On October 1, 2026, the main parts of Japan's new cyber defense law took effect, launching what the government calls "active cyber defense." 258 operators in 15 critical infrastructure sectors must now notify the government of key equipment and report cyber incidents, and police and the Self-Defense Forces can act against attack servers. Most companies have no new legal duty, but vendors, cloud providers and group companies that serve those operators will be asked for equipment data and fast breach notices.
Key points
- Equipment notification, incident reporting and "access and neutralization" of attack servers started on October 1, 2026. The government's use of communications information is planned for autumn 2027.
- Legal duties apply only to 258 designated operators in 15 sectors, including electricity, telecom, finance and credit cards. Initial incident reports are due within 3 to 5 days (DDoS as soon as possible) and detailed reports within 30 days.
- Equipment already in use on October 1, 2026 must be notified by March 31, 2027. Breaching a government order can bring a fine of up to 2 million yen, and companies can be fined.
- Article 42 lets the government ask makers and sellers of IT products for vulnerability information and countermeasures. It also applies to overseas suppliers whose products are supplied in Japan.
Who is affected beyond the 258 operators
The law targets operators already designated under Japan's Economic Security Promotion Act. But the equipment they must notify can include systems owned by group companies, system vendors and cloud services, and incidents on equipment managed by contractors or running in the cloud are reportable too. In practice, a designated operator can only meet a 3 to 5 day reporting deadline if its suppliers tell it about a compromise quickly.
That makes three groups of foreign companies part of the picture. Global IT vendors, managed service providers and cloud providers with customers in the 15 sectors can expect requests for product names, versions and breach notification commitments. Makers and sellers of IT products, including those based outside Japan, can receive vulnerability information requests from the Japanese government under Article 42. And Japanese subsidiaries or group companies of designated operators may own equipment that falls within the notification scope.
For everyone else, there is no new obligation or penalty. The government's common incident report format is still worth keeping at hand, because any company can use it when consulting the police after an attack.