There was a time when a piece of factory or office equipment could be chosen on spec sheet and price alone. That time is ending. JC-STAR, the IoT product security conformity assessment and labeling scheme that entered operation in March 2025, makes it visible through a label how far a connected device meets a defined set of security requirements, and through 2026 the number of labeled products has grown noticeably. Explanations of the scheme itself are easy to find. What procurement teams actually want to know is blunter than that — who has already obtained one. This article organizes the publicly available information on JC-STAR certified manufacturers by category, and then covers how to check the compliance status of your own installed equipment.
Why a list of certified manufacturers beats another explanation of the scheme
Reading an explanation of a scheme tells you what will be expected of you in the future. The questions that actually stop work sit earlier than that.
You are replacing network equipment in next year’s capex round. You are swapping out the monitoring system on a solar array. You are moving factory access control over to electric locks. At that moment, does the model number printed on the quotation carry a JC-STAR compliance label or not? And if it does not, is that because the manufacturer has not addressed the scheme, or because the product was never in scope to begin with? Take a proposal into an approval meeting without being able to separate those two cases and you will be asked later why nobody checked.
Equipment also stays in service for five to ten years once it is installed. Anything specified in 2026 will still be running when the requirements have hardened. In other words, today’s procurement decision quietly sets tomorrow’s remediation cost. That is exactly why it is worth stepping past understanding the scheme and getting a read on where the supply side actually stands right now.
For how the scheme came about, and for the argument that the dates on which requirements become mandatory matter more than the presence of a label, see our earlier article JC-STAR in 2026 and why the requirement dates matter more than the label. This piece picks up where that one left off and looks at the supply side.
A minimum refresher on the JC-STAR scheme
JC-STAR is the IoT product security conformity assessment and labeling scheme operated by the IPA (Information-technology Promotion Agency, Japan) together with the Ministry of Economy, Trade and Industry. It sorts the security requirements an IoT device should meet into levels and permits products that satisfy them to display a label. Applications for Level 1 opened on March 25, 2025, and the scheme has been in motion since then.
There are four levels, and the decisive difference between them is who confirms conformity.
| Level | How conformity is confirmed |
|---|---|
| Level 1 | Self-declaration of conformity to the IPA |
| Level 2 | Self-declaration of conformity to the IPA |
| Level 3 | Assessment by a third-party evaluation body |
| Level 4 | Assessment by a third-party evaluation body |
At Levels 1 and 2, the manufacturer itself confirms conformity with the requirements and declares it to the IPA. From Level 3 upward a third-party evaluation body must assess the product, which naturally raises both the cost and the lead time of certification.
Given that design, market behaviour is fairly predictable. Level 1 spreads broadly first, and the higher levels are stacked on later for specific applications. That is what the evidence shows — every manufacturer case that can be confirmed from public information within the scope of this article is Level 1 as of 2026.
The primary source is the IPA’s official list
The other point worth fixing in mind is that the IPA publishes a list of products that have obtained the conformity label. It is provided as an Excel file showing the registration number, the name of the business that obtained the label, the product name and the level, and it is updated on an ongoing basis — an update dated August 3, 2026 can be confirmed.
In procurement practice, this is where verification ends. Manufacturer press releases and catalogue entries are useful as information, but they go stale, and they often name only a product series without letting you pin down an individual model number. If you need to confirm that a particular model really is registered, looking it up by registration number in the IPA list is the certain route.
Everything presented in this article is an organized snapshot of information published at the time of writing. For the current position, always check the IPA list.

Network equipment and what Buffalo has achieved
The category where JC-STAR adoption has advanced furthest is network equipment — Wi-Fi routers, access points, switches and NAS units. That is a natural outcome, because these products are precisely the archetypal IoT devices the scheme was designed around. They connect directly to the internet, they carry a management interface, and they stay in service for years while their firmware is updated. To an attacker they are an ideal point of entry, which is why the debate about mandatory requirements started early here.
44 series and 150 models
Within that category, Buffalo stands out on sheer volume. As of January 2026, 44 series covering 150 models hold the Level 1 label.
It would be a mistake to underrate what that number means. 150 models is not the profile of a vendor that has certified a handful of flagship products for show. It is coverage across product lines — certification pursued as a surface rather than a point. From the buyer’s side, it means that as long as you are choosing from this manufacturer’s range, labeled options genuinely exist at a practical level.
On specific products, the Wi-Fi 7 capable WSR6500BE6P series obtained the JC-STAR compliance label on February 12, 2026. A new product on a leading-edge standard carrying the label at launch is a sign that label acquisition is being built into the product planning process rather than bolted on afterwards.
Why the label reaching entry-level models matters
The other development worth noting is that the Wi-Fi 6 entry-level model WSR-3000AX4L began shipping as Level 1 compliant on June 16, 2026.
When only high-end units carry a label, writing must hold a JC-STAR label into a procurement standard instantly inflates the budget. Once the label reaches entry-level models, the calculation changes. You can put the presence of a label into the selection criteria for standard equipment without a heavy cost penalty.
When a factory or office wants to standardize on the same model across sites, or wants a lower-cost tier for branch locations, whether labeled options exist in that price band is a very practical concern.
A certified manufacturer is not the same as a certified model number
There is one pitfall here that deserves more attention than any other. If 150 models are certified, the flip side is that models which are not certified also exist inside the same brand.
A common failure in JC-STAR IoT device procurement is ordering on the basis of a coarse assumption — this manufacturer supports JC-STAR, so we are fine. The label is granted to a product, not to a company. It is entirely normal for two products of the same brand, for the same application, differing only in model number, to differ in whether they carry a label.
So always push the granularity of verification down to the model number. Take the model number straight off the quotation and search for it in the IPA list. That single habit prevents a lot of accidents.
One caveat. The network equipment cases that can be confirmed from public information at the time of writing are centred on consumer and SOHO products. For industrial switches and factory-grade access points, do not carry over the same assumption that certification must already be in place — check them individually.
Solar and battery storage monitoring equipment
After network equipment, the category with the next largest cluster of cases is monitoring equipment for photovoltaic generation and battery storage systems. These products assume an internet connection for remote monitoring, and because they sit close to social infrastructure, interest in their security ran high from an early stage.
The main acquisitions that can be confirmed from public information are set out below.
| Manufacturer | Product | Date of acquisition or registration | Level |
|---|---|---|---|
| Omron Social Solutions | Gateways for the multi-battery storage platform (KP-GWBP-A, KP-GWPV-B, KP-GWEP-A, KP-GWPV-A and others) | February 2026 | Level 1 |
| Laplace System | Solar Link ZERO remote monitoring and control terminals (T4, T5) | November 7, 2025 | Level 1 |
| Canadian Solar | iQ Storage energy management system | Registration on the IPA portal confirmed as of January 29, 2026 | Level 1 |
| FieldLogic | DataCube4 monitoring device | April 24, 2026 | Level 1 |
Where registration numbers have been published, they are 2025119900001050 for Laplace System’s Solar Link ZERO, 2026020600001537 for Canadian Solar’s iQ Storage energy management system, and 2026040600002182 for FieldLogic’s DataCube4. When searching the IPA list, these numbers are by far the most reliable handle.
What the four cases have in common
Line those four up and a structure becomes obvious.
Every product that holds a label is a box that handles communication. Omron Social Solutions certified gateways. Laplace System certified remote monitoring and control terminals. Canadian Solar certified an energy management system. FieldLogic certified a monitoring device. Not a single solar panel. Not a single battery cell.
In other words, what falls under JC-STAR in this category is not the generation or storage function itself, but the component whose job is to connect that function to an external network. That lens matters for understanding the Yaskawa Electric position discussed below, and for applying the same logic to equipment that has nothing to do with solar power.
The timeline clusters between late 2025 and the first half of 2026
The other thing to notice is the sequence of dates. November 2025, January 2026, February 2026, April 2026 — acquisitions arriving in a comparatively short window. Roughly one to one and a half years after the scheme began operating, the players in this category worked through it in turn.
That carries an important implication for buyers. A manufacturer that looks uncertified at this moment may well be in a different position six months from now. Conversely, recycling research you carried out in the past will put you out of step with reality. Assume that primary sources have to be pulled fresh every time you specify equipment.

Smart locks and where Miwa Lock fits
As an illustration of how far the scheme reaches, Miwa Lock is worth holding on to. Its iEL Zero smart series of smart electric locks for residential entrance doors became the first product from a lock manufacturer to obtain a Level 1 JC-STAR compliance label.
The suggestive part is the fact itself — a manufacturer whose heritage is a purely mechanical product stepping into an IoT security labeling scheme. The moment a physical security product joins a network, it becomes something evaluated as an IoT device. That sounds obvious stated plainly, but in day-to-day procurement the mental switch often fails to happen.
Translate it to a factory and it becomes concrete. Access control systems. Electronic locks on tooling stores and chemical cabinets. Server room doors. Interlocks on machine safety guards. It is not unusual for all of these to be selected by facilities management out of a physical security budget. Yet today’s products unlock from a smartphone, keep entry and exit history in the cloud, and update firmware over the network. The result is a pattern in which network-connected devices multiply inside the plant without the information systems team or anyone responsible for OT security ever touching the specification.
The Miwa Lock case shows that the old dividing line — this is not IT equipment, so it is not our concern — no longer holds.
The easily missed point that a standalone PCS is out of scope
Everything so far has been about the side that holds a label. Now for something equally important — the side that was never in scope at all.
What Yaskawa Electric stated in April 2026
On April 13, 2026, Yaskawa Electric issued an official position on its Enewell-SOL P3A and P3H photovoltaic power conditioners, making clear that because they have no IP communication function, a standalone PCS falls outside the scope of the JC-STAR scheme. The company states that this reading was confirmed with the Ministry of Economy, Trade and Industry.
It is not hard to guess what prompted the statement. If a manufacturer is repeatedly asked whether its PCS holds a JC-STAR label, and told that without one the product cannot be specified, it eventually has to publish a formal clarification.
The crucial point is that this is in no sense a story about a vendor falling behind. The scheme is a framework for assessing the security of devices that connect to a network. A device with no IP communication function has nothing for the scheme to assess. It is not that the label has not been obtained — there is nothing there to obtain it for.
So how should that equipment be handled
Of course, a standalone PCS being out of scope does not make the whole solar installation irrelevant to security. In a real installation the PCS is used in combination with some form of monitoring equipment.
Yaskawa Electric’s own explanation sets out the thinking — by combining the PCS with monitoring devices, gateways or EMS units that do have IP communication, such as Solar Link ZERO, DataCube4 or the Energy Solutions solar monitor, the overall configuration can be made JC-STAR compliant.
The unit of assessment, then, is not the system but the component that handles communication. The label is demanded of the part that connects the installation to the outside world, not of the generating equipment. It is exactly the same structure that emerged from the solar monitoring table above.
This is not limited to PCS units
That way of thinking is not somebody else’s problem for a plant with no solar installation. The identical structure applies right across manufacturing equipment.
- A machine tool may run on a closed control system, but the retrofitted IoT gateway collecting its utilization data is on the network
- A measuring instrument may offer only an analog output, but the data logger or converter receiving that output has an Ethernet port
- The item handling communication is not the air conditioner or the substation gear, but the controller added afterwards for remote monitoring
- What comes under assessment is not the inspection machine itself, but the communication unit that sends image data to a server
As long as equipment is viewed as a monolithic system, this distinction stays invisible. Spread out the network diagram and count every box that holds an IP address. For each of those boxes, confirm the model number, the manufacturer and whether a label exists. It is unglamorous work, and it is the only reliable method.
What makes it awkward is that these communication boxes tend to multiply through retrofits and partial upgrades. They never appear in the original specification documents, yet they accumulate on the floor. That is precisely why an inventory should start from the network side rather than from the asset register.

How to treat manufacturers with no label or no disclosure
Having worked through the categories, there are obviously many manufacturers whose names do not appear in any list. How you write about them and how you treat them both need care.
For some of the large overseas players such as HUAWEI and SUNGROW, for example, the position as of 2026 is that no JC-STAR acquisition under their own brand can be confirmed from public information.
It would be wrong to read that fact in any of the following ways.
- Products without a label are less secure
- Products from uncertified manufacturers must not be used
- The absence of a label means the manufacturer has no intention of complying
None of these conclusions follow from public information. Cannot be confirmed and does not exist are entirely different statements. An application may be in progress. The product may fall outside the definition of an in-scope product. The treatment of a Japan-market model number and an international model number may differ.
Equally, conformity with other schemes such as PSE or JET sits on a different axis from JC-STAR. The inference that a product certified under electrical safety law must therefore be secure does not hold, and neither does the reverse — that a missing JC-STAR label casts doubt on other certifications. Merging schemes that assess different things into a single yardstick of safety is a habit worth avoiding.
The healthy way to handle this in practice runs as follows. Check the IPA list first. If nothing is found, record in the approval document, as a matter of fact, that no acquisition could be confirmed from public information. Then, where necessary, put a written enquiry to the manufacturer or distributor and keep the answer on file. If the answer is that the product is out of scope, keep the reason — no IP communication function, for instance — on file with it.
With that record in place, when an audit or a query from head office arrives a few years later, you can explain what reasoning led to the choice at the time. The trace of the decision ends up mattering more than the presence or absence of the label itself.
What procurement should take away from this list
Restated from a procurement standpoint, everything above comes down to five points.
- The unit of verification is the model number, not the manufacturer. Labeled and unlabeled products coexist within one brand
- The unit of verification is the component, not the system. Look at every box that holds an IP address
- A missing label has several possible causes. Separate not yet certified from not in scope
- The primary source is the IPA’s published list. Catalogues and press releases are supporting information
- The picture moves on a scale of months. Do not reuse past research — pull it again for every selection
Of these, the second has the largest practical impact. The question is this equipment JC-STAR compliant is framed too coarsely to produce a useful answer. Change it to which components in this configuration have an IP communication function, and what is the label status of each, and the conversation suddenly starts to connect.
On top of that, you need a design decision about where the label sits in your selection criteria and how much weight it carries. Mandatory requirement, or scored bonus? How are out-of-scope devices handled? That design question is worked through concretely in our earlier article JC-STAR device procurement for manufacturers and the selection criteria to set in 2026, which is the one to read when you are actually rewriting a procurement standard.
Notes for plants in Thailand buying overseas-made equipment
Everything so far has been framed as a Japanese domestic scheme. Seen from the position of most TOMAS TECH readers — Japanese-affiliated manufacturers operating in Thailand and elsewhere in ASEAN — the situation is a little more complicated.
To state the obvious first, JC-STAR is a Japanese scheme and has no direct legal force over a plant in Thailand. Nothing will be held at customs or blocked at installation in Thailand because a device lacks a JC-STAR label.
And yet the scheme still reaches local operations, not through regulation but through group procurement standards. Head office in Japan revises its security procurement policy and inserts wording into a global guideline requiring IoT devices to meet JC-STAR equivalent requirements. From that moment, equipment bought locally in Thailand is held to the same standard.
That is where the local difficulties start.
- The model numbers circulating locally often differ from the Japan-market model numbers, so a search of the IPA list returns nothing
- Local distributors may be unaware that the scheme exists, so an enquiry produces no usable answer
- The share of Chinese and European manufacturers is higher than in Japan, so situations arise where the only viable products are ones that were never going to appear in the list
- Retrofits and modifications are carried out by local contractors, so communication-capable boxes accumulate outside the asset register
The realistic way to face these head-on is to stop chasing the presence of a label and instead push the requirements behind it into your verification criteria — how initial passwords are handled, whether firmware updates are actually supplied, whether unnecessary communication ports are closed. The label is a means of demonstrating that requirements are met. It is not the objective.
One more thing. At overseas plants, the problem is very often the design of the network itself rather than the conformity of individual devices. Where the office Wi-Fi and the production lines share a single segment, where authentication is one shared passphrase, where equipment has been added ad hoc at every expansion, tidying up device labels one unit at a time will only get you so far.
For the overall picture of how to design a factory network and where the costs land, our earlier article Factory wireless LAN and industrial network design in 2026 breaks it down layer by layer. Device selection and network design belong together, and pushing only one of them forward guarantees rework somewhere down the line.
Frequently asked questions
Which manufacturers already hold JC-STAR labels?
In network equipment, Buffalo is well ahead on volume. In solar and battery storage monitoring, Omron Social Solutions, Laplace System, Canadian Solar and FieldLogic have all obtained labels. In smart locks, Miwa Lock became the first lock manufacturer to do so. Every one of these cases is Level 1. Note that verification has to be done product by product against the IPA list, because a certified manufacturer is not the same thing as a certified model number.
Does a power conditioner need JC-STAR on its own?
A PCS with no IP communication function is outside the scope of the scheme. Yaskawa Electric published an official position to this effect on April 13, 2026 covering the Enewell-SOL P3A and P3H, stating that the reading had been confirmed with the Ministry of Economy, Trade and Industry. In practice, what you should check is not the PCS but the gateway, monitoring device or EMS paired with it, since that is the component carrying the communication function.
What should we do if our installed equipment is not JC-STAR compliant?
Start by separating two different situations — equipment that is out of scope, and equipment that is in scope but not yet labeled. For out-of-scope equipment, record the reason and keep it on file so the decision can be explained later. For in-scope but unlabeled equipment, plan the replacement into the next refresh cycle, and in the meantime reduce exposure through network segmentation, changing default passwords, closing unused ports and putting a firmware update routine in place.
Is a Level 1 label good enough on its own?
Level 1 is a self-declaration by the manufacturer and covers a baseline set of requirements. Depending on the application, a higher level may be warranted, although as of 2026 almost all publicly visible cases sit at Level 1, so in most categories it is the only option available. Rather than treating the label as the whole answer, also look at the vendor’s posture on updates and support — how long firmware will be supplied and how vulnerabilities are disclosed.
Can overseas manufacturers not obtain JC-STAR?
There is no structural exclusion. For companies such as HUAWEI and SUNGROW, the position is simply that no acquisition under their own brand can be confirmed from public information as of 2026. That says nothing about an inability to certify, and nothing about a security problem with the products. The correct handling is to record the fact that acquisition could not be confirmed, and to put an enquiry to the manufacturer or distributor if the decision requires it.
If a product is not in the IPA list, what should we ask the manufacturer?
First ask whether the model is in scope at all. If the answer is that it is out of scope, get the reason in writing and keep it. If it is in scope, ask about the status and expected timing of an application, and which of the requirements the product currently meets. If no answer comes back at all, treat that silence as one factor when evaluating alternative models — a vendor that cannot answer a security question today is unlikely to answer one during an incident.
Summary
Looking at JC-STAR acquisitions category by category, several patterns come into focus.
In network equipment, Buffalo leads on volume with 44 series and 150 models as of January 2026, and labeled options now span everything from new Wi-Fi 7 products down to Wi-Fi 6 entry-level models. In solar and battery storage monitoring, acquisitions by Omron Social Solutions, Laplace System, Canadian Solar and FieldLogic clustered between late 2025 and the first half of 2026. The Miwa Lock case shows the reach of IoT device assessment extending into territory long regarded as purely mechanical.
And Yaskawa Electric’s clarification that a standalone PCS without IP communication is out of scope teaches us the granularity at which the scheme should be read. What is assessed is not the system but the component that handles communication. Hold on to that lens and you can inventory your own equipment through the same procedure, whether it is solar, machine tools, measuring instruments or air conditioning.
The conclusion for procurement is simple. Verify at model-number level, box by box for anything with a communication function, against the IPA’s published list. Where nothing is found, record that it could not be confirmed and raise an enquiry. And because the information moves within months, pull it again every time you specify. Build those three habits into your operation and no amount of tightening in the requirements will catch you off guard.
Talk to us about your plans or a current-state check
If you are trying to work out which equipment in your plant actually has a communication function, or how to check its compliance status, or how to apply a head office security standard to equipment bought locally in Thailand, we are happy to think it through with you. It is entirely fine to get in touch while the plan is still vague and nothing has been decided — often the most useful first step is simply mapping what is connected to what. Reach us through the TOMAS TECH contact form.
References
- METI press release on the launch of JC-STAR
- IPA official list of products holding the JC-STAR conformity label
- Buffalo press release on the WSR6500BE6P series JC-STAR label
- Buffalo press release on the start of WSR-3000AX4L shipments
- Omron Social Solutions JC-STAR information page
- Laplace System page on the Solar Link ZERO JC-STAR label
- Solar Link NET article on JC-STAR certified manufacturers, the source of the Canadian Solar and FieldLogic registration numbers
- Miwa Lock page on the iEL Zero smart JC-STAR label
- Legal analysis of overseas PCS units and JC-STAR, the source for the Yaskawa Electric statement
- Splight article on JC-STAR and IoT security trends