SCS 評価制度対応

取引先に「SCS対応」を求められたら、何から始めるか。

経営層向けサマリ
  • SCS評価制度(経済産業省・IPA)は、サプライチェーン全体のセキュリティ水準向上を目的とした任意の制度です。2社間の取引契約等において、委託元が委託先に求めるセキュリティ対策の段階(★)を提示し、その対策の実施と実施状況の確認を行うことを想定しています。
  • ★3・★4は2027年3月頃の運用開始が予定されています(2026年7月時点の公開情報)。制度が動き出す前の、今の現状把握と改善が準備のすべてです。
  • CISOaaSは★3・★4の評価基準に沿って現状を可視化し、ギャップ把握・改善計画づくりで申請準備を支援します(★の取得や適合を保証するものではありません)。
このページで分かること
  • SCS評価制度の全体像(★1〜★5・スケジュール・任意性)
  • CISOaaSでできること(画面サンプル付き)
  • 進め方とプラン対応(★3=自己診断プラン以上/★4=専門家レビュー プラン以上)
Understanding the scheme

What is the SCS Evaluation Scheme?

Its formal name is the "Supply-chain Security Evaluation Scheme" (SCS). Japan's Ministry of Economy, Trade and Industry (METI) leads the scheme's design, and the Information-technology Promotion Agency (IPA) operates it.

The purpose is to raise security countermeasure levels across the supply chain: in two-party transaction contracts, the commissioning party is expected to present an appropriate level (★) to its supplier and confirm the status of countermeasures. It is a voluntary scheme, not a legal obligation. It targets all supply-chain organizations, with the greatest expected benefit for small and medium enterprises.

Five levels, ★1 through ★5
LevelEvaluation methodRequirementsValidity
★1 / ★2SECURITY ACTION (self-declaration)
★3Self-assessment with expert confirmation26 items1 year
★4Third-party assessment (including on-site review)43 items3 years
★5Under consideration
  1. 1Around October 2026: guidance and application procedures expected to be published
  2. 2Around March 2027: ★3/★4 expected to launch
  3. 3Fees to be announced (not yet determined as of July 2026)

The scheme information on this page is based on publicly available information (METI/IPA) as of July 2026. Please check METI's and IPA's official information for the latest details.

What CISOaaS does for you

Visualize your current state,
one evaluation criterion at a time.

Using the ★3/★4 evaluation criteria, an AI hearing captures your current state, and CISOaaS delivers category-level scores, gaps, an improvement plan, and a report end to end.

What we support

  • Current-state visibility against ★3 (81 evaluation criteria) and ★4 (153 evaluation criteria, including ★3)
  • Scores and gaps across the 7 major categories
  • Improvement planning based on risk analysis
  • A PDF report you can use to explain to management and partners
  • Expert review (Expert Review plan and above) to back the quality of the assessment

What we don't do

  • Guarantee acquisition of, or conformance to, a ★ level (a ★ level is granted through the scheme's own process)
  • Substitute for the ★4 third-party assessment by an assessment body, or for the confirmation itself by a registered security expert meeting the scheme's qualification requirements
STEP 1

Choose ★3 or ★4 and start against the evaluation criteria.

Simply choose the level you're targeting, and the AI hearing questions align with the matching evaluation criteria.

  • ★3 = 81 evaluation criteria (basic)
  • ★4 = 153 evaluation criteria (includes ★3; recommended/advanced level)
  • The levels available to you depend on your plan
Fig. 01SCS Level SelectSample
★3 (Basic)

Basic countermeasures recommended for all organizations

81 evaluation criteria
★4 (Recommended / Advanced)

Advanced level required for supplier and public procurement requirements

153 evaluation criteria (includes ★3)

Professional plan and above

STEP 2

The AI breaks down the criteria's technical language into plain questions.

You don't need to parse the evaluation criteria's wording yourself. The AI asks plain-language questions in a conversational flow and records your answers.

  • Questions are organized by subcategory, such as supplier management
  • Most answers are a click on a choice
  • Attach internal policy documents and the AI reads and reflects them
Fig. 02AI Hearing (SCS)Sample
★3 hearing progress17 / 81 items complete (21%)
302Supplier management
Do your supplier contracts define security requirements?

Choices

Yes, this is in place
Partially in place
Not in place
Our contracts state a basic policy, but we haven't defined a specific required level yet.
STEP 3

See your current state and gaps across all 7 major categories.

From governance to recovery, CISOaaS scores each of the 7 major categories and identifies weak points.

  • Each major category is scored out of 100
  • Prioritize improvement starting from the lowest-scoring categories
  • Flows directly into risk analysis and improvement planning
Fig. 03Category ScoresSample
Category-level summary
1
ガバナンスの整備
88/ 100
2
取引先管理
62/ 100
3
リスクの特定
74/ 100
4
攻撃等の防御
45/ 100
5
攻撃等の検知
80/ 100
6
インシデントへの対応
30/ 100
7
インシデントからの復旧
68/ 100
STEP 4

Turn the results into a report.

A PDF report including a category-level summary is generated automatically, ready to explain to management and partners.

  • Includes a category-level summary
  • Presents the improvement plan alongside the scores
  • Ready to use for internal approval and partner explanations
Fig. 04Report (PDF)Sample
SCS Evaluation Report
Level: ★3
Category-level summary
IDCategoryScore
1ガバナンスの整備88
2取引先管理62
3リスクの特定74
4攻撃等の防御45
5攻撃等の検知80
6インシデントへの対応30
7インシデントからの復旧68
How to proceed, and plan mapping

Three steps to get ready to apply.

  1. 1

    Assess

    Self-assess against the ★3-level evaluation criteria and identify gaps.

  2. 2

    Improve

    Work through countermeasures in priority order, guided by risk analysis and an improvement plan.

  3. 3

    Apply

    Prepare your application ahead of the expected launch around March 2027 (★3 expert confirmation can be handled in-house if you meet the qualification requirements; ★4 requires engaging an assessment body).

Self-Assessment planSupports up to ★3
Expert Review plan and aboveSupports up to ★4

The Self-Assessment plan lets AI run the assessment, analysis, and report on its own — it does not include review or approval by our security consultants. On the Expert Review plan and above, our security consultants check and approve the assessment before it is finalized.

View pricing plans

Start with self-assessment and get a ★3-level current-state read.

Answer questions aligned with the evaluation criteria and see your current score and gaps.

Start SCS prep with self-assessment

よくあるご質問

SCS評価制度は義務ですか?

任意の制度です。2社間の取引で委託元が段階(★)を提示し、対策を促す仕組みとして想定されています。

いつから申請できますか?

★3・★4は2027年3月頃の運用開始が予定されています。解説書・申請方法は2026年10月頃に公開予定です(2026年7月時点の公開情報)。

CISOaaSを使えば★を取得できますか?

★の取得や適合を保証するものではありません。評価基準に沿った現状の可視化と改善計画づくりで、申請準備を支援します。なお★3の専門家確認は、資格要件(情報処理安全確保支援士・CISSP等)と研修受講・事務局登録を満たせば社内の方でも担当できます。当社のセキュリティコンサルタントはCISSP資格を保有しており、専門家レビュー プラン以上をご利用の場合、制度の研修・登録の仕組みが整い次第、★3の専門家確認を担える見込みです(2026年7月時点では研修受講・事務局登録の制度自体が未整備のため、確定した対応ではありません)。★4の第三者評価は評価機関への依頼が必要です(当社は評価機関・登録セキュリティ専門家としての登録主体ではありません)。

どのプランが必要ですか?

★3水準の評価は自己診断プラン以上、★4水準の評価は専門家レビュー プラン以上でご利用いただけます。

取引先要件になる前に、現状を知る。

貴社の状況・目標段階に合わせた進め方をご案内します。

お問い合わせ