As governments tighten cybersecurity requirements for defense and critical-infrastructure suppliers, the weakest link is increasingly the network of smaller companies sharing sensitive information across borders. Exostar and Fujitsu are targeting that problem in Japan with a managed Microsoft 365 environment designed to give suppliers a controlled space for collaboration, identity management and compliance.
Aerospace and defense supply chains are becoming cybersecurity systems in their own right. Prime contractors may have sophisticated security operations, but sensitive engineering, procurement and operational information still moves through hundreds or thousands of suppliers, contractors and business partners.
Exostar and Fujitsu are betting that one way to reduce that exposure is to give those organizations a common, managed environment for collaboration.
The companies announced that Exostar is providing the secure-environment technology behind Fujitsu’s new Fujitsu Trusted Supplychain Service, launched in Japan on August 20. The service uses Exostar Managed on Microsoft 365 to provide a controlled environment for information sharing and collaboration among organizations in defense and critical-infrastructure supply chains. Fujitsu says the service is designed to support NIST SP 800-171 requirements while keeping data management and operations within Japan.
That combination is significant because Japan’s defense ecosystem increasingly has to work with international security expectations while also dealing with domestic requirements around data handling and infrastructure.
At the core of the service is a managed Microsoft 365 enclave. Exostar says it provides centralized identity and access management, multi-factor authentication, partner onboarding, information-sharing controls and audit logging. The objective is straightforward: keep sensitive information inside a controlled environment rather than allowing suppliers to exchange it through a patchwork of consumer-grade collaboration tools, unmanaged accounts and disparate systems.
Why supply-chain security is becoming a platform problem
The cybersecurity challenge is larger than compliance.
Modern defense programs depend on extended networks of manufacturers, engineering firms, logistics providers and technology companies. A compromise at one supplier can create consequences far beyond that company’s own IT environment.
NIST’s SP 800-171 framework is specifically designed to protect Controlled Unclassified Information held by nonfederal organizations. Its requirements apply to systems that process, store or transmit CUI, making the framework particularly relevant to contractors and suppliers participating in government programs.
The U.S. Department of Defense’s CMMC program builds on NIST security requirements for protecting CUI in the Defense Industrial Base. That means cybersecurity has increasingly become a condition of participation in sensitive government supply chains rather than simply an internal IT concern.
Japan is moving in a similar direction. Fujitsu says its new service is aligned with NIST SP 800-171 and operates on infrastructure registered under Japan’s ISMAP government cloud-security assessment framework. The company describes the offering as the first Japanese SaaS service using Exostar’s capabilities for this purpose.
The architectural choice is notable. Rather than asking every supplier to independently build a security environment capable of meeting demanding requirements, a managed enclave allows participating organizations to inherit a portion of the underlying technical controls.
That does not make compliance automatic. Organizations remain responsible for governance areas such as policies, employee training, personnel controls and physical security. But the shared-responsibility model can reduce the infrastructure burden for suppliers that otherwise might struggle to implement sophisticated security controls themselves.
Microsoft 365 becomes the collaboration layer
Microsoft 365 is central to the approach because it is already familiar to many enterprise users.
For Exostar, the value is not simply putting Microsoft productivity applications behind additional controls. The company’s platform adds identity, access, partner onboarding, governance and auditing around collaboration involving sensitive information.
That places the offering in an increasingly important category of secure collaboration platforms for regulated industries.
The competitive landscape includes Microsoft’s own government and sovereign-cloud capabilities, dedicated secure file-sharing platforms, identity providers and third-party governance tools. The differentiator for Exostar is its specialization in highly regulated ecosystems, particularly defense and aerospace, where the question is not merely whether a collaboration platform is secure but whether it can support the contractual, regulatory and trust relationships spanning an entire supply chain.
Exostar says its technology already supports U.S. Defense Industrial Base organizations through a Microsoft GCC High environment with FedRAMP Moderate Equivalency. Its integration into Fujitsu’s Japan-operated infrastructure extends that model into a different national regulatory and data-residency context.
That distinction matters for multinational programs. A U.S.-centric security architecture cannot simply be copied into every allied market if data-residency, sovereign-cloud and national compliance requirements differ.
The business case is reducing fragmentation
The larger trend is toward consolidating third-party risk management rather than treating every supplier as an isolated security project.
Gartner said in 2025 that organizations were increasingly turning to technology platforms to manage growing third-party risks, while warning that many enterprises still use multiple tools with overlapping capabilities. Gartner also said multinational organizations are experiencing increasing complexity in the number of third parties they depend on.
A separate Gartner analysis published in May 2026 identifies third-party vendors, technology partners and software providers as potential paths for attackers to bypass primary defenses.
For defense organizations, that creates an uncomfortable equation: expanding the supplier network can increase manufacturing capacity and innovation while simultaneously expanding the cyberattack surface.
Exostar and Fujitsu are approaching the problem through infrastructure rather than assessment alone. The proposition is to provide a trusted environment in which suppliers can actually conduct business under defined security controls.
The companies have worked together since 2019, when Fujitsu incorporated Exostar’s secure collaboration and identity capabilities into its Fort# Forum offering for Japanese suppliers. The new service extends that relationship to a broader supply-chain audience.
For enterprise technology teams, the important question will be whether managed enclaves can provide enough flexibility without undermining the security model they are designed to enforce. Suppliers still need integration with their own systems, identity processes and business workflows. Excessive isolation can create operational friction just as easily as inadequate controls can create security risk.
The emerging model is therefore less about building an impenetrable digital island and more about establishing trusted boundaries for collaboration.
That is likely to become increasingly important as the United States, Japan and other allied economies seek more resilient industrial bases. Secure supply-chain infrastructure may ultimately become as important to cross-border manufacturing programs as the underlying cloud, ERP and communications systems that run them.
Market Landscape
The market is moving toward several overlapping approaches to supply-chain cybersecurity:
- Managed secure enclaves: Providers such as Exostar create controlled collaboration environments where organizations can share sensitive information under centralized security policies.
- Sovereign and regulated cloud: Hyperscalers including Microsoft, Amazon and Google are expanding environments designed around government, residency and regulatory requirements.
- Third-party risk management: Platforms increasingly help enterprises assess suppliers, monitor risk and maintain evidence of compliance. Gartner notes that the market remains fragmented, with many organizations using multiple solutions.
- Identity-centric security: MFA, access controls and centralized identity management are becoming foundational to supplier ecosystems rather than optional security features.
- Compliance-as-infrastructure: Instead of treating compliance as documentation layered onto IT, enterprises are increasingly embedding audit trails, access controls and data boundaries directly into operating environments.
The strategic opportunity for vendors such as Exostar is to make compliance-oriented infrastructure usable enough that suppliers actually adopt it. In complex industrial ecosystems, security controls only work at scale when they can coexist with procurement, engineering, manufacturing and collaboration workflows.
Top Insights
- Exostar is providing the secure Microsoft 365 environment behind Fujitsu’s new Japanese supply-chain service, targeting defense and critical-infrastructure organizations.
- The platform combines identity management, MFA, controlled information sharing and audit logging to reduce security fragmentation across supplier ecosystems.
- Fujitsu operates the service on Japan-based ISMAP-registered infrastructure, addressing data-residency requirements alongside NIST SP 800-171 alignment.
- The model reflects a wider shift from supplier-by-supplier cybersecurity toward managed infrastructure that standardizes controls across complex industrial networks.
- Enterprise buyers must still evaluate governance, integration and operational responsibilities because a managed security environment does not eliminate customer-side compliance obligations.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI









