Technology and Procurement
An IoT security label is becoming a market-entry credential.
By Japan Legible
- Published
- Last checked
- Reading time
- 9 minutes

A company selling an internet-connected product into Japan should now decide whether JC-STAR belongs on the market-entry critical path.
The answer is not automatically yes. JC-STAR is a voluntary security labeling scheme, and its scope does not include every digital product. But the label is moving from a general trust signal toward a procurement credential. Government policy has identified JC-STAR as an equipment-selection criterion, while local government, critical-infrastructure, and private-sector adoption is being promoted.
For an in-scope vendor, waiting for a tender to mention the label can be too late. The useful action is to determine product scope, target buyer expectations, required star level, evidence gaps, and support commitments before the sales process begins.

That is a readiness decision, not a claim that the label is universally mandatory.
What JC-STAR is
The Ministry of Economy, Trade and Industry, or METI, and the Information-technology Promotion Agency, or IPA, launched the Labeling Scheme based on Japan Cyber-Security Technical Assessment Requirements on March 25, 2025. JC-STAR evaluates and makes visible whether an IoT product conforms to defined security requirements.
The scheme is intended to help government bodies, companies, and consumers identify products that meet an expected security level. A label contains a QR code linked to an IPA-managed product page. That page can provide vendor and product information, label status, security updates, vulnerability information, and contact details.
The official launch release describes a four-level structure. STAR-1 is a common baseline for minimum threats across products in scope. STAR-2, STAR-3, and STAR-4 add requirements developed for particular product categories and expected risk levels.
JC-STAR is designed with international work in view, including alignment with concepts in ETSI EN 303 645 and NISTIR 8425 and discussions about interoperability with overseas regimes. That does not make a JC-STAR label automatically interchangeable with a foreign certification. A vendor should verify any mutual-recognition arrangement and the exact product and level it covers.
Start with product scope
The scheme covers a broad range of products that communicate using Internet Protocol, including products connected directly or indirectly to the internet. The launch materials give routers, network cameras, and sensors as examples. Consumer and industrial IoT can be in scope.
Personal computers and smartphones are outside the scheme's stated scope. A software service without an associated in-scope IoT product should not be described as JC-STAR labeled merely because it communicates over the internet.
The practical unit is the product and its identified models, not the company in the abstract. IPA's public register lists the relevant product name, label holder, star level, registration number, status, issuance date, and expiry. A buyer should verify the exact model or family entry rather than accept a vendor-wide statement.
This distinction matters when one hardware platform has many model numbers, regional variants, firmware branches, or bundled configurations. The first STAR-1 publication in May 2025 covered 11 companies and 26 applications, representing 477 product model numbers. That early result shows why application count and sellable-SKU count are not the same measure.

Before planning an application, map every Japan SKU to the hardware, firmware, default configuration, support channel, and vulnerability contact that will be represented by the evidence.
A label has different assurance at different levels
JC-STAR's levels should not be presented as one uniform certification method.
For STAR-1 and STAR-2, the vendor evaluates its product against the defined criteria and procedures, prepares a checklist, and submits a self-conformity declaration. IPA reviews the application and grants the label when the process is satisfied. The reliability of the underlying evaluation therefore depends substantially on the vendor's assessment and evidence.
For STAR-3 and STAR-4, an independent JC-STAR evaluation body assesses the product, and IPA uses the resulting evaluation report in certification and label issuance. These higher levels are intended for contexts requiring greater assurance, including products used in important government, local-government, large-enterprise, and critical-infrastructure systems.
The distinction is central to procurement communication. “JC-STAR labeled” identifies conformity at a stated level. It should not be expanded into “independently certified” when the product holds a self-declaration-based level.
IPA also states that a label confirms the minimum level defined for the threats anticipated by the applicable criteria. It does not guarantee complete or perfect security. IPA may conduct inspection or surveillance where conformity is in doubt, and label cancellation is possible.
The label is therefore a structured claim with continuing consequences, not a permanent security award.
Validity changes the product lifecycle
A STAR-1 label is initially valid for up to two years. IPA's current scheme explanation says extensions can be requested in one-year increments, with total validity extending no further than five years from the initial issuance date.
That period is operationally meaningful. A connected product can remain in distribution or deployment for longer than a label cycle. Firmware changes, component substitutions, vulnerability discoveries, support-policy changes, and end-of-life plans can all affect the maintained claim.
A vendor needs a named owner for the label after launch. That owner should track registered configurations, security advisories, updates, customer contact information, surveillance requests, changes requiring notification, renewal evidence, and the relationship between sales end and support end.

A procurement credential that expires during a buying cycle can create more friction than one that was never claimed. Renewal and change control belong in the commercial release plan.
Why the label is becoming commercially important
At launch, METI stated that revised government cybersecurity guidance set a policy direction to include STAR-1 or higher in equipment-selection criteria by the end of fiscal 2025, taking scheme readiness into account. Higher levels were to be reflected as product categories expanded. METI also said it would work toward use in local-government and critical-infrastructure procurement.
This is enough to change vendor preparation, but not enough to say that every Japanese public buyer must reject every unlabeled IoT product. Procurement rules can differ by organization, system sensitivity, product category, and timing. A tender may specify a star level, request equivalent evidence, or apply additional security conditions.
The label also has potential value outside formal government requirements. It gives a buyer a common baseline, a public status record, and a defined security-information channel. In a market where buyers otherwise need to interpret proprietary questionnaires, this can reduce initial uncertainty.
Its value is strongest when paired with usable evidence. A QR-linked record cannot compensate for an unclear update period, weak vulnerability intake, inconsistent Japan model mapping, or support information that does not reach the deploying customer.
The counterargument
The strongest counterargument is that JC-STAR may add cost and process without materially changing demand.
The scheme is voluntary. STAR-1 and STAR-2 use self-assessment rather than independent evaluation. Some customers will continue to rely on their own security questionnaires, testing, contractual terms, or sector rules. A vendor serving consumer channels may find that buyers rarely recognize the mark. Product changes and renewals create recurring work.
That counterargument is especially strong for a product outside government, regulated infrastructure, or enterprise procurement. It is also strong when the product has a short market life or when an applicable higher-level standard is not yet established for its category.
The response should not be “every IoT product needs the label.” It should be a segmented commercial test. Ask target buyers whether JC-STAR is required, preferred, accepted as partial evidence, or currently irrelevant. Compare the cost and lead time of labeling with the revenue and procurement friction attached to those segments.
For a router, network camera, control device, or other product likely to enter managed infrastructure, the credential may be increasingly important. For a product with no in-scope buyer demand, monitoring may be the proportionate choice.

What remains unknown
The precise rollout of procurement requirements remains buyer-specific. Official policy establishes direction, but an operator still needs to confirm the effective rule used by each ministry, agency, municipality, critical-infrastructure operator, subsidy program, or prime contractor.
The required level can also be uncertain. STAR-1 is a common baseline; higher requirements depend on product category and use context. A label sufficient for a low-risk deployment may not satisfy a buyer protecting an important system.
International recognition requires case-by-case verification. Government discussions and announced cooperation do not justify saying that one label automatically opens the European Union, United Kingdom, United States, or Singapore market.
Market recognition is another unknown. IPA's public register provides adoption evidence, but it does not show how often the label determined an award, reduced diligence time, or changed consumer demand.
Finally, the scheme and its procedures are living materials. Criteria, forms, fees, eligible evaluation bodies, and implementation guidance can change. A plan based on an old application pack can fail administratively even if the underlying product security remains sound.
A practical operator decision
First, determine whether the sellable product is in scope. Record how it uses IP communication, whether it connects directly or indirectly to the internet, and which exact models and firmware versions are intended for Japan.
Second, segment the market. List government, municipal, critical-infrastructure, enterprise, and consumer channels separately. For each channel, obtain a current answer on whether JC-STAR is mandatory, preferred, or simply informative, and which level is expected.
Third, run a STAR-1 readiness assessment even if immediate application is undecided. Review identity and access controls, secure defaults, update mechanisms, vulnerability handling, documentation, product-page information, and the evidence needed for the published criteria. Treat missing evidence as a product-management issue, not only a certification issue.
Fourth, estimate lifecycle cost. Include application work, any testing support, localization, model maintenance, vulnerability disclosures, firmware updates, surveillance response, extension work, and the possibility of redesign for a higher category-specific level.
Fifth, define the sales claim. Use the exact registered product, level, status, and validity period. Do not advertise “planned conformity” as though a label has been granted. IPA specifically cautions applicants against statements such as “JC-STAR conformity planned” before issuance because applications can be rejected.

The decision rule is straightforward: place JC-STAR on the release critical path when a meaningful target segment uses it as an entry criterion or when the label materially reduces repeated buyer diligence. Otherwise, preserve readiness, monitor requirements, and avoid a premature market claim.
Program-scope caution
JC-STAR is an IoT product security conformity and labeling program. It does not replace product-safety law, radio or telecommunications approvals, privacy obligations, sector cybersecurity rules, contractual security commitments, or a buyer's independent assessment. A current label is evidence against defined criteria at a stated level, not a warranty that the product cannot be compromised.
Source limitation
This analysis relies on METI and IPA primary materials available through August 11, 2026, including the March 2025 launch release, IPA's current scheme explanation, the May 2025 first-label release, and IPA's live product register. Living pages and procedures may change. The sources establish policy direction for procurement, but do not prove universal implementation by every buyer. METI content is generally available under its stated Public Data License 1.0-based terms, subject to attribution, modification notices, and listed exclusions.
Evidence
Sources
- Launch of JC-STAR applicationsMinistry of Economy, Trade and Industry · March 25, 2025
- JC-STAR scheme detailsInformation-technology Promotion Agency
- First STAR-1 labelsInformation-technology Promotion Agency · May 21, 2025
- JC-STAR labelled products registerInformation-technology Promotion Agency