Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

Differences Between SCS Rating 3-Star and 4-Star: Requirements, Evaluation Methods, and Validity Period

Compare SCS rating levels 3 and 4 across requirements, evaluation methods, validity periods, renewals, and log management. Learn how to choose the right level based on client requests, with official guide-based examples for training, monitoring, and log preparation.

SCS Rating System 3-Star and 4-Star: Requirements and Evaluation Differences

The main differences between 3-Star (★3) and 4-Star (★4) ratings in the Supply Chain Security Evaluation System (SCS Evaluation System) for strengthening supply chains lie in the scope of required security controls, the evaluation methodology, and post-certification maintenance procedures. 4-Star requires third-party assessment in addition to the controls required for 3-Star. Achieving 3-Star first is not a prerequisite for obtaining 4-Star. IPA Graduated Evaluation

This comparison table and practical examples clarify "what to prepare for 3-Star" and "what additional requirements are needed if a business partner requests 4-Star."

As of September 17, 2026. 3-Star and 4-Star operations are scheduled to start around March 2027. Note the distinction between the publication of system documentation and the opening of applications for enterprises. IPA FAQ

Comparison of 3-Star and 4-Star Differences

Comparison Points

3-Star (★3)

4-Star (★4)

Control Level

Addressing common cyber threats

In addition to intrusion prevention, preventing damage expansion and protecting business partner information and systems

Number of Requirements

26 items

43 items (includes 3-Star requirements)

Evaluation Method

Self-assessment with expert validation

Third-party evaluation (document review, on-site assessment, technical verification)

Validity Period

1 year from registration notification date

3 years from registration notification date

Maintenance & Renewal

Receive expert validation/advice before expiration and submit an updated self-assessment

Submit annual self-assessments to the evaluation body, and apply for renewal with third-party evaluation every 3 years

Log Acquisition

Requires network log and alert analysis, etc.

In addition to the left, requires 6-month log retention and monthly review of authentication logs, etc.

Requirements and log bases are sourced from Official Requirements & Evaluation Criteria, evaluation methods from IPA System Details, and validity/renewal from SCS-100 Basic Regulations Sections 3.1.2 & 3.2.2.

4-Star Is Not Simply "Adding 17 Items to 3-Star"

The 26 and 43 counts represent the number of "Requirements." Each requirement contains multiple "Evaluation Criteria" to verify compliance.

4-Star adds requirements such as log acquisition, supply chain security posture checks, and device behavior monitoring. Furthermore, even for requirements shared with 3-Star, 4-Star-specific evaluation criteria are added. When creating a task list, align them down to the Evaluation Criteria ID rather than comparing requirement names alone. Official Requirements & Evaluation Criteria

Additionally, 3-Star is not a self-declared check completed by internal staff. It requires validation and signature by an expert, followed by a self-conformity declaration by management before submission. For 4-Star, enterprises must prepare a self-assessment and then undergo evaluation by an authorized body. SCS-100 Basic Regulations Sections 3.1.1 & 3.2.1

Should You Target 3-Star or 4-Star?

The starting point for decision-making is supply chain impact rather than company size. Assess whether your customer's critical operations stop if your services fail, if you hold sensitive confidential data, or if you connect to your customer's systems. METI also indicates business continuity and information management risks as key metrics for selecting a target tier. System Development Policy Page 15

For example, if you maintain a customer’s production system and hold administrative access, you must account for the impact if those privileges are compromised. Confirm with your business partners regarding the "required tier," "target scope/systems," "deliverables," and "deadlines" to align preparations. Note that this is a practical example for clarifying business terms, not an official auto-determination rule.

The SCS Evaluation System is voluntary. Avoid misunderstandings that the system as a whole is universally mandatory or that certification can be achieved simply by purchasing specific security products. For official terminology, target IT infrastructure, and OT relationships, refer to METI System Explanation and SCS Evaluation System Overview.

What Records to Prepare for Training, Monitoring, and Logs

The following are practical examples to translate official requirements into internal workflows.

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。