Your devices
produce the paperwork.

Japan's new supply-chain security (SCS) scheme rates suppliers from ★1 to ★5, and your Japanese customers will ask you for ★3. Instead of a spreadsheet and a consultant, let the machines themselves produce the evidence — mapped to SOC 2 and ISO 27001, held in Japan.

Applications are expected to open around March 2027. ★3 is a self-assessment with expert review: 26 requirements, 81 criteria, valid one year. No accredited body needed. But you need months of records behind you, so the clock is already running.

Star ledger
Self-check · 7 areas

Tap or click each row to match your situation. ● covered / ○ gap

An open-plan office with colleagues working at their desks in natural light

What Japan's SCS scheme is

METI, Japan's Ministry of Economy, Trade and Industry, and the Cabinet Secretariat's National Cyber Office published the build policy for a supply-chain security (SCS) evaluation scheme on 27 March 2026. It rates a company's security posture in stars, so buyers can see it.

★1 and ★2 correspond to SECURITY ACTION, the self-declaration program that IPA, Japan's Information-technology Promotion Agency, already runs. The scheme proper begins at ★3.

★3 is a self-assessment with expert review. 26 requirements, 81 criteria, valid one year. No application to an accredited body.

★4 is a third-party assessment plus technical testing. 43 requirements, 153 criteria, valid three years. An on-site audit is involved.

None of it is legally mandatory. But large Japanese buyers are expected to name ★3 as a condition of doing business, which makes it a requirement in practice. If you sell into a Japanese enterprise's supply chain — manufacturing, IT, logistics — or you are the Japan subsidiary of a foreign group, expect the question. Moving early is worth more.

If you already hold SOC 2 or ISO 27001, the evidence overlaps heavily, but the rating does not carry over: ★3 is assessed against IPA's own criteria. What does carry over is the habit of collecting evidence continuously. Kana stores what it collects against the ★3 requirements, and the security and compliance page shows which SOC 2 and ISO 27001 controls each kind of evidence supports.

Note: the official requirements and criteria are those published by IPA and METI. The seven areas used on this site are a simplified grouping, in English, for self-checking.

How it works

The first step is free. If you have no gaps, you pay nothing.

An IT manager at a desk, reviewing a printed checklist beside an open laptop
1

Free star check

Answer 26 questions. Fifteen minutes. One person can finish it. No sales call attached.

Free
2

You get the gap list

One page: what is missing, and what closes it. Where a product you already run covers something, we say so.

Free · delivered as PDF
3

Close the gaps

Roll out one agent alongside Intune, Jamf, CrowdStrike or Defender. It collects encryption, screen lock, patch state, malware protection and logs every day, and keeps them as evidence.

Monthly · per device

We show you what's inside

Evidence you hand an assessor should not come out of a box you cannot see into. Everything we collect is readable, and the queries are published.

Collection agent

Built on osquery, the open-source agent that exposes device state as SQL tables. Every query we run is published as a config file, so your security team can read it before the agent goes near a device. There are no hidden commands.

Open source · every query published

EPP / EDR

Licensed from Endpoint Solutions, Inc. in the United States. The detection and prevention core is the same one already running in production elsewhere; we did not write a detection engine from scratch. It is optional. If CrowdStrike or Defender already covers you, stay on the Evidence plan and the agent records that your protection is on.

Licensed · Endpoint Solutions, Inc. (US) · optional

MDM

MDM is no longer a product. Apple launched Apple Business on 14 April 2026 with MDM included at no cost. We let the free thing stay free and put the evidence layer on top. Keep Intune, Jamf or CLOMO exactly as it is.

Runs alongside your MDM · does not replace it

Evidence and reporting

What we collect is stored against the ★3 requirements, and each kind of evidence is mapped to the SOC 2 and ISO 27001 controls it supports. Hand an assessor, a customer or your own auditor the screen, or the exported PDF. The manual register goes away.

Data held in Japan · Japanese-language support · assessor accounts available

What fills itself in, and what doesn't

Software handles about half. The rest is people and policy. Better you hear it now.

● agent produces the evidence / ◐ partly automatic, rest is written in / blank human work
AreaAutomatedWhat actually happens
Asset management Every device, OS and installed application is inventoried daily. The register stays current on its own.
Device protection Disk encryption, screen lock and malware protection are checked on every machine and recorded.
Patching Missing updates are found and applied. The date each one landed is kept as evidence.
Logging Device activity logs are retained. You can show the retention period was met.
Access control Local accounts and privileges are collected. Permissions inside your business systems still need a human check.
Incident response Detection and isolation are automatic. You decide the call list and the procedure; we hand you a template.
Training Naming an owner, running training, doing internal audit. This part is human work. Your partner or MSP helps.

Talk to a partner

Evidence your auditor already understands

You will not find a SOC 2 badge here; we do not claim one. What we can show is how each piece of evidence the agent collects lines up with the controls you already report against, where the data sits, and exactly what the agent runs.

SOC 2 control mapping

Encryption, screen lock, accounts, patching, malware protection and logs map to the Trust Services Criteria your auditor already works from: CC6 logical access, CC7 system operations and monitoring, CC8 change management. The full table is on the security and compliance page.

Mapping to SOC 2 TSC · not a SOC 2 report

ISO/IEC 27001 control mapping

The same evidence is mapped to ISO/IEC 27001:2022 Annex A: asset inventory, endpoint devices, cryptography, malware, technical vulnerabilities, logging, monitoring. Useful when your group runs an ISMS and the Japan office reports into it.

Mapping to Annex A · not a certificate

Data held in Japan

Evidence and logs are stored in Japan. Support and monitoring are in Japanese. For a subsidiary that answers to a Tokyo customer and a head-office auditor at the same time, that is usually the combination that gets through.

Data residency: Japan · Japanese support

Nothing hidden in the agent

The agent is built on osquery. Every query it runs is published as a config file your security team can read before rollout. If a query is not in the file, the agent does not run it.

Open source · every query published

Built for ★3 and ★4

Everything collected is stored against the ★3 requirements. Hand the assessor the screen or the PDF, or give them their own account. When a customer raises the bar to ★4, the same records are where a third-party assessor starts.

SCS ★3 · ★4 · assessor accounts available

Two ways to reach ★3

Ready to get started? Talk to one of our partners.

On your ownThrough your partner
Pricing Per module, per quote. The total is known after scoping. One published price per device, per month. Every tier is on this page.
Integration You connect the tools you already run, and keep them in step. One agent. It reads what your existing tools already report.
What comes out Logs and telemetry. Someone still has to turn them into an answer. A ★3 verdict per requirement, with the record behind it.
Assessment evidence Assembled when you need it, from whatever happened to be retained. Collected continuously from day one, exported as a pack.
Existing tools Nothing needs replacing, but keeping it all aligned is your job. Trend Micro, CrowdStrike, Intune, Jamf, SKYSEA — all stay. We read them, we do not replace them.
Who you call Each vendor separately. Your partner. One contract, handled in Japan, in Japanese.
Two people in business dress talking across a meeting-room table with a laptop open between them

Pricing

Per device, per month, in US dollars. No minimum. Annual or monthly, your choice.

Star check
26 questions, plus the list of what you are missing. Delivered as a PDF.
Free
Evidence
Collection agent, asset register, encryption and lock checks, patching, log retention, ★3 control map.
$4 per device / month
Protection
Everything in Evidence, plus EPP and EDR. Detection, isolation, recovery and incident records.
$7 per device / month
Monitored
Everything in Protection, plus Japanese-language monitoring and first response. Nights and weekends included.
$13 per device / month

Check your ★3 gaps — free

Image credits: Photo by Arlington Research on Unsplash · Photo by Amy Hirschi on Unsplash · Photo by Vitaly Gariev on Unsplash