Blog

2026.08.14

JC-STAR for Manufacturing — Device Procurement Criteria for 2026

JC-STAR for Manufacturing — Device Procurement Criteria for 2026

When you refresh a factory network, the quotation in front of you lists access points, switches, NAS units and network cameras. Until now, the columns you compared were price, performance and support terms. Another column is about to be added — the JC-STAR conformity label. JC-STAR looks complicated from the procurement side of a manufacturing business mainly because everyone gravitates to the wrong question, namely “do we need to obtain it?” The label is obtained by the vendor that builds the device, so that is not where the factory’s work sits. This article sets out how to treat JC-STAR as a decision criterion for factory IT/OT equipment procurement, following the dates that are actually documented in publicly available primary sources.

What Actually Changes for Factory IT/OT Procurement

Almost every enquiry we receive about JC-STAR from the factory side takes the same shape. “Do we have to get certified too?” The framing itself is slightly off from operational reality. The party that applies for a JC-STAR conformity label is the vendor placing a product on the market, not the factory that buys and operates it. For a factory, this scheme is not a certification question. It is a procurement question.

The argument of this article comes down to a single point. JC-STAR is not a matter of whether to obtain it. It is a procurement decision about when, and at which level, to build it into the selection criteria for factory IT/OT equipment. There are only two things to decide. The first is when to add JC-STAR to the selection criteria for equipment you are about to buy. The second is the order in which to revisit installed equipment that is approaching its replacement window.

The reason this needs sorting out now is that the scheme’s own calendar has started moving in concrete steps. Level 1 opened for applications on 25 March 2025, and Level 2 and above are rolling out from January 2026, product category by product category. Leading that rollout are network cameras and communication equipment, and the draft Level 3 conformance criteria covering them were published on 12 June 2026. Network cameras and communication equipment are precisely the devices factories buy as a matter of routine.

A second shift is coming from the buying side. It has been reported that guidelines were revised in September 2025 and that the equivalent of JC-STAR Level 1 was built into the selection criteria for IoT equipment in Japanese government procurement. This is a case of Secure by Demand — pressure from the buyer’s side to prioritise secure products — landing in an actual procurement document in Japan. Buyer-side criteria have a habit of propagating, from government to the private sector, and from the ordering company down to its suppliers.

For the buyer, the other thing that matters is whether the options already exist. The list of products holding a conformity label, published by IPA, stood at more than 500 entries from more than 100 vendors as of 3 August 2026. The categories on that list include network equipment such as routers, switches and gateways, surveillance cameras and recorders, NAS and storage devices, and products related to battery storage systems and PCS units. In other words, writing “products with a JC-STAR label are preferred” into your selection criteria is no longer a move that leaves you with zero candidates and a stalled purchase.

This article is written for people who procure IT/OT equipment for Japanese-affiliated manufacturers, including overseas sites in Thailand and elsewhere, and its purpose is to turn the scheme into a usable procurement frame. The detailed mechanics of the scheme itself belong to another article; here we concentrate on how it bites in day-to-day factory practice.

A Quick Recap of What JC-STAR Is, with Full Details in the Scheme Explainer

JC-STAR (Japan Cyber-Security Technical Assessment Requirements) is a labelling scheme that makes the security conformity of IoT products visible. The framework was established by the Ministry of Economy, Trade and Industry and it is operated by IPA, the Information-technology Promotion Agency, Japan. It covers products that communicate over IP and may be connected to the internet, and it defines four levels, from Level 1 to Level 4, according to the security requirements met. Levels 1 and 2 can be obtained through vendor self-declaration of conformity, while Levels 3 and 4 require evaluation by an independent third party. Level 1 is the baseline that opened for applications on 25 March 2025, and Level 2 and above are designed to come online progressively from January 2026, one product category at a time.

How each level defines its requirements, and why the scheme came about in the first place, are covered in our JC-STAR scheme explainer. This article deals with how to apply that scheme to factory procurement rather than with the scheme’s internals, so if you want the level definitions in detail, reading that piece first will make this one easier to follow.

Which Devices You Buy Could Fall Under JC-STAR, from APs and Switches to NAS, Network Cameras and PCS

JC-STAR for Manufacturing — Device Procurement Criteria for 2026 - figure 1

Before you get to the procurement decision, you need to know which of the devices you already buy sit within the scheme’s reach. The entry test is simple — does the device communicate over IP and could it be connected to the internet? Look back over your factory equipment list with that filter and you will find more in-scope devices than you expected.

EquipmentTypical factory useWhy it tends to fall in scopeWhat to check at procurement
Access point (AP)Wireless connectivity for handheld terminals, tablets and AGVsIP communication is its core function, and the management interface is easily exposed across the networkProtection of the management interface, handling of default passwords, the period for which firmware updates are provided
SwitchSeparating control and information networks, aggregating devicesManaged models are IP-reachable, and they are the linchpin of network segmentationHandling of the management VLAN, the channel used to announce vulnerabilities, end-of-support timing
NASStorage of drawings, recipes, production data and recordsFile sharing by nature creates access paths from outsideDefault settings for remote access features, backup paths, update provision period
Network cameraSite surveillance, line monitoring, remote witnessing, quality recordsVideo is often viewed from outside, so internet connectivity tends to be assumedStorage and transmission paths for video, default credentials, requirements on the recorder side
PCS (power conditioner)Control of solar generation and battery storage systemsModels with remote monitoring features communicate over IPWhether the specific model has IP communication at all, and whether to assess the whole system including monitoring functions

There is one entry in this table that deserves care, and that is PCS. Depending on the model, a power conditioner may have no IP communication capability, in which case it falls outside the scheme. One vendor has in fact stated publicly that its PCS unit on its own is out of scope. The lesson to take from that is not “PCS is out of scope” but the underlying principle that two products sharing a category name can differ in scope depending on whether they have IP communication. Do not decide in or out of scope from the catalogue category name; look at whether that specific model communicates. Put the other way round, in configurations where a remote monitoring unit or gateway is sold separately and combined with the device, that unit can be the part that falls in scope.

There is a second point that is specific to factories. Many of the devices listed above sit somewhere along the path that carries data up from production equipment. Collecting data from PLCs and moving it to a server via switches and gateways is now an ordinary architecture. It is precisely because every device on that path can have internet reachability that checking requirements at the procurement stage pays off. For the design of the network connections and the collection path itself, our PLC data collection implementation guide covers the technical side, and reading it alongside the security procurement criteria here will give you the full picture of the path. The split is simple — this article is about the criteria for choosing devices, and the linked article is about how you collect data through them.

It is also worth noting that the categories actually listed on IPA’s conformity label product list include network equipment, surveillance cameras and recorders, NAS and storage devices, and battery storage and PCS-related products. The overlap between what the scheme has in view and what factories are buying is, it is fair to say, considerable.

The 2026 Timeline and Why Level 2 and Above Starts with Network Cameras and Communication Equipment

JC-STAR for Manufacturing — Device Procurement Criteria for 2026 - figure 2

To turn this into a procurement plan you need the dates. Three milestones can be confirmed from public information.

WhenWhat happened or will happenEvaluation methodEffect on procurement practice
25 March 2025Applications open for Level 1Vendor self-declaration of conformityProducts holding the label already exist, so it can go into selection criteria today
From January 2026Levels 2 to 4 start progressively by product categoryLevel 2 is self-declaration, Levels 3 and 4 require third-party evaluationStart dates differ by product category, so this has to be tracked per equipment category
12 June 2026Draft Level 3 conformance criteria published for network cameras and communication equipmentThird-party evaluationEquipment categories that factories buy are in the leading group

Laid out this way, you can see the centre of gravity moving from spreading a baseline widely towards demanding a higher standard of specific product categories. Level 1 is obtainable through self-declaration, so it spreads easily, and as of 3 August 2026 the product list has reached more than 500 entries from more than 100 vendors. Levels 3 and 4, by contrast, require evaluation by an independent third party, which takes time both in the vendor’s preparation and in the evaluation itself.

So why do network cameras and communication equipment lead the rollout of Level 2 and above? This is not explicitly explained in the published material, but it becomes easier to understand if you consider what these two categories have in common. Both are frequently placed at the boundary with external networks, and both are used on the assumption that someone will look in, or come in, from a distance. They are deployed in large numbers, and they tend to keep running untouched for years after installation. In short, they are devices with high internet reachability that rarely get updated. If you were choosing which categories to raise the bar for first, starting with ones that have those properties would be a natural choice. This reading is our own interpretation and not an official explanation from the scheme’s operators, and we say so plainly.

The implication for factories is clear. If a surveillance camera refresh or a network equipment replacement is on your capital plan, that purchase falls squarely into a category whose required standard is moving right now. The fact that draft criteria have been published also means vendors have entered the stage of preparing compliant products. Conversely, rushing a purchase now on conventional specifications risks leaving you with equipment at the older standard until the next replacement cycle comes round.

Why the Question Is When and Which Level, Not Whether to Obtain It

This is the heart of the article. When a factory handles JC-STAR as a matter of practice, the variables to decide are not yes or no but “from when” and “at which level”. The difference is easiest to see through three common misconceptions.

Misconception 1 — we need to get certified ourselves. As already noted, the party applying for a conformity label is the vendor putting a product on the market. There is no arrangement under which a factory obtains a label for its own installed equipment. The factory’s role is to state criteria as the buyer. There is one exception. If the products your company manufactures are themselves IoT devices that communicate over IP, you face this scheme as a supplier. That is a product development question rather than a procurement one, and it needs to be considered outside the frame of this article.

Misconception 2 — we can wait until the scheme is fully settled. The scheme is designed to come online category by category, so the moment when “everything is settled” will not arrive for a long time. Level 1 has been running since 25 March 2025 and is ready to be written into selection criteria. Deciding to wait until things settle is, in practice, the same as deciding to do nothing.

Misconception 3 — the higher the level, the better. Levels 3 and 4 require third-party evaluation, so the lead time until compliant products appear is long and the cost shows up in the price. A procurement specification that demands the highest level uniformly across all equipment will either leave you with zero candidate vendors or make you pay more than you need to. In practice, the level you demand should vary with where the device is installed and where it sits on the network.

With those three in mind, the ways of writing selection criteria fall into three tiers.

How it is writtenWhat it meansWhere it fits
Mandatory requirementNon-conforming products are excluded from considerationDevices placed at the external boundary, in categories where compliant products are plentiful
Scored requirementWhere other conditions are equal, conforming products are preferredCategories where compliant products are starting to appear, which in practice covers most equipment
Disclosure requirementVendors must state current label status and any plans to obtain oneCategories where compliant products are still scarce, with the aim of gauging vendor posture and product roadmap

For most factories the realistic starting point is the scored and disclosure tiers. Jumping straight to a mandatory requirement risks excluding your incumbent vendors and grinding procurement to a halt. Even a disclosure requirement on its own sends the vendor a signal that this customer is watching. Unless the demand side states criteria, the supply side has no reason to move this up its priority list.

For choosing between levels, the most explainable approach is to think in terms of position on the network. Devices that touch the internet directly, devices placed at the boundary between the information and control networks, and devices that stay closed inside the control network simply carry different kinds of risk. Demand a higher level the closer a device sits to the outside, and judge the closed, inside devices in combination with your other security controls. That framing tends to land well with people on the floor.

Government Procurement and Secure by Demand, and How It Spreads to the Private Sector

What supports the case for writing this in even as a scored requirement is the structure by which requirements spread from the demand side. It has been reported that guidelines were revised in September 2025 and that the equivalent of JC-STAR Level 1 was built into the selection criteria for IoT equipment in government procurement. This information is press-based, and detailed figures such as adoption rates by ministry have not been confirmed against primary sources, so we make no numerical assertions here. The direction of travel, however, is clear enough to read.

Behind this movement lies the idea of Secure by Demand. Rather than leaving security to the efforts of the product side, the buyer declares that it will preferentially purchase secure products, and in doing so lifts the standard of the market as a whole. If Secure by Design, which builds security in from the design stage, is the supply-side effort, then Secure by Demand is its counterpart on the demand side.

For manufacturers, what matters is the route along which this requirement travels. Buyer-side criteria flow downstream along contractual relationships.

  • Government builds the standard into its procurement criteria
  • Companies supplying government reflect the same thinking in their own procurement criteria
  • Those companies’ suppliers are asked to meet security requirements as part of their commercial terms
  • Each company revisits the procurement criteria for its own factory equipment and IT devices

If your company sits anywhere along that route, a question about JC-STAR will sooner or later appear on a customer’s security questionnaire. In sectors such as automotive, electrical equipment and precision machinery, customer security checklists are already an established fixture. Given the nature of the scheme, an item asking “do you verify security conformity when selecting network equipment?” joining the existing question set is a development you should plan for.

The difficulty at that moment is less the requirement itself than being unable to answer. Plenty of factories do not know the model numbers of the access points and network cameras they are running, let alone whether the vendor holds a conformity label. Starting the research after the questionnaire arrives means starting by tracing cabling on the shop floor. The decision framework in the next section is also a way of resolving that situation in advance.

The Two-Track Decision Framework for Factories, Covering New Purchases and Ageing Installed Equipment

JC-STAR for Manufacturing — Device Procurement Criteria for 2026 - figure 3

Now we turn all of this into something you can act on tomorrow. Factory practice becomes much less confusing when you split it along two tracks — equipment you are about to buy and equipment already installed that is approaching replacement. These two differ in purpose and in the speed at which you can decide, so putting them in the same frame will always stall you.

TrackScopeWhat to doTiming
Track 1, new purchasesEquipment on the upcoming capital planWrite selection criteria into the enquiry specification and ask vendors for label status and plansAt the quotation request stage, because after installation it is too late
Track 2, replacing installed equipmentEquipment currently running and approaching replacementIdentify the in-scope categories and line replacement timing up against the scheme’s rolloutBefore the Level 2 and above requirements for that category are finalised

Track 1, Where One Line in the Specification Does the Work

New purchases do not call for an elaborate evaluation process. Adding a single line to the specification at the enquiry stage changes the picture considerably. Of the three tiers of selection criteria — mandatory, scored and disclosure — starting from the disclosure tier is the path of least friction. A single sentence is enough, along the lines of “please state whether this product holds a JC-STAR conformity label, and if not, whether there are plans to obtain one.”

That one sentence has three effects. First, it lets you compare the current status of candidate products side by side. Second, it reveals how each vendor engages with the topic. A vendor that can explain its approach to the scheme and a vendor that does not understand the question may well differ later in how they handle vulnerabilities. Third, it leaves a record that you, as the buyer, stated a criterion. That record earns its keep when you answer a customer’s security questionnaire.

Once the responses are in, evaluate them against each device’s position on the network. If you are placing a device at the external boundary and several conforming products exist, raise it to a scored requirement. If the category still offers few options, leave it as a disclosure requirement and revisit at the next refresh. Think of criteria not as something you write once and file away, but as something you ratchet upward in step with how each category matures.

Track 2, Take Inventory of Ageing Equipment Ahead of Time

For equipment already running, this is not a case for ripping anything out now. What is realistically achievable is being in a position to decide when the replacement window arrives. That calls for an inventory. Pull the following items into a single register.

  • Equipment category, such as AP, switch, NAS, network camera or PCS-related device
  • Manufacturer, model number and year of installation
  • Position on the network, meaning internet reachability and whether it sits on the information or control side
  • Firmware update provision status and expected end-of-support date
  • Planned replacement timing

Once that register exists, two things fall into place at once. The first is the order of priority — which equipment to tackle first. Devices with internet reachability, an approaching end of support and a near-term replacement date come first. The second is the comparison against the scheme’s rollout. Categories such as network cameras, where draft Level 3 conformance criteria have already been published, are worth considering for an earlier replacement. There is a lag between criteria being finalised and compliant products reaching the market in numbers, so gathering information while the requirements are still moving leaves you deciding with options in hand.

The usual stumbling block in building the register is that installation history was never kept on site. At overseas locations the contractor who did the network cabling at start-up has often changed, and the wiring diagrams were never updated. In that case, building the register starts with tracing the cabling itself, which is exactly why waiting until a customer questionnaire arrives leaves you short of time.

Working It into the Budget Cycle

The practical lever that makes these two tracks turn is budget timing. Network equipment replacement does not come round often, so a misjudgement at that moment means you cannot raise the standard until the next opportunity. Read the other way, if you lift the criteria one notch at each replacement, the overall standard of your estate turns over across successive refreshes without a large additional investment. Setting JC-STAR readiness up as a separate line item labelled “special security investment” makes approval hard to win, but folding it into the selection criteria of a normal replacement plan keeps the incremental cost contained.

Points for Manufacturers with Operations in Thailand

If you run factories at overseas sites in Thailand or elsewhere, one premise is worth confirming. JC-STAR is a Japanese scheme, with the framework set by the Ministry of Economy, Trade and Industry and operated by IPA. Thai law does not require this label. So the understanding that “we have to comply because we are a Thai factory” is not accurate.

Even so, there are real routes by which the scheme reaches practice at overseas sites. The Japanese head office may set procurement criteria and apply them to overseas locations. A security questionnaire from a Japanese customer may require answers at the site level. And where equipment is bought from Japanese manufacturers, the status of compliance in Japan carries straight through. It is also worth noting that equipment procured locally from Thai vendors and equipment bought under the head office framework are in different situations.

Local procurement brings its own considerations. The product line-up available in Thailand does not match Japan exactly, and a model that holds a conformity label in Japan is not necessarily obtainable locally. Applying the same criteria unchanged in that situation will simply stop procurement. This is a case where starting from a disclosure requirement rather than a mandatory one, adapted to local conditions, is the sensible judgement.

Considerations specific to Thai sites — how to convey requirements to local suppliers, how to divide procurement authority between site and head office, and the relationship with cyber security legislation in Thailand — go beyond the scope of this article, so we will not go deeper here. There is enough in that topic alone to fill a separate article, which we plan to write. Here we stop at understanding the structure, which is that JC-STAR is a Japanese scheme whose effects reach overseas procurement through Japanese commercial channels.

Summary and How to Think About a Procurement Checklist

Here is the content of this article organised as a procurement checklist.

JC-STAR is not a scheme that factories obtain. It is a criterion that factories use as buyers. The decisions come down to two — when to build it into selection criteria, and which level to require for each type of equipment. Level 1 is the baseline that opened for applications on 25 March 2025, and it is obtained through vendor self-declaration of conformity. Level 2 and above start progressively from January 2026 by product category, and for network cameras and communication equipment, which lead that rollout, the draft Level 3 conformance criteria were published on 12 June 2026. Levels 3 and 4 require evaluation by an independent third party.

What can fall in scope is equipment that communicates over IP and may be connected to the internet. Among factory purchases, access points, switches, NAS units, network cameras and PCS-related products with IP communication are the ones most likely to fall in scope. Note, though, that products such as PCS can differ in communication capability from model to model within the same category name, so judge by the model’s communication capability rather than the catalogue classification.

On the question of whether options exist, IPA’s list of products holding a conformity label had reached more than 500 entries from more than 100 vendors as of 3 August 2026. It includes network equipment, surveillance cameras and recorders, NAS and storage devices, and battery storage and PCS-related products, so writing the criterion no longer leaves you with an empty candidate list.

As for the spread from the demand side, it has been reported that a September 2025 guideline revision built the equivalent of JC-STAR Level 1 into government procurement selection criteria, and the Secure by Demand approach is structurally set to propagate into the private sector and the supply chain. Whether you can answer when the question appears on a customer’s security questionnaire is the practical dividing line.

On that basis, the action for factories runs on two tracks. For new purchases, add a line to the enquiry specification asking for label status and plans to obtain one. For installed equipment, gather the in-scope categories into a register and line replacement timing up against the scheme’s rollout. With those two turning, you stay able to decide as the scheme advances into whichever category comes next.

For overseas sites, the starting point is to recognise that JC-STAR is a Japanese scheme, and to understand the structure by which it propagates through commercial channels, namely head office procurement criteria and requirements from Japanese customers.

How far your own equipment could fall in scope, and which categories to raise the bar for first, is not something you can settle by reading catalogues. It takes working through the network diagram alongside a check of which devices actually communicate with the outside. TOMAS TECH supports Japanese-affiliated factories in Thailand with production management systems and OT/IoT network implementation, and we are happy to talk even at the exploratory stage, before you have settled on an approach to JC-STAR. A sounding-board conversation about what the framework in this article would look like applied to your own equipment register is perfectly welcome. Feel free to get in touch through our contact page.

Frequently Asked Questions

How does JC-STAR relate to IT/OT equipment procurement in manufacturing?

The party applying for a conformity label is the vendor placing the device on the market. A factory does not obtain a label for its own installed equipment. For a manufacturer, this scheme is relevant as a buyer-side selection criterion. Concretely, the decisions are whether to add an item to your specifications asking about JC-STAR label status, and which level to require for each type of equipment. Part of the reason the relevance is growing is that guidelines were reportedly revised in September 2025, with the equivalent of JC-STAR Level 1 built into the selection criteria for IoT equipment in government procurement and the same thinking now spreading into the private sector and the supply chain. When that kind of question appears on a customer’s security questionnaire, whether you can explain the compliance status of your equipment becomes the practical dividing line. Note also that if the products you manufacture are themselves IoT devices communicating over IP, you need to consider the scheme separately, from the supplier’s side.

Do factory access points and switches fall under JC-STAR?

They are within the range of what can fall in scope. The entry test is whether the device communicates over IP and could be connected to the internet. IP communication is an access point’s core function, and its management interface is easily exposed across the network. Managed switches are likewise IP-reachable. IPA’s published list of products holding a conformity label does include categories of network equipment such as routers, switches and gateways, and as of 3 August 2026 it holds more than 500 entries from more than 100 vendors. Do not judge from the category name alone, however. Products such as PCS power conditioners can lack IP communication in a given model and therefore fall outside the scheme, even within the same product category. The accurate test is whether that specific model actually communicates, not how the catalogue classifies it.

Will equipment without JC-STAR become unusable right away?

No. JC-STAR is a labelling scheme that makes conformity visible, and it does not prohibit the use of equipment without a label. Level 1 only opened for applications on 25 March 2025, and Level 2 and above are at the stage of starting progressively from January 2026 by product category. The scheme is not designed to switch over all at once. What bites in practice is not a ban on use but the selection criteria used in procurement. In government procurement, it has been reported that a September 2025 guideline revision built the equivalent of Level 1 into the selection criteria, and that thinking is structurally set to spread through business relationships. What factories need to do, therefore, is not to rush into replacing equipment currently in use, but to get an equipment register in place so that you can decide when the replacement window arrives.

How is OT security different from JC-STAR?

They differ in what they cover and how broad they are. OT security is a wide concept referring to the overall effort to protect a factory’s control systems. It includes network segmentation, access rights management, asset visibility, incident response structures and operational rules, so it covers mechanisms and operations, not only devices. JC-STAR, by contrast, is a product-side labelling scheme that makes the level of security requirements met by an individual IoT product visible on a scale from Level 1 to Level 4. In terms of the relationship, JC-STAR corresponds to the part of OT security that assures the standard of the equipment you procure. Lining up devices with conformity labels therefore does not complete a factory’s OT security, and conversely, thorough network segmentation still leaves risk if the devices at the boundary are of a low standard. Rather than running the two as separate initiatives, the practical approach is to position JC-STAR as a procurement criterion within your overall OT security plan.

When does JC-STAR compliance become mandatory for network cameras?

No blanket mandatory date has been published. What can be confirmed is that Level 2 and above start progressively from January 2026 by product category, that network cameras and communication equipment lead that rollout, and that the draft Level 3 conformance criteria covering them were published on 12 June 2026. Level 3 requires evaluation by an independent third party, so time is needed both for vendor preparation and for the evaluation itself. In practice, “mandatory” arrives not as a prohibition under the scheme but as a requirement in the buyer’s procurement criteria. In government procurement, it has been reported that a September 2025 guideline revision built the equivalent of Level 1 into the selection criteria, and similar requirements may well be reflected in private-sector procurement criteria. Factories with a surveillance camera refresh on their capital plan should assume this is a category whose standard is still moving, and start asking vendors about label status and plans early.

References

  • Official information on the JC-STAR scheme, covering the Level 1 to Level 4 definitions and the application framework IPA, Information-technology Promotion Agency, Japan verified as of August 2026
  • List of products holding a conformity label, the source for entry counts, vendor counts and product categories IPA conformity label product list verified as of 3 August 2026
  • Press release announcing the opening of Level 1 applications Ministry of Economy, Trade and Industry verified as of August 2026
  • Column on the position of JC-STAR in government procurement and on the Secure by Demand approach PwC Japan Group verified as of August 2026
  • Explanatory article on the JC-STAR overview and the schedule for Level 2 and above Unitis verified as of August 2026
  • Interview article introducing one device vendor’s approach to JC-STAR readiness Buffalo verified as of August 2026