29.09.2026
Newsletters

“Japan’s New Cyber Incident Reporting Regime: What Foreign Cloud and Software Providers Should Review Before 1 October 2026”: Emerging Industries Team

Details

Japan’s New Cyber Incident Reporting Regime:
What Foreign Cloud and Software Providers Should Review Before 1 October 2026

 

Key takeaways

  • From 1 October 2026, certain designated Japanese critical infrastructure operators must notify the government of the specified critical computers they use — including relevant computing resources provided through cloud services — and report cyber incidents on short reporting timelines. Foreign cloud and software providers are not direct incident-reporting entities merely by virtue of being providers.
  • The regime attaches to what an operator uses, not what it owns: a cloud service hosted outside Japan can fall within scope, and, where notification is required, the service name and provider name go into a government filing (existing systems must be notified by 31 March 2027).
  • The Act’s supplier provisions (Article 42) reach suppliers outside Japan that supply covered computers, programs or services to persons in Japan: government vulnerability information, requests for remedial measures, and an effort-based duty to respond to requests for reports and materials.
  • The first demands will come from customers, not the government: expect requests for notification data and renegotiation of incident-notification clauses and SLAs against rapid reporting timelines that the draft commentary interprets as “as soon as possible” for DDoS and three to five days from recognition for ransomware and other reportable incidents.
  • Before 1 October: map exposure to the 258 designated operators, prepare notification data, review SLAs, document vulnerability-response (PSIRT) arrangements, and assign an owner for Japanese government contact.

Please click here for the full article.

 

[Contents]

1.    Why this matters outside Japan

2.    What takes effect — and what does not

3.    Who bears the direct duties: your customers

4.    Notification: where your product name appears

5.    Incident reporting: the clock your customers are on

6.    Article 42: the provisions that reach you directly

7.    What to review before 1 October 2026

8.    Timeline

9.    Closing observation

 

 

* This article reflects laws, subordinate legislation and official materials published as of 28 September 2026.

Publication date
2026.09
Services
Data Protection, Privacy, and Cybersecurity
Publisher

Newsletter

Authors
Partner

Yuka Daimon

Contact