Web Articles Legislative Changes, Business Knowledge, Operational Efficiency, Advanced Management
June 25, 2026
[Starting in Fiscal Year 2026] How Will the Security Measures Evaluation System Change Practical Procedures for System Procurement?
How will the “Security Measures Evaluation System (SCS),” set to fully launch at the end of fiscal year 2026, impact future system procurement practices? In this article, we explain—from the perspective of the purchasing company—the system’s overview, schedule, differences from traditional security checklists, and specific practical implications.
Table of Contents
1. Overview of the Security Measures Evaluation System (SCS) and Differences from “Existing Systems”
1-1. What Is the Security Measures Evaluation System (SCS)?
The Security Measures Evaluation System (SCS: Supply Chain Security Assessment Model; hereinafter referred to as the “SCS Evaluation System”) is a system led by the Ministry of Economy, Trade and Industry (METI), Japan’s first public third-party certification system that objectively evaluates and rates cybersecurity measures in business-to-business transactions is Scheduled to begin full-scale operations at the end of fiscal year 2026 is
This system applies to all companies that make up the domestic supply chain, including IT vendors and development and manufacturing contractors. It also covers small and medium-sized enterprises (SMEs), which have historically found it difficult to obtain such evaluations.Under this system, accredited assessment bodies will conduct objective evaluations based on unified public standards, resulting in a rating expressed as a “number of stars (★3–★5).”
As a result, the “actual security level of business partners”—which was previously opaque—will now be immediately apparent from an external perspective.
1-2. How Does It Differ from Previous Security Checks?
Until now, many purchasing companies have developed proprietary “security checklists (Excel)” containing over 100 items to secure liability exemptions for their own risk management purposes, distributed them to manufacturing contractors and IT vendors, and required them to respond.However, for small and medium-sized enterprises (SMEs) on the supplier side, responding to a vast number of questionnaires—with questions that varied slightly depending on the client—imposed an excessive workload, structurally creating the risk of “responses that do not reflect reality.”Furthermore, for the ordering companies themselves, it was difficult to secure the specialized knowledge and resources required to scrutinize and evaluate the hundreds or thousands of Excel sheets collected from multiple business partners; as a result, these documents often became little more than formalities—merely evidence that they had been “submitted.”
The SCS Evaluation System is a public, third-party certification system introduced to break through this “formalistic security.” Based on uniform security standards established by the government, a specialized audit agency objectively evaluates a company’s security measures and visualizes the results using a “star rating.” This makes the security level of the entire supply chain immediately apparent, An “objective and visualized common yardstick” for B2B transactions .
With the introduction of this system, buyers are freed from the tedious task of distributing and compiling Excel spreadsheets, and Instantly assess a business partner’s security risk simply by checking the number of stars resulting in...
1-3. The Key Difference Between “ISMS” and the “SCS Evaluation System”
Until now, the presence or absence of “ISMS certification” has been the objective indicator that ordering companies have relied on to ensure the security of their contractors. However, there is a Significant differences in “Purpose” and “Practical Approach” There are two main types of cases in which Web APIs are used in ERP.
| Comparison Criteria | ISMS Certification | SCS Evaluation System (Newly Established) |
| Purpose | Establishing a system for self-managed risk and continuous improvement (PDCA) | Visualizing and enhancing security measures across the entire supply chain |
| Scope of Evaluation | “Systems and processes” for managing security | "Specific technical measures" currently in place |
| Main Target Companies | All industries (relatively large and mid-sized companies) | All companies comprising the supply chain (including small and medium-sized enterprises) |
| Practical Features | High operational and maintenance costs make it difficult to comprehensively cover small and medium-sized suppliers. It is hard to see the specific technical measures being implemented. | Based on standards such as the NIST CSF, the measures to be implemented are clearly defined, and effectiveness can be instantly assessed using a “star rating.” |
Existing ISMS certification verifies whether an organization’s “systems and processes” for maintaining security comply with international standards. While it is a robust framework, its operation and maintenance require significant costs and human resources; therefore, it was not realistic for small and medium-sized suppliers with limited resources to comprehensively obtain and maintain it.Furthermore, from the perspective of the client, there was the challenge of determining whether a supplier “holds ISMS certification but is capable of addressing the specific system operations being outsourced in this instance,”It is difficult to see exactly which specific measures (such as encryption and access control) are actually working "
The SCS Evaluation System, based on standards such as the NIST CSF (National Institute of Standards and Technology Cybersecurity Framework), defines the minimum (★3) and standard (★4) levels of implementation that companies should achieve Specific security measures are clearly defined , and the results are visualized as a star rating following an objective assessment by experts and evaluation bodies.
Since the SCS Evaluation System was designed from the outset with “business relationships within the supply chain” in mind, it serves as a “common yardstick” for contractors and clients, providing a shared language to clarify “which level (number of stars) is required” in bilateral contracts.
2. “Practical Measures” Required of Procuring Companies Following the System’s Introduction
At first glance, this may seem to offer only benefits to the purchasing company, but it also requires a corresponding level of preparation on their part.
2-1. Establishing “★” Criteria Based on the Classification (Importance) of Procured Systems
If a uniform requirement of “★4 or higher” is imposed on all system procurements, the pool of eligible vendors may become too narrow, posing the risk of skyrocketing procurement costs or an inability to find contractors. Therefore, the purchasing company must It is necessary to establish “criteria” that differentiate the number of ★s required based on the nature and role of the systems the company procures must
-
[Cases Requiring ★4–★5]
Systems that handle large volumes of customer personal information, systems directly connected to infrastructure, and other systems where downtime or data breaches would be fatal to the business. -
[Cases where ★3 or lower is acceptable]
Information-sharing tools used by limited internal departments, or the development of websites that do not handle confidential information.
2-2. Shift from Proprietary Checklists to “Official Standards (SCS)” and Changes to Internal Rules
It will be necessary to gradually replace the “vendor security checklists” previously handled individually by general affairs and IT departments with the SCS evaluation system. While this will significantly reduce the man-hours required for checks, on the other hand, Changes to “security verification rules” within internal procurement regulations and approval processes will be necessary.
2-3. [Establishing Digital Governance] Turning Resilience into a Competitive Asset
It is also effective to incorporate the data obtained from the SCS evaluation system as the core of the company’s digital governance. Integrate each supplier’s SCS evaluation score with the company’s own systems—such as procurement management systems or ERP—to visualize supply chain risks This will enable management and procurement managers to make data-driven decisions regarding which suppliers pose concentrated risks and in which areas alternative suppliers need to be secured.
Furthermore, the “resilient and secure supply chain” built in this way can itself serve as a powerful marketing message to your company’s customers—namely, that “the security of our Products / Services is guaranteed all the way to the end of the supply chain.” This also serves as a unique differentiator for the company .
3. A Roadmap Counting Back from the Operational Launch at the End of Fiscal Year 2026
With the full-scale launch of the SCS evaluation system scheduled for the end of fiscal year 2026, purchasing companies do not have much time left. It takes a certain amount of lead time for suppliers to obtain certification and for companies to overhaul their procurement standards and systems. Therefore, systematic preparation is necessary starting now.
[Example Roadmap for the SCS Evaluation System, Working Backward from the Start of Operations (Current as of 2026 – March 2027)]
![[Example Roadmap for the SCS Evaluation System, Working Backward from the Start of Operations (Current as of 2026 – March 2027)]](https://www.worksap.co.jp/assets_c/2026/06/supply-chain-security_1.png)
Summary
For purchasing companies, the “Security Measures Evaluation System (SCS)” will serve as a powerful tool to dramatically reduce the effort required to verify security during system procurement while strengthening supply chain governance.
On the other hand, in an era where the SCS evaluation system—a set of objective assessment metrics—exists, the excuse that “we were unaware of the security status of our contractors” will no longer hold water. No matter how low the unit price of a product or service may be, selecting a vendor with a low SCS rating and a high probability of causing a cyber incident This would result in the company taking on a massive “future liability” for the entire organization . This is because, in the unlikely event of a data breach or system outage caused by a contractor, the costs incurred by the client for incident response, post-incident compensation, and restoring trust will be tens or even hundreds of times greater than the small amount saved on procurement costs at the time of ordering.
Taking steps now to prepare for this new system will help eliminate future procurement risks. Start by identifying the major systems your company currently uses, Internal discussions on what level of security (number of stars) should be required .
“HUE Purchase,” a purchasing and procurement management system for major Japanese corporations
“HUE Purchase,” a purchasing and procurement management system for major corporations, provides standard support for Japan’s complex laws and regulations, internal governance, and supplier evaluation. It enables data-driven, appropriate transactions and “proactive procurement” without requiring front-line staff to be consciously aware of the process.