Japan's Ministry of Economy, Trade and Industry (METI) and the National Cybersecurity Office have built a voluntary scheme that rates a company's security measures with stars. Applications for the 3-star and 4-star levels are expected to open around the end of fiscal 2026, roughly January to March 2027. Japanese customers may soon ask suppliers whether they can get 3 stars, so it pays to know what each level requires before that question arrives.

Key points

  • The SCS scheme is voluntary and has no penalties. Whether a customer requires a star level is decided in the contract between the two parties.
  • 3 stars is a self-assessment against 26 requirements, checked and signed by a registered security expert. 4 stars is a third-party evaluation against 43 requirements, with technical verification.
  • Registration fees paid to IPA are 10,000 yen (one year) for 3 stars and 60,000 yen (three years) for 4 stars until March 31, 2028. Expert and evaluator fees are extra.
  • No specific product, such as EDR, is required. The requirements are already published in Excel, so a self-check can start now.

Why it matters to companies outside Japan

SCS stands for supply chain security. The scheme assesses a company's IT infrastructure, including cloud, against a common standard and shows the result as a star level. The idea is that buyers tell suppliers which level they need and suppliers improve to meet it. METI says it is not a ranking meant to make companies compete. Factory control systems (OT) and the products a supplier delivers are not directly covered; other schemes and guidelines handle those. IPA, the Information-technology Promotion Agency, runs it under METI and National Cybersecurity Office supervision.

For global companies there are three angles. Japanese subsidiaries that supply Japanese companies may be asked for a star level. Procurement and third-party risk teams buying from Japanese suppliers can use the published requirements as a common checklist. And the experts who sign off 3-star assessments must hold one of several qualifications that include CISSP, CISA, CISM and ISO 27001 lead auditor, so global security teams may already have qualified staff, although each expert must also complete scheme training and register.

METI describes ISMS (ISO 27001) and SCS as complementary. The Japanese sources do not say whether companies outside Japan can apply, so confirm that with IPA before planning around it.