JC-STAR ★3: New Security Baseline for Connected Devices
What IPA Just Published
On February 6, 2026, Japan’s Information-technology Promotion Agency (IPA) released the ★3 (Level 3) security requirements for two IoT product categories, network devices and network cameras, under the Japan Cyber Security Technical Assessment Requirements labeling scheme, known as JC-STAR. A minor correction to reference links followed on February 12, bringing both documents to version 1.1. For anyone tracking IoT compliance across the region, this is the first real look at what higher-tier JC-STAR conformance will demand for products bound for government and critical-infrastructure procurement.
Why These Two Product Categories Come First
Network devices are the routing and switching equipment that governments and critical infrastructure operators install in secured facilities. Network cameras cover surveillance systems used for perimeter monitoring and remote site oversight. Both categories were prioritized as the first JC-STAR ★3 product types because they’re expected to see the earliest government procurement activity. IPA built both JC-STAR requirement sets around the same threat model, one centered on mid-tier attackers using publicly available tools and known techniques, drawing on real-world incidents like Mirai-style botnet infections, credential-based intrusions, and supply-chain backdoors.
Network Device Security Requirements
The network device document (JST-CR-03-01) lays out 47 individual JC-STAR requirements organized under 21 protection categories. The backbone is familiar territory for anyone who has worked with ETSI EN 303 645 or NISTIR 8425:
- No default or weak passwords, plus brute-force resistance on all authentication mechanisms
- A mandatory, publicly posted vulnerability disclosure policy
- Automatic software updates with integrity and authenticity checks, plus anti-rollback protection
- Secure storage of cryptographic keys, authentication data, and configuration settings
- Encrypted, tamper-protected transmission of sensitive information over the network
- A minimized attack surface, with unused ports, Bluetooth, USB, and debug interfaces disabled
- Secure boot verification for all software loaded at startup
- Tamper-resistant enclosures to deter physical attacks
A few requirements are distinctly router-flavored:
- VPN gateway functions must support multi-factor authentication and restrict which source devices can connect
- Wi-Fi-capable devices must implement IEEE 802.1X device authentication alongside encrypted wireless transport
- Devices with switching or routing functions must identify connected equipment and reject unauthorized connections
Network Camera Security Requirements
The camera document (JST-CR-03-02) mirrors that same JC-STAR 21-category framework but runs to 45 requirements, reshaped around what a camera actually handles. The baseline protections carry over directly from the device requirements:
- No default or weak passwords, plus brute-force resistance
- A vulnerability disclosure policy paired with automatic, verified software updates
- Encrypted transmission and secure storage of sensitive data
- A minimized attack surface, secure boot, and tamper-resistant housing
Where cameras really differ is in what counts as protected information. The following are folded into the same “information assets to protect” list as passwords and encryption keys, meaning the encryption, secure-storage, and secure-deletion rules apply directly to them:
- Video and audio streams, both recorded and live
- AI-generated analytics data, such as loitering duration or equipment temperature readings
- Motion-detection configuration and detection thresholds
- Alert signals and pan-tilt-zoom control commands
Where the Two Documents Diverge
- Access control depth: cameras add a standalone provision (S3.2-27) requiring a user-configurable permission-minimization mechanism, on top of the default least-privilege baseline both documents share
- Reference standards: cameras additionally draw on the domestic RBSS security camera certification standard, which has no equivalent in the network device requirements
- Protected data scope: cameras extend protection obligations to video, audio, and AI-derived analytics, a scope network devices simply don’t need to account for
What’s Still Missing
Both documents represent only one layer of the three-part JC-STAR ★3 conformance package. The detailed conformance requirements (specifying exactly what functionality vendors must implement) and the accompanying evaluation guide (spelling out document review and hands-on testing procedures) have not yet been published and remain under preparation. Until those follow, vendors have the JC-STAR security requirements themselves but not the full checklist an accredited third-party evaluation body will use to certify against them.
Key Takeaways
Clients targeting government or critical-infrastructure procurement in Japan for routers, switches, or network cameras should start gap-assessing against these JC-STAR ★3 requirements now, even though the conformance checklist and evaluation guide aren’t finalized yet.
Source: https://www.ipa.go.jp/en/security/jc-star/tekigou-kizyun-guide/label3/index.html
Not Sure Where to Start?
Request a free initial consultation or product assessment.
Our experts are here to help.
