Key Points of This Article
On August 7, the Financial Services Agency (FSA) announced a partial amendment proposal to the "Comprehensive Supervisory Guidelines for Major Banks and Others." The proposal aims to unify the reporting formats that businesses must submit to authorities in the event of computer system failures or cybersecurity incidents into a common format based on agreements among relevant ministries. This applies to 17 areas, including administrative guidelines for cryptocurrency exchange operators.
The background for the amendment is the revision of the "Agreement on Reporting Procedures in the Event of Damage from Cyber Attacks" (Agreement among relevant ministries on May 28, 2025). Previously, only DDoS attack incidents and ransomware incidents could be reported using a common format, but a new format is expected to be established for other types of incidents as well.
The amendment proposal organizes the reporting categories from businesses into three types. DDoS attack incidents will be reported using the DDoS Attack Incident Common Format, while ransomware incidents will be reported using the Ransomware Incident Common Format. Incidents that do not fall into either category will be reported using the newly established "Common Format for Other Cyber Attacks and Incidents."
In the administrative guidelines related to cryptocurrency exchange operators, the reporting procedures for incidents such as system failures will be rewritten according to these three categories. The practice of the financial bureau contacting the relevant department of the FSA immediately upon receiving reports from cryptocurrency exchange operators will remain unchanged.
Transitional measures have also been established. Until the end of March 2027, businesses designated as specific social infrastructure operators under the Economic Security Promotion Act will be allowed to report using the old "Incident Report" format, except for those designated operators. Designated operators are expected to adapt to the new common format after the amendment.
The public comment period will be open until September 7, 2026, at 17:00. After the public comment period ends, the necessary procedures will be followed, and the amendments to the supervisory guidelines are expected to be applied. Target businesses, including cryptocurrency exchange operators, will need to prepare for practical responses based on the forthcoming official decisions.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.



















Today’s WEEX TradFi Daily Brief covers the July jobs report, weakness in storage stocks, Tesla and SpaceX’s Terafab project, and renewed oil supply concerns.










