Japan's Cabinet Office, together with seven ministries, opened a five-week public comment window on July 21 for a draft order that would name two specific products, Microsoft's Windows and Windows Server, as the "widely and generally used" software covered by the country's new critical-infrastructure cyber-incident reporting regime. The move fills in a blank left by the underlying statute: which mainstream operating systems actually fall inside the reporting net once the law takes hold.
What the draft actually designates
The order sits inside a broader ministerial rule that sets incident-reporting duties for what the law calls specified critical-infrastructure operators, under the Act on Prevention of Damage Caused by Unauthorized Acts Against Critical Computers (Reiwa 7 Law No. 42). Article 2, paragraph 1 of that ministerial rule carries a proviso covering software "widely and generally used," and the draft names exactly two products as meeting that description: Windows and Windows Server, both attributed to Microsoft Corporation. The eight-agency drafting group, the Cabinet Office plus the ministries overseeing internal affairs, justice, finance, health and welfare, agriculture, industry, and land and transport, points to a reporting regime meant to reach operators well beyond a single sector.
Timeline
Comments are due by August 25 at midnight Japan time, filed either through the e-Gov online submission form or by post to the Cabinet Office's cyber-security policy unit in Akasaka, Tokyo. The government expects to promulgate the finished order in September 2026, with the rule taking effect on October 1, 2026, the same day the underlying law itself comes into force.
| Milestone | Date |
|---|---|
| Comment period opens | July 21, 2026, 00:00 JST |
| Comment deadline (must arrive by) | August 25, 2026, 00:00 JST |
| Expected promulgation | September 2026 (stated as expected) |
| Order and underlying law take effect | October 1, 2026 |
What the record leaves open
Pinning the "widely used software" designation to two named products, rather than a general description of common operating systems, gives operators and Microsoft a concrete reference point once the reporting duties activate. What the published notice and overview do not spell out is which specific reporting obligations attach to a critical computer once its software carries this designation, nor whether other products are under consideration for a similar listing. The materials released for this comment round also stop short of sector-by-sector compliance guidance, so healthcare, finance, transport and other covered operators are left to work out the practical mechanics before the October start date, or to say so in their comments before the window closes.
