The Paradox of Japan's Cybersecurity Regulation: The Unauthorized Access Act, the Active Cyber Defense Law, and the RISS Credential

Laws written to prevent cybercrime may, at the same time, narrow the path that produces strong defenders. This article establishes the facts about three institutions — the Unauthorized Computer Access Act, the Active Cyber Defense legislation passed in 2025, and Japan's national Registered Information Security Specialist credential — and then examines the structure that lets "institutional depth" and "operational depth" drift apart.

The Question This Article Asks

Japan's cybersecurity institutions have been built out steadily over the past quarter century. The Unauthorized Computer Access Act of 1999; the Basic Act on Cybersecurity of 2014; the national Registered Information Security Specialist credential (情報処理安全確保支援士, commonly "登録セキスペ" / RISS) launched in 2017; and, in 2025, the legislation commonly called the Active Cyber Defense Law. Counting statutes and responsible agencies, Japan is emphatically not a country that has ignored cybersecurity.

And yet the recurring sentiment among practitioners is that "the institutions have multiplied, but it remains hard to grow — or to hire — engineers who can actually think on the same terrain as the attacker." This article tries to take that sentiment seriously rather than dismissing it as grumbling, and to examine it from the side of institutional design. There is one question:

When you combine a law that criminalizes unauthorized access broadly, a compliance-oriented national certification pipeline, and information asymmetry between executives and engineers, does Japan's private-sector defensive capability end up thinner than the institutional apparatus makes it look?

Let me state the epistemic status up front: this is an analytical hypothesis, not a demonstrated causal relationship. As discussed below, views on it differ within Japan's own security community. This article raises a structural concern for discussion; it does not assert a settled conclusion.

1. What the Unauthorized Computer Access Act Actually Criminalizes

The formal name is the Act on Prohibition of Unauthorized Computer Access (不正アクセス行為の禁止等に関する法律, Act No. 128 of 1999). It was enacted and promulgated in August 1999 and took effect on February 13, 2000. It was then substantially amended in 2012 in response to the spread of phishing, expanding both the set of punishable acts and the statutory penalties.

Article by article, the current law prohibits roughly the following:

  • Article 3 — the act of unauthorized access itself. This covers both the "impersonation" form (entering another person's identification codes — IDs, passwords and the like — without authorization to get past access control) and the "security hole" form (entering information or commands other than identification codes in order to circumvent an access control function). Penalty: up to 3 years' imprisonment or a fine of up to ¥1 million (raised by the 2012 amendment from 1 year / ¥500,000)
  • Article 4 — improperly obtaining another person's identification codes for the purpose of unauthorized access. Up to 1 year / ¥500,000
  • Article 5 — facilitating unauthorized access, i.e. providing another person's identification codes to a third party without legitimate business or other justification
  • Article 6 — improperly retaining another person's identification codes. Added by the 2012 amendment
  • Article 7 — improperly soliciting the input of identification codes, i.e. standing up phishing sites or sending phishing email. Added by the 2012 amendment

The operationally important part is the second limb of Article 3 — the "security hole" form. It does not necessarily require the intuitively obvious wrongdoing of stealing and using someone's credentials. Japanese case law has held that circumventing an access control function so that otherwise-restricted functionality becomes usable can satisfy the elements of the offense even where no password was ever entered. The operative test, in other words, is not "did you break authentication" but "did you get past a state of restriction that the administrator had established."

That structure is a natural consequence of the law's purpose. Access control is not implemented through authentication alone, so a statute that criminalized only authentication bypass would leave the protection full of holes. The problem is that this breadth also overlaps with good-faith vulnerability research.

2. The Gray Zone Around Good-Faith Research: A Recurring International Pattern

A researcher who finds a vulnerability and wants to report it usually needs a minimal proof of concept to show that the vulnerability is real. But that minimal step can, as a matter of statutory text, amount to "circumventing an access control function so that restricted functionality became usable." This is the tension that has arisen between security research and unauthorized-access law all over the world.

The issue is not specific to Japan — if anything it is a pattern that has recurred internationally. The best-documented version is the long-running debate over the United States' Computer Fraud and Abuse Act (CFAA). The CFAA was criticized for years on the grounds that it was difficult to tell which conduct it actually criminalized, and that this very vagueness chilled security research. The turning point was the Supreme Court's decision in Van Buren v. United States (2021), which read the phrase "exceeds authorized access" narrowly and held that merely accessing information for an improper purpose does not violate the CFAA. Then, on May 19, 2022, the U.S. Department of Justice revised its CFAA charging policy to state expressly that it will not charge good-faith security research as a CFAA violation. The same revision also removed, as a matter of policy, charging based on contractual access restrictions such as terms-of-service violations.

The important point is that this was not an amendment to the statute; it was the formalization of prosecutorial policy. Even so, publicly establishing the predictability of "you will not be charged for this" was understood to change researcher behavior. Put the other way round: the absence of publicly established predictability is itself taken to be the principal driver of the chilling effect.

Does Japan Have an Equivalent?

Japan does have a framework for reporting vulnerabilities through a proper channel: the Information Security Early Warning Partnership, established under a METI notice, and its accompanying guideline. Someone who finds a vulnerability in a software product or a web application reports it to IPA; for products, JPCERT/CC asks the developer to verify, and for web applications, IPA notifies the site operator. Reporters are asked to identify themselves by name and contact details.

This needs to be understood precisely, though. The Partnership is a procedure for safely circulating vulnerability information that has already been found; it is not a mechanism that legally immunizes the access performed while finding it. The guideline itself presupposes that the finder's investigation stayed within the law. In other words, an explicit, public safe-harbor declaration along the lines of the U.S. Justice Department's 2022 policy — "good-faith research will not be prosecuted" — does not exist in Japan at the same strength and with the same visibility, as best we can determine at the time of writing.

In practice that difference shows up as an extremely conservative line: do not perform active testing against any system other than your own without permission. Most Japanese-language explainers say exactly that — always obtain the owner's authorization and run it as a penetration test — and they are right to. But the side effect is structural: an independent researcher with nobody to grant them permission has a much narrower place to lawfully build the skill.

How to Treat the Japanese Cases

So is there a well-known Japanese case that can be squarely characterized as "a security researcher prosecuted under the Unauthorized Computer Access Act"? Within the scope of this research, we could not confirm an established, representative case of that shape. That is an important caveat and it is stated here as such.

What does exist in Japan are cases under a different provision that prompted intense discussion of chilling effects within the engineering community — specifically Article 168-2 of the Penal Code (the offense concerning unauthorized commands in electromagnetic records, colloquially the "virus offense"). Two are well known:

  • The Coinhive case. A web designer was charged with retention of an unauthorized command electromagnetic record for placing a cryptocurrency mining script on his own site without visitors' consent. After an acquittal at first instance and a reversal to conviction on appeal, the Supreme Court reversed again and acquitted him on January 20, 2022, the judgment becoming final. The Court reasoned that the impact was not significantly different from that of displaying advertising and fell within the socially acceptable range, so illegality was not established. The defense framed the litigation not as one defendant's fight but as a fight to prevent a chilling effect across Japan's entire technical development community.
  • The "alert loop" case. In March 2019, several people were subjected to search warrants, referral to prosecutors, or juvenile guidance on suspicion of attempted supply of an unauthorized command electromagnetic record, for posting links on an online forum to JavaScript that repeatedly re-displayed a dialog box after being dismissed. The two adults referred to prosecutors were not indicted (suspension of prosecution) in May of the same year. The case was widely criticized as liable to chill the IT industry, and a fundraising effort was organized to support those involved.
A caveat about which statute applies: both cases above arose under Article 168-2 of the Penal Code, and neither is a case under the Unauthorized Computer Access Act, which is this article's subject. They therefore cannot be cited as "examples of the Unauthorized Computer Access Act being used against researchers." What they do support is the more general proposition that in Japan too, uncertainty about the reach of criminal law over technical conduct has lowered predictability for engineers and produced real episodes that made chilling effects a live topic of debate. That distinction is maintained deliberately here.

To summarize: the "chilling effect of the Unauthorized Computer Access Act" in Japan is not an empirically demonstrated phenomenon that can be shown through an accumulated body of case law. It is more accurately treated as a structural concern derived from three things: (a) the breadth of the statutory text, (b) the absence of an explicit safe harbor, and (c) lived experience of chilling effects being debated under adjacent provisions. That is the position this article takes.

3. What the Active Cyber Defense Legislation Actually Authorizes

Next, the largest institutional change on the government side: the 2025 legislation. It is popularly called the "Active Cyber Defense Law" (能動的サイバー防御法), but that is a nickname. It is in fact two statutes:

  • The Act on Prevention of Damage Caused by Unauthorized Acts Against Important Electronic Computers (重要電子計算機に対する不正な行為による被害の防止に関する法律), commonly the "Cyber Response Capability Enhancement Act"
  • The accompanying Act on Arrangement of Related Laws for its implementation

It passed the plenary session of the House of Councillors on May 16, 2025 and was promulgated on May 23, 2025 (Act No. 42 of Reiwa 7). Entry into force is phased; per published summaries, roughly as follows:

  • July 1, 2025 — general provisions and certain articles took effect first
  • April 1, 2026 — provisions establishing the independent oversight body, the Cyber Communications Information Oversight Committee (サイバー通信情報監理委員会)
  • October 1, 2026 — the core of the main body: mandatory reporting of specified intrusion events by designated critical infrastructure operators, provision of consolidated analytical information from government back to operators, and the public-private council framework
  • A date to be set by cabinet order within 2 years and 6 months of promulgation (i.e. by November 22, 2027) — the chapters (Chapters 3 through 7) governing acquisition and handling of communications information

The scheme has four main pillars. (1) Strengthened public-private cooperation (incident reporting by critical infrastructure operators, and threat information flowing back from government to the private sector). (2) Use of communications information (a framework under which the government may, under defined conditions, acquire and analyze information about communications). (3) Access and neutralization measures (the police and the Self-Defense Forces may proactively access servers being used in an attack and neutralize malicious programs). (4) Oversight (prior approval and subsequent supervision by the Cyber Communications Information Oversight Committee).

Put simply, this is legislation that extends the government's cyber capability from passive defense into active intervention. Under Japan's previous legal framework, a government agency reaching into attack infrastructure first had almost no legal basis and was effectively impossible. Filling that gap is the law's primary purpose.

The Issues Raised in the Diet

The bill drew substantial constitutional argument on its way through. The center of gravity was its relationship to Article 21(2) of the Constitution — the secrecy of communications. The Japan Federation of Bar Associations published an opinion on April 17, 2025 calling for careful deliberation, objecting that the provisions on acquiring communications information would operate without judicial warrant review. Where the Communications Interception Act sits inside the warrant requirement, this law conditions acquisition on approval from an administrative body — the Oversight Committee — and opposition members in the Diet argued this amounted to circumventing the warrant principle. Additional debate concerned the relationship to other states' sovereignty when access and neutralization measures reach servers abroad, and whether the Committee's independence would be effective in practice.

These are not this article's subject, so we will not go further into them — with one exception that connects directly to the thread here. Among the arguments raised against the bill was the point that more fundamental cybersecurity capacity-building ought to be prioritized before access and neutralization measures. That objection has exactly the same shape as the question this article is asking.

4. Authority Grew. Did the Number of People Who Can Defend?

Here is the central hypothesis.

What the Active Cyber Defense legislation expanded is the legal authority of government agencies. The police and the Self-Defense Forces now have a basis for acting against attack infrastructure; the government has a framework for analyzing communications information; and there is a channel for information to flow from critical infrastructure operators up to the state. This is a reform that changes the distribution of capability.

But Japan's overall cyber defense is not composed of government agencies. The entities actually attacked are overwhelmingly private companies, and the first to detect, first to triage, and first to contain are private IT departments and security vendors. Imposing a reporting obligation on critical infrastructure operators implies, read in reverse, that the private side is presumed to possess enough detection capability to have something to report.

Authority and talent depth are separate variables. The first can be moved in a single legislative act; the second is a product of education, employment, career paths, and legal predictability. If only the first moves, total defensive capability is redistributed toward government rather than increased in aggregate. That is the first pillar of the hypothesis.

Moreover, for government agencies to actually operate access and neutralization measures, they need people who understand attacker tradecraft from the inside — and the supply of such people is, in the end, the private sector and the research community. If the private layer is thin, the state's new authority is itself constrained by the number of people who can exercise it. Authority and talent are not independent variables; they are wired in series.

5. The Registered Information Security Specialist Credential

So how is Japan's public talent pipeline designed? At its center sits 情報処理安全確保支援士 — the Registered Information Security Specialist, known colloquially as 登録セキスペ. The facts first.

  • The system began in 2017. IPA (the Information-technology Promotion Agency) administers the examination, maintains the register of credential holders, and runs the training. It is a national credential, designed as the first registration-based professional credential in Japan's cybersecurity field
  • The first cohort, registered as of April 1, 2017, numbered 4,172. It was reported at the time that every prefecture had at least one registrant
  • It is registration-based, with protected title use. Passing the exam alone does not entitle you to the title; you must pay a registration license tax (a ¥9,000 revenue stamp) and a registration fee (¥10,700) to be entered on the register
  • Renewal every three years. Registration expires three years from the date of registration or last renewal, and renewal is conditioned on completing prescribed training (online courses plus a practical course) during that period. There is no renewal fee as such, but the training costs money — choosing IPA's practical course, three rounds of online training plus the practical course runs to a figure on the order of ¥140,000 across the three-year cycle
  • As of October 1, 2025, there were 24,937 registrants. The average age is 44.3; 36.9% are in their forties and 25.5% in their fifties — an age profile weighted heavily toward mid-career and above. By region, the Kanto area accounts for 69.2%
  • The system continues to evolve; from April 2026 a training track for those with practical work experience has been introduced

By the numbers, the system works. Registrants have accumulated steadily from 4,172 in 2017 to roughly 25,000 in 2025. The original objective of establishing the credential as a recognized fixture of Japanese professional life has been substantially achieved.

The Structural Question Worth Raising

With that established, what this article wants to raise is not a question about volume but about what kind of capability the design incentivizes.

The RISS examination and training cover information security management, risk assessment, relevant law, secure design and operations, and building incident response structures. This is the body of knowledge required to make security work as an organizational function, and it is designed around people who will architect and supervise a company's security controls. The design is internally coherent with respect to that goal.

There is, however, a second axis of capability that matters at the point where attacks are actually stopped: exploit development, reverse engineering, vulnerability research, red team operations — the kinds of skill where you can reproduce the attacker's reasoning with your own hands. Defense gets sharper the more concretely you know the attacker's procedure. Writing EDR detection logic or designing YARA signatures comes out differently depending on whether you know how evasion actually works in practice.

Internationally, certification ecosystems tend to divide this labor. CISSP, for instance, is a globally recognized credential that systematically covers a broad domain including security management, backed by an experience requirement and maintained through continuing professional education. Certifications like OSCP, which require hands-on penetration testing under examination conditions, put their weight on demonstrating offensive, practical skill. This is not a question of which is better; they measure different things. A mature talent ecosystem has both routes available.

So the question is this. When a credential designed by the state, with training provided by the state and maintained through registration and renewal, sits at the center of the talent pipeline, does that pipeline naturally optimize toward people who can carry compliance and governance? And does the route that builds offensive skill get left outside the institution — while, as Section 2 described, the places to build that skill on a legally safe footing remain limited?

On the intent of this section: the argument here is not that the RISS system is a bad institution. The credential has a clear purpose — raising the professional standing and the supply of people who can run organizational security governance — and against that purpose it works. Nor is there any intent to criticize CISSP or any other credential. What is being raised is a structural question about which kind of capability the institution at the center is designed to incentivize, and the answer is genuinely not obvious. The position that "offensive skill development should be handled not by a certification regime but by other policy instruments — bug bounties, cyber ranges, CTF support, legal safe harbors" is entirely defensible. In fact, opinion among Japanese security practitioners is divided on exactly this point.

6. Information Asymmetry Between Executives and Engineers

The third element is not in the law but inside organizations. It is not specific to Japan — it is a well-known pattern in organizational behavior — but interlocking with the first two amplifies its effect.

Security work has an intrinsic evaluation problem: when it is going well, nothing happens. When the return on investment manifests as "an incident that did not occur" — something unobservable — an evaluator who does not understand the technical substance cannot assess the outcome directly.

What the evaluator can use instead are proxy signals:

  • Headcount on the security team
  • The type and number of certifications held
  • Whether certifications such as ISMS have been obtained, and the number of audit findings
  • The number of security products deployed
  • The state of documentation — policies, standards, procedures

Every one of these is observable, easy to put in a slide deck, and comparable year over year. That is precisely why they get chosen. The problem is that they correlate with real defensive capability without being identical to it. Whether an organization with ten certification holders or one with two engineers who track current attacker tradecraft is more likely to actually stop an intrusion is not something the proxies can tell you.

Two side effects follow.

First, translation labor becomes permanent. Engineers must translate the value of their work into non-technical vocabulary and re-explain it at every budget cycle. This translation cost adds nothing to technical output, but it reliably consumes engineering time. The "overhead" of security work swells in this layer of translation and re-justification.

Second, the organization optimizes for the proxy. Once it becomes clear that evaluation runs on proxy signals, organizations choose the actions that improve those signals. Adding three certification holders is easier to explain to an evaluator than spending three months researching attack techniques. This is not individual laziness; it is a rational response to the evaluation function.

And this is where it connects back to Section 5. When a national credential — clear, countable — is established as an institution, it becomes an exceptionally convenient metric for a non-technical evaluator. "We employ N registered specialists" fits in an approval document. "Our engineers keep up with current loader obfuscation techniques" does not. The result is a force pulling organizational investment toward whatever proxy the institution supplies — independently of what the institution's designers intended. The evaluation structure does that on its own.

This dynamic is not unrelated to the structure of Japan's IT industry. In a structure where multi-tier subcontracting and man-month billing have made "effort" the unit of value, the habit of estimating by headcount and credentials rather than capability is already built in. We cover that in detail in our article on Japan's SI industry structure.

7. Synthesis: When Three Forces Point the Same Way

Lining up the three elements:

  • (a) Broad criminalization of unauthorized access with no explicit safe harbor — the places where offensive skill can be built on a legally safe footing are effectively limited to authorized, contracted penetration testing. That entrance is open only to people who already have an employer willing to grant permission
  • (b) A compliance-oriented national certification pipeline — the route that is publicly recognized, countable, and connected to a career is optimized for governance and control capability
  • (c) Information asymmetry on the management side — evaluation runs on proxy signals, (b) serves as that proxy, and the overhead of translation and re-justification grows

Individually, each of these is a reasonable piece of institutional design. But they point the same way. All three push toward increasing capability that is visible, countable, and explainable, and none of them pushes toward increasing capability to reason on the same terrain as an attacker. And (a) attaches legal risk to the route by which someone might acquire that capability on their own.

The hypothesis that follows is this: Japan's private-sector cyber defense capability may be thinner than one would infer from the state of its statutes and the size of its certification register. And this coincides with a period of rising threat from state-sponsored actors and organized criminal groups.

In that context, the Active Cyber Defense legislation can be read as a measure that raises government-side capability sharply through law. That is a rational choice. But if the hypothesis above is even partly right, expanding state authority alone does not close the aggregate gap. If the private layer stays thin while state authority grows, the people available to implement that authority become the bottleneck — and the capability to detect and contain first, in the private sector, still needs to be provided for separately.

A caveat about what this article is: the foregoing is an analytical hypothesis, not a demonstrated causal relationship. The subject is multi-causal, and assessments differ among Japanese security practitioners. Positions such as "the chilling effect of the law is barely an issue in practice," "the RISS credential functions appropriately for its purpose, and offensive skill development is properly the job of other policy instruments," and "the main cause of the talent shortage is compensation levels and employment practices, not the legal framework" are all seriously argued. Even the frequently cited estimate from a METI-commissioned study — a shortfall of roughly 193,000 information security personnel as of 2020 — is a figure whose methodology and definition of "personnel" are themselves debated. This article does not present any particular position as settled fact; it organizes the issues through the lens of institutional design and incentive structure, to provide material for discussion. Where a legal judgment is required, always consult the primary text of the statute and qualified professional advice.

8. Directions That Could Move the Structure

Supposing the framing above has some validity, which variables are movable? Without asserting conclusions, here are the responses that follow logically.

  • Making predictability explicit. As the U.S. Justice Department's 2022 policy showed, predictability for researchers can change without amending a statute — simply by publicly formalizing charging and enforcement policy. There would be value in Japan publicly clarifying how far good-faith vulnerability investigation is safe, and where it stops being so
  • Expanding lawful practice environments. Places to build offensive skill without legal risk — official bug bounties, cyber ranges, CTFs, more companies publishing vulnerability disclosure policies — directly relieve the bottleneck at (a)
  • Building vocabulary for evaluation. Executives fall back on proxy signals partly because there is no shared vocabulary for discussing capability. Folding operational measures of detection and response performance (MTTD/MTTR, threat hunting results, exercise outcomes) into the standard vocabulary of board reporting would reduce the distortion at (c)
  • Making the pipeline multi-track. Keep the national credential at the center, but place an official route for evaluating and recognizing offensive skill alongside it. If both are publicly recognized, the one-directional pull of (b) is eased

None of these can be settled here. But it does seem possible to observe, from the structure alone, that there is territory the two familiar axes — "strengthen the regulation" and "increase the number of credential holders" — do not reach.

Summary

  • The Unauthorized Computer Access Act (Act No. 128 of 1999; enacted 1999, in force February 2000; amended in 2012 to expand punishable conduct and penalties) prohibits under Article 3 not only impersonation using another's credentials but also security-hole-style access that bypasses authentication entirely
  • That breadth follows naturally from the law's purpose, but it can overlap with good-faith proof of a vulnerability. The same tension was debated for years around the U.S. CFAA, and Van Buren (2021) plus the DOJ's 2022 charging policy revision publicly established the predictability that good-faith research will not be prosecuted
  • Japan has the Information Security Early Warning Partnership as a reporting framework, but it is a procedure for circulating information, not a legal immunity. No equivalent explicit safe-harbor declaration could be confirmed as of this writing
  • Within the scope of this research, no established representative Japanese case of "a researcher prosecuted under the Unauthorized Computer Access Act" could be confirmed. The Coinhive case (final acquittal at the Supreme Court in 2022) and the alert loop case (2019, no indictment) both arose under Article 168-2 of the Penal Code — a different provision
  • The Active Cyber Defense legislation consists of the Cyber Response Capability Enhancement Act and its accompanying arrangement act, passed May 16, 2025 and promulgated May 23, 2025 (Act No. 42 of Reiwa 7). The core of the main body takes effect October 1, 2026, with the communications-information chapters to follow on a cabinet-order date no later than November 22, 2027
  • Its pillars are mandatory reporting by critical infrastructure operators, use of communications information, access and neutralization measures by the police and Self-Defense Forces, and oversight by the Cyber Communications Information Oversight Committee. Diet debate centered on Article 21(2) of the Constitution (secrecy of communications) and the warrant principle
  • The Registered Information Security Specialist credential began in 2017, growing from an initial 4,172 registrants to 24,937 as of October 1, 2025 (average age 44.3). It requires renewal and training every three years
  • This article's hypothesis is that (a) broad criminalization without an explicit safe harbor, (b) a governance-oriented credential pipeline, and (c) proxy-signal dependence driven by management-side information asymmetry all push in the same direction, potentially leaving private-sector operational defense thinner than the institutional apparatus suggests
  • This is not a demonstrated causal relationship. It is a live policy question on which Japanese security practitioners themselves disagree

Read It From Another Angle: Japan's Industry Structure

The "measure value by effort and headcount" structure touched on in Section 6 is tied to the design of Japan's software development industry itself. We break it down along four axes: contract law, the billing unit, market structure, and development methodology.

Read Japan's SI Industry Structure