that case, the division of responsibility for export control matters. The CSP has handled classification and filings at the infrastructure layer, but if you implement additional cryptographic features at the application layer, that layer is yours to classify.
Third, API delivery. Letting overseas users hit your SaaS endpoints is not the same thing as "passage of encrypted data" under METI's notice — the provision of the function itself may qualify as a service transaction. Concretely: providing API specifications and technical manuals to overseas customers, providing implementation support as a customer success function to overseas engineers, and contributing technical know-how in joint development are all service transaction questions. Under the catch-all controls covering conventional weapons and WMD, screening whether your customer falls into a restricted country or a suspect end user is a must.
Running this trio on manual spreadsheets is honestly at its limit. Our product TRAFEED (formerly ZEROCK ExCHECK) is an AI agent that handles customer screening, classification support, and technical information management end to end — billed as the world's first AI-based export control tool, operated in line with METI standards. A SaaS company using SaaS to protect its SaaS is a bit nested, but the reduction in manual effort is dramatic.
AI SaaS cannot relax, even "post-AI-Diffusion rescission"
In January 2025, the Biden administration published the "Framework for Artificial Intelligence Diffusion." It was an ambitious package that controlled the flow of AI model weights and advanced compute chips, reaching even into access controls via IaaS (Infrastructure as a Service). Many AI SaaS companies braced for impact — I remember it well.
But on May 13, 2025, BIS issued guidance rescinding that framework. Since then BIS has enforced the worldwide license requirement on advanced computing items (ECCNs 3A090.a, 4A090.a and related ".z" entries) only for destinations in Country Groups D:1, D:4, and D:5 — excluding those also listed in A:5 or A:6 — and for entities headquartered, or with an ultimate parent headquartered, in Country Group D:5 or Macau, wherever located10. Then on January 15, 2026, BIS's final rule "Revision to License Review Policy for Advanced Computing Commodities" was published in the Federal Register and took effect the same day. It moves the license review policy for exports from the United States to end users located in China or Macau of items at the NVIDIA H200 / AMD MI325X level (TPP under 21,000 and total DRAM bandwidth under 6,500 GB/s) from a presumption of denial to a conditional case-by-case review11. Read in isolation, that looks like loosening.
However, the parts that concern AI SaaS have not really loosened. Even the January 2026 final rule keeps a presumption of denial for reexports (including exports from abroad) and in-country transfers destined for Macau or a Country Group D:5 destination, and for entities headquartered or ultimately parented in Macau or a Country Group D:5 destination. On top of that, a license applicant must submit a list of "IaaS remote end users" located in — or whose ultimate parent is headquartered in — Belarus, China, Cuba, Iran, Macau, North Korea, Russia, or Venezuela, and BIS and the reviewing agencies decide on that basis case by case11. A Japanese AI SaaS offering a large language model via API that issues API keys to a mainland Chinese startup is already in the scope of that question. User-onboarding KYC (Know Your Customer), IP-based geoblocking, token usage limits, and audit log retention need to be designed together.
My personal read is that the AI Diffusion Rule rescission is best interpreted as "the framework is rescinded, but the individual rules continue and intensify." Let the surface-level easing news push you into "our AI SaaS is fine" and you may eat heavy penalties later. Civil penalties for EAR violations are capped, under the Export Control Reform Act (ECRA, 50 U.S.C. 4819), at the greater of twice the transaction value or a statutory maximum that is adjusted for inflation every year; as of July 2026 that maximum is USD 374,474 under ECRA and USD 377,700 under IEEPA (50 U.S.C. 1705(b))12. Add exclusion from the U.S. market and SDN listing, and these become management risks that hit the top line directly.
Domestically, METI is likewise moving to explicitly cover AI and cloud APIs, as I laid out in The 2026 Amendments to AI, Semiconductor, and Cloud Export Controls. Combined with the trend toward excluding Chinese IT from government and local government procurement, which I covered in Exclusion of Chinese IT from Japanese Local Governments in 2026, export control infrastructure is becoming an upfront investment for Japanese AI SaaS to survive domestic government and municipal markets. The shift is from "do it to differentiate" to "do it or be cut in the first round."
If you start on SaaS export control today in 2026
Running through these five topics, the common thread is that SaaS tends to become a party to export control before it notices. Unlike manufacturing, there is no physical customs event, so the trigger is hard to see. That invisibility is the biggest risk, and once an issue surfaces, customer churn and brand damage can be worse than the equivalent in physical goods smuggling.
A realistic starting sequence. First, refresh classification for your SaaS at the product level. EAR applicability, Foreign Exchange Act applicability, encryption classification — just holding these three in a single table moves the internal discussion forward. Second, embed an overseas-hire deemed export check into the hiring process. Don't leave it to HR alone; pull in legal and engineering, and close the loop all the way to post-hire access control. Third, re-evaluate ISMAP. The start date for the revised baseline has not been fixed yet, but the direction — detailed controls consolidated from 1,163 to 322 — is already on the table, so companies that had given up should re-read the requirements now.
Fourth, systematize customer screening. Manual effort cannot keep up with the pace of sanctions list updates and will miss entries. Offload it to an AI agent like TRAFEED and let people focus on review and judgment. SaaS as a business now moves too fast for manual export control operations to keep up, which means export control operations need to run at the same cadence.
Export control is often seen as being at odds with "offensive" management, but watching the past three years — U.S.-China confrontation, the economic security trend, the EU AI Act, Japan's tightening of catch-all controls — I would say that companies that have built out their export control are precisely the ones who can accelerate overseas expansion. Reframe it not as defensive spend but as the ground floor for taking your product overseas. For SaaS companies, 2026 is the year that turning point lands.
If you are reviewing export-control operations or classification workflows, download the TRAFEED product catalog (PDF) or contact us.
References
Footnotes
-
PwC Japan, "New developments in ISMAP: the broad revision of the ISMAP control baseline and the outlook for ISMAP going forward" https://www.pwc.com/jp/ja/knowledge/column/awareness-cyber-security/explanation-of-ismap2.html ↩
-
e-Gov Public Comment, "Results of the public comment on the draft ISMAP Control Baseline and related documents," case no. 060250918 (draft published September 18, 2025 / comments closed October 17, 2025 / results published December 25, 2025 / 60 submissions) https://public-comment.e-gov.go.jp/pcm/1040?CLASSNAME=PCM1040&Mode=1&id=060250918 ↩ ↩2
-
National Cyber Office, Digital Agency, MIC and METI, "[Reference] On the revision of the ISMAP Control Baseline (draft)," September 18, 2025 (detailed controls cut from 1,163 to 322) https://public-comment.e-gov.go.jp/pcm/download?seqNo=0000299114 ↩
-
IIJ, "Cloud-based authentication service and cloud-based web security service registered with ISMAP" January 13, 2026 https://www.iij.ad.jp/news/pressrelease/2026/0113.html ↩
-
IPA, "Security Requirements Compliance Assessment and Labeling Scheme (JC-STAR)" https://www.ipa.go.jp/security/jc-star/index.html ↩
-
METI Trade Control Department, "Clarification of deemed export control operations" https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf ↩
-
EY Japan, "METI publishes draft amendments — strengthening security trade control including catch-all controls" https://www.ey.com/ja_jp/technical/ey-japan-tax-library/tax-alerts/2025/tax-alerts-02-06-03 ↩
-
Personal Information Protection Commission, "Promulgation of the Act Partially Amending the Act on the Protection of Personal Information and Related Acts (July 17, 2026)" https://www.ppc.go.jp/news/press/2026/260717/ ↩
-
Digital Agency, "Digital Society Promotion Standard Guideline DS-310: Basic policy on appropriate use of cloud services in government information systems" https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/e2a06143-ed29-4f1d-9c31-0f06fca67afc/5167e265/20230929_resources_standard_guidelines_guideline_01.pdf ↩
-
U.S. Bureau of Industry and Security, "Enhanced Favorable Treatment for the United Arab Emirates Under the Export Administration Regulations," Federal Register, July 14, 2026 (states the enforcement scope based on BIS guidance of May 13, 2025 and May 31, 2026) https://www.federalregister.gov/documents/2026/07/14/2026-14132/enhanced-favorable-treatment-for-the-united-arab-emirates-under-the-export-administration ↩
-
U.S. Bureau of Industry and Security, "Revision to License Review Policy for Advanced Computing Commodities," Federal Register, published and effective January 15, 2026 (document no. 2026-00789) https://www.federalregister.gov/documents/2026/01/15/2026-00789/revision-to-license-review-policy-for-advanced-computing-commodities ↩ ↩2
-
15 CFR § 6.3 (U.S. Department of Commerce civil monetary penalty inflation adjustments; USD 374,474 under ECRA and USD 377,700 under IEEPA in the current eCFR) https://www.ecfr.gov/current/title-15/subtitle-A/part-6 ↩
![Export Control for SaaS and Software Companies: Deemed Export, ISMAP, and Cloud Regulations in Practice [2026 Edition]](/images/columns/saas-software-industry-export-control/cover.png)





