Active Cyber Defense Act (Act on Preventing Damage from Unauthorized Acts Against Critical Computers)
Creates Japan's active cyber defense framework, requiring designated critical infrastructure operators to report incidents and letting the government acquire and analyze cross-border communications data under review by a new independent oversight commission.
Where it stands
In forceIntroducedCommitteeFloorLawIn forceFurther provisions enter into forceApr 15 months ago
Timeline
Nov 22, 2027 in 1 year
Remaining provisions scheduled to apply on a date set by cabinet order, no later than this date
Oct 1 in 4 days
Incident reporting provisions for designated critical infrastructure operators scheduled to apply
Apr 1 5 months ago
Jul 1, 2025 1 year ago
May 23, 2025 1 year ago
Promulgated as Act No. 42 of 2025, with initial provisions taking effect
Feb 7, 2025 1 year ago