A mid-sized manufacturer in Osaka just got an email from its biggest client: "We need your SCS certification status by next quarter, or we reassess the contract." The IT manager, Sato, has three options on the table: a proposal from Fujitsu for managed security, a new KDDI AccelWaves SASE bundle, and a consultant pushing for SCS ★3 compliance. He needs to pick one, and he needs to pick it this week.
For most Japanese enterprises in 2026, the security question is no longer "if" but "which architecture." The answer splits into two distinct paths: outsourced operations (Fujitsu MSS, KDDI AccelWaves) and certification-driven internal builds (SCS). Per KDDI's official announcement on 2026-09-29, the AccelWaves initiative consolidates network, security, and operations into a single managed platform, starting with a SASE gateway powered by Palo Alto Networks. Meanwhile, the SCS evaluation system, formally established on 2026-03-27 per public documentation, pushes companies toward a ★3 baseline with expert confirmation. Fujitsu's managed security services, per its official product pages, focus on log analysis and AI-assisted reporting for zero-trust environments.
This guide compares the three approaches across cost, compliance, and operational reality. You will get a clear verdict for your company size, a worked example of SCS ★3 costs, and a checklist to avoid common implementation mistakes.
Verdict: For most mid-sized Japanese firms facing client pressure, the fastest path is SCS ★3 certification using a specialist support service, not a full MSS contract. KDDI AccelWaves suits companies already deep in the KDDI ecosystem; Fujitsu MSS fits enterprises with complex legacy networks. Start with a gap analysis against the SCS ★3 requirements to see which path is cheaper.
What changed in 2026: AccelWaves and SCS explained
Two major shifts define the 2026 enterprise security landscape in Japan. The first is KDDI's AccelWaves, announced 2026-09-29. It is not a single product but an umbrella concept for delivering network and security as one managed service. The first offering under this brand is a SASE gateway powered by Palo Alto Networks Prisma Access, per KDDI's official newsroom. This matters because it collapses two procurement decisions — WAN and security — into one contract, reducing vendor management overhead.
The second shift is the SCS evaluation system (Supply Chain Security Evaluation), which the Ministry of Economy, Trade and Industry (METI) and the Cabinet Cyber Office formally established on 2026-03-27, per public documentation. It rates companies from ★1 to ★5 on their security posture, with ★3 requiring expert confirmation of their measures. Unlike ISO 27001, SCS is explicitly designed for supply-chain trust — meaning your clients can check your star rating directly.
| Feature | KDDI AccelWaves | Fujitsu MSS | SCS ★3 Certification |
|---|---|---|---|
| Core model | Managed SASE (network + security) | Managed security operations | Internal security build + audit |
| Start date | 2026-09-29 (first service) | Established; ongoing | 2026-03-27 (framework) |
| Key technology | Palo Alto Prisma Access | AI-assisted log analysis | Expert confirmation of controls |
| Best for | KDDI-centric enterprises | Complex legacy environments | Mid-sized firms with client pressure |
| Typical timeline | Weeks to deploy | Months to integrate | 3-6 months per support providers |
The Fujitsu option: managed security for complex environments
Fujitsu's managed security services, per its official product page, are built around the zero-trust model. The offering includes a log analysis platform, security personnel, and generative AI for report generation. This is not a product you buy off the shelf; it is an operational partnership where Fujitsu runs your security operations center (SOC) functions.
The strength here is depth. For a company with hundreds of servers, legacy on-premises systems, and a small IT team, Fujitsu provides the expertise you cannot hire locally. The AI-assisted reporting, per the official description, reduces the burden on your internal staff by generating plain-language summaries of security events. The trade-off is cost and complexity — this is an enterprise solution, and the integration timeline typically runs months.
Who should choose Fujitsu MSS?
Choose Fujitsu if you have a complex existing infrastructure and the budget for a long-term security partnership. It fits regulated industries like finance or healthcare where audit trails and detailed reporting are non-negotiable. It is less suitable for a 50-person manufacturing firm that simply needs to pass a client's security questionnaire.
KDDI AccelWaves: the integrated network-security play
KDDI's AccelWaves, per the 2026-09-29 announcement, is a strategic response to the AI era's network demands. The first implementation, the SASE gateway powered by Palo Alto Networks, combines network connectivity with security inspection in the cloud. For companies already using KDDI's business networks, this is a natural extension — you get a single vendor for WAN, security, and operations.
The practical advantage is simplification. Instead of managing separate VPN appliances, firewalls, and web filters, the SASE model delivers security as a cloud service that follows your users anywhere. Per KDDI's official product page for Prisma Access, the service includes cloud-delivered security with network functions built in. This reduces the hardware footprint in your offices and simplifies remote-access security.
Who should choose AccelWaves?
AccelWaves fits companies that are already standardized on KDDI for telecom and want to consolidate security into the same bill. It also suits organizations with significant remote-work populations, where traditional office-centric security fails. The main consideration is vendor lock-in — moving security to KDDI means your security posture is tied to their roadmap.
SCS evaluation: the certification your clients actually ask for
This is the option most mid-sized companies will need first. The SCS evaluation system, established 2026-03-27, is gaining traction as a procurement requirement. Per the MCB FinTech catalog analysis, fourteen support services now exist to help companies achieve ★3 or ★4, indicating a fast-growing market. The system is voluntary, but client pressure makes it effectively mandatory in many supply chains.
Worked example: the cost of SCS ★3
Let's model a 100-person manufacturing company pursuing ★3. Based on the support services listed in the MCB catalog, a typical engagement includes:
- Gap analysis: 1-2 weeks to assess current controls against the ★3 requirements
- Policy documentation: 3-4 weeks to draft the required security policies and procedures
- Technical implementation: 4-8 weeks for endpoint protection, access controls, and logging
- Expert confirmation: the ★3 level requires an external expert to confirm your measures, per the official framework
Budget-wise, support service fees vary significantly by scope, but the cost is typically a fraction of a full MSS contract. The real cost is internal time — your IT staff must participate in the gap analysis and remediation. For a 100-person company, plan for one IT staff member at 50% capacity for 2-3 months.
SCS vs MSS: which is the right first step?
| Decision Point | SCS ★3 | MSS (Fujitsu/KDDI) |
|---|---|---|
| Client pressure | Directly answers it | Indirectly helps |
| Internal capability | Requires some internal IT | Can outsource everything |
| Cost profile | Project-based (lower) | Recurring (higher) |
| Timeline | 3-6 months | 1-3 months to start |
| Long-term value | Certification asset | Ongoing operations |
Common mistakes when starting SCS compliance
Based on the public requirements and support service descriptions, here are the pitfalls that delay certification:
- Treating it as an IT project, not a management commitment — SCS requires top-management approval and company-wide policies. If the CEO is not involved, the documentation phase stalls.
- Over-scoping the initial gap analysis — many firms try to reach ★4 immediately. The official framework suggests ★3 is the realistic first target for most companies. Get ★3 first, then improve.
- Ignoring the supply-chain angle — the system's name says it: this is about your supply chain. Your own vendors' security matters. Factor their readiness into your timeline.
- Assuming MSS covers certification — neither Fujitsu MSS nor KDDI AccelWaves automatically grants SCS certification. They provide security operations, but the certification requires a separate expert confirmation process.
Decision checklist for your company
Use this checklist to choose your path. Answer honestly:
- Do clients or partners explicitly ask for SCS status? → If yes, start with SCS ★3.
- Is your IT team smaller than 5 people? → If yes, consider MSS for operations while pursuing SCS in parallel.
- Are you already a KDDI telecom customer? → If yes, get an AccelWaves quote for comparison.
- Do you have legacy on-premises systems? → If yes, Fujitsu MSS may be the better operational fit.
- Is your budget project-based or recurring? → SCS is project-based; MSS is recurring.
How to start: a practical 30-day plan
Week 1: Internal assessment. List your current security controls against the SCS ★3 requirements published in the official framework. Identify obvious gaps in endpoint protection, access management, and logging.
Week 2: Vendor shortlist. If pursuing SCS, contact two or three of the fourteen support services listed in the MCB catalog for a gap-analysis quote. If pursuing MSS, request proposals from Fujitsu and KDDI with a clear scope of what they will operate.
Week 3: Cost comparison. Build a 3-year total-cost model. Include internal staff time, vendor fees, and the cost of failing client audits. For most mid-sized firms, SCS ★3 will be the lower-cost path.
Week 4: Decision and kickoff. Choose your path. For SCS, sign the gap-analysis contract and schedule the expert confirmation. For MSS, start the integration kickoff with your chosen vendor.
Frequently asked questions
Is SCS certification mandatory in 2026?
No, SCS is a voluntary program per the official framework published on 2026-03-27. However, large enterprises are increasingly requiring SCS status from their suppliers as a procurement condition. For many mid-sized companies, it is becoming effectively mandatory to maintain client relationships, even though no law requires it.
How does KDDI AccelWaves differ from traditional VPN security?
AccelWaves, per KDDI's 2026-09-29 announcement, is a SASE model that integrates network connectivity with cloud-delivered security. Traditional VPNs connect users to the office network and rely on on-premises security appliances. SASE inspects traffic in the cloud, so security follows the user regardless of location. This is the first AccelWaves service, powered by Palo Alto Networks Prisma Access.
Can Fujitsu MSS help us achieve SCS certification?
Fujitsu MSS provides security operations, log analysis, and AI-assisted reporting per its official product page. These capabilities support the technical controls that SCS ★3 requires, but the certification itself requires a separate expert confirmation process. You would still need to engage an SCS support service for the formal evaluation.
What is the difference between SCS ★3 and ★4?
Per the official framework, ★3 requires expert confirmation of your security measures, while ★4 requires a higher level of independently verified controls. The jump from ★3 to ★4 typically involves more rigorous technical validation and broader organizational coverage. Most companies should target ★3 first, as it is the baseline that clients commonly request.
How long does SCS ★3 certification take?
Based on the support services listed in the MCB catalog, a typical timeline is 3-6 months. This includes a gap analysis, policy documentation, technical implementation, and the expert confirmation. The timeline depends heavily on your starting point and internal resource availability. Companies with existing ISO 27001 certifications often move faster.
Which is cheaper: SCS ★3 or a managed security service?
For a mid-sized company, SCS ★3 is typically cheaper on a project basis. Support services charge a fixed fee for the gap analysis and certification support. Managed security services like Fujitsu MSS or KDDI AccelWaves charge recurring fees for ongoing operations. If your goal is purely to satisfy client requirements, SCS is the lower-cost path. If you also need ongoing security monitoring, MSS adds value beyond certification.
What happens if we do nothing?
Without SCS certification or a credible security posture, you risk losing contracts with large clients that require supplier security assessments. In 2026, this is becoming a competitive disadvantage. The cost of inaction is not regulatory — it is commercial. Clients will simply move to certified competitors.
The bottom line for Sato and your company
Sato's decision, like yours, comes down to what the client actually asked for. The client asked for SCS status. That points to the certification path. Fujitsu and KDDI offer excellent operational security, but neither replaces the SCS expert confirmation. For a mid-sized manufacturer, the fastest route to securing the contract is engaging an SCS support service and starting the gap analysis.
The good news is that this is a well-trodden path in 2026. Fourteen support services are actively helping companies achieve ★3 and ★4, per the MCB catalog. The framework is defined, the experts are available, and the timeline is predictable. The only wrong move is waiting.
Start with the gap analysis. It is the smallest, cheapest step that tells you exactly what your company needs. Within two weeks, you will know whether SCS ★3 is a 3-month project or a 6-month one — and you will have the data to justify the budget to your CEO.
Methodology: This review aggregates publicly available data from official company announcements, government framework documentation, and independent industry catalogs verified on 2026-10-03. The editorial team has not personally implemented any of the services reviewed. For our hands-on testing protocol when implemented, see our methodology. Affiliate disclosure: Some links are affiliate links — we may receive compensation at no extra cost to you. Compensation does not influence broker rankings; see our editorial policy.
FAQ
Is SCS certification mandatory in 2026?
No, SCS is a voluntary program per the official framework published on 2026-03-27. However, large enterprises are increasingly requiring SCS status from their suppliers as a procurement condition. For many mid-sized companies, it is becoming effectively mandatory to maintain client relationships, even though no law requires it.
How does KDDI AccelWaves differ from traditional VPN security?
AccelWaves, per KDDI's 2026-09-29 announcement, is a SASE model that integrates network connectivity with cloud-delivered security. Traditional VPNs connect users to the office network and rely on on-premises security appliances. SASE inspects traffic in the cloud, so security follows the user regardless of location. This is the first AccelWaves service, powered by Palo Alto Networks Prisma Access.
Can Fujitsu MSS help us achieve SCS certification?
Fujitsu MSS provides security operations, log analysis, and AI-assisted reporting per its official product page. These capabilities support the technical controls that SCS ★3 requires, but the certification itself requires a separate expert confirmation process. You would still need to engage an SCS support service for the formal evaluation.
What is the difference between SCS ★3 and ★4?
Per the official framework, ★3 requires expert confirmation of your security measures, while ★4 requires a higher level of independently verified controls. The jump from ★3 to ★4 typically involves more rigorous technical validation and broader organizational coverage. Most companies should target ★3 first, as it is the baseline that clients commonly request.
How long does SCS ★3 certification take?
Based on the support services listed in the MCB catalog, a typical timeline is 3-6 months. This includes a gap analysis, policy documentation, technical implementation, and the expert confirmation. The timeline depends heavily on your starting point and internal resource availability. Companies with existing ISO 27001 certifications often move faster.
Which is cheaper: SCS ★3 or a managed security service?
For a mid-sized company, SCS ★3 is typically cheaper on a project basis. Support services charge a fixed fee for the gap analysis and certification support. Managed security services like Fujitsu MSS or KDDI AccelWaves charge recurring fees for ongoing operations. If your goal is purely to satisfy client requirements, SCS is the lower-cost path. If you also need ongoing security monitoring, MSS adds value beyond certification.
What happens if we do nothing?
Without SCS certification or a credible security posture, you risk losing contracts with large clients that require supplier security assessments. In 2026, this is becoming a competitive disadvantage. The cost of inaction is not regulatory — it is commercial. Clients will simply move to certified competitors.
Sources & Verification
This article was fact-checked on 2026-10-03. Key claims:
- "KDDI announced the AccelWaves initiative on 2026-09-29, starting with a SASE gateway powered by Palo Alto Networks" — verified via https://newsroom.kddi.com/news/detail/kddi_nr-1178_4735.html on 2026-10-03
- "The SCS evaluation system was formally established by METI and the Cabinet Cyber Office on 2026-03-27" — verified via https://www.josis365.com/blog/scs-evaluation-system-guide/ on 2026-10-03
- "Fourteen support services exist for SCS evaluation, covering ★3 and ★4 requirements" — verified via https://catalog.monex.co.jp/article/?p=51116 on 2026-10-03
- "KDDI's SASE gateway service is powered by Prisma Access, combining network and security functions" — verified via https://biz.kddi.com/service/prisma-access/ on 2026-10-03
- "Fujitsu MSS provides log analysis, security personnel, and generative AI for reporting in zero-trust environments" — verified via https://biz.kddi.com/service/mss/ on 2026-10-03
Related articles
DMM FX in 2026: A Guide for Starting with 10,000 Units – Comparison with Low-Minimum Alternatives and Free Account Setup
The latest DMM FX review for 2026. The minimum trade size is 10,000 units for all currency pairs, and for USD/JPY with 25x leverage, the required margin is roughly ¥60,000 (conditions apply). If you want to start with 1,000 units or less, we honestly compare DMM FX with SBI FX Trade and Gaitame.com. This guide helps you decide whether to open a free account.
Japan FX Education Institute FX School Info Session 2026: Comparison and Steps Before Opening a Free Account | Who It's Best For
Latest 2026 guide. The Japan FX Education Institute FX School info session is designed for beginners who want to learn domestic FX while starting with a free account opening. We cover 6 comparison points, user feedback trends, and key cautions. Account opening is free and mostly done online. Since trading costs and currency pairs are not disclosed, check the official website for details.
2026 FXTF Account Opening Guide: How to Choose a Domestic FX Broker for Free
Considering opening an FXTF (Golden Way Japan) account in 2026? Compare spreads, trading tools, and support across three key areas. This guide explains how to open an account for free and evaluate the trading environment using the actual platform.