JAPAN Trends and Developments Contributed by: Yasushi Kudo, Yukiko Konno and Takayuki Inukai, Nagashima Ohno & Tsunematsu
Cybersecurity Response Capability Enhancement Act The Cybersecurity Response Capability Enhance - ment Act (official title: Act on Prevention of Damage Caused by Unauthorized Acts Against Important Computers; the “Act” in this section), promulgated on 23 May 2025, aims to prevent harm caused by specified unlawful acts (“Specified Unlawful Acts”) defined under the Act, such as unauthorised access, against important computers (“Important Computers”) as defined under the Act. These computers are used by the national government, critical infrastructure, and business operators that hold important information (ie, information classified under Japanese national secu - rity related laws, including special defence secrets, designated secrets, defence equipment secrets, and critical economic security information). It establishes a comprehensive framework for the government’s acquisition and analysis of telecommunications infor - mation defined under the Act, reporting systems for special social infrastructure operators (“Special-SIO”) defined under the Act, agreement-based public–pri - vate information sharing, requests for co-operation to telecommunications carriers, and supervisory and inspection mechanisms. Implementation will be phased, and the Act’s core provisions, including the notification and reporting obligations described below, are scheduled to come into force on 1 October 2026 (not yet formally determined). The Act is one of the key components of Japan’s Active Cyber Defense policy and establishes the principle that the exercise of powers must be strictly limited to the minimum necessary, with due regard for the constitutionally guaranteed secrecy of telecom - munications. In imposing incident reporting obligations on critical infrastructure operators, structuring public–private information sharing, and providing for governmental supervision and enforcement to improve cybersecu - rity, the Act shares common elements with the Euro - pean Union’s NIS 2 Directive. Affected companies Under the Act, it is the Special-SIO who will need to take certain measures. Their requirements are as fol - lows: (i) to fall under the definition of a specified social
infrastructure operator (“Specified-SIO”) (ie, a social infrastructure operator designated across 15 sectors, including electricity, telecommunications, finance, and railway, under the Economic Security Promotion Act), and (ii) to use specified important computers (SIC) defined under the Act. Although, by their nature, Special-SIOs are unlikely to be foreign companies, computer vendors that supply Special-SIOs may be affected in practice. According - ly, companies that are not themselves Special-SIOs should nevertheless take note of the Act. Reporting upon the occurrence of specified compromise events Where an entity qualifies as a Special-SIO and uses SICs, it must submit notifications upon initial deploy - ment and upon configuration changes, and it is obliged to promptly report upon becoming aware of a specified compromise event defined under the Act (ie, a situation where the cybersecurity of important computers is compromised due to specified unlawful acts). The statute does not impose a legal duty of co-opera - tion on vendors of computers and related equipment. However, vendors that supply such equipment to Spe - cial-SIOs may be required, under their contracts with those operators, to provide necessary co-operation for such reporting. Reporting obligation for vulnerabilities Under the Act, a framework will be established for providing, requesting, and collecting vulnerability information from vendors of computers and related equipment. Accordingly, foreign vendors may be required by the Prime Minister or by the minister with jurisdiction over the supply of computers and related equipment to submit reports or materials concerning the products they have supplied. Special-SIOs may also require contractual provisions calling for ongoing remediation of vulnerabilities in delivered equipment; this aligns with existing practice. Participant agreements A participant agreement (PA) defined under the Act is a bilateral arrangement under which a business pro - vides telecommunications information defined under
241 CHAMBERS.COM
Powered by FlippingBook