{"rewrite":{"id":"r_44dd834fad6791aa6acaf1f8","clusterId":"c_a7b25c0a528bb4c343c20614","slug":"scs-evaluation-system-pressures-small-manufacturers-to-rethink-security","model":"deepseek-v4-flash","headline":"SCS Evaluation System Pressures Small Manufacturers to Rethink Security","summary":"Mid-sized and small manufacturers are wrestling with the reality of the SCS Evaluation System, a Japanese supply chain security certification slated to begin around the end of fiscal year 2026. The system grades companies from 3 to 5 stars, with 3 and 4 star criteria forming 153 total evaluation items. Fuji Holdings, the administrative arm of kitchen equipment maker Fuji Kogyo Group, shared its progress at the 21st Factory Security Guideline Awareness Seminar in July 2026. Hideaki Urabe, general manager of corporate planning, detailed a two-year-old project triggered by a president's question about ransomware countermeasures. The group set a five-year plan through 2029 to achieve 3 and 4 star compliance, adopting a three-pillar strategy of rules, tools, and skills. They standardized on CrowdStrike EDR and introduced Rubrik for backups, while consolidating department NAS into file servers. Urabe admitted that IT and OT networks remain mixed at production sites, with old operating systems still in use, and that IT/OT separation will take time due to factory renovations. The group also plans to establish human and physical security management regulations and redefine IT roles.","whyItMatters":"The SCS system's 153 criteria are weighted heavily toward evidence and accountability, not product purchases, which means small manufacturers must build operational structures rather than buy their way to compliance.","webCardHtml":"\u003cp\u003eThe seminar where Fuji Holdings presented was the 21st Factory Security Guideline Awareness Seminar, co-hosted by the Japan Network Security Association\u0026#39;s OT Security Working Group and the University of Tokyo Green ICT Project. The Fuji Kogyo Group, known by the corporate brand FUJIOH, holds a 61.8 percent domestic share in range hoods, according to Fuji Keizai\u0026#39;s 2026 market data handbook.\u003c/p\u003e\u003cp\u003eUrabe\u0026#39;s project began the same day the president asked about ransomware readiness. He consulted Hitachi Solutions, with which he had a 15-year relationship, and the project started as co-creation with that company. \u0026#34;In strengthening security, having top management\u0026#39;s understanding was extremely significant,\u0026#34; he said.\u003c/p\u003e\u003cul\u003e\u003cli\u003eTools: CrowdStrike EDR standardization runs through Hitachi Solutions\u0026#39; MDR service; Rubrik handles core system backups, with department systems piggybacking on the same platform.\u003c/li\u003e\u003cli\u003eRules: New human security management and physical security management regulations will be set to SCS requirement levels, then \u0026#34;gradually systematize while observing operations,\u0026#34; Urabe said.\u003c/li\u003e\u003cli\u003eRoles: The vague \u0026#34;IT promoter\u0026#34; role is being replaced by department IT managers and IT administrators, with department heads bearing maintenance and operation responsibility.\u003c/li\u003e\u003cli\u003eSkills: IT Passport certification, already mandatory for managers, will expand to other employees, linked to ITSS qualifications.\u003c/li\u003e\u003cli\u003eMotivation: A compensation and evaluation system is planned for skill acquisition and managerial positions.\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eDropbox Japan\u0026#39;s Yuki Ue, a CISSP holder, told a separate seminar that about 70 percent of the 153 criteria require building structures and evidence for accountability, not product purchases. METI issued a warning in April 2026 about inappropriate product solicitation tied to the system.\u003c/p\u003e","blueskyPost":"SCS is not a shopping list. 70% of its 153 criteria demand structures, rules, and evidence. Fuji Kogyo's real work: separating IT and OT networks in a factory that still runs old OSes.","twitterPost":"Fuji Kogyo's SCS push started when a president asked about ransomware and heard 'not sufficient due to costs.' The fix: CrowdStrike, Rubrik, and a five-year plan through 2029. But IT/OT separation? That needs factory renovations.","threadsPost":null,"newsletterBlurb":"Japan's SCS supply chain security certification is coming, and small manufacturers are scrambling. Fuji Kogyo's plan shows the real challenge is not buying tools but building evidence and accountability. Also: experts say 70% of the 153 criteria are about operations, not products.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/425/4425249/?rss\",\"title\":\"The Reality of Mid-Sized and Small Manufacturers Aiming to Acquire the \\\"SCS Evaluation System\\\": Fuji Kogyo's Answer to \\\"Is Security Useful for Management?\\\"\"},{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/428/4428605/?rss\",\"title\":\"Experts Analyze the SCS Evaluation System's 153 Items: What Is the Optimal Approach for SMEs?\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":14739,"outputTokens":1463,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1787877464,"createdAt":"2026-08-28T00:32:14.000Z","publishedAt":"2026-08-28T00:36:44.000Z","updatedAt":"2026-08-28T00:32:14.000Z"},"cluster":{"id":"c_a7b25c0a528bb4c343c20614","canonicalTitle":"「SCS評価制度」取得を目指す中堅・中小製造業のリアル　富士工業が考える「セキュリティは経営に役立つのか」の答え","representativeArticleId":"a_14511118dfecaed9f52e1197","sourceCount":1,"writtenSourceCount":1,"writeAttempts":1,"isSolo":false,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-24T02:00:00.000Z","lastSeenAt":"2026-08-25T02:00:00.000Z","updatedAt":"2026-08-28T00:36:44.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/428/4428605/?rss","title":"専門家が分析するSCS評価制度・153項目　中小企業に最適な対策のアプローチは？"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["The SCS Evaluation System is scheduled to begin operation around the end of fiscal year 2026.","The system's 3 star and 4 star criteria total 153 evaluation items, organized into three axes: access management, sharing rules, and evidence and accountability.","Fuji Holdings started a security enhancement project about two years ago, triggered by a president's question about ransomware countermeasures at a management meeting.","Fuji Holdings set a five-year plan through 2029 to achieve 3 and 4 star SCS compliance, with a three-pillar strategy of rules, tools, and skills.","METI issued a warning in April 2026 that introducing specific security products is not mandatory to achieve SCS evaluation criteria."]}
