Insight
Differences Between SCS Rating 3-Star and 4-Star: Requirements, Evaluation Methods, and Validity Period
Compare SCS rating levels 3 and 4 across requirements, evaluation methods, validity periods, renewals, and log management. Learn how to choose the right level based on client requests, with official guide-based examples for training, monitoring, and log preparation.

The main differences between 3-Star (★3) and 4-Star (★4) ratings in the Supply Chain Security Evaluation System (SCS Evaluation System) for strengthening supply chains lie in the scope of required security controls, the evaluation methodology, and post-certification maintenance procedures. 4-Star requires third-party assessment in addition to the controls required for 3-Star. Achieving 3-Star first is not a prerequisite for obtaining 4-Star. IPA Graduated Evaluation
This comparison table and practical examples clarify "what to prepare for 3-Star" and "what additional requirements are needed if a business partner requests 4-Star."
As of September 17, 2026. 3-Star and 4-Star operations are scheduled to start around March 2027. Note the distinction between the publication of system documentation and the opening of applications for enterprises. IPA FAQ
Comparison of 3-Star and 4-Star Differences
Comparison Points | 3-Star (★3) | 4-Star (★4) |
|---|---|---|
Control Level | Addressing common cyber threats | In addition to intrusion prevention, preventing damage expansion and protecting business partner information and systems |
Number of Requirements | 26 items | 43 items (includes 3-Star requirements) |
Evaluation Method | Self-assessment with expert validation | Third-party evaluation (document review, on-site assessment, technical verification) |
Validity Period | 1 year from registration notification date | 3 years from registration notification date |
Maintenance & Renewal | Receive expert validation/advice before expiration and submit an updated self-assessment | Submit annual self-assessments to the evaluation body, and apply for renewal with third-party evaluation every 3 years |
Log Acquisition | Requires network log and alert analysis, etc. | In addition to the left, requires 6-month log retention and monthly review of authentication logs, etc. |
Requirements and log bases are sourced from Official Requirements & Evaluation Criteria, evaluation methods from IPA System Details, and validity/renewal from SCS-100 Basic Regulations Sections 3.1.2 & 3.2.2.
4-Star Is Not Simply "Adding 17 Items to 3-Star"
The 26 and 43 counts represent the number of "Requirements." Each requirement contains multiple "Evaluation Criteria" to verify compliance.
4-Star adds requirements such as log acquisition, supply chain security posture checks, and device behavior monitoring. Furthermore, even for requirements shared with 3-Star, 4-Star-specific evaluation criteria are added. When creating a task list, align them down to the Evaluation Criteria ID rather than comparing requirement names alone. Official Requirements & Evaluation Criteria
Additionally, 3-Star is not a self-declared check completed by internal staff. It requires validation and signature by an expert, followed by a self-conformity declaration by management before submission. For 4-Star, enterprises must prepare a self-assessment and then undergo evaluation by an authorized body. SCS-100 Basic Regulations Sections 3.1.1 & 3.2.1
Should You Target 3-Star or 4-Star?
The starting point for decision-making is supply chain impact rather than company size. Assess whether your customer's critical operations stop if your services fail, if you hold sensitive confidential data, or if you connect to your customer's systems. METI also indicates business continuity and information management risks as key metrics for selecting a target tier. System Development Policy Page 15
For example, if you maintain a customer’s production system and hold administrative access, you must account for the impact if those privileges are compromised. Confirm with your business partners regarding the "required tier," "target scope/systems," "deliverables," and "deadlines" to align preparations. Note that this is a practical example for clarifying business terms, not an official auto-determination rule.
The SCS Evaluation System is voluntary. Avoid misunderstandings that the system as a whole is universally mandatory or that certification can be achieved simply by purchasing specific security products. For official terminology, target IT infrastructure, and OT relationships, refer to METI System Explanation and SCS Evaluation System Overview.
What Records to Prepare for Training, Monitoring, and Logs
The following are practical examples to translate official requirements into internal workflows.



