Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

What is the SCS Evaluation System? Supply Chain Risk Evaluation Targets, 3/4 Stars, and Preparation

An explanation of target companies under the Security Measures Evaluation System for Strengthening Supply Chains (SCS Evaluation System), the differences between 3-star and 4-star ratings, the planned launch around March 2027, and preparation steps. Based on primary sources from METI and IPA, this guide covers its voluntary nature, differences with ISMS, cost considerations, and how to organize personnel and evidence.

What is the SCS Evaluation System? Target Companies and Overview of Measures

"A client has requested an evaluation of our security measures," or "We need to prepare for the supply chain risk assessment system." In these scenarios, you should check the Security Measure Evaluation System for Strengthening Supply Chains (SCS Evaluation System). This framework verifies the security posture of corporate IT infrastructures against a common standard, making it easier to explain to business partners.

Date of verification: September 17, 2026. This article is based on materials published by METI and the IPA. It also references the designation criteria and procedures for evaluation bodies published on September 11. Note that the official announcement of the system is separate from when companies can start applying.

Key Points of the SCS Evaluation System

  • What is evaluated: The implementation status of security measures across corporate IT infrastructure, including cloud environments.

  • When it starts: Operations for ★3 and ★4 are scheduled to begin around March 2027. Do not treat this as a fixed application start date; check the IPA's official announcements.

  • Is it mandatory?: It is a voluntary scheme. However, it is expected to be used in individual business transactions to verify required security levels.

  • Evaluation method: ★3 involves self-assessment with expert verification, while ★4 requires third-party evaluation and technical verification.

  • Next steps: Identify the levels required by your business partners, map the target IT infrastructure, review existing measures and evidence, and assign owners and deadlines for addressing gaps.

Sources: METI System Overview, IPA System FAQ.

Relationship between "Supply Chain Risk Assessment" and SCS

When searching for supply chain risk assessment systems, look for the formal name and its abbreviation, the "SCS Evaluation System" (SCS stands for Supply Chain Security). This article focuses on this specific system run by METI and the IPA.

Supply chain risk assessment itself is a broad activity that evaluates business continuity, information management, and the products/services of business partners. Not all of these aspects are covered by the SCS Evaluation System. For general concepts, please refer to Supply Chain Risk Management (SCRM).

The system aims to address the visibility gap where buyers struggle to understand their suppliers' security postures, while reducing the burden on suppliers who face fragmented, vendor-specific questionnaires. It is not a rating system designed to rank companies, nor does it guarantee a future free of incidents.

Scope and Targets: Do SMEs and Manufacturers Need to Worry?

The system targets organizations within the supply chain. Do not dismiss it as "only for large enterprises" or "irrelevant to us" based on company size alone. Review the nature of your transactions, the data shared, and the systems connected.

The direct target of the evaluation is the corporate IT infrastructure. Operational Technology (OT) on manufacturing floors and the actual products delivered to clients are generally outside this scope, as they are covered by other frameworks. Manufacturing companies can clarify their scope by separating factory equipment from IT infrastructure like email, authentication, and core business systems.

Buyers should determine the required level based on the criticality of the outsourced tasks and shared information. Suppliers should confirm the desired ★ level, the scope, and the timeline with their clients to align on an approach. There is no need to assume that companies without certification will immediately be barred from transactions. Source: METI Scope & System Objectives.

Differences and Evaluation Methods for ★3, ★4, and ★5

★3: Self-Assessment of Basic Measures Verified by Experts

★3 targets protection against common cyber threats. Organizations perform a self-assessment and have it verified by security experts who meet the system's requirements. This involves a formal declaration of conformity from management, not just a simple checklist completed by IT staff.

In the March 2026 release, ★3 consists of 26 requirements. Requirements are distinct from the detailed evaluation criteria used to verify each item. Keep this in mind when comparing numbers in the documentation.

★4: Expanded Scope with Third-Party Evaluation and Technical Verification

★4 focuses on preventing lateral movement and protecting partner data and systems, in addition to initial intrusion prevention. Evaluation bodies perform third-party assessments and technical verification to confirm actual implementation beyond documentation.

There are 43 requirements, which build upon the ★3 scope. This is not a simple cumulative addition of 26 and 43. Note that ★3 is not a mandatory prerequisite for obtaining ★4.

Validity Period and Renewal Differences

The validity period is 1 year for ★3 and 3 years for ★4, starting from the registration date. Maintaining ★3 requires an annual update of the self-assessment with expert verification. ★4 also requires action during the 3-year term, with self-assessments submitted to the evaluation body annually. Source: IPA General Rules 3.1.2 / 3.2.2.

To compare requirements, evaluation methods, and post-registration operations side-by-side, see the SCS Evaluation System ★3 vs. ★4 Comparison Table. Since ★4 increases the evaluation criteria even for shared requirements, the workload cannot be measured by the number of requirements alone.

★5: Details to Be Confirmed

★5 is designed for advanced targeted attacks. Unlike ★3 and ★4, the application steps and detailed requirements are not yet finalized.

Sources: IPA Evaluation Levels & Methods, System Construction Policy, ★3 and ★4 Requirements & Evaluation Criteria.

Timeline: What was Decided as of September 2026?

The IPA FAQ states that ★3 and ★4 operations are expected to launch around March 2027. This aligns with METI's "end of FY2026" timeline. Do not assume applications will open during 2026.

The system's General Rules were published on August 28, 2026, followed by designation criteria and procedures for evaluation bodies, technical verification vendors, and training providers on September 11. These updates establish the administrative framework and do not mean that certification applications are open for general enterprises yet.

Project leaders must monitor the latest versions of application steps, evaluation guides, and submission templates, rather than relying solely on requirement tables. Avoid using outdated timelines marked "planned release" from older briefing materials.

Sources: IPA System Rules, Criteria, & Procedures, IPA FAQ.

Preparation Checklist: Who Prepares What?

To break down tasks for your organization, check the SCS Evaluation System Preparation Checklist. We offer a downloadable Preparation Registry (CSV, no registration required) to organize owners, evidence, and deadlines. This is a planning resource containing examples for training, monitoring, and log management, and does not replace the official evaluation sheets.

Below is a practical preparation workflow mapped out by Yagura. This is not an official application template or a definitive checklist for certification. Use it to cross-reference requirements and evaluation criteria during your planning phase.

1. Confirm Client Requirements

Owners: Sales, Procurement, IT. Collect questionnaires and requests from clients, and document the required level, deadlines, target operations, and data types. Clarify with the client's contact: "Which operations, what security level, and by when do you want to verify?" Avoid purchasing security products or evaluation services before confirming the target level.

2. Identify Target IT Infrastructure and Owners

Owners: IT, Business Unit Heads. List all endpoints, servers, cloud environments, authentication infrastructure, external connections, and environments managed by subcontractors. Identify the administrator, data types, and maintenance vendors for each environment. If using a corporate asset registry, clearly define the boundaries of the target scope.

3. Map Existing Measures to Documentation

Owners: Security Measure Leads. For each requirement, document current implementations, available evidence, gaps, owners, and remediation deadlines. Evidence examples include configuration settings, access review logs, training records, log analysis logs, incident response plans, and disaster recovery drill results. Distinguish between having a policy and having operational records to uncover gaps.

4. Allocate Budget and Deadlines for Gaps

Owners: Management, IT, Procurement. Group outstanding gaps into simple configuration changes, process improvements, or tasks requiring external support. Estimate costs beyond initial setups and tools, including internal labor, training, daily operations, evaluation fees, and renewal costs.

5. Verify Operational Continuity Before Evaluation

Owners: Operations Leads, Management. Verify who detects alerts, who is contacted when leads are absent, and where response records are kept. Ensure that the organization can detect, judge, escalate, and recover from anomalies, rather than just filling documentation gaps. Report preparation status to management, highlighting unresolved issues and key decisions.

Through these steps, aim to reach a state where you can clearly explain your target level, scope, implementation status, evidence, and plans for outstanding gaps.

Preparing for Training, Log Monitoring, and Incident Response

Document Training Records, Not Just Attendance

The evaluation criteria for the official ★3 requirement "4-2-2" includes incident response training and its records/reviews. Check the official text for specific frequencies, such as training for new hires or annual sessions.

In practice, you must record content, methods, dates, and attendance, while managing follow-ups for absentees and documenting improvements identified during drills. Refer to Targeted Attack Simulation Concepts for training ideas.

Align Log Storage with Monitoring Responsibilities

The evaluation criteria for ★3 requirement "5-1-1" covers unauthorized access detection, log/alert analysis, and notification. The criteria for ★4 requirement "4-4-3" includes conditions for log retention and authentication log reviews. Verify the exact scope and alternative conditions in the official criteria.

Simply gathering logs does not guarantee detection. Define retention targets, periods, access permissions, review owners, and escalation paths as a single operational flow. For response steps, see First Response and SOC Integration.

SOC and AI SOC options help streamline investigation and analysis. The SCS Evaluation System does not mandate specific products. Confirm your operational gaps before selecting vendors. Sources: Official Requirements & Evaluation Criteria, METI System Overview.

Differences from ISMS, SECURITY ACTION, and MoD Standards

vs. ISMS: ISMS focuses on information security management frameworks tailored to organizational risk. SCS ★3 and ★4 evaluate the implementation of specific, predefined security measures. They are complementary; having an ISMS certification does not grant automatic SCS certification. Use existing policies and records to identify gaps against SCS criteria.

vs. SECURITY ACTION: This is a self-declaration security framework for SMEs. It is independent of the SCS ★3 and ★4 registration process. Do not assume the assessment procedures are identical based on star ratings alone.

vs. Ministry of Defense (MoD) Standards: The MoD procurement security standard applies to specific defense contracts and protected data. It is not the same as the SCS Evaluation System. For defense-related supply chains, refer to Defense Supply Chain Security Standards and SOC Requirements.

Sources: METI ISMS Guidance, IPA SECURITY ACTION, MoD Information Security Standards.

SCS Evaluation System FAQ

How much does certification cost?

The General Rules establish application and registration fees, but specific amounts are to be determined. Costs for external experts and evaluation bodies depend on individual service contracts. Request quotes based on your scope, current readiness, target level, and the level of external support required. Source: SCS General Rules 6.5.

Should SMEs aim for ★3 first?

Not necessarily. Determine your target level by evaluating the criticality of outsourced tasks and requirements from business partners. If ★4 is required, obtaining ★3 first is not a mandatory prerequisite. Source: IPA Evaluation Levels.

Can we get certified by meeting only some of the items?

No. You must satisfy all requirements and evaluation criteria specified for the target level. If applicability conditions apply to certain criteria, evaluate them accordingly. Confirm scoping and applicability questions with the official guidelines and your designated experts. Source: IPA FAQ.

Will implementing an AI SOC or security products guarantee certification?

Product installation alone does not guarantee certification. The system evaluates organizational, technical, and operational controls. Yagura provides support for security training, simulations, and alert investigations. If you identify gaps in training, monitoring, or incident response while preparing, check the scopes of Yagura Awareness and Yagura AI SOC, and reach out via our Contact Us page.

References and Verification Date

On September 17, 2026, we updated this page with details on validity periods, renewals, and the ★3 vs. ★4 comparison. The basic system description was verified on September 12, 2026. Because schedules, templates, and evaluation methods may change, always check the latest official sources before applying or signing contracts.

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。