What happened
Japan enacted Acts 42 and 43 of 2025, establishing the Active Cyber Defense (ACD) framework. From 1 Oct 2026, designated critical‑infrastructure operators must notify the government of qualifying cyber incidents and submit an initial notification within six months for existing systems. The statutes also grant authorities the ability to collect communications metadata and to neutralize hostile infrastructure starting 23 Nov 2027.
Why it matters for trust and compliance
- The ACD mandate introduces a mandatory incident‑response and reporting control that maps directly to governance objectives in NIST CSF 2.0, demanding continuous monitoring and defensible evidence of notifications.
- Provides a clear control objective for incident‑response governance that can be continuously monitored.
- Enables collection of audit‑ready evidence of mandatory reporting and evidence preservation.
Who is affected
Critical‑infrastructure operators (energy, utilities, transport, finance, telecom, etc.) Supply‑chain vendors, hosting providers, and carriers supporting covered systems
Recommended actions
- Map the new reporting requirement to your incident‑response control framework and define required evidence artifacts.
- Implement continuous monitoring that triggers reporting workflows when a qualifying incident is detected.
- Update third‑party contracts to include obligations for evidence preservation and remediation assistance.