Overview of the SCS Evaluation System for Supply Chain Resilience
Overview
IPA’s SCS Evaluation System is a new evaluation framework designed to raise the level of security measures across the entire business and IT service supply chain. It envisions a mechanism in which commissioning parties present contracted parties with an appropriate level of security measures based on their position in the business relationship, encourage implementation, and then verify the status. Commissioning parties face challenges in visualizing the status of measures and ensuring that requirements are appropriate, while contracted parties face the burden of receiving different requirements from multiple commissioning parties. The system aims to organize these issues. It covers all supply chain companies and is expected to be particularly beneficial for small and medium-sized enterprises with limited resources. Since the system website was launched in April 2026, system information, committee materials, and email newsletters have been developed successively.
Key points
- The system organizes the evaluation and requirements-related challenges faced by both commissioning parties and contracted parties.
- It envisions presenting security levels according to business relationships and verifying implementation status.
- It aims to improve security measures across the entire supply chain, including small and medium-sized enterprises.
- Publication of system information and development of the operating structure have progressed since April 2026.
Overview
In recent years, security incidents occurring through supply chains have become frequent, creating a need for measures across the entire supply chain, including contracted parties.
For commissioning companies, challenges have emerged in visualizing contracted parties’ security measures and ensuring that requirements such as checklists are appropriate.
For contracted companies, being required to meet different requirements from multiple commissioning parties under complex business relationships has become an excessive burden. Against this background, the SCS Evaluation System is positioned as a framework that presents a common approach to evaluating measures according to business relationships.
Key figures
- New system website launch date
- April 21, 2026
- Special website launch date
- May 29, 2026
- Email newsletter registration start date
- July 7, 2026
- Latest notice update date
- July 13, 2026
Impact
Through acquisition of a mark based on this system, it encourages implementation of measures against risks such as interruption of the company’s business and service provision originating from cyberattacks on contracted parties, leakage or alteration of confidential information, and unauthorized intrusion using contracted parties as stepping stones.
Presenting the necessary measures according to a company’s position in the supply chain is expected to make it easier for companies to decide on measures and contribute to raising the overall level of supply chain security. The system is expected to be particularly beneficial for small and medium-sized enterprises because they have limited resources for available security measures and face difficulty implementing measures based on their own risks.
Details
In operating the system, it is envisioned that, for each transaction contract between two companies, the commissioning party will present the contracted party with an appropriate level, encourage the measures indicated, and verify their implementation status.
The system covers all supply chain companies, and its website provides information on requirements and evaluation criteria, security experts and evaluation organizations, related systems and measures, system rules and committees, and frequently asked questions.
Public information about the system has been updated through the website launch on April 21, 2026; the cautionary notice on April 30, 2026; the special website launched by the Ministry of Economy, Trade and Industry on May 29, 2026; publication of materials such as those from the first Operating Deliberation Committee meeting on June 12, 2026; the start of email newsletter registration on July 7, 2026; and publication of the committee member list and second committee materials, along with the launch of recruitment for a demonstration project for a new type of Cybersecurity Otasuketai Service, on July 13, 2026.
The latest information and seminar announcements are distributed through the email newsletter, and the registration form uses the external service WEBCAS. Cooperation with a survey that contributes to developing the operating structure is also requested. The contact is the Security System Group of the Risk Management Department at the IPA Security Center.
Related Articles
2026-07-23 | 情報処理推進機構(IPA)
Open Data Spaces and Distributed Data Management
2026-07-23 | 情報処理推進機構(IPA)
IPA Defines Data-Sharing Requirements for Stable Automotive Semiconductor Supply
2026-07-23 | 情報処理推進機構(IPA)
IPA Publishes Common Data-Sharing Requirements for Supply Chains
2026-06-05 | Ministry of the Environment
Japan’s Circular Economy Vision Under the Action Plan | Chapter 1 | Japan’s Action Plan to Accelerate the Circular Economy