Skip to content

Japan's Government Cloud Shift: Why Sakura Internet's Selection Reset the Sovereign Cloud Map

Japan's Government Cloud (ガバメントクラウド) was certified to AWS, Azure, Google and Oracle before Sakura Internet became the first domestic provider. What the programme is, who qualifies, and what sovereign cloud means in practice.

Japan's Government Cloud Shift: Why Sakura Internet's Selection Reset the Sovereign Cloud Map

For any multinational technology vendor selling into Japan’s public sector, the Digital Agency’s late-2023 decision to certify Sakura Internet as a government cloud provider was a structural event, not a procurement headline. It was the moment Tokyo formally signaled that economic security concerns had overtaken pure cost-and-capability benchmarking in how Japan buys sovereign cloud services, and it reset the competitive map that had been dominated by Amazon Web Services, Microsoft Azure, Google Cloud, and Oracle.

The move reflects a broader policy current running through Japanese government relations: critical digital infrastructure is being reclassified as national infrastructure, with all the industrial-policy implications that entails. Foreign hyperscalers are not being pushed out, but they are being reframed from default suppliers into one option among several.

Context note: This post was written in late 2023, when Sakura Internet’s initial certification was announced and commercial rollout was targeted for the second half of fiscal 2025. The strategic logic below has only intensified under successive administrations.

What the Digital Agency decided

In November 2023, Japan’s Digital Agency selected Osaka-headquartered Sakura Internet as a qualified provider for the government cloud, the shared cloud infrastructure that central ministries and local governments rely on to manage sensitive citizen and administrative data.

Breaking the four-hyperscaler lock

Until that point, the government cloud register had been populated entirely by U.S. cloud majors: AWS, Microsoft Azure, Google Cloud, and Oracle. The Digital Agency had revised its selection framework in September 2023 specifically to allow domestically produced services onto the list, and signaled that bundled bids combining multiple providers could satisfy the full requirement set by the end of fiscal year 2025.

Sakura Internet, founded in 1999 and listed on the Tokyo Stock Exchange prime section, became the first Japanese-headquartered provider to clear that revised bar. Digital Minister Taro Kono captured the political framing directly: “For the first time, the possibility of a domestically produced government cloud has emerged.”

Why this was treated as a milestone

The decision mattered for three reasons that ran well beyond a single contract.

First, it validated that Japan’s economic security agenda, accelerated since the passage of the Economic Security Promotion Act, extends to cloud. Second, it gave Japanese-origin vendors a credible pathway into a market they had been effectively excluded from on capability grounds. Third, it put every incumbent foreign provider on notice that their presence on the register, while still essential, no longer guaranteed default wins.

Why sovereign cloud is now a policy priority in Japan

To understand the Sakura Internet decision, it helps to place it in the broader public policy arc.

Economic security moves from doctrine to procurement

Japan’s economic security framework, developed under Prime Minister Kishida and expanded under successive administrations, treats certain categories (semiconductors, critical minerals, power grids, telecoms, and cloud infrastructure) as strategic. The shift from writing strategy documents to embedding them in procurement rules is the transition that vendors need to track, and the government cloud register is one of the clearest examples.

Local governments are the scale play

Central ministries get the headlines, but the volume lives at the municipal and prefectural level. Japan has more than 1,700 local governments, many of which were being pushed to migrate onto standardized government cloud services under the Digital Agency’s broader local-government digitalization program. Qualifying providers have the chance to become long-term infrastructure partners to tens of millions of citizen records and administrative workflows.

Data sovereignty concerns are not theoretical

Japanese regulators have been increasingly vocal about the risks of storing sensitive citizen data (tax, social security, health, local administrative) on infrastructure controlled by foreign entities subject to foreign legal orders. Sovereign cloud is the technical answer to a political question, and a domestic provider on the register makes that answer easier to defend publicly.

What this meant for foreign providers

Nothing about the Sakura Internet selection removed the incumbent hyperscalers from the Japanese government cloud market. They remained on the register, and many workloads continued to run on their platforms. What changed was the strategic posture required to win and keep that business.

From vendor to partner

Foreign providers that treated Japan as a sales territory with a local language pack found the ground shifting. The vendors that adapted kept their seats at the table: they invested in domestic data centers, formed technology partnerships with Japanese firms, offered localized compliance certifications, and visibly supported Japanese cybersecurity initiatives. Those that did not found procurement conversations becoming harder.

Public affairs became table stakes

Selling sovereign cloud to a Japanese government agency is now a public affairs and government relations exercise as much as a technical sale. That includes engagement with the Digital Agency, METI, the Ministry of Internal Affairs and Communications, and the National Center of Incident Readiness and Strategy for Cybersecurity (NISC). Vendors without a structured stakeholder engagement plan are, in practice, ceding ground.

Lessons for technology public affairs in Japan

The Sakura Internet moment generalizes well beyond cloud. Similar dynamics are playing out in semiconductors, AI infrastructure, and quantum computing.

Track procurement rule changes, not just tenders

The decisive event in the cloud story was the September 2023 revision of the selection framework, not any individual contract award. Public affairs teams that monitor regulatory and procurement rule changes at the source (the Digital Agency, METI, and the Cabinet Office) spot shifts months before they show up as RFPs.

Build coalition credibility, not just bid documents

Japanese agencies increasingly favor providers that can show ecosystem contributions: training local engineers, supporting Japanese startups, co-developing with domestic firms, and engaging with Japan’s standards bodies. This is credibility-building work, not procurement work, and it takes years.

Treat economic security as a design input

For any critical-infrastructure category, foreign vendors should assume the Japanese government will, over time, want a domestic option. Planning for that future (through partnerships, joint ventures, or local entity structures) is more productive than contesting the trend.

Forward look

The Sakura Internet decision was an opening move, not an endpoint. Expect continued expansion of domestically produced options across critical infrastructure, continued tightening of procurement rules that weight economic security, and continued pressure on foreign providers to localize meaningfully. The hyperscalers that thrive in Japan over the next decade will be the ones that stop treating Tokyo as a global region and start treating it as a sovereign market with its own industrial-policy logic.

Why this matters for public affairs in Japan

Sovereign cloud, semiconductors, and AI infrastructure are no longer pure commercial categories in Japan. They are public policy categories with procurement implications. Winning in that environment requires sustained engagement with the Digital Agency, METI, and related ministries, plus credible local partnerships that answer the economic security question before it is asked.

Gemini Group advises global technology companies on government relations, procurement engagement, and economic security positioning across Japan’s regulated sectors. If you are refining your Japan sovereign cloud or digital infrastructure strategy, contact us.

Frequently asked questions

What is Japan's Government Cloud?
The Government Cloud (ガバメントクラウド) is the Digital Agency's shared cloud infrastructure programme for Japanese public bodies. Rather than each ministry and municipality procuring its own systems, providers are certified centrally against a common set of security and operational requirements, and government users build on that certified infrastructure. It underpins the wider standardisation of local government IT systems.
Which cloud providers are certified for Japan's Government Cloud?
The programme initially certified the major American hyperscalers: Amazon Web Services, Microsoft Azure, Google Cloud and Oracle. Sakura Internet was subsequently selected as the first domestic Japanese provider, on a conditional basis requiring it to meet the full requirement set by a target date. That selection is the reason the programme became a sovereignty question rather than purely a procurement one.
Why does a domestic provider matter for government cloud?
Because of jurisdictional reach over data. Where a provider is subject to a foreign legal regime, that government may in principle compel disclosure of data regardless of where it is physically stored, which is uncomfortable for a state hosting its own administrative records. Certifying a domestic provider gives Japan an option outside that exposure. The trade-off is capability: the hyperscalers have a substantial head start in the breadth and maturity of their services.
What is sovereign cloud?
Sovereign cloud describes cloud infrastructure designed so that the data and the operations sit under a single jurisdiction's legal control, typically through domestic ownership, domestic operations staff, and data residency. The term is used loosely by vendors, and the meaningful question is usually narrower: which government could lawfully compel access to this data, and through which entity.
What does this mean for technology vendors selling to Japanese government?
Certification is increasingly the gate. If your product runs on certified infrastructure and meets the Digital Agency's requirements, you are in the procurement conversation; if it does not, individual ministries have progressively less freedom to buy it. That shifts the important engagement earlier, towards the body writing the requirements rather than the ministry issuing the tender.