Japan's Information-technology Promotion Agency publishes security guidelines for small and medium enterprises, and the 2026 edition is the most detailed yet. At 87 pages, it is not a document most business owners will read cover to cover. This article pulls out the sections that are most relevant to the manufacturers and distributors we work with in Gifu and Aichi, and explains what they mean in practical terms.

Supply chain risk is now a baseline expectation

The 2026 guidelines expand significantly on supply chain security. The IPA now expects SMEs to assess the security posture of their key suppliers and subcontractors, not just their own internal systems. For manufacturers with complex supply chains, this means having a conversation with your suppliers about their backup procedures, access controls, and incident response plans. The guidelines do not specify exactly how to do this, but they make clear that 'we only manage our own systems' is no longer an acceptable position.

The 3-2-1 backup rule is now the stated baseline

The updated guidelines explicitly recommend a 3-2-1 backup structure as the minimum for all SMEs: three copies of your data, stored on two different types of media, with one copy stored offsite. Several organisations we work with are currently running a single on-site backup, which the guidelines flag as insufficient. An offsite backup does not have to mean cloud storage. A physical backup stored at a separate location, rotated regularly, satisfies the requirement.

Access control reviews should happen at least annually

The guidelines recommend that SMEs review user access rights at least once per year, and immediately when an employee leaves or changes roles. This sounds straightforward, but in practice many organisations have accumulated years of access permissions that nobody has reviewed. Former employees, contractors, and vendors may still have active credentials. An annual access review is a low-cost, high-value security practice that the guidelines now treat as a baseline expectation.

The IPA guidelines are a useful framework, but they are most valuable when translated into a specific action list for your organisation. If you want help mapping your current setup against the 2026 guidelines, our Security Readiness Review is designed for exactly that purpose.