Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フ

Japan's day, wrapped and delivered by morning.

Policy Watch

Japan Proposes Naming Windows as the 'Widely Used' Software Under New Cyber-Reporting Order

Eight Japanese government bodies have opened a five-week comment window on a draft rule naming Microsoft's Windows and Windows Server as the widely used software covered by the country's incoming critical-infrastructure incident-reporting law, due to take effect October 1.

Jul 21, 20262 min read
Editorial illustration of server racks behind an abstract regulatory checkpoint gate, symbolizing a new mandatory cyber-incident reporting threshold for critical infrastructure operators.

Japan's Cabinet Office, together with seven ministries, opened a five-week public comment window on July 21 for a draft order that would name two specific products, Microsoft's Windows and Windows Server, as the "widely and generally used" software covered by the country's new critical-infrastructure cyber-incident reporting regime. The move fills in a blank left by the underlying statute: which mainstream operating systems actually fall inside the reporting net once the law takes hold.

What the draft actually designates

The order sits inside a broader ministerial rule that sets incident-reporting duties for what the law calls specified critical-infrastructure operators, under the Act on Prevention of Damage Caused by Unauthorized Acts Against Critical Computers (Reiwa 7 Law No. 42). Article 2, paragraph 1 of that ministerial rule carries a proviso covering software "widely and generally used," and the draft names exactly two products as meeting that description: Windows and Windows Server, both attributed to Microsoft Corporation. The eight-agency drafting group, the Cabinet Office plus the ministries overseeing internal affairs, justice, finance, health and welfare, agriculture, industry, and land and transport, points to a reporting regime meant to reach operators well beyond a single sector.

Timeline

Comments are due by August 25 at midnight Japan time, filed either through the e-Gov online submission form or by post to the Cabinet Office's cyber-security policy unit in Akasaka, Tokyo. The government expects to promulgate the finished order in September 2026, with the rule taking effect on October 1, 2026, the same day the underlying law itself comes into force.

Draft designation timeline
Dates as stated in the public comment notice and overview document; the promulgation date is described as expected, not final.
MilestoneDate
Comment period opensJuly 21, 2026, 00:00 JST
Comment deadline (must arrive by)August 25, 2026, 00:00 JST
Expected promulgationSeptember 2026 (stated as expected)
Order and underlying law take effectOctober 1, 2026

What the record leaves open

Pinning the "widely used software" designation to two named products, rather than a general description of common operating systems, gives operators and Microsoft a concrete reference point once the reporting duties activate. What the published notice and overview do not spell out is which specific reporting obligations attach to a critical computer once its software carries this designation, nor whether other products are under consideration for a similar listing. The materials released for this comment round also stop short of sector-by-sector compliance guidance, so healthcare, finance, transport and other covered operators are left to work out the practical mechanics before the October start date, or to say so in their comments before the window closes.