Japan FSA adopts unified cyberattack reporting forms across financial-sector supervision rules

Japan
Sep 18, 20261 sources
  • 01The FSA will apply standardized cyberattack incident-reporting forms across the financial sector from October 1, 2026.
  • 02Crypto-asset exchange service providers and crypto-asset service intermediaries are among the firms moving to the new reporting forms.
  • 03The standardized forms cover DDoS attacks, ransomware, and a new category for other cyberattacks or cyber-related incidents.
  • 04Affected firms should update incident-response procedures and reporting templates to use the common forms and the FSA’s supplemental instructions.

Japan’s Financial Services Agency (FSA) has finalized amendments to its supervisory guidelines and administrative guidance that replace sector-specific cyber incident reporting forms with government-wide common forms. The amendments take effect on October 1, 2026.

The change implements a September 15, 2026 revision to an interagency arrangement on reporting damage from cyberattacks. Its purpose is to align reports made to financial supervisors with standardized forms used across relevant government bodies.

The common forms now cover three categories: distributed denial-of-service (DDoS) attacks, ransomware incidents, and other cyberattacks or cyber-related incidents. The new third category expands the standardized framework beyond the previously established DDoS and ransomware forms.

The changes apply broadly across regulated financial businesses, including major banks, regional and smaller financial institutions, insurers, financial instruments business operators, money lenders, fund transfer providers, prepaid payment instrument issuers, crypto-asset exchange service providers, electronic payment instrument transaction businesses, and crypto-asset and electronic payment service intermediaries. They also cover clearing and settlement institutions and certain cooperative financial institutions.

For crypto-asset businesses, the amendments update the FSA’s administrative guidance for crypto-asset exchange service providers and for crypto-asset and electronic payment instrument service intermediaries. When these firms recognize a system failure or cybersecurity incident requiring a report to the supervisory authority, they will transition to the interagency common forms. The FSA has also published supplemental material on using the forms, including a mapping between old and new reporting fields.

The FSA received seven comments directly related to the proposal during the public-comment period, which ran from August 7 to September 7, 2026, and published its responses alongside the final amendments.

Sources (1)

fsa.go.jpSep 18, 2026

Japan FSA adopts unified cyberattack reporting forms across financial-sector supervision rules