Japan's Ministry of Internal Affairs and Communications (MIC) promulgated Ministerial Ordinance No. 111 of Reiwa 8 (令和8年総務省令第111号) on September 24, 2026, partially amending the Terminal Equipment Regulations (端末設備等規則) under the Radio Act framework. The ordinance takes effect on April 1, 2027, giving manufacturers and importers a defined window to bring connected products into line.
The amendment tightens Japan's mandatory IoT-security baseline for terminal equipment that connects to public networks. It prohibits guessable identification codes (推測識別符号), meaning default or weak credentials, requires software-update capability (ソフトウェアの更新) for regulated devices, and brings terminal equipment with an internet-connection function (インターネット接続機能) expressly within the technical-conditions scope. The official ordinance text was published by MIC on September 24, 2026.
Who must comply with the amended baseline, and by when?
The rules bind any manufacturer or importer placing terminal equipment on the Japanese market, plus the Registered Certification Bodies (RCBs) such as TELEC and JATE that issue the conformity certification those products need. The exposed audience is broad: Japanese equipment makers including NEC, Panasonic, Fujitsu and Sharp, global vendors selling into Japan such as Cisco, TP-Link, Netgear, D-Link and Huawei, and the test labs that support them. Products in scope include routers, IP cameras and any internet-connected device that attaches to a Japanese public telecommunications network.
Compliance is required from the effective date, April 1, 2027. Review the ordinance's supplementary provisions for any transitional relief on existing certifications, because recertification timing will turn on them.
What the ordinance changes for connected terminal equipment
Three changes drive the recertification wave. First, the prohibition on guessable identification codes (推測識別符号) bars default and easily guessable passwords and similar credentials, forcing a reset on shipped devices rather than merely recommending one. Second, the software-update mandate (ソフトウェアの更新) requires regulated terminal equipment to support updates over its service life, aligning Japan with the direction taken by the EU Cyber Resilience Act and the UK Product Security and Telecommunications Infrastructure (PSTI) regime. Third, the express coverage of internet-connection-function (インターネット接続機能) terminal equipment widens the set of devices caught by the security conditions.
Read together, the three moves convert what was a 2020 access-control baseline into a harder, product-lifecycle security floor. The changes track the tightening MIC signaled for 2026 following NICT NOTICE vulnerability surveys, which found widespread default-credential exposure across consumer IoT in Japan.
How the new rules build on the existing Article 34-10 regime
Japan has regulated IoT-terminal security since April 2020 through Article 34-10 of the Terminal Equipment Ordinance, which already required access control, a forced change of default credentials and firmware-update capability for directly connected terminal equipment. Ordinance No. 111 hardens that regime rather than replacing it, and runs alongside the voluntary JC-STAR security-labeling scheme operated by METI and the IPA, open since March 2025.
| Obligation | Article 34-10 baseline, from April 2020 | Under Ordinance No. 111, from April 1, 2027 |
|---|---|---|
| Default credentials | Forced change of defaults required | Guessable identification codes prohibited outright |
| Software updates | Firmware-update capability expected | Software-update capability expressly mandated |
| Scope of equipment | Terminal equipment directly connected to public networks | Expressly includes internet-connection-function equipment |
What manufacturers and importers should do before April 2027
Audit current product lines against the three amended conditions, prioritizing any device that still ships with a default password. Build or verify the software-update mechanism and its support window. Engage an RCB early, because recertification queues will tighten as the 2027 deadline approaches. Update technical documentation and conformity filings to reflect the amended conditions, and align import records so the customs Giteki check at the border does not catch a stale certification.
Verify which of your products fall under the internet-connection-function scope, confirm the April 1, 2027 deadline against your certification expiry dates, and brief your regulatory-affairs and firmware teams now. Obsidian's continuous, per-jurisdiction real-time monitoring surfaces this kind of change the moment it publishes, which matters when one MIC ordinance can reset a product family's certification basis overnight.


