started · updated
Japan prepares SCS cybersecurity evaluation system for supply chains
Japan is preparing to implement the Supply Chain Security (SCS) Evaluation System, scheduled to begin operations around March 2027. Managed by the Ministry of Economy, Trade and Industry and the Cabinet Secretariat, the system aims to visualize cybersecurity levels across supply chains to mitigate risks from cyberattacks targeting less secure vendors.
The system categorizes security measures into levels, specifically focusing on ★3 and ★4 requirements. These requirements emphasize not just technology adoption, but the establishment of operational frameworks, access management, information sharing rules, and accountability through evidence-based processes.
In response to the upcoming mandate, Internet Initiative Japan (IIJ) has launched an assessment solution to help companies achieve ★3 and ★4 ratings. The two-month package includes self-check sheets, consultant-led interviews, and the development of improvement roadmaps. Additionally, companies like Atomitech are hosting educational webinars to assist businesses in navigating the new compliance landscape and managing vendor risks effectively.
Entities
Atomitech Inc. · Cabinet Secretariat · Dropbox Japan · Internet Initiative Japan Inc. · MIXI Inc. · Ministry of Economy, Trade and Industry · SCS Evaluation System