“Can we just pick products that carry the JC-STAR label?” Since the start of 2026, we have been asked this more and more often. Half of the answer is yes, but in day-to-day practice the answer is no. What bites in this scheme is not whether a label is attached, but the date on which the equipment category you buy becomes subject to a requirement. This article lays out the shape of the scheme and what buyers should be checking right now.
What JC-STAR Is: A Labeling Scheme Operated by IPA Under METI Supervision
The Official Name Is the Security Requirements Conformity Assessment and Labeling Scheme
JC-STAR is an abbreviation. Its official Japanese name translates as the Security Requirements Conformity Assessment and Labeling Scheme. It was built and is operated by the Information-technology Promotion Agency, Japan (IPA), under the supervision of Japan’s Ministry of Economy, Trade and Industry (METI).
That single sentence already settles two things that matter in practice. The first is that this is not a private certification business or a voluntary mark from an industry association, but a scheme designed as Japanese national policy. The second is that because IPA handles the day-to-day operation, information on conforming products is consolidated into a public list maintained by IPA. From the buyer’s side, that means you can confirm whether a product really conforms by looking at the public list rather than at a vendor’s sales deck.
The purpose of the scheme is equally clear. It is to make it easy for procurement staff and consumers to obtain information on the security status of a product. In other words, the emphasis is less on raising the level of security itself and more on making the differences that already exist visible from the outside. Misread this point and you will misread the entire scheme from the start.
What Actually Started on March 25, 2025
Here is the timeline. The scheme writes its levels as star ratings, and this article renders them as STAR-1 through STAR-4.
| Period | Event |
|---|---|
| August 2024 | METI publishes its policy for building the scheme |
| March 2025 | The scheme enters operation |
| March 25, 2025 | Applications open for STAR-1, and the list of products holding a conformity label goes public |
| January 2026 onward | Announced plan to begin accepting applications for STAR-2 and above (two product categories: network cameras and communication equipment) |
| June 12, 2026 | The conformity requirements for STAR-3 are published |
What deserves attention is that two things started on March 25, 2025: the acceptance of applications, and the publication of the product list. The day the scheme began operating was also the day buyers became able to search for products. News coverage of a scheme launch tends to frame it as a story about the supply side, but for procurement work the second item was the more direct change.
Why IoT Product Security Certification, and Why Now
For background, the number of cyberattack-related packets observed by NICTER reached a record high of approximately 686.2 billion packets in 2024. The number of IoT products has also continued to rise every year since 2019 (confirmed through 2023 data).
Unit counts are going up and observed attack volume is going up. When those two overlap, buyers no longer have the capacity to evaluate how each individual product was built. If you had to run a security audit on every network device, camera and sensor gateway that enters the plant, procurement would grind to a halt. So the approach chosen was to make the product side draw a minimum line in advance and to make that line visible from the outside. JC-STAR sits in that context.
How JC-STAR Relates to ETSI EN 303 645 and NISTIR 8425
JC-STAR is described as a scheme that harmonizes with domestic and international standards such as ETSI EN 303 645 and NISTIR 8425, while confirming and visualizing the conformity of IoT products against conformity criteria that it defines independently.
That phrase, “harmonizes with, while defining independently”, is worth reading carefully. JC-STAR is not a certification scheme for ETSI EN 303 645 itself. The structure is that the thinking behind the requirements is aligned with international standards, while the scheme holds its own separate conformity criteria as a Japanese scheme. So even when a vendor tells you a product “complies with ETSI EN 303 645”, that does not automatically mean it conforms to JC-STAR STAR-1. The reverse holds as well.
When you write a procurement specification, do not conflate the two. “Complies with an international standard” and “holds a JC-STAR STAR-1 conformity label” are information of completely different grain. The former is a claim; the latter is a fact you can cross-check against a public list.

JC-STAR Levels Are Divided by Who Evaluates, More Than by How Strict the Requirements Are
The Overall Picture of STAR-1 to STAR-4
This is the single sharpest point in understanding the scheme. Reading the number of stars as “STAR-1 is easy, STAR-4 is tough” is only half right.
| Level | Content | Evaluation method |
|---|---|---|
| STAR-1 | The minimum security requirements commonly required of a product | Self-declaration of conformity by the vendor |
| STAR-2 | Basic security requirements to be added to STAR-1, taking into account the characteristics of each product category | Self-declaration by the vendor |
| STAR-3 | Requirements assuming products for government agencies and critical infrastructure operators | Certified by IPA on the basis of an evaluation report from an independent third-party evaluation body |
| STAR-4 | Higher than STAR-3 (assuming government agencies and critical infrastructure operators) | Certified by IPA on the basis of an evaluation report from an independent third-party evaluation body |
The requirements do indeed become stricter as you move from STAR-1 to STAR-4. But the nature of the scheme changes between STAR-2 and STAR-3. STAR-1 and STAR-2 are self-declarations by the vendor; STAR-3 and STAR-4 are certified by IPA on the basis of an evaluation report from an independent third-party evaluation body. A thick line is drawn right there.
Self-Declaration of Conformity and Third-Party Certification Play Different Roles
When people learn that STAR-1 is a self-declaration of conformity, the reaction is sometimes “then the STAR-1 label is meaningless, isn’t it”. That reading is not accurate.
Self-declaration of conformity is a mechanism for spreading a minimum line across a large number of products in a short time. Third-party evaluation is a mechanism for securing confidence by spending time and money. The two are not competitors; they are a division of labor between coverage and depth. The IoT devices that go into a plant come in many varieties, and if each product had to pass a third-party evaluation one at a time, the device generation would turn over before the scheme could spread. Making STAR-1 a self-declaration is what makes it possible to draw a line across a broad range of categories in a short period.
At the same time, precisely because it is a self-declaration, the presence of a label alone does not let you say “this product is safe”. STAR-1 indicates the fact that the manufacturer has declared that the commonly required minimum requirements are met; it is not a comprehensive quality guarantee for the product. These two statements do not contradict each other. It is simply how the scheme is designed.
For buyers, the straightforward way to use the levels is as follows.
- STAR-1 and STAR-2 — Use them as a cut-off. A lower-bound filter that says “products without this drop out of the candidate list”.
- STAR-3 and STAR-4 — Use them as a plus. Because third-party evaluation is involved, they work as grounds for selecting equipment on high-importance lines or at points of external connection.
Try to use STAR-1 as “proof of quality” and you will be disappointed, but use it as “the lower bound that narrows the candidates” and there are few indicators this easy to apply. All it takes is cross-checking a model number against the public list.
The Schedule and Target Categories for STAR-2 and Above
For STAR-2 through STAR-4, at the point when operation began in March 2025, only STAR-1 was running ahead, and STAR-2 and above were said to be planned to start in fiscal 2026 (the Japanese fiscal year beginning April 2026) or later.
Subsequent announcements state a plan to begin accepting applications for STAR-2 and above from January 2026 onward, covering two product categories, “network cameras” and “communication equipment”, which are expected to be used in government procurement. In addition, the conformity requirements for STAR-3 were published on June 12, 2026.
Read from the plant side, the way those two categories were chosen carries meaning. Network cameras and communication equipment are both devices that are easy to see from outside, present in large numbers, and easy to push to the back of the queue when updates come around. In a plant, that means the site surveillance cameras and the network equipment such as wireless access points, industrial switches and routers sit close to these two categories. How these devices sit as components of the plant network is covered separately in Factory Wireless LAN and Industrial Network Design.
Note that what this article states about applications for STAR-2 and above goes only as far as the “announced plan” above. For the actual opening of applications and any addition of target categories, please check the latest information on IPA’s official pages. Because the scheme is advancing field by field, gaps can open up between an announced plan and actual progress.
Devices That Do Not Use IP Communication Fall Outside the Scheme
There is one more distinction to keep in mind alongside the discussion of levels. Devices that do not have IP communication functionality may be treated as outside the scope of the scheme.
As a concrete example, Yaskawa Electric announced officially on April 13, 2026 that its PCS (power conditioner) on its own has no IP communication function and is therefore outside the scope of the scheme. The absence of a label does not in itself mean “this vendor is behind”.
This is an important distinction for procurement work. Build an equipment list and color-code it by “label or no label” alone, and devices that were never in scope in the first place turn red as non-compliant. The first move in an inventory is not checking for labels but sorting on the question “does this device use IP communication?”. We come back to this point in the checklist later in the article.
What JC-STAR STAR-1 Requirements Ask For, Translated Into Shop-Floor Language
The STAR-1 security requirements published as specifications for conforming products are the following five items. Left in their original wording they are hard to drop into a procurement specification, so here they are retranslated into operational language.
| STAR-1 requirement | Translated into shop-floor language | What the buyer should check |
|---|---|---|
| Unique initial password for administrative screen login (consumer products), or mandatory password change at initial setup (business products) | The device cannot be operated with the shared factory-default password | Does the initial setup procedure have a step that will not let you proceed without changing it |
| Access restriction for a set period in response to failed login attempts | Brute-force attacks are stopped on the device side | Are the lockout threshold and the time until release stated explicitly in the specification |
| Encryption of configuration values | Even if the device or a configuration file leaves the site, the contents cannot be read | Is the configuration backup file something other than plain text |
| Automatic firmware update function | Updates are not left to human hands alone | Can you choose automatic update on or off, the timing of application, and the reboot behavior |
| Provision of security updates within the support period | It is settled how long you will keep getting fixes | Is the support end date published for each model number |
Of the Five Items, the Fifth Is the One That Bites in Procurement
The five items look like equals on the page, but the one with the biggest impact on the purchasing decision is the last one, “provision of security updates within the support period”.
The reason is simple. For the other four items, you check whether they are satisfied at the time of delivery and you are done, whereas only the fifth is a promise against a future time axis. Plant equipment stays in service for 10 or 15 years. Bring in a device whose security update provision ends five years after installation, without a replacement plan in hand, and from that point on you are keeping a device on the plant network that will not be fixed even when a vulnerability is published.
How to reflect this fifth item in a procurement specification is written out concretely in the checklist later in the article. To state the conclusion up front: what you need to check is not “is there support” but “when does it end“.
Where the Third Item, Encryption of Configuration Values, Matters
The other item that tends to be overlooked in the field is the third one, encryption of configuration values.
Where it matters is not when you install a device, but when you let go of it and when you hand it over. Lease returns, shipping units back to the manufacturer for repair, disposal of failed units, and moving equipment between overseas sites. If, at that moment, the configuration file still holds the network topology, password hashes and connection destination details without being encrypted, all of that walks out the door with it.
For a company with a site in Thailand, handing physical units to a local vendor for repair or replacement tends to happen more often than it would in Japan. Understanding encryption of configuration values as a requirement that lowers the risk of that workflow on the device side makes its significance easier to see. Security design across the plant as a whole, including network equipment, is covered in OT Security and IEC 62443 for Thai Factories.
The STAR-1 Requirements Ask for Nothing Special
Lining up the five items, you will have noticed that everything STAR-1 asks for has been standard advice in the security world for a long time. Force the initial password to be changed, stop brute force, encrypt the configuration, distribute updates, and decide how long you will distribute them. Not one of them is a novel technical requirement.
That is exactly why the meaning of STAR-1 is not “a high bar has been cleared” but “products that fail to meet these five can now be told apart in the market“. The value of the scheme lies not in raising the ceiling but in making the floor visible. That understanding leads into the next chapter.

The Date Is What Bites: The Roadmap Runs Ahead in the Solar and Storage Battery Field
The Roadmap in the Solar and Storage Battery Field
This is the main theme of the article. What bites in practice with JC-STAR is not the presence of a label but the date on which it becomes a requirement.
And at this point in time, the field with clear dates lined up is solar and storage battery.
| Period | Content | Applies to |
|---|---|---|
| March 2025 | The scheme enters operation | — |
| Fiscal 2026 | Effectively mandatory under the Ministry of the Environment’s Storage Parity subsidy | Subsidy applicants |
| April 2027 | Becomes a grid interconnection requirement (high voltage) | Newly connected facilities |
| October 2027 | Becomes a grid interconnection requirement (low voltage, under 50 kW) | Newly connected facilities |
This table is about the solar and storage battery field. Do not generalize it to other fields. No comparable dates have been fixed for production equipment, factory automation equipment or office network equipment.
That said, the structure this table shows does have general applicability. Look at the order. The scheme starts, then it becomes a subsidy requirement, and then it becomes a condition of grid interconnection. When a voluntary scheme starts to bite in practice, it very often follows this sequence. From “you had better get it”, to “without it the subsidy will not come through”, to “without it you cannot connect”.
In other words, the indicator buyers should be watching is not “how many products have obtained a label”. It is whether JC-STAR has started to show up in subsidy requirements or connection conditions for your own equipment categories. The former is a supply-side indicator; the latter is an indicator of whether your own procurement is about to stop.
“Effectively Mandatory” Is Not “Legally Mandated”
Let us be precise about terminology. “Effectively mandatory” in the context of the Ministry of the Environment’s Storage Parity subsidy in fiscal 2026 means that you will in practice need to line this up if you apply for the subsidy. It does not mean that obtaining the label is imposed on everyone who buys the product.
As things stand, no provision has been confirmed that uniformly obliges anyone to obtain JC-STAR. If you come across the phrase “JC-STAR has been made mandatory”, that is not accurate. What is actually happening is that the scheme remains voluntary while it begins to be cited as a requirement in specific fields and in specific situations.
This distinction pays off in internal explanations. Tell people “apparently it is being made mandatory” and a company-wide inventory starts that sweeps in equipment that was never in scope, and it usually stalls partway. Tell them “in the fields we are involved in, when will it be cited as a requirement” and the scope of investigation is bounded and you get an answer.
The Local Government Procurement Story Is a Prediction, Not a Settled Decision
There is one more frequently cited story worth touching on.
Regarding IoT product procurement by local governments and similar bodies, one commentary states that from April 2025 onward it is predicted that products will be required to have obtained JC-STAR, or to be expected to obtain it (this was a prediction as of the time the commentary was published).
This is a prediction in a commentary, not a settled matter. This article does not assert it either. As a practical way of handling it, however, the following reasoning is sound. Compare the cost of the prediction coming true with the cost of it not coming true. If the prediction comes true and the product in question has not obtained JC-STAR, there is a possibility of not even being able to enter the bid. If it does not come true, all you lose is the effort of adding one sentence to a specification. The asymmetry means the reasonable call is to include a sentence in the specification requiring either “already obtained” or “an explicit statement of the expected date of obtaining it”.
Even if you are not in the position of supplying products to local governments, this structure is worth remembering. Requirements do not always arrive as information you can state with certainty. In many cases you have to decide your response while it is still at the “predicted” stage.
What Happens to Factory IoT and OT Equipment
“So when is it our plant equipment’s turn?” This is probably the point readers most want answered, but clear dates of the kind seen in the solar and storage battery field have not been confirmed at this point. Since they have not been confirmed, this article does not offer speculative dates.
What can be said is that the leading targets for STAR-2 and above are the two categories of network cameras and communication equipment, and that these two categories also exist in large numbers inside plants. How to weave this scheme into factory IoT and OT equipment procurement and equipment replacement planning is covered in detail, down to how it maps onto the replacement cycle, in Factory IoT and OT Equipment Procurement and the Impact of JC-STAR.
International Position: Japan-Singapore Mutual Recognition Took Effect on June 1, 2026
JC-STAR is a domestic scheme, but its international connections have already begun. On March 18, 2026, Japan and Singapore signed a memorandum on the mutual recognition of JC-STAR and Singapore’s Cybersecurity Labelling Scheme (CLS). The mutual recognition took effect on June 1, 2026, and the baseline requirements of JC-STAR STAR-1 are recognized as equivalent to Level 1 of Singapore’s CLS. Japan is the fifth country to conclude mutual recognition with Singapore’s CLS, following Finland, Germany, South Korea and the United Kingdom.
In addition to this mutual recognition with Singapore, METI has indicated a policy of continuing negotiations on Japan’s own mutual recognition arrangements with the United Kingdom (PSTI Act), the United States (U.S. Cyber Trust Mark) and the EU (Cyber Resilience Act). What matters for a company with overseas sites is how far the conformity of a product that obtained STAR-1 in Japan will carry in another country’s scheme. How this mutual recognition can be used in building procurement criteria for overseas sites including Thailand, and what to set as the criterion in a situation where there is no equivalent scheme on the Thai side, is covered in The Japan-Singapore MRA and Procurement Criteria for Thai Sites.

Practical Steps for Buyers: A Checklist of What to Check Now
Let us bring the discussion of the scheme down to work you can start tomorrow. The order matters, so proceed in this sequence.
Step 1: Sort Your Equipment Into Four Groups (Inventory)
Before you look into labels, sort.
| Group | Condition | What to do |
|---|---|---|
| A | Uses IP communication, and scheduled for procurement or replacement within the next two years | Top priority. Add a sentence to the specification |
| B | Uses IP communication, already installed, replacement still some way off | Just confirm the support end date and record it in the register |
| C | Does not use IP communication | Likely outside the scope. Lower the priority, and if you cannot judge, move it to D |
| D | Cannot be judged | Ask the manufacturer whether the product is within the scope of the scheme |
Getting C out of the way first is the trick to finishing this inventory. As noted above, devices without IP communication functionality can fall outside the scope of the scheme. Mix them in and the list fills up with “non-compliant” entries and you can no longer set priorities.
For the D enquiries, sending them to a support desk rather than the manufacturer’s sales contact often gets an answer faster. Frame the question not as “have you obtained JC-STAR?” but as a set of three points: “is this model number within the scope of the scheme, and if so, has it already been obtained, and if not, when is it expected to be obtained?” If it is out of scope, you get an out-of-scope answer, and that completes the inventory for that item.
Step 2: Check Each Category for Signs That Requirements Are Coming
For the equipment that landed in group A, check whether there is any movement toward requirements in that category. There are three places to look.
- Subsidy application guidelines — Check whether the requirements of the subsidies your company uses include JC-STAR or a similar conformity requirement. In the solar and storage battery field it is effectively mandatory under the Ministry of the Environment’s Storage Parity subsidy in fiscal 2026.
- Connection and interconnection conditions — Check whether it has been built into conditions for connecting to infrastructure, as with grid interconnection.
- Bid specifications from national and local government — For local government procurement this is at the prediction stage as noted above, but once the wording starts appearing in actual bid specifications, that is confirmed information.
All three are information issued by the buying side and the scheme side, not by vendors. They move faster than chasing vendor product pages.
Step 3: Wording to Put Into the Procurement Specification
Here are example sentences to put into the specification for group A equipment. They are written so you can use them as they are.
Requirements Concerning Security Conformity
1. For those of the target devices that have IP communication functionality, a JC-STAR conformity label shall have been obtained as of the time of delivery. Where it has not been obtained, the proposal shall state explicitly whether the product is within the scope of the scheme and, if it is, the expected date of obtaining it.
2. Where it has been obtained, the proposal shall state the level obtained (STAR-1 to STAR-4), the range of model numbers covered, and the date obtained.
3. The planned end date of security update provision for the delivered devices shall be stated explicitly for each model number.
All three have different purposes.
- The first is the cut-off. However, making “has obtained it” the sole condition would exclude good equipment that was never in scope, so it is framed to ask first whether the product is within the scope.
- The second confirms who did the evaluating. The grounds for confidence differ between STAR-1 and STAR-3, so have them write down the level. Along with that, be sure to have them state the range of model numbers covered. There are cases where conformity is advertised under a series name while the actual scope of conformity is per individual model number.
- The third is in fact the one that keeps working the longest. The support end date is the date from which the next replacement plan starts.
Step 4: Write the Dates Into the Replacement Plan
Transfer the “planned end date of security update provision” collected under the third item of Step 3 into the register for your equipment replacement plan.
Plant equipment replacement plans are normally built around failure rates and depreciation. Adding a third axis, the support end date, is the most practically useful thing you get out of this scheme. Physically still running, fully depreciated, but no security updates are coming. Not many plants have a grip on how many devices in that state sit on their network.
Three columns in the register are enough: “model number”, “planned end date of security update provision”, and “planned replacement fiscal year”. The rows where the third column falls later than the second are where the risk sits.
Step 5: When You Find a Label, Check Three More Things
When you find a conformity indication on the public list or a product page, it only becomes usable for a procurement decision once you have checked the following three points.
- Level — STAR-1 and STAR-2 are a self-declaration of conformity; STAR-3 and STAR-4 are IPA certification based on an evaluation report from a third-party evaluation body. Who did the evaluating changes.
- Granularity of the covered model numbers — Is it the whole series, or only specific model numbers? Cross-check that the model number you intend to buy is included.
- Date obtained — If the date obtained is old, check whether subsequent model number revisions are included in the scope.
For what it is worth, uptake has started in categories used in plants as well. Buffalo, for example, has published STAR-1 conforming products across product lines such as Wi-Fi access points, routers, switches and NAS. At the same time, the pace of uptake differs by category. How far uptake has progressed across manufacturers and categories is laid out in JC-STAR Adoption Status by Manufacturer and Product. This article does not weigh in on the merits of specific manufacturers.
Frequently Asked Questions (FAQ)
What is JC-STAR?
Its official Japanese name translates as the Security Requirements Conformity Assessment and Labeling Scheme, and it is a security conformity assessment and labeling scheme for IoT products, built and operated by the Information-technology Promotion Agency, Japan (IPA) under the supervision of Japan’s Ministry of Economy, Trade and Industry (METI). METI published its policy for building the scheme in August 2024, and operation began in March 2025. It harmonizes with domestic and international standards such as ETSI EN 303 645 and NISTIR 8425 while confirming and visualizing product conformity against conformity criteria that it defines independently. The purpose is to make it easy for procurement staff and consumers to obtain information on the security status of a product.
Who evaluates JC-STAR STAR-1?
STAR-1 is a self-declaration of conformity by the vendor. STAR-2 is also a self-declaration, while STAR-3 and STAR-4 are certified by IPA on the basis of an evaluation report from an independent third-party evaluation body. In other words, the number of stars expresses not only how strict the requirements are but also a difference in who confirmed the conformity. STAR-1 indicates that the manufacturer has declared that the common minimum requirements are met; it is not a comprehensive quality guarantee for the product. The practical approach is to use it as a lower-bound filter for narrowing candidates, and to treat STAR-3 or above as a plus for applications where a higher level of assurance is needed.
Is obtaining JC-STAR mandatory?
No, the scheme itself is voluntary. That said, it is starting to be cited as a specific requirement field by field. In the solar and storage battery field it has been made effectively mandatory under the Ministry of the Environment’s Storage Parity subsidy in fiscal 2026, and it is planned to become a grid interconnection requirement for high voltage in April 2027 and for low voltage under 50 kW in October 2027. This is a matter for the solar and storage battery field, and the same dates do not apply to other fields. For buyers, tracking “when will it start to be cited as a requirement in my equipment categories” connects to practice more directly than asking “is it mandatory”.
When can you apply for JC-STAR STAR-2 and above?
For STAR-2 and above, it has been announced that applications are planned to open from January 2026 onward, covering the two product categories of “network cameras” and “communication equipment”, which are expected to be used in government procurement. In addition, the conformity requirements for STAR-3 were published on June 12, 2026. At the start of operation only STAR-1 ran ahead, and STAR-2 through STAR-4 were planned to start in fiscal 2026 or later. For the actual application status and any addition of target categories, please check the latest information on IPA’s official pages.
Is JC-STAR the same as ETSI EN 303 645 certification?
It is not the same. JC-STAR is a scheme based on conformity criteria it defines independently, while harmonizing with ETSI EN 303 645 and NISTIR 8425. So even when a vendor explains that a product “complies with ETSI EN 303 645”, that does not mean it has obtained a JC-STAR conformity label. In a procurement specification, write the two as separate items. Treating compliance with an international standard as a claim, and JC-STAR conformity as a fact you can cross-check by model number against the public list, is the distinction that is easiest to work with in practice.
Can JC-STAR be used for equipment procured at overseas sites?
Because it is a Japanese scheme, it does not automatically become a legal requirement at an overseas site. However, on March 18, 2026 Japan and Singapore signed a memorandum on the mutual recognition of JC-STAR and Singapore’s CLS, and it took effect on June 1, 2026. The baseline requirements of JC-STAR STAR-1 were recognized as equivalent to Level 1 of CLS. Japan is the fifth country, following Finland, Germany, South Korea and the United Kingdom. For the thinking behind placing JC-STAR STAR-1 as a common lower bound when building internal procurement criteria for overseas sites, see The Japan-Singapore MRA and Procurement Criteria for Thai Sites.
Summary: The Question Is Not Whether a Label Is Attached, but When Its Absence Will Stop You Buying
Here are the key points of this article, restated as decision criteria.
- JC-STAR is not a scheme for raising security; it is a scheme for making the floor visible. It is operated by IPA under METI supervision, entered operation in March 2025, and from March 25, 2025 applications for STAR-1 and publication of the list of conforming products have been running.
- The number of stars expresses both how strict the requirements are and who did the evaluating. STAR-1 and STAR-2 are self-declarations of conformity; STAR-3 and STAR-4 are IPA certification based on an evaluation report from a third-party evaluation body. This dividing line is not a defect in the scheme but a division of labor between coverage and depth.
- Of the five STAR-1 requirements, the one that bites longest in procurement is “provision of security updates within the support period”. What you check is not whether it exists but the date it ends.
- The field where the requirement dates are clearly lined up is, for now, solar and storage battery. It starts to bite in the order of scheme launch, then subsidy requirement, then grid interconnection requirement. It should not be generalized to other fields, but the sequence itself works as a monitoring indicator.
- The scheme is voluntary, and it has not been made mandatory. The story about local government procurement is a prediction, not a settled decision. Even so, the cost of adding one sentence to a specification is small, and so is the loss if the prediction turns out to be wrong.
- The work on the buyer’s side is five steps. Sort equipment into four groups, check each category for signs that requirements are coming, put three items into the specification, transfer the support end dates into the replacement plan, and when you see a label, check the level, the granularity of the model numbers, and the date obtained.
Whether a label is attached is a question about today. When its absence will stop you buying is a question about your next equipment replacement plan. What you need to grasp as a matter of understanding the scheme is the former, but what bites in approval routing and budgets is the latter.
Which of your devices are within the scope of the scheme and which are outside it. This sorting can often be brought into view in a single day if you have an equipment register and a network diagram, and once you get that far, the order of “what to confirm by when” falls into place naturally. At TOMAS TECH we work day to day with the plant networks and IoT and OT systems of Japanese manufacturers with sites in Thailand, and we take enquiries from the equipment inventory stage onward. If you are unsure where to start, please get in touch through our contact page.