Full Report
Learn about Japan's Active Cyber Defense (ACD) strategy, mandatory reporting rules, and key impacts on critical infrastructure.
Analysis Summary
# Regulation/Compliance: Japan’s Active Cyber Defense (ACD) Framework
## Overview
The Active Cyber Defense (ACD) framework marks a strategic shift in Japan’s national security posture, moving from voluntary information sharing to a mandatory, proactive regime. It empowers the government to analyze communications data and disrupt malicious infrastructure to prevent serious cyberattacks against government and critical infrastructure before they cause significant damage.
## Key Details
- **Issuing Authority:** National Diet of Japan (Laws promulgated May 23, 2025)
- **Effective Date:** Phased (October 1, 2026, for reporting; November 23, 2027, for communications analysis)
- **Jurisdiction:** Japan (including overseas affiliates/vendors impacting Japanese "covered systems")
- **Status:** Final (Statutes Passed: Act No. 42 and Act No. 43 of 2025)
## Requirements
### Mandatory Requirements
1. **Notification of Covered Systems:** Designated critical infrastructure operators must notify the government regarding the systems that fall under ACD protection.
2. **Incident Reporting:** Mandatory notification to the government of "qualifying incidents" affecting covered systems.
3. **Information Cooperation:** Carriers and hosting providers may be required to assist government measures in identifying or neutralizing threats.
4. **Remediation Compliance:** Vendors and operators should expect and comply with government-led remediation requests following threat detection.
### Recommended Practices
1. **Supply Chain Visibility:** Organizations should extend monitoring to foreign subsidiaries and non-designated suppliers, as these are identified as high-risk "access paths" likely to be targeted to circumvent ACD.
2. **Evidence Preservation:** Establish robust forensic logging and evidence preservation protocols to support government investigations.
3. **Enhanced Escalation Procedures:** Update incident response plans to include specific triggers for ACD mandatory reporting.
## Affected Organizations
- **Industries:** Designated Critical Infrastructure (CI) sectors (Energy, Finance, Transport, Government, etc.), Telecommunications Carriers, and Hosting Providers.
- **Organization Size:** Primarily large-scale CI operators and their key technology vendors.
- **Geographic Scope:** Organizations operating within Japan, including their overseas affiliates and supply chains if they connect to Japanese "covered systems."
## Compliance Timeline
- **May 23, 2025:** Acts No. 42 and 43 promulgated.
- **October 1, 2026:** **Mandatory Cyber Incident Reporting begins.**
- **April 1, 2027:** Deadline for existing systems to submit initial notifications (6-month grace period from Oct 2026).
- **November 23, 2027:** **Full enforcement** of government communications-information collection and analysis authorities.
## Implementation Guidance
### Assessment Phase
- **System Categorization:** Identify which internal systems meet the definition of "Important Computers" under Act No. 42.
- **Dependency Mapping:** Analyze data flows between overseas subsidiaries/vendors and Japanese covered systems to identify reporting triggers.
### Implementation Phase
- **Registry Filing:** Submit notifications for all covered systems by the April 2027 deadline.
- **Process Integration:** Integrate ACD reporting requirements into the existing Security Operations Center (SOC) workflows.
- **Contractual Updates:** Revise vendor contracts to ensure suppliers provide the necessary data and access to meet government remediation requests.
### Validation Phase
- **Reporting Drills:** Conduct tabletop exercises specifically testing the "Qualifying Incident" reporting path to the government.
- **Audit:** Verify that communications analysis hooks (for carriers/providers) are technically feasible and compliant with the new legal framework.
## Technical Requirements
- **Incident Detection:** Capabilities to identify unauthorized acts against "Important Computers."
- **Data Sharing Interoperability:** Systems must be capable of sharing indicators and communications information with government oversight bodies.
- **Infrastructure Neutralization Support:** Telecommunications and hosting providers must maintain the technical ability to assist in the "access and neutralization" of malicious infrastructure.
## Penalties & Enforcement
- **Fines:** TBD (Statutory penalties for non-compliance with reporting or obstructive behavior).
- **Other Consequences:** Government-led disruption of company-owned infrastructure if it is being leveraged for attacks; reputational risk via public-private information sharing.
- **Enforcement:** Managed via new institutional structures established under Act No. 43, including independent oversight to balance national security with privacy.
## Related Standards
- **NIST CSF / ISO 27001:** Alignment expected regarding incident response and risk assessment.
- **International Norms:** Aligns Japan with "defend forward" postures seen in the US and UK.
## Resources
- **Official Documentation:** *Cyber Response Capability Strengthening Act (Act No. 42 of 2025)* [h-t-t-p-s://japan-diet.go.jp/...] (Defanged)
- **Official Documentation:** *Act on the Arrangement of Laws for Cyber Response (Act No. 43 of 2025)*
## Practical Recommendations
- **Broaden the Scope:** Do not treat ACD as a siloed compliance task. Treat it as a fundamental change to how the organization handles intelligence sharing.
- **Watch the "Gap":** Prepare for the 13-month gap between mandatory reporting (2026) and government detection support (2027); internal visibility remains critical during this period.
- **Monitor Subsidiaries:** Actively secure "non-designated" access points (employees, foreign branches) that threat actors (China, Russia, North Korea) will likely pivot toward to avoid ACD detection.