Loading…
Loading…
The CESI Act creates Japan's first cross-cutting peace-time security-clearance regime for non-defence economic information. It operates through three formally distinct components:
(1) Designation of Critical Economic Security Information. Competent ministers (under direction of the Minister of Economic Security in the Cabinet Office) designate as CESI information whose unauthorised disclosure would harm Japan's national security where the information is not already covered by the 2013 Specially Designated Secrets Act (SDS Act). Three statutory categories are protected: (a) threat-intelligence on cyber-attack methods and counter-measures targeting critical-infrastructure sectors; (b) information generated through regulatory reviews and notifications of essential-infrastructure operators (including those filed under ESPA Pillar 2); (c) vulnerability information about supply chains for "specified critical products" (the December 2022 ESPA Cabinet Order list: semiconductors, storage batteries, permanent magnets, machine tools, critical minerals, cloud programs, etc.).
(2) Provision and handling of CESI. CESI may only be provided to natural persons who have passed an "適性評価" (suitability assessment / clearance) administered by the Cabinet Office. The assessment examines criminal record, foreign-influence ties, financial stability, substance use, and information-handling history. Clearances are valid for ten years subject to periodic review. Private-sector firms that hold CESI must enter into government contracts that require physical and information-security safeguards comparable to government installations (controlled access areas, encrypted handling systems, audit logs).
(3) Criminal penalties for leakage. Persons engaged in CESI handling who disclose CESI obtained in the course of their duties are punishable by up to five years' imprisonment or a fine (or both). Lower penalties apply to attempts, conspiracies, and incitement. The five-year ceiling is below the SDS Act's ten-year maximum, reflecting CESI's lower (Confidential-equivalent) classification tier.
Effective dates. Preparatory provisions (administrative rule-making, advisory-council formation, contractor-screening framework build-out) entered into force on 17 May 2024 with promulgation. Full operation — including contractor screening, clearance issuance, and the criminal-penalty regime — began on 16 May 2025 by Cabinet Order, within the statutory deadline of one year from promulgation.
SDS Act covers defence, diplomacy, counter-intelligence, and counter-terrorism but is widely viewed as too narrow for dual-use civilian R&D, critical-infrastructure cybersecurity, and supply-chain vulnerability data. The CESI Act fills that gap and is structurally significant — not a point intervention.
by central-government and defence personnel, CESI clearances are designed to be issued at scale to private-sector engineers, executives, and researchers at critical-infrastructure operators, semiconductor firms, and defence-industrial-base contractors. This is a structural shift in the Japan-side compliance burden for joint R&D programs.
argued for years that the absence of a CESI-equivalent regime locked Japanese firms out of certain US Department of Defense, AUKUS Pillar II, and EU Horizon dual-use research consortia. The new regime is the legislative key to fuller Five Eyes (including the planned "FVEY+JP" coordination) and EU Permanent Structured Cooperation (PESCO) third-state participation.
than direct capital deployment (CHIPS Act, IRA) or a market-access prohibition (export controls, tariffs).
ESPA covers four pillars — supply chains, critical infrastructure, specified critical technologies, sensitive patents — but contains no general framework for protecting government-shared sensitive information flowing to ESPA-regulated firms. The CESI Act closes that loop. Pillars 2 (critical-infrastructure ICT pre-screening) and 3 (specified critical technologies R&D) feed directly into CESI category designations.
counter-intelligence/counter-terrorism information; CESI Act protects economic-security information. The two regimes share a common clearance philosophy but operate under separate statutes, separate competent ministers, and separate penalty ceilings.
Information generated through METI's foreign-user diversion checks for controlled lithography/etch/deposition tools is a candidate for CESI designation in the December 2024 administrative rule-making.
semiconductor-equipment / device players gain a clearance pathway to participate fully in US DoE / DoD and EU dual-use R&D programmes — a modest tailwind for EWJ semiconductor weights via reputation/access rather than direct subsidy.
AWS Japan, Microsoft Japan** and other ESPA-Pillar-2 critical-infrastructure operators face elevated compliance overhead — clearance issuance, secure handling rooms, contractor vetting — to remain eligible for government- shared threat intelligence.
base contractors gain access to AUKUS Pillar II and certain US DoD dual-use programmes that previously declined Japanese participation due to information-handling concerns.
cooperation, complementing the ongoing CHIPS Act / METI co-funding of Rapidus and TSMC Kumamoto.
Cabinet Office's first full-year CESI report (expected mid-2026) is the metric to watch for adoption pace.
to include hydrogen, quantum-computing hardware, or biosecurity inputs, pulling additional firms into CESI scope?
certain existing SDS-classified items be reclassified as CESI to broaden industry access, or will the two regimes remain strictly siloed?
formally recognise Japanese CESI clearances for joint-programme purposes, versus requiring parallel national clearance in each jurisdiction.