Japan Is Narrowing Investment Screening for Software. The Test Now Turns on Product Design

Introduction
Since 2019, Japan's Foreign Exchange and Foreign Trade Act (外国為替及び外国貿易法, Gaikoku Kawase oyobi Gaikoku Bōeki-hō, "FEFTA") has designated most software and information processing businesses, by industry classification, as sectors subject to investment screening. Today, a foreign investor acquiring shares in such a company, at any level for an unlisted company or 1% or more for a listed one, must file a prior notification and wait before closing, or qualify for an exemption and report afterwards.
In acquisitions we have worked on, this rule has delayed the closing of deals for software companies and startups whose business had nothing to do with national security. We have long seen this as a problem, and we welcome the reform's narrower focus on software that raises real security questions.
The broad designation ends for investments made on or after 3 February 2027. On 16 September 2026, Japan promulgated the Cabinet Order and related rules that implement the FEFTA amendment of June 2026. According to the Ministry of Finance announcement, the new rules come into force on 4 January 2027 and become fully applicable on 3 February 2027. Among them is a rewrite of how software is designated. The broad categories are removed, and a defined list of software and services takes their place.
Our earlier article covered the parts of the 2026 amendment that tighten the regime, such as indirect acquisitions and risk mitigation. This article covers the software change, which narrows the regime, and what it means for foreign investors in Japanese tech companies.
Why the software designation is being narrowed
FEFTA screening works by sector. Foreign investors acquiring shares in a Japanese company that operates in a designated business sector must notify the Minister of Finance and the minister responsible for the business, and in principle may not close for 30 days after the notification is accepted (FEFTA Article 27(2)). The authorities can shorten that period, or extend it to four or five months for cases that need full review.
Cybersecurity-related sectors, including software and information processing services, were added to the designated list in 2019. The Ministry of Finance's FY2025 annual report records 3,401 prior notifications in FY2025. Counted by business sector, with a notification for a company active in several sectors counted in each, cybersecurity-related sectors (data processing and information services, software services, integrated circuits, semiconductor memory media and others) accounted for 55%.
The same report states that, in light of the recent increase in prior notifications, the government intends to optimise the scope of sectors subject to prior notification so that it reflects the level of risk. One of the two planned revisions it names is to limit the information and communications technology designation "to activities for which designation is genuinely necessary from the perspective of cybersecurity and other national security considerations." The stated aim is more efficient screening and the promotion of sound investment.
What changes
According to the Ministry's summary of the reforms, the prior notification requirement for "software services sectors" will be narrowed. For core sectors, the requirement will in principle be maintained. For non-core sectors, it will be limited to a defined set of services, including software related to critical infrastructure and to the essential goods defined under the Economic Security Promotion Act, and software that deals with large volumes of personal data or with technological information managed as trade secrets.
The amended Public Notice removes the general designation of contract software development, embedded software, packaged software and information processing services. In its place, it lists specific activities. The main entries are:
- cybersecurity services, such as monitoring, vulnerability assessment and forensics
- software specially designed for critical infrastructure, including electricity, gas, water, telecommunications and railways
- holding technologies used for cloud services, namely virtualisation, cryptographic key generation and management, and authentication and access control
- programs specially designed to handle non-public technical information managed as trade secrets
- programs specially designed to handle the personal information of one million people or more
- holding artificial intelligence-related technologies
- certain systems for government agencies, and systems handling geospatial information that the business collects itself
The reform also adds some sectors elsewhere, such as manufacturing related to magnetic sensors and ship hulls. The Ministry's summary notes that these additions are not expected to materially affect the number of prior notifications.
The test moves from industry code to product design
Several of the new entries ask what a product was "specially designed" to do. The authorities' answers to public comments, published with the final rules, apply that test to concrete cases.
On personal data, a business that designs software or a service on the assumption that it will not handle the personal information of a million people does not fall under the entry, even if the product is technically capable of doing so. On trade secrets, the question is whether the provider designed the software to handle non-public technical information. If a provider builds in features for managing trade secrets, the entry applies regardless of how customers actually use the product.
The cloud and AI entries turn on holding technology. Merely using virtualisation or authentication technology for a cloud service does not count, while developing it, or aiming to hold it, does. A business offering AI services in partnership with a generative AI provider does not fall under the cloud entry for that reason alone. Under the AI entry, a program that lets others use AI technology the business did not develop itself, such as a user interface that calls a third party's model, is in principle not covered. The entry does cover programs that directly affect and enhance a model's output, and the authorities give retrieval-augmented generation (RAG) as an example.
Under the current rules, the target's industry classification largely answers the question. From February 2027, the answer depends on the architecture and the roadmap of the target's product, and two Japanese SaaS companies with the same industry code can come out differently.
The roadmap also matters after closing. The authorities state that when a company's plan to handle the personal information of a million people becomes concrete, the foreign investor should file a prior notification for consenting to the change in the company's business purpose. A product decision taken after the original investment can therefore trigger a filing.
A regime split by investor type
Sector designation applies to an investment whoever the investor is. Several of the other 2026 reforms, by contrast, treat investors differently depending on whether they can use the prior notification exemption scheme.
For investors who can use the scheme:
- consenting to the reappointment of a director first appointed after a prior notification in principle no longer needs a new notification, as long as there are no material changes such as the director's nationality
- the new rules on indirect acquisitions, where control of a foreign holding company with Japanese shareholdings changes hands, require notification only if the acquisition results in holding 50% or more of the Japanese company, and certain intra-group transactions are excluded
For investors who cannot use the scheme, such as foreign governments and state-owned enterprises, the reappointment relief does not apply. For indirect acquisitions, their notification threshold is 1% of a listed company, with no threshold for an unlisted one. In non-designated sectors, where such an investor acquires 10% or more and changes in international circumstances or other developments make it particularly necessary, the authorities may request reports for up to five years after the investment, and may recommend, and then order, the disposal of the shares. This measure applies to investments made on or after 4 January 2027.
Some procedural changes apply to everyone. Information that the authorities used to request by questionnaire during review, covering the investor, the target, the investor's shareholders and its ultimate parent, becomes a required attachment to the notification. Risk mitigation measures become a formal part of the notification, and once notified, changing them generally requires a further notification and review.
Which rules apply to your deal
For the designated sector changes, the dividing line is the date the investment is made. For a share purchase, that is the date the shares are acquired, which in a typical deal is closing rather than signing. Deals closed before 3 February 2027 remain under the current rules, including the broad software designation, and deals closed on or after that date are assessed under the new list.
For deals now in negotiation, a transaction signed this year that closes on or after 3 February 2027 may not need the filing that the current rules require, or may need a different one. Whether the target falls on the list should be assessed under the new Public Notice, and the closing date fixed with that date in mind.
When to get advice
Products that sit near one of the new entries need a closer look, for example:
- a SaaS product designed, or being redesigned, to handle the personal information of a million people or more
- a product with features for managing non-public technical information that customers hold as trade secrets
- an AI company that builds tools to enhance model output, compared with one that offers an interface to another provider's model
Failing to file a required prior notification can lead to criminal penalties under FEFTA, and the Ministry reports finding 580 cases in FY2025 where a required prior notification or report had not been filed.
This article is general information, not legal advice. If you are assessing whether a Japanese investment needs a FEFTA filing under the new rules, or need a filing prepared and submitted on your behalf as your agent, get in touch.