Japan's Ministry of Economy, Trade and Industry (METI) is establishing a Cybersecurity Measures Evaluation System for Strengthening Supply Chains, operated with the Information-technology Promotion Agency (IPA). The system sets out the cybersecurity measures each company in a supply chain should meet in proportion to its importance, and makes that posture visible through a star-rating certification mark. It is built on the NIST Cybersecurity Framework 2.0 and harmonized with schemes such as the United Kingodm's Cyber Essentials and the ISMS conformity assessment.
The system applies to every company in a business, IT, or service supply chain, and is described as especially valuable for small- and medium-sized enterprises. It is market-driven rather than a statutory penalty regime, so the cost of not meeting a required rating is commercial: lost or restricted business, competitive disadvantage, and greater exposure to the supply chain incidents the system is designed to prevent. Because those incidents so often hinge on stolen credentials, overprivileged access, and unmonitored privileged sessions across connected systems, privileged access management (PAM) is central to meeting the system's access control requirements.

PAM Maturity Model eBook
Explore the stages of PAM maturity and how your organization can progress to the highest level of privileged access security.

PAM Buyer’s Guide eBook
Get expert advice on selecting the right PAM solution for your organization, with key considerations and feature comparisons.

Cost of a PAM implementation
A true cost assessment of PAM implementation must factor in hidden expenses, from infrastructure and maintenance to integration and ongoing management.
Disclaimer: The complete implementation of the NIS2 Directive requires a variety of process, policy, people, and technology controls.The solutions mentioned above are some of the ways in which privileged access management controls help with the NIS2 Directive requirements. Coupled with other appropriate solutions, processes, people controls, and policies, ManageEngine's PAM solutions can help organizations align with the NIS2 Directive. This material is provided for informational purposes only, and should not be considered as legal advice for the NIS2 Directive compliance. ManageEngine makes no warranties, express, implied, or statutory, as to the information in this material. Please contact your legal advisor to learn how the NIS2 Directive impacts your organization and what you need to do to comply with the NIS2 Directive.