Japan's SCS scheme is coming. Your customers will ask you for ★3. Instead of a spreadsheet and a consultant, let the machines themselves produce the evidence.
Applications are expected to open around March 2027. ★3 is a self-assessment with expert review: 26 requirements, 81 criteria, valid one year. No accredited body needed. But you need months of records behind you. Start now.
Tap each row to match your situation. ● covered / ○ gap
METI and the Cabinet Secretariat's National Cyber Office published the build policy on 27 March 2026. It rates a company's security posture in stars, so buyers can see it.
★1 and ★2 map to SECURITY ACTION, the self-declaration IPA already runs. The scheme itself begins at ★3.
★3 is self-assessment with expert review. 26 requirements, 81 criteria, valid one year. No application to an accredited body.
★4 is third-party assessment plus technical testing. 43 requirements, 153 criteria, valid three years. An on-site audit is involved.
None of it is legally mandatory. But buyers are expected to name ★3 as a condition of doing business, which makes it a requirement in practice. If you sit inside a large company's supply chain — manufacturing, IT, logistics — moving early is worth more.
Note: the official requirements and criteria are those published by IPA and METI. The seven areas used on this site are a simplified grouping for self-checking.
The first step is free. If you have no gaps, you pay nothing.
Answer 26 questions. Fifteen minutes. One person can finish it. No sales call attached.
One page: what is missing, and what closes it. Where another vendor's product already covers something, we say so.
Roll out one agent. It collects encryption, screen lock, patch state, malware protection and logs every day, and keeps them as evidence.
Evidence you hand an assessor should not come out of a box you cannot see into. Everything we collect is readable.
Built on osquery, the open-source agent that exposes device state as SQL tables. Every query we run is published as a config file. There are no hidden commands.
Licensed from Endpoint Solutions, Inc. in the United States. The detection and prevention core is the same one already running in production elsewhere. We did not write a detection engine from scratch.
MDM is no longer a product. Apple launched Apple Business on 14 April 2026 with MDM included at no cost. We let the free thing stay free and put the evidence layer on top. Keep your Intune, Jamf or CLOMO exactly as it is.
What we collect is stored against the ★3 requirements. Hand an assessor or a customer the screen, or the exported PDF. The manual register goes away.
Software handles about half. The rest is people and policy. Better you hear it now.
| Area | Automated | What actually happens |
|---|---|---|
| Asset management | ● | Every device, OS and installed application is inventoried daily. The register stays current on its own. |
| Device protection | ● | Disk encryption, screen lock and malware protection are checked on every machine and recorded. |
| Patching | ● | Missing updates are found and applied. The date each one landed is kept as evidence. |
| Logging | ● | Device activity logs are retained. You can show the retention period was met. |
| Access control | ◐ | Local accounts and privileges are collected. Permissions inside your business systems still need a human check. |
| Incident response | ◐ | Detection and isolation are automatic. You decide the call list and the procedure; we hand you a template. |
| Training | Naming an owner, running training, doing internal audit. This part is human work. Your partner helps. |
The console is free. We make our money on the agent. You make yours on the service.
Send the free check to every account. Most answers come back failing on the same three things: encryption, patching and logs. Those three are exactly what the agent closes. Call the ones that failed.
Trend Micro, CLOMO, SKYSEA — all of it stays. You add the evidence layer without breaking the existing supply chain. That is a far easier internal approval than a replacement proposal.
Per device, per month. No minimum. Annual or monthly, your choice.