This guide explains how to prepare for the SCS evaluation system, covering supplier verification, scoping, alignment with official evaluation tables, and the management of assignees, evidence, and deadlines. It organizes your next steps using practical examples of training, monitoring, and log acquisition, alongside an importable CSV template.

When starting your SCS evaluation system compliance, you must first align on "what your business partners require," "what scope you need to verify," and "who will keep the records." Starting with product purchases or policy creation can lead to wasting time on out-of-scope tasks or failing to retain evidence of implemented security controls.
This article provides a preparation checklist to organize personnel, evidence, and deadlines, along with practical examples of education, monitoring, and log management. Evidence refers to records or configuration information that verify security controls have been implemented.
This article and the input CSV are unique preparation materials provided by Yagura. They do not replace the official evaluation forms and do not guarantee or determine whether you will pass or fail the star rating. The basic explanations were verified on September 12, 2026, and post-acquisition renewal management was added on September 17, 2026.
Download the SCS Preparation Ledger (CSV, registration not required)
First, Clarify the Requirements with Your Business Partners
The official name of the SCS evaluation system is "Security Measures Evaluation System for Strengthening Supply Chains." It is a voluntary program, and Star 3 and Star 4 are scheduled to start operations around March 2027. Distinguish the scheduled launch of the system from the specific response deadlines requested by individual business partners. Click here for an overview of the system, targets, and differences between levels.
If you receive a request from a business partner, record the following four points:
Objective and Level: Which transaction requires Star 3 or Star 4.
Scope: Which legal entities, locations, operations, and systems are targeted.
Deliverables: What they require, such as explanations of the current status, improvement plans, or obtained star ratings.
Deadline and Contact Point: Response deadlines, implementation deadlines, and the contact point for inquiries or adjustments.
Before aiming for the highest level across the board, clarify the transaction details and your company's role. This is a practical procedure for organizing transaction conditions and is not an official application procedure. METI System Explanation, IPA FAQ
Preparation Checklist: Mapping the Official Evaluation Form to Your Tasks
1. List the Scope
Organize the legal entities, sites, networks, devices, servers, cloud services, and their respective administrators. For assets managed by contractors, separate the configurations your company can verify from the items you need to confirm with the contractor. If the same system is duplicated in ledgers across different departments, unify the names.
The system covers the IT infrastructure of companies, including cloud services. Since OT systems (such as manufacturing environments) and delivered products are not directly targeted, verify their connections to IT and any separately applicable standards. METI Scope of Application
2. Reference the Latest Official Evaluation Form
Get the official Excel sheet from IPA's "Requirements and Evaluation Criteria" and record the date of the referenced materials. Identify the evaluation criteria required for Star 3 and Star 4, and map each of them to your company's configurations, procedures, and records.
Requirement ID "4-2-2" is different from its internal Evaluation Criteria ID "4-2-2-1." Listing down to the Evaluation Criteria ID when managing tasks makes it easier to avoid confusing the implementation of training with the storage of records. Simply ticking off a short, custom checklist does not mean you meet all the criteria.
3. Define Personnel, Reviewers, and Evidence
Ledger Item | Content to Enter |
|---|---|
Assignee/Reviewer | The person doing the work and the person verifying the results |
Scope | Locations, systems, target users, and periods |
Current Status | Unverified, Incomplete, In Progress, Pending Review, Verified |
Evidence Location/Verification Date | Location of configuration records or reports, and the date verified |
Gaps/Next Actions/Deadlines | Reason for the gap, specific actions, and the agreed deadline with the assignee |
"Verified" refers to internal task status. This is separate from the official system compliance determination. Even if you think an item is out of scope, do not delete the row arbitrarily; keep the reason and the verified details.
4. Inspect the Actual System to Turn Gaps into Tasks
Even if a configuration screen exists, verify whether it is applied across the entire target environment and if records can be retrieved. For "trained" status, verify the target users against training records; for "logs saved" status, verify the searchable period and required fields. Gaps should be written as executable tasks, such as "Identify untrained users and notify them of the deadline," rather than vague actions like "Handle training."
Practical Example 1: Preparing Education and Training Records
Requirement 4-2-2 is "Education and Training for Security Incident Occurrence." For Star 3 and Star 4, this requires education and training upon onboarding and at least once a year, storage of implementation records, and an annual review of the content. Targets include executives, employees, temporary staff, and seconded personnel. Ensure that e-learning or classroom training is conducted in addition to distributing or posting materials. Official Excel 4-2-2-1 to 3
As a preparation example, HR provides the list of target users, and the training lead records the content, method, date, and completion status. The IT department verifies whether the reporting contacts and initial response procedures in the materials match the current status. Separating onboarding training from annual training and tracking outstanding tasks for non-attendees makes auditing easier.
Examples of evidence include training material versions, implementation records, attendee lists with completion status, and records of content reviews. Showing completion rates alone is insufficient to explain what was taught.
Practical Example 2: Verifying the Flow from Detection to Decision and Notification
Requirement 5-1-1 is "Network Connection and Data Monitoring." For Star 3 and Star 4, this requires real-time detection and blocking of unauthorized bidirectional traffic at boundaries or endpoints, analysis of logs and alerts to determine incidents, and prompt alert emission and preliminary report notifications. Official Excel 5-1-1-1 to 3
In practice, map the flow from the detecting device, the verifying analyst, and the recipient of the determination. If outsourced, clarify the scope handled by the service, the decisions remaining in-house, and after-hours contact methods.
An example of a preparation check is to test notifications using an approved, safe method and record the emission time, recipient, and verification results. Because notification tests alone do not validate detection capabilities, keep separate records of product configurations, scope, and detection/blocking verification results. Do not simplify compliance conditions down to just deploying a specific SOC product.
Practical Example 3: Separating Log Retention Periods from Verification Tasks
Requirement 4-4-3 is "Log Acquisition," which is a Star 4 item. It requires acquiring and retaining firewall, proxy, and authentication server logs for 6 months. This includes cloud environments, and if specifications prevent this, there are conditions to acquire and retain equivalent logs using other devices or features. Official Excel 4-4-3-1
Check the acquired fields for each log type to ensure that necessary items such as timestamp, source/destination, user, and success/failure are present. Even if "service retention is set to 6 months," if collection started last month, you do not have 6 months of historical data. Record the configuration setting separately from the actual oldest date available for retrieval.
Also, verify multi-factor authentication when accessing log storage over the internet, and monthly monitoring of authentication server logs. Manage retention, access protection, and periodic reviews as separate tasks, and record verification results and responses to suspicious attempts. Official Excel 4-4-3-2 to 3
Managing Renewal Deadlines and Annual Reviews After Star 3/4 Acquisition
Star 3 (★3) is valid for 1 year, and Star 4 (★4) is valid for 3 years. For Star 3, schedule the required expert reviews and self-evaluation updates needed for renewal. For Star 4, submit annual self-evaluations to the assessment body to prepare for the third-party assessment every 3 years. Source: IPA Basic Rules 3.1.2/3.2.2.
Alongside your preparation ledger, manage the registration completion notification date, expiration date, next scheduled self-evaluation/submission date, personnel, and contact info for the assessment body or experts. These are internal management items proposed by Yagura, not official application forms. The downloadable CSV does not include renewal management columns, so add them to your company's annual schedule.
Especially for Star 4, reassessment is required if there are major changes that significantly impact the scope of application or compliance with criteria. When changing locations, systems, or contractors, verify with the assessment body separately from regular renewals. See also Comparison of Star 3 and Star 4 Requirements, Evaluation Methods, and Validity Periods.
How to Use the Input CSV
The CSV provides 4 rows for basic setup and task examples matching the 9 evaluation criteria mentioned above. Enter your company's scope, personnel, current status, evidence location, verification date, next actions, and deadlines, and add necessary rows as you match them against the official evaluation form. Modify the practical examples columns to fit your environment. When loading in Excel, import the Requirement ID and Evaluation Criteria ID columns as text strings to ensure they are not converted to dates.
Education and log management alone do not cover the entire system compliance. After reviewing the overall criteria, start by identifying tasks that do not yet have assigned personnel or deadlines.
Yagura introduces services for security education and security operations using AI SOC. If you find gaps in training records or monitoring operations during your preparation, organize your scope and current status, and contact us.



