Overview of the SCS Evaluation System for Supply Chain Resilience

Overview

IPA’s SCS Evaluation System is a new evaluation framework designed to raise the level of security measures across the entire business and IT service supply chain. It envisions a mechanism in which commissioning parties present contracted parties with an appropriate level of security measures based on their position in the business relationship, encourage implementation, and then verify the status. Commissioning parties face challenges in visualizing the status of measures and ensuring that requirements are appropriate, while contracted parties face the burden of receiving different requirements from multiple commissioning parties. The system aims to organize these issues. It covers all supply chain companies and is expected to be particularly beneficial for small and medium-sized enterprises with limited resources. Since the system website was launched in April 2026, system information, committee materials, and email newsletters have been developed successively.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • The system organizes the evaluation and requirements-related challenges faced by both commissioning parties and contracted parties.
  • It envisions presenting security levels according to business relationships and verifying implementation status.
  • It aims to improve security measures across the entire supply chain, including small and medium-sized enterprises.
  • Publication of system information and development of the operating structure have progressed since April 2026.

Overview

In recent years, security incidents occurring through supply chains have become frequent, creating a need for measures across the entire supply chain, including contracted parties.

For commissioning companies, challenges have emerged in visualizing contracted parties’ security measures and ensuring that requirements such as checklists are appropriate.

For contracted companies, being required to meet different requirements from multiple commissioning parties under complex business relationships has become an excessive burden. Against this background, the SCS Evaluation System is positioned as a framework that presents a common approach to evaluating measures according to business relationships.

Key figures

New system website launch date
April 21, 2026
Special website launch date
May 29, 2026
Email newsletter registration start date
July 7, 2026
Latest notice update date
July 13, 2026

Impact

Through acquisition of a mark based on this system, it encourages implementation of measures against risks such as interruption of the company’s business and service provision originating from cyberattacks on contracted parties, leakage or alteration of confidential information, and unauthorized intrusion using contracted parties as stepping stones.

Presenting the necessary measures according to a company’s position in the supply chain is expected to make it easier for companies to decide on measures and contribute to raising the overall level of supply chain security. The system is expected to be particularly beneficial for small and medium-sized enterprises because they have limited resources for available security measures and face difficulty implementing measures based on their own risks.

Details

In operating the system, it is envisioned that, for each transaction contract between two companies, the commissioning party will present the contracted party with an appropriate level, encourage the measures indicated, and verify their implementation status.

The system covers all supply chain companies, and its website provides information on requirements and evaluation criteria, security experts and evaluation organizations, related systems and measures, system rules and committees, and frequently asked questions.

Public information about the system has been updated through the website launch on April 21, 2026; the cautionary notice on April 30, 2026; the special website launched by the Ministry of Economy, Trade and Industry on May 29, 2026; publication of materials such as those from the first Operating Deliberation Committee meeting on June 12, 2026; the start of email newsletter registration on July 7, 2026; and publication of the committee member list and second committee materials, along with the launch of recruitment for a demonstration project for a new type of Cybersecurity Otasuketai Service, on July 13, 2026.

The latest information and seminar announcements are distributed through the email newsletter, and the registration form uses the external service WEBCAS. Cooperation with a survey that contributes to developing the operating structure is also requested. The contact is the Security System Group of the Risk Management Department at the IPA Security Center.

Related Articles