Establishment of the "Crypto Asset Management-Related Service Provider" Regime — A Notification-Based Supply Chain Regulation under the Amended FIEA

Positioning and Background
As part of the broader migration of crypto asset regulation from the Payment Services Act to the FIEA, the amendment bill newly introduces "Crypto Asset Management-Related Service Providers" under Chapter III-VI of the amended FIEA. The framework codifies issues discussed under the label "critical system providers" in the December 2025 FSA Working Group Report, integrating into a single supply chain regulation: (i) statutory obligations for safety management of customer assets by crypto asset trading business operators (the renamed entity replacing "crypto asset exchange service providers"), (ii) prior notification for critical system providers, and (iii) restrictions on outsourcee selection by crypto asset trading business operators.
The Scope of "Crypto Asset Management-Related Services"
The bill groups together as "Crypto Asset Management-Related Services": continuously enabling crypto asset trading business operators to use information systems necessary for customer asset management; providing maintenance and management of those systems under entrustment; and other related business outsourcing as specified by Cabinet Office Order. All categories target services performed for crypto asset trading business operators; direct services to general users are outside the regime's scope. The substantive scope is delegated to Cabinet Office Order, with the biggest issue being how far the scope extends to wallet software, MPC platforms, HSMs, signing orchestration, and blockchain node/RPC infrastructure.
Two-Tier Regulatory Structure — Capturing Both Outsourcer and Provider
The defining feature is that hard rules apply not only to providers but also to outsourcing crypto asset trading business operators. Under amended FIEA Article 43-13, when outsourcing part of crypto asset trading business, operators must implement measures necessary for outsourcee guidance and quality management, including outsourcing across two or more stages (multi-tier outsourcing). This brings management responsibility for stratified supply chains — including cloud providers, node infrastructure, and custody technology suppliers — back to the operator. Providers, in turn, are subject to prior notification, business management system obligations, and information safety management measures. This approach is structurally analogous to the EU's Digital Operational Resilience Act (DORA), which subjects critical ICT third-party providers to direct supervision.
Integrated Design with Adjacent Regulations
The regime functions not in isolation but as part of an integrated regulatory package. The new loss reserve accumulation obligation (amended FIEA Article 46-5) requires crypto asset trading business operators to accumulate compensation funds at rates corresponding to their crypto asset balances under management. Furthermore, lending/borrowing operations (borrowing user crypto for lending or staking) are added to the scope of crypto asset trading business, requiring credit risk management systems. Together, these form a multi-layered defense for user asset protection.
Effective Date and Cabinet Office Order Delegations
According to the FSA's official explanatory materials, the crypto asset regulation reform will take effect within one year of promulgation. This differs from the schedules for sustainability information disclosure and assurance (effective April 1, 2027) and startup financing promotion (effective October 1, 2027). While the bill sets the framework in statute, many practically critical requirements are delegated to Cabinet Office Order and Cabinet Order — including the scope of "information systems," outsourcer-side selection and guidance specifics, provider-side financial base and structural requirements, and enforcement and transition details.
Business Development Insights
1. The Renaming from "Critical System Provider" to "Crypto Asset Management-Related Service Provider" Signals a Design Shift
Moving from a function-based label at the WG stage to an activity-based label suggests a shift in capture target — from "specific systems" to "the conduct of continuously providing, maintaining, or operating information systems." This enables technology-neutral regulatory design independent of hardware/software form, while equally capturing SaaS, cloud, and MPC business models.
2. The Cabinet Office Order's Definition of "Information Systems" Determines Survival
How "information systems necessary for managing customer crypto assets" is drawn becomes the biggest issue. While wallet software and HSMs that directly handle signing keys are clearly within scope, whether transaction screening and signing orchestration platforms, blockchain node/RPC infrastructure, and KYC/AML integration layers will be captured remains undetermined. The presence or absence of notification obligations directly affects entry barriers, operational costs, and contract terms — making industry input during public comment periods decisive for business value.
3. Connection to EU DORA-Style Supply Chain Regulation Strengthens International Positioning
This regime structurally resembles the EU DORA critical ICT third-party provider regime, meaning Japanese notification acquisition can serve as a springboard to European regulatory compliance for global technology providers. Conversely, providers designated as critical ICT third-party providers in Europe may find Japanese notification relatively smooth to obtain. The interoperability of Japan-EU regulation is becoming a new axis of international competitiveness for crypto asset infrastructure businesses.
Sources
- FSA, "Bills Submitted to the Diet" (Bill to Amend the FIEA and Payment Services Act, Outline, Explanatory Materials) https://www.fsa.go.jp/common/diet/index.html
- FSA, "Explanatory Materials on the Bill to Amend the FIEA and Payment Services Act" (April 2026) https://www.fsa.go.jp/common/diet/221/02/03.pdf
- FSA Financial System Council, "Working Group on the Crypto Asset System" Materials https://www.fsa.go.jp/singi/singi_kinyu/angoshisanseido_wg/angoshisanseido_wg_index.html
- FSA, "Report of the Working Group on the Crypto Asset System under the Financial System Council" (December 10, 2025) https://www.fsa.go.jp/singi/singi_kinyu/tosin/20251210/01.pdf
- European Banking Authority, "Digital Operational Resilience Act (DORA)" https://www.eba.europa.eu/regulation-and-policy/digital-operational-resilience-act-dora
- e-Gov Law Search (Financial Instruments and Exchange Act) https://elaws.e-gov.go.jp/
Akihisa Ishida
Cabinet Inc. Founder CEO
Disclaimer
This report has been prepared solely for informational purposes regarding crypto assets and related markets, and is not intended to recommend, solicit, or offer the purchase, sale, holding, or any other transaction of any specific crypto asset. It does not constitute investment advice, investment solicitation, or the sale or intermediation of financial products as defined under the Financial Instruments and Exchange Act or any other applicable laws and regulations, nor does it constitute tax, legal, or accounting advice.
The information contained in this report is based on sources believed to be reliable at the time of preparation; however, we make no representation or warranty, express or implied, as to its accuracy, completeness, timeliness, or usefulness. Crypto assets are subject to significant price volatility and may result in the loss of principal or other financial losses. Any investment decision shall be made solely at the user's own discretion and responsibility, and we accept no liability whatsoever for any damages arising out of or in connection with the use of this report.
Blockchain Business Consultation
From idea-stage brainstorming and technical validation (PoC) to implementation and operations, Cabinet provides end-to-end business development consulting. Start with a free consultation today.
Perpetual Futures Decoded — From Shiller's 1993 Paper to the Rise of Hyperliquid: The Complete History of the "Never-Expiring" Contract That Conquered Global Derivatives
The Blockchain Privacy Inflection Point — Institutional Finance Reaches Its "SSL Moment"
Sign Up for Newsletter
Beyond the content of this report, we will deliver the latest industry information and exclusive reports by email.

