Cybersecurity 2026

JAPAN Trends and Developments Contributed by: Yasushi Kudo, Yukiko Konno and Takayuki Inukai, Nagashima Ohno & Tsunematsu

recent years and to enhance the overall security level across the supply chain. Background and purpose of system development A significant challenge exists where ordering compa - nies find it difficult to visualise the security measures status of their suppliers, while these suppliers (espe - cially SMEs) experience an excessive burden due to the diverse requirements of multiple ordering com - panies. To address this issue, the security evaluation system aims to promote effective countermeasures against supply chain risks, such as information leaks, business interruptions, and unauthorised intrusions, and to enhance visibility of the response status. This is achieved through the acquisition of the “Mark ( ★ )”, assigned based on compliance with the system’s standards. This visualisation clarifies the necessary countermeas - ures for contractors while enabling ordering compa - nies to easily and appropriately assess the security status of their partners. Scope and positioning of the system This system targets companies’ IT infrastructure including both on-premises and cloud environments. It does not extend to manufacturing environment con - trol systems (OT) or the products themselves. This system identifies three primary risks: (i) disruption of the company’s own business or service provision, (ii) leakage or tampering of confidential information; and (iii) unauthorised intrusion using business partners as a stepping stone. Overview of the tiered assessment system ( ★ 3 to ★ 5) Three levels are established based on a company’s position and risk profile. • ★ 3 (Basic): this level outlines fundamental organi - sational and system defences against common cyberthreats. It requires an annual self-assessment with expert verification. • ★ 4 (Standard): this level outlines comprehensive and standard countermeasures to prevent damage escalation and strengthen supply chain resilience. It requires third-party evaluations, including on-site audits and technical verification, every three years.

• ★ 5 (Advanced): this level addresses advanced cyber-attacks, including unknown threats, through a risk-based improvement process. Details regard - ing third-party assessments for this level will be specified in the future. Security requirements and evaluation criteria Requirements are structured based on classifications aligned with the NIST CSF (Cybersecurity Framework), with the addition of “Vendor Management.” Key items include governance establishment, vendor manage - ment, risk identification, defence, detection, response, and recovery measures. Implementation promotion measures To promote the adoption of this system, multifaceted support measures are planned, including the follow - ing. For SMEs, support measures include developing new types of “Cybersecurity Assistance Team Services” and establishment of mechanisms for matching them with experts. Furthermore, to ensure appropriate cost pass-through, the framework clarifies concepts under the Antimonopoly Act and the Proper Transactions Act to prevent security measures costs from being consid - ered “unreasonable costs.” This promotes the estab - lishment of appropriate partnerships between large enterprises and SMEs. Additionally, there are plans to encourage adoption of these measures in government procurement and by critical infrastructure operators. Future schedule In 2025, METI finalised the above institutional frame - work policy, conducted demonstration projects, and solicited public comments. In 2026, METI aims to advance the preparation of the operational infrastruc - ture and commence operations in the latter half of the year.

244 CHAMBERS.COM

Powered by