SecureBase (Headquarters: Meguro-ku, Tokyo; CEO: Jitsuyo Abe) has launched support for the 'Security Assessment System for Supply Chain Strengthening' (SCS Evaluation System) promoted by Japan's Ministry of Economy, Trade and Industry (METI) and the IPA, through its AI and expert-driven cyber risk governance platform, CISOaaS®. This feature enables companies lacking dedicated security personnel to complete compliant status assessments quickly by simply answering questions posed by an AI.

What is the SCS Evaluation System? The SCS Evaluation System is a voluntary framework developed by METI and the IPA to evaluate and visualize corporate cybersecurity measures. It aims to improve security levels across the entire supply chain, with operational expectations where principals set the necessary security level (stars) for their contractors to verify their security readiness.

Targeted Use Cases While the SCS Evaluation System is voluntary, it is expected that small-to-medium and high-growth enterprises within major corporate supply chains will increasingly face requests from business partners to comply with the system. However, the evaluation criteria are extensive, making it burdensome for companies without dedicated security managers to handle while balancing other responsibilities.

CISOaaS® manages the initial hearing of assessment items via AI, which is then reviewed by SecureBase’s professional consultants. This two-tier flow allows companies unable to employ a dedicated CISO or security manager to move forward with compliance.

Key Features 1. Support for ★3 and ★4 Levels of the SCS Evaluation System The platform assists in assessing and complying with ★3 and ★4 levels, depending on the requirements of business partners. By using an AI-driven Q&A format, companies can navigate complex evaluation items with reduced administrative burden.

2. Consolidated Evaluation of Major Frameworks With this update, CISOaaS now manages 5 frameworks and 560 evaluation items, including the SCS standard. Users can concurrently evaluate against standards like CIS Controls v8.1, NIST CSF 2.0, and risks specific to generative AI (OWASP Top 10 for LLM 2025) within the same environment.

3. Actionable Insights for Management Beyond assessment, the system calculates the significance of risks, projected annual losses, recommended investment amounts, and ROI using loss distribution simulations and optimal investment models. It provides a prioritized action plan and an AI-generated improvement roadmap, producing PDF reports suitable for management board meetings.

Future Outlook SecureBase plans to continuously update the CISOaaS® compliance support features as the final specifications of the SCS Evaluation System (such as the assessment guide) are released around autumn 2026.

FACT BOX

  • Source: PR TIMES
  • Category: New Product
  • Organizations: IPA
  • Products / services: CISOaaS®