What Was NISC? Japan's Cybersecurity Center and Its NCO Successor
NISC was Japan's national cybersecurity center until 1 July 2025, when it was reorganised into the National Cyber Office (NCO). What NISC was, what the acronym meant, and what changed when the NCO replaced it.
Update: NISC no longer exists under that name. On 1 July 2025 it was reorganised into the National Cyber Office (国家サイバー統括室, NCO), following the Cyber Response Capacity Strengthening Act enacted on 16 May 2025. The NCO sits in the same place, inside the Cabinet Secretariat, and inherits NISC’s functions with broader authority. This article covers both: what NISC was, and what the NCO changed.
NISC was Japan’s national cybersecurity center, sitting inside the Cabinet Secretariat (内閣官房) rather than in any ministry. It set national strategy, coordinated incident response across government, and issued the guidance that critical infrastructure operators were expected to follow. Those functions now belong to the NCO.
The acronym is worth explaining, because it trips up anyone reading older material. By the end NISC stood for the National center of Incident readiness and Strategy for Cybersecurity (内閣サイバーセキュリティセンター). It originally stood for the National Information Security Center, and when the body was restructured in 2015 under the Basic Act on Cybersecurity the letters were kept while the words behind them changed.
Its placement mattered more than its name, and that has carried over. Cybersecurity in Japan is split across METI for industry, MIC for telecommunications, the National Police Agency for crime and the Ministry of Defense for national security. Housing the central body in the Cabinet Secretariat puts it above that split rather than inside it. What changed in 2025 is the strength of the hand: NISC could coordinate but not direct, which is precisely the limitation the NCO was created to address.
Japan’s cybersecurity posture went through the biggest structural overhaul in two decades, and NISC was at the centre of it until that overhaul replaced it. For foreign and multinational firms operating in Japan, particularly in critical infrastructure, telecommunications, finance, healthcare, and defense-adjacent sectors, NISC’s evolution from a coordinating body into a more operational cyber command is reshaping compliance expectations, incident reporting obligations, and government relations requirements. Companies that treat cybersecurity in Japan as a purely technical matter are underestimating both the risk and the policy opportunity.
What the National Cyber Office (NCO) changed
The reorganisation on 1 July 2025 was not a rebrand. Three things changed in substance.
Authority. NISC could coordinate but not direct. It convened, advised and published, and when ministries disagreed it had no means of settling the question. The Cyber Response Capacity Strengthening Act gave the successor body a stronger hand, which is the whole reason the restructuring happened rather than simply expanding NISC’s headcount.
Seniority. The reform created the post of Cabinet Cyber Officer (内閣サイバー官) at vice-ministerial level. In Japanese government, where a function sits in the hierarchy determines which meetings it attends and whose objections it can overcome. Elevating the role changes what the office can actually accomplish more than any change to its written remit would.
Mission. NISC was built around incident readiness, meaning preparation and response. The NCO exists in a policy environment that has committed to active cyber defense (能動的サイバー防御), which contemplates detecting and disrupting hostile activity before damage occurs. That is a different job requiring different legal authority, and it is why the enabling legislation and the new organisation arrived together.
What did not change is placement. The NCO remains within the Cabinet Secretariat, above the ministerial split rather than inside it, and it still works through strategy, standards and guidance rather than licensing or fines.
For companies, the practical implication is that the central body is now more likely to set expectations that reach you, and to do so faster. Guidance that would previously have taken time to filter through sector regulators now originates from an office with more weight behind it.
NISC’s mandate
NISC stands for the National center of Incident readiness and Strategy for Cybersecurity (formerly the National Information Security Center). It was established in 2005 and reorganised under the Cabinet Cybersecurity Strategy Headquarters following the 2014 Basic Act on Cybersecurity. NISC operates within the Cabinet Secretariat, reporting ultimately to the Prime Minister through the Chief Cabinet Secretary.
Its statutory role is to formulate and coordinate national cybersecurity strategy, drive implementation across government, protect critical information infrastructure, and coordinate response to significant cyber incidents. Crucially, NISC’s role is policy and coordination, not direct operational cyber defense in the way that, say, US Cyber Command operates. That division is now being re-examined.
Structure and reporting lines
Cabinet Cybersecurity Strategy Headquarters
NISC serves as the secretariat to the Cybersecurity Strategy Headquarters, chaired by the Chief Cabinet Secretary and including the Ministers in Charge of Cybersecurity, Digital Transformation, and other relevant portfolios. Strategic direction flows from this body.
Inter-ministry coordination
NISC coordinates across METI (industrial cyber policy, IPA), MIC (telecom security), MOD (defense cyber), MOFA (international cyber diplomacy), MOJ/NPA (law enforcement), FSA (financial sector cyber), and sector regulators overseeing critical information infrastructure. This is one of the most multi-ministerial operating environments in Tokyo, which is why NISC engagement cannot be siloed.
Planned reorganisation
The government has announced plans to establish a new unified cyber agency that would elevate NISC’s successor body and give it expanded operational authority, including under the forthcoming Active Cyber Defense (ACD) legal framework. The ACD legislation and the agency restructuring are landmark developments that foreign companies should track closely.
Key policies and initiatives
The Cybersecurity Strategy
NISC drives the National Cybersecurity Strategy, the master policy document that sets Japan’s cyber priorities. The current strategy emphasises free, fair, and secure cyberspace, public-private partnership, international cooperation, and resilience of critical infrastructure.
Critical Information Infrastructure (CII) protection
Japan designates 14 CII sectors (including information and communications, finance, aviation, airports, railways, electricity, gas, government services, medical, water, logistics, chemicals, credit, and petroleum) and expects operators to meet baseline cybersecurity standards. NISC issues Safety Guidelines for CII and coordinates with sector-specific regulators on enforcement.
Active Cyber Defense
The most significant legal development is the Active Cyber Defense (ACD) framework, which will authorize the government to monitor certain communications, identify attack infrastructure, and take proactive measures against hostile cyber actors, within a defined legal framework and with independent oversight. This represents a meaningful expansion of Japanese state cyber capability and will shape public-private information sharing and obligations on telecom carriers and platform operators.
Government system cybersecurity
NISC sets Common Standards for Information Security Measures for Government Agencies, and audits government systems. Procurement of technology by the government is subject to these standards, which is directly relevant for IT vendors.
Economic Security and cyber supply chain
The Economic Security Promotion Act and its critical infrastructure review mechanism intersect with NISC’s work on supply chain cybersecurity. Foreign vendors of critical equipment and software should expect security review obligations.
How NISC interacts with other stakeholders
NISC works closely with METI (via IPA and JPCERT/CC), MIC and the telecom sector, the FSA and financial sector ISACs, and industry bodies such as J-CSIP and the Cyber Defense Council. Internationally, NISC coordinates with CISA (US), NCSC (UK), ANSSI (France), BSI (Germany), ENISA, and participates in multilateral fora including the Quad and the G7 Ise-Shima Cyber Group.
The Information-technology Promotion Agency (IPA), which also houses the AI Safety Institute, provides significant technical capacity for NISC’s work, including vulnerability coordination and the IPA Security Center.
Implications for companies
Mandatory incident reporting is expanding
Under sector-specific laws and the evolving CII framework, mandatory cyber incident reporting obligations are expanding. The Personal Information Protection Act, the Telecommunications Business Act, and financial regulations all require notification within defined windows. Foreign firms need a Japan-specific incident response plan that maps notification obligations by regulator.
Government procurement is scrutiny-heavy
Vendors selling into government systems must meet NISC’s security standards, increasingly including supply chain security and economic-security-linked obligations. Foreign firms should prepare for documentation-heavy procurement and potential exclusion of equipment from designated risk categories.
Active Cyber Defense reshapes the telecom and platform operating environment
Once ACD legislation is in force, telecom carriers, platform operators, and security vendors will be part of an expanded information-sharing and response ecosystem. Companies in this space should engage early on the implementing regulations.
CII operators face rising expectations
Operators in designated CII sectors face rising baseline security expectations, audit obligations, and potential business improvement orders after incidents. Board-level cyber governance is effectively a regulatory expectation.
Cybersecurity is a public affairs issue, not just an IT issue
NISC, METI, MIC, and the FSA all shape binding expectations. Engagement with policy-setting processes, industry associations, and advisory panels is how companies influence how rules are written.
Why this matters for public affairs in Japan
Japan’s cyber regime is moving from principles to enforcement, and from coordination to active defense. Companies that engage NISC and the broader cyber policy network early will shape workable compliance obligations and access to government-led information sharing. Companies that wait will find themselves absorbing whatever the final rules impose.
Gemini Group supports multinationals on Japan cybersecurity policy, NISC and ministry engagement, Active Cyber Defense legislative monitoring, and incident response stakeholder management. Contact us to discuss your Japan cyber public affairs strategy.
Frequently asked questions
- Does NISC still exist?
- No. NISC was reorganised into the National Cyber Office (国家サイバー統括室, NCO) on 1 July 2025, roughly twenty years after the original body was created. The change followed the Cyber Response Capacity Strengthening Act and its related legislation, enacted on 16 May 2025. The NCO remains within the Cabinet Secretariat and inherits NISC's coordinating role, with expanded authority and a new vice-ministerial post, the Cabinet Cyber Officer.
- What was NISC?
- NISC was Japan's national cybersecurity body, housed within the Cabinet Secretariat rather than in a line ministry. It set national cybersecurity strategy, coordinated incident response across government, issued guidance to critical infrastructure operators, and served as the government's central point of contact with international counterparts on cyber matters. Those functions now sit with the NCO.
- What did NISC stand for?
- At the end it stood for the National center of Incident readiness and Strategy for Cybersecurity (内閣サイバーセキュリティセンター). The acronym was a legacy: it originally stood for the National Information Security Center, and when the organisation was restructured in 2015 under the Basic Act on Cybersecurity the letters were kept while the words behind them changed. This is why sources disagree about what NISC stood for, and why a good deal of material still refers to NISC rather than the NCO.
- Why was NISC replaced by the NCO?
- Because its powers had not kept pace with its remit. NISC could coordinate but not direct, and Japan's move towards active cyber defense required an organisation able to act rather than convene. The 2025 legislation created that capacity and the NCO to exercise it, alongside a Cabinet Cyber Officer at vice-ministerial level giving the function more weight inside government than a centre director had.
- What is active cyber defense in Japan?
- Active cyber defense (能動的サイバー防御) is the shift from responding to intrusions after the fact towards detecting and disrupting threats before they cause damage, including access to communications data and the ability to neutralise hostile infrastructure. The enabling legislation passed on 16 May 2025 after prolonged debate, because it sits in tension with the constitutional protection on secrecy of communications. It is the largest change to Japanese cybersecurity policy in two decades, and the reason the institutional structure changed with it.
- Did NISC regulate private companies?
- Not directly, and neither does the NCO in the sense of licensing or fining. The instruments are strategy, standards and guidance, and binding obligations generally reach companies through sector regulators applying those expectations, or through the Economic Security Promotion Act for designated critical infrastructure. The practical effect is unchanged: the central body shapes what your sector regulator will eventually require, which makes it worth watching earlier than its formal powers suggest.