I run an IT services firm in Tokyo. We're currently working through ISO/IEC 27001 certification — the international ISMS standard, adopted in Japan as JIS Q 27001 (the two documents are substantively identical; Japanese government materials cite the JIS flavor) — and somewhere in the middle of that process I stumbled onto something called SECURITY ACTION. It's run by the IPA (Information-technology Promotion Agency, Japan), costs nothing, and it takes an afternoon to complete.
This post is for the Japan small-business operator — especially ones run by non-Japanese — who has never heard of the scheme. Let me share what I learned, because two recent changes — IPA moved SECURITY ACTION signup behind gBizID Prime as of April 2026, and METI just finalised a new supply-chain security scheme called SCS that will start landing in procurement contracts from 2027 — together make this more relevant than it looked six months ago. Both are explained below.
If you operate a SME in Japan, it's time to sign up, and polish up your stance toward security.
What IPA SECURITY ACTION is
SECURITY ACTION (セキュリティアクション) is a self-declaration scheme, not an audited certification. You sign up, you commit publicly to specified security behaviours, and in return you get a logo you can put on your website and business cards.
There are two tiers:
| Tier | Requirements |
|---|---|
| ★1 (一つ星) | Commit to working through the IPA's SME information security guidelines. That's the entire bar. It's a public statement of intent. |
| ★2 (二つ星) | Publish your own basic information security policy, and complete the IPA's 25-item self-check (5分でできる自社診断). |
The self-check itself is an IPA-published PDF and it's surprisingly readable. The English version is here if you want to see the actual questions before committing: 5-Minute Information Security Self-Assessment (IPA, EN, PDF). The full underlying Japanese SME security guideline — which is what ★1 asks you to work through — is SME情報セキュリティ対策ガイドライン v4.0 付録3 (IPA, JA, PDF). These are mirrored on my media server; the authoritative copies are on ipa.go.jp.
Both tiers are free to use with the gBizID Prime, self-declared and renewed annually. That's the whole scheme.
If that sounds unimpressive, that's because on its own it is. ★2 is "we wrote down a security policy and filled out a checklist." Nobody's going to mistake it for ISO 27001 or SOC 2. What matters is what it signals inside Japan and what it's about to become connected to.
International context: it sits where UK Cyber Essentials sits
If you're coming from outside Japan and trying to place this scheme in a mental map, the closest international analogue is the UK government's Cyber Essentials (launched 2014). The philosophy's the same: a low-friction, government-backed, two-tier program(me) explicitly aimed at SMEs that would otherwise not engage with security formally at all. Cyber Essentials has the basic tier plus Cyber Essentials Plus, which layers an external technical assessment on top. Cyber Essentials is somewhat more rigorous than SECURITY ACTION — even its basic tier is externally verified — but the role the two schemes play in their respective national ecosystems is parallel: raise the bar a bit, cheaply, visibly.
SECURITY ACTION isn't officially derived from Cyber Essentials. IPA developed it independently, and IPA public materials don't claim a foreign reference model. But the resemblance is close enough if a UK reader asked me "does Japan have a Cyber Essentials?", I'd point to SECURITY ACTION, with the caveat that Japan's basic tier is purely self-declared, with no external verification at either level.
Where Japan isn't improvising is underneath. The substance behind ★1 and ★2 — the IPA SME Information Security Guideline — is mapped to ISO/IEC 27001 / JIS Q 27001 and to the NIST Cybersecurity Framework. So the outer wrapper is Japan-originated, but the control set it points at is aligned with the same international standards Japanese enterprises already run on. That alignment is also why SCS can bolt cleanly on top: SCS's requirement set is explicitly NIST CSF 2.0.
The April 2026 rules change
Until April 2026, SECURITY ACTION declarations were made through a lightweight online form. That changed on April 1, 2026: the IPA rebuilt the whole thing around gBizID — the Japanese government's unified business identity system.
To self-declare SECURITY ACTION now, you need a gBizID Prime account. Prime is the highest of the three gBizID tiers, and it's tied to the 代表者 (daihyō, representative director) of the company. There are two application paths, and the choice matters — turnaround differs by about two weeks:
| Path | Requirements | Turnaround (Digital Agency) |
|---|---|---|
| Online (オンライン申請) | The daihyō's My Number card with an active signing certificate, a PC with email, and a smartphone with the GビズID app installed (for NFC card-reading + SMS) | Same day (最短即日) |
| Postal (書類郵送申請) | The daihyō's registered personal 印鑑 (inkan, seal) and a fresh 印鑑証明書 from the ward office, a printed 登録申請書, and a physical mailing to the Digital Agency | Within 2 weeks (原則2週間以内) |
Both paths and their official turnaround figures come straight from the Digital Agency's GビズID Quick Manual for 法人代表者 (v1.4, March 2026, PDF) — see the アカウント体系 table on page 1. The full manual index has equivalent editions for 個人事業主 and 府省・地方公共団体職員 if your situation differs.
The online path is the one the Digital Agency is clearly steering people toward. You start the application on a PC at gbiz-id.go.jp, the portal hands you a QR code to install the GビズID app on your phone, the app reads your My Number card over NFC, you enter the signing-certificate PIN, and the daihyō's electronic signature authenticates the submission. Done the same day.
Once the daihyō has Prime, they can issue gBizID Member accounts to other staff inside the company. The member accounts can then be used for operational work — including SECURITY ACTION declarations, subsidy applications, and increasingly a long list of other government-facing services.
So gBizID isn't just a login for this one scheme, but quietly becoming the identity layer for business-to-government interactions in Japan. If you're operating a company in Japan and you don't have gBizID Prime yet, getting it is worth doing regardless of SECURITY ACTION, because the next thing you might need it for is probably months away.
The real friction for a foreign daihyō isn't either path itself — it's the prerequisite underneath both. The online path needs a valid My Number card, which requires a 住民票 (Japanese resident registration) to obtain. The postal path needs a registered 印鑑 plus 印鑑証明書, which also require resident registration. A daihyō who has neither hits the wall upstream of gBizID, not inside it.
So, why now? SCS is coming
In March 2026, METI (Ministry of Economy, Trade and Industry) finalised the 制度構築方針 — the design document — for a new scheme called SCS (Supply Chain Security) 評価制度. Full program launch is targeted for the end of FY2026 (around March 2027). SCS will have tiers, probably numbered ★1 through ★5, and the requirements draw on NIST CSF 2.0 — the same framework large US prime contractors (the companies at the top of a supply chain that hold the customer contract and push requirements down to their subcontractors) already use.
What's SCS for? It's the scheme that large Japanese primes are expected to start writing into their procurement requirements. If you sell to a Toyota, an NTT, or a Mitsubishi subsidiary, and today they ask for ISMS or Pマーク, in a couple of years they'll increasingly ask for your SCS star rating. That's the explicit intent of the program.
SECURITY ACTION re-enters the picture precisely because ★1 and ★2 are the on-ramp. METI and IPA have been aligning the schemes so that a company with SECURITY ACTION ★2 has already done the substance needed to move up into SCS ★1/★2 without starting from zero. The two-star self-check is effectively the baseline that SCS builds on.
%%{init: {'flowchart': {'nodeSpacing': 20, 'rankSpacing': 25, 'padding': 6, 'curve': 'basis'}}}%%
flowchart TD
S5[★5 · SCS — frontier tier, specs not yet published]
S4[★4 · SCS — third-party evaluation · document + onsite + technical]
S3[★3 · SCS — expert-confirmed self-evaluation · 登録セキスペ sign-off]
S2[★2 · SECURITY ACTION — published policy + 25-item self-check]
S1[★1 · SECURITY ACTION — public commitment to improve]
S5 --> S4 --> S3 --> S2 --> S1
style S5 fill:#1a4d7a,color:#fff
style S4 fill:#2980b9,color:#fff
style S3 fill:#3498db,color:#fff
style S2 fill:#7fb3d8,color:#000
style S1 fill:#b8d8eb,color:#000
Two schemes share one numbering: SECURITY ACTION (IPA) covers ★1–★2; SCS (METI) covers ★3–★5. Separate registries, separate requirements, separate costs — ★4 in particular is a full third-party assessment and not going to be cheap — but METI deliberately made the numbering continuous, so a SECURITY ACTION ★★ holder sees a next step rather than a reset. That's exactly what makes ★★ the cheapest way for an SME to get onto the bottom rung of a ladder being built right above it.
SA is a commitment signal for the Japan market
I want to be direct about what this scheme is and isn't, because I think the IPA marketing materials are a little coy about it.
SECURITY ACTION isn't a certification. Nobody verifies your claims. If you declare ★2, nobody audits whether you wrote a policy or filled out the self-check honestly. The logo means "this company publicly committed to doing the thing," not "this company was independently verified to do the thing."
That's not a criticism. Pマーク and ISO 27001 occupy the "verified" slot. SECURITY ACTION occupies a deliberately lower-cost slot where the point is to get a large number of SMEs to at least raise their hand and publicly commit. The gap between "haven't thought about it" and "wrote a policy and filled out the checklist" is bigger than the gap between ★2 and ISMS, even if the optics look the other way round.
If you have ISO 27001, SECURITY ACTION ★2 is trivially satisfied. The substance required for ★2 — a published policy and a 25-item self-check — is a subset of what any credible ISMS already produces. My firm has its ISMS documentation in flight for certification, so as soon as gBizID Prime lands we'll roll straight into ★★. The self-check is a formatting exercise against evidence we've already written.
But SECURITY ACTION fills a niche ISO 27001 doesn't. Japanese SMEs, Japanese consumers, and Japanese procurement teams recognise the ★★ logo on a footer in a way they often don't recognise an ISMS registration number. It's a locally legible signal. Overseas buyers will care about ISO 27001; the local 取引先 asking whether you take security seriously at all will care about the ★★. Both are valid, and they're cheap to carry together.
It's also the cheapest way to qualify for the Digital Introduction Subsidy (IT導入補助金). If your small business is going to apply for that subsidy to defray the cost of Microsoft 365, an accounting system, or an EDR deployment, ★1 or ★2 is a hard prerequisite. Declaring it is cheaper than not being able to apply.
Practical steps
If you decide you want to do this, the sequence is:
- Decide which path the daihyō will use for gBizID Prime.
- Fastest (online, ~same day): The daihyō needs a My Number card with the signing certificate active, plus an iPhone or Android that can read the card. On a PC, start at gbiz-id.go.jp, scan the portal's QR code to install the GビズID app on the phone, read the card with the app, enter the signing-certificate PIN, and submit.
- Paper (postal, ~2 weeks): The daihyō needs a registered personal 印鑑 and a 印鑑証明書 from the ward office. Fill out the 登録申請書 from the portal, print it, stamp it, attach the 印鑑証明書, and mail to the Digital Agency.
- Issue a gBizID Member account from the Prime admin console for whoever runs things day-to-day.
- Log into the IPA 管理システム with either account, work through the declaration wizard, and submit.
- For ★1: commit and you're done. For ★2: you'll be asked to confirm you have a published information security policy and have completed the self-check. Both are trivially satisfied if your company has any written security posture at all; both take a couple of hours from scratch if you don't.
- Update your corporate website with the ★ or ★★ logo, following the IPA usage guidelines.
- Renew annually. Calendar reminder. It's free to renew.
The SECURITY ACTION work itself, once the daihyō has gBizID Prime, is an afternoon. The long pole is Prime — same day if the daihyō has an activated My Number card, about two weeks if they go the postal route.
Bottom line
If you're running a small company in Japan and you don't have SECURITY ACTION ★★ declared, there's very little reason not to. It's free, it takes an afternoon, and gBizID Prime is something you'll end up needing anyway. If you have neither ★★ nor ISO 27001, ★1 is a respectable first step on its own — a public commitment to improve is more than most companies of any size have actually put in writing.
For us, gBizID Prime is in flight right now, and ★★ goes on the to-do list the moment it lands. SCS ★3 is a later problem.
Useful links: SECURITY ACTION (IPA) · gBizID portal · IPA SME security guidelines · METI SCS program page

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.