ISMAP (Japan Government Cloud Procurement Certification)
Last reviewed: August 2026
Overview
Section titled “Overview”ISMAP (Information system Security Management and Assessment Program, 政府情報システムのためのセキュリティ評価制度) is a program under which the security level required when Japanese government agencies procure cloud services is assessed and registered in advance. It began operating in June 2020. The National Cybersecurity Office (国家サイバー統括室, NCO — the organization created by reorganizing NISC in July 2025), the Digital Agency (デジタル庁), the Ministry of Internal Affairs and Communications, and the Ministry of Economy, Trade and Industry participate as the responsible ministries, while the Information-technology Promotion Agency (IPA) serves as the operating support body that assists with registration review.
The Japanese government has adopted a cloud-by-default principle (クラウド・バイ・デフォルト原則) through its “Basic Policy on the Appropriate Use of Cloud Services in Government Information Systems,” and the Digital Agency’s Government Cloud (ガバメントクラウド) — the shared cloud infrastructure for the government — also lists ISMAP registration as a condition of use. In other words, similar to other government cloud security certifications (such as the US FedRAMP or Korea’s CSAP), ISMAP functions as the de facto entry gate for public-sector cloud procurement in Japan.
Registration Process
Section titled “Registration Process”ISMAP registration generally proceeds in the following order.
- Determine the target service — finalize the cloud service (including region and service scope) for which registration will be sought.
- Build and operate an internal control framework — build an in-house security framework aligned with the ISMAP management standards (information security management standards, governance standards, management standards, etc.) and actually operate it.
- External audit — undergo an external audit by an ISMAP-registered auditing body to assess compliance with the management standards.
- Registration application — submit documentation, including the audit results, to IPA.
- Technical review — IPA technically reviews the content of the audit results.
- Registration decision — the ISMAP Steering Committee (the highest decision-making body of the ISMAP system) makes the final registration decision. The program aims, in principle, to reach a registration decision within six months of accepting the application.
Even after registration, a renewal review is conducted at least once a year, so this is not a one-time certification but a framework that must be maintained continuously.
ISMAP and ISMAP-LIU
Section titled “ISMAP and ISMAP-LIU”Out of concern that requiring the full ISMAP-level review even for SaaS handling relatively low-importance information would set the entry bar too high for small and medium-sized SaaS providers, ISMAP-LIU (ISMAP for Low-Impact Use) was introduced in November 2022.
| Category | ISMAP | ISMAP-LIU |
|---|---|---|
| Scope | Government information systems in general (may include highly confidential information) | SaaS handling relatively low-confidentiality information |
| Review items | The full set of management standards | Narrowed down to focus on risks that significantly affect cloud infrastructure and configuration |
| Audit scope | Broad verification of management strategy | Focused on management strategy related to core risks |
| Suitable for | Large-scale infrastructure (IaaS/PaaS), services shared across multiple ministries | Small and medium-sized SaaS, SaaS for specific business functions |
Registration Status of Hyperscalers and Major Providers (as of August 2026)
Section titled “Registration Status of Hyperscalers and Major Providers (as of August 2026)”| Provider | Registration status | Notes |
|---|---|---|
| AWS | Registered (includes Tokyo and Osaka regions, numerous services) | Has maintained registration since the early days of the ISMAP program, with renewal repeated before each expiry |
| Microsoft Azure | Registered (includes Japan East/Japan West and contractually available overseas regions) | Related services such as Microsoft 365 are also registered |
| Google Cloud | Registered (individual services such as Looker are also registered progressively) | Registration timing can differ by service, so check the latest list |
| Oracle Cloud Infrastructure (OCI) | Registered (initially registered June 2021, subsequently expanded to PaaS, Exadata Cloud@Customer, etc.) | |
| Sakura Internet (さくらのクラウド) | Registered (December 2021) | The first domestic Japanese provider to also be selected as a Government Cloud provider |
| Cloudflare | Registered (announced January 2026, effective from December 22, 2025) | Includes numerous services such as CDN/WAF, DDoS protection, Zero Trust, and Workers |
Gate-Like Nature: Exclusion from Public Procurement When Unregistered
Section titled “Gate-Like Nature: Exclusion from Public Procurement When Unregistered”ISMAP functions less like a certification and more like a list of procurement-eligible services. Government agencies are, in principle, required to procure from among the services listed on the ISMAP Cloud Service List or the ISMAP-LIU list, so services not on the list are effectively excluded from government procurement without a separate individual review. ISMAP registration is also a condition of participation in the Government Cloud, so as local government systems increasingly migrate to the Government Cloud, ISMAP’s reach is trending to extend beyond the central government to local governments and public bodies as a whole.
Practical Implications for Foreign Companies and Global SaaS Entering Japan’s Public Sector
Section titled “Practical Implications for Foreign Companies and Global SaaS Entering Japan’s Public Sector”- Both an entry barrier and a trust signal: ISMAP is a prerequisite for entering Japan’s public sector, but registration itself is also used as a signal that demonstrates security maturity to large private-sector and regulated-industry customers. It is worth considering even for companies that are not targeting public procurement.
- Audit and review cost and duration: selecting an external auditing body, addressing the management standards, IPA’s technical review, and the Steering Committee’s decision can together take anywhere from several months to nearly a year, so this should be factored into a Japan market-entry roadmap early on.
- Room to leverage ISMAP-LIU: foreign companies starting with a specific-purpose SaaS rather than a government-wide system may find the ISMAP-LIU route relatively less burdensome. However, since the abolition of pre-application in April 2025 has brought the procedure closer to standard ISMAP, the latest requirements should be checked.
- Local entity and local audit response required: Japanese-language documentation and collaboration with Japan-based auditing bodies are effectively essential during the audit and review process.
- Foreign Company Registration Status: outside of global hyperscalers, the registration of independent non-Japanese SaaS providers remains relatively limited, making early preparation essential (checking the latest registration status directly on the ISMAP Portal is recommended).
References
Section titled “References”- ISMAP Portal — the official source for the registered service list and program rules
- ISMAP Program Overview (NISC, Digital Agency, Ministry of Internal Affairs and Communications, Ministry of Economy, Trade and Industry, November 2023)
- ISMAP-LIU Introduction Materials (April 1, 2025)
- Cabinet Cybersecurity Center: Information system Security Management and Assessment Program (ISMAP)
- AWS ISMAP Compliance Page
- Microsoft ISMAP Compliance Page
- Google Cloud ISMAP Registration Announcement
- Oracle Cloud Infrastructure ISMAP Compliance
- Sakura Cloud ISMAP Information
- Cloudflare ISMAP Registration Announcement (January 2026)