SCS Evaluation System Pressures Small Manufacturers to Rethink Security
The SCS system's 153 criteria are weighted heavily toward evidence and accountability, not product purchases, which means small manufacturers must build operational structures rather than buy their way to compliance.
Key Facts
- The SCS Evaluation System is scheduled to begin operation around the end of fiscal year 2026.
- The system's 3 star and 4 star criteria total 153 evaluation items, organized into three axes: access management, sharing rules, and evidence and accountability.
- Fuji Holdings started a security enhancement project about two years ago, triggered by a president's question about ransomware countermeasures at a management meeting.
- Fuji Holdings set a five-year plan through 2029 to achieve 3 and 4 star SCS compliance, with a three-pillar strategy of rules, tools, and skills.
- METI issued a warning in April 2026 that introducing specific security products is not mandatory to achieve SCS evaluation criteria.
Reporting from 1 source: ASCII.jp.
Mid-sized and small manufacturers are wrestling with the reality of the SCS Evaluation System, a Japanese supply chain security certification slated to begin around the end of fiscal year 2026. The system grades companies from 3 to 5 stars, with 3 and 4 star criteria forming 153 total evaluation items. Fuji Holdings, the administrative arm of kitchen equipment maker Fuji Kogyo Group, shared its progress at the 21st Factory Security Guideline Awareness Seminar in July 2026. Hideaki Urabe, general manager of corporate planning, detailed a two-year-old project triggered by a president's question about ransomware countermeasures. The group set a five-year plan through 2029 to achieve 3 and 4 star compliance, adopting a three-pillar strategy of rules, tools, and skills. They standardized on CrowdStrike EDR and introduced Rubrik for backups, while consolidating department NAS into file servers. Urabe admitted that IT and OT networks remain mixed at production sites, with old operating systems still in use, and that IT/OT separation will take time due to factory renovations. The group also plans to establish human and physical security management regulations and redefine IT roles.
The seminar where Fuji Holdings presented was the 21st Factory Security Guideline Awareness Seminar, co-hosted by the Japan Network Security Association's OT Security Working Group and the University of Tokyo Green ICT Project. The Fuji Kogyo Group, known by the corporate brand FUJIOH, holds a 61.8 percent domestic share in range hoods, according to Fuji Keizai's 2026 market data handbook.
Urabe's project began the same day the president asked about ransomware readiness. He consulted Hitachi Solutions, with which he had a 15-year relationship, and the project started as co-creation with that company. "In strengthening security, having top management's understanding was extremely significant," he said.
- Tools: CrowdStrike EDR standardization runs through Hitachi Solutions' MDR service; Rubrik handles core system backups, with department systems piggybacking on the same platform.
- Rules: New human security management and physical security management regulations will be set to SCS requirement levels, then "gradually systematize while observing operations," Urabe said.
- Roles: The vague "IT promoter" role is being replaced by department IT managers and IT administrators, with department heads bearing maintenance and operation responsibility.
- Skills: IT Passport certification, already mandatory for managers, will expand to other employees, linked to ITSS qualifications.
- Motivation: A compensation and evaluation system is planned for skill acquisition and managerial positions.
Dropbox Japan's Yuki Ue, a CISSP holder, told a separate seminar that about 70 percent of the 153 criteria require building structures and evidence for accountability, not product purchases. METI issued a warning in April 2026 about inappropriate product solicitation tied to the system.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.