Japan's new supply-chain security (SCS) scheme rates suppliers from ★1 to ★5, and your Japanese customers will ask you for ★3. Instead of a spreadsheet and a consultant, let the machines themselves produce the evidence — mapped to SOC 2 and ISO 27001, held in Japan.
Applications are expected to open around March 2027. ★3 is a self-assessment with expert review: 26 requirements, 81 criteria, valid one year. No accredited body needed. But you need months of records behind you, so the clock is already running.
Tap or click each row to match your situation. ● covered / ○ gap
METI, Japan's Ministry of Economy, Trade and Industry, and the Cabinet Secretariat's National Cyber Office published the build policy for a supply-chain security (SCS) evaluation scheme on 27 March 2026. It rates a company's security posture in stars, so buyers can see it.
★1 and ★2 correspond to SECURITY ACTION, the self-declaration program that IPA, Japan's Information-technology Promotion Agency, already runs. The scheme proper begins at ★3.
★3 is a self-assessment with expert review. 26 requirements, 81 criteria, valid one year. No application to an accredited body.
★4 is a third-party assessment plus technical testing. 43 requirements, 153 criteria, valid three years. An on-site audit is involved.
None of it is legally mandatory. But large Japanese buyers are expected to name ★3 as a condition of doing business, which makes it a requirement in practice. If you sell into a Japanese enterprise's supply chain — manufacturing, IT, logistics — or you are the Japan subsidiary of a foreign group, expect the question. Moving early is worth more.
If you already hold SOC 2 or ISO 27001, the evidence overlaps heavily, but the rating does not carry over: ★3 is assessed against IPA's own criteria. What does carry over is the habit of collecting evidence continuously. Kana stores what it collects against the ★3 requirements, and the security and compliance page shows which SOC 2 and ISO 27001 controls each kind of evidence supports.
Note: the official requirements and criteria are those published by IPA and METI. The seven areas used on this site are a simplified grouping, in English, for self-checking.
The first step is free. If you have no gaps, you pay nothing.
Answer 26 questions. Fifteen minutes. One person can finish it. No sales call attached.
One page: what is missing, and what closes it. Where a product you already run covers something, we say so.
Roll out one agent alongside Intune, Jamf, CrowdStrike or Defender. It collects encryption, screen lock, patch state, malware protection and logs every day, and keeps them as evidence.
Evidence you hand an assessor should not come out of a box you cannot see into. Everything we collect is readable, and the queries are published.
Built on osquery, the open-source agent that exposes device state as SQL tables. Every query we run is published as a config file, so your security team can read it before the agent goes near a device. There are no hidden commands.
Licensed from Endpoint Solutions, Inc. in the United States. The detection and prevention core is the same one already running in production elsewhere; we did not write a detection engine from scratch. It is optional. If CrowdStrike or Defender already covers you, stay on the Evidence plan and the agent records that your protection is on.
MDM is no longer a product. Apple launched Apple Business on 14 April 2026 with MDM included at no cost. We let the free thing stay free and put the evidence layer on top. Keep Intune, Jamf or CLOMO exactly as it is.
What we collect is stored against the ★3 requirements, and each kind of evidence is mapped to the SOC 2 and ISO 27001 controls it supports. Hand an assessor, a customer or your own auditor the screen, or the exported PDF. The manual register goes away.
Software handles about half. The rest is people and policy. Better you hear it now.
| Area | Automated | What actually happens |
|---|---|---|
| Asset management | ● | Every device, OS and installed application is inventoried daily. The register stays current on its own. |
| Device protection | ● | Disk encryption, screen lock and malware protection are checked on every machine and recorded. |
| Patching | ● | Missing updates are found and applied. The date each one landed is kept as evidence. |
| Logging | ● | Device activity logs are retained. You can show the retention period was met. |
| Access control | ◐ | Local accounts and privileges are collected. Permissions inside your business systems still need a human check. |
| Incident response | ◐ | Detection and isolation are automatic. You decide the call list and the procedure; we hand you a template. |
| Training | Naming an owner, running training, doing internal audit. This part is human work. Your partner or MSP helps. |
You will not find a SOC 2 badge here; we do not claim one. What we can show is how each piece of evidence the agent collects lines up with the controls you already report against, where the data sits, and exactly what the agent runs.
Encryption, screen lock, accounts, patching, malware protection and logs map to the Trust Services Criteria your auditor already works from: CC6 logical access, CC7 system operations and monitoring, CC8 change management. The full table is on the security and compliance page.
The same evidence is mapped to ISO/IEC 27001:2022 Annex A: asset inventory, endpoint devices, cryptography, malware, technical vulnerabilities, logging, monitoring. Useful when your group runs an ISMS and the Japan office reports into it.
Evidence and logs are stored in Japan. Support and monitoring are in Japanese. For a subsidiary that answers to a Tokyo customer and a head-office auditor at the same time, that is usually the combination that gets through.
The agent is built on osquery. Every query it runs is published as a config file your security team can read before rollout. If a query is not in the file, the agent does not run it.
Everything collected is stored against the ★3 requirements. Hand the assessor the screen or the PDF, or give them their own account. When a customer raises the bar to ★4, the same records are where a third-party assessor starts.
Ready to get started? Talk to one of our partners.
| On your own | Through your partner | |
|---|---|---|
| Pricing | Per module, per quote. The total is known after scoping. | One published price per device, per month. Every tier is on this page. |
| Integration | You connect the tools you already run, and keep them in step. | One agent. It reads what your existing tools already report. |
| What comes out | Logs and telemetry. Someone still has to turn them into an answer. | A ★3 verdict per requirement, with the record behind it. |
| Assessment evidence | Assembled when you need it, from whatever happened to be retained. | Collected continuously from day one, exported as a pack. |
| Existing tools | Nothing needs replacing, but keeping it all aligned is your job. | Trend Micro, CrowdStrike, Intune, Jamf, SKYSEA — all stay. We read them, we do not replace them. |
| Who you call | Each vendor separately. | Your partner. One contract, handled in Japan, in Japanese. |
Per device, per month, in US dollars. No minimum. Annual or monthly, your choice.