Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Policy Watch

FSA Drafts Would Add Corporate Numbers to Critical-Infrastructure Supplier and Intermediary Filings

Six draft orders from the FSA would have designated operators report corporate numbers for suppliers, holders of 5% or more of their voting rights and supply-chain intermediaries, with comments due by noon on 31 October 2026.

By Tokyo Brief DeskOct 2, 20263 min read
Illustration of server racks connected through intermediary nodes to supplier blocks, with ownership-share arcs and ID tags on each link.

The Financial Services Agency has drafted six orders that would widen what designated critical-infrastructure operators tell the government about who supplies, installs and maintains their key equipment. Comments are open until noon on 31 October 2026.

The package implements the June 2026 amendment of the economic security law, which the FSA says provided for operational improvements to the regime, including changes to what an introduction plan must contain. It is one Cabinet Office order plus five joint orders with the Justice, Finance, Health and Agriculture ministers. Under the regime, a designated operator files an introduction plan before installing specified critical equipment or outsourcing its critical maintenance.

Who must be named

Equipment suppliers would be reported with a corporate number alongside name, representative, address and place of incorporation. The same goes for holders of 5% or more of a supplier's voting rights, who must now be listed with corporate number, place of incorporation and their share. The form tells filers to leave the corporate-number box blank for individuals and for companies that have not been assigned one. The rules extend to component suppliers, maintenance contractors and subcontractors.

A new Article 16 item writes the persons involved in the introduction into the order itself. The existing form already asks for them; the draft adds a corporate number to each entry. The form defines them as intermediaries between operator and supplier that play an important part in managing the supply chain, or parties who check cybersecurity measures and could alter the equipment's function. Each entry lists name, representative, address, place of incorporation and the nature of its role.

Filing mechanics

Supporting documents without an expiry would have to be dated within six months of filing, not three. Evidence that the operator has anti-interference measures in place is a new required document, and it is exempt from that recency test. The Article 9(2)(ii) document, which backs officers' dates of birth and nationality, can be left out if the content already filed under the Act's critical-infrastructure chapter is unchanged and the plan says so, unless the authorities ask for it.

The ownership snapshot would be taken within six months before filing, rather than two. Equipment locations would be reported at least to prefecture level. Cloud users would name the cloud provider and may give the cloud region instead of a prefecture, and data-centre users would name the data-centre operator. Each box an operator ticks on the anti-interference checklist would need a supporting document.

Changes after filing

Adding a supplier would count as a significant change, while a change in a supplier's name drops off that list. Article 25 already covers changes to a component's type, name or function; the draft adds changes to a component supplier's name, address, corporate number or place of incorporation that accompany them. A new Article 2-2 would credit a successor in a merger, split or business transfer with the transferred business's results when testing designation criteria, and remove them from the transferor's.

Timing

The FSA says the orders will be promulgated and enforced after the comment period and the necessary procedures. They remain drafts until then.

Earlier Tokyo Brief coverage