The landscape surrounding IT procurement for small and medium-sized enterprises (SMEs) is changing quietly but surely. The recent news that multiple IT service providers have successively begun offering “SCS Evaluation System Support Services” can be seen as an event symbolizing this shift.
At first glance, this might seem like very limited news: “a support service to help SMEs meet government security standards.” However, digging deeper into this trend from an executive’s perspective reveals a fundamental management decision that has often been ambiguous until now: “How should we procure IT?” This is not just about obtaining a certification; it hints at a turning point in the IT investment decision-making process itself.
The “Two Layers of Value” Provided by SCS Evaluation Support Services
First, let’s clarify the service content that various companies have started offering with this news. The SCS (Security Cloud Service) evaluation system is a government program that rates the security level of cloud services with “stars” (1 to 4). Particularly, a rating of ★3 or higher often becomes a de facto requirement for bidding in transactions with government agencies and large corporations, making it an important “passport” for SMEs to expand business opportunities.
The newly announced support services comprehensively handle procedures like “expert reviews” and “signatures,” which are high hurdles for SMEs to tackle alone, required to obtain ★3. While price ranges haven’t been disclosed, the investment is expected to range from several thousand to tens of thousands of US dollars.
Here, what executives must not overlook is that the value provided by this service is divided into “two layers.”
The first value is superficial and obvious: the outcome of “obtaining SCS ★3” itself. This is direct value that meets transaction conditions and opens doors to new customers.
However, the second, deeper value is more important. It is the value of “making the IT procurement process and quality ‘visible’ and ‘structured’ by external experts.” Experts review the company’s actual cloud usage, identify lacking security measures, and implement corrections. Through this series of processes, executives can, for the first time, objectively understand “by what standards and in what state” their company’s IT usage exists.
This can be a valuable opportunity for many SMEs to break away from the state where “IT procurement is left to the person in charge” and “anything usable is fine.”
The Background Accelerating “Outsourcing IT Procurement” and the Management Decision
Why have such services emerged simultaneously from multiple companies now? The background lies in the increasing complexity of SME IT environments and the accompanying “manifestation of procurement risks.”
In the past, IT procurement centered on “hardware” like servers and PCs, and the criteria for procurement decisions were relatively simple. However, the core of modern IT investment is SaaS (Software as a Service). Salesforce, Microsoft 365, freee, Slack… While these can be easily introduced with monthly subscriptions, it is difficult to grasp actual usage, and security policies and data management guidelines vary from service to service. This “proliferation of SaaS” has made integrated security management difficult, creating a need for evaluation by external standards like SCS.
Furthermore, changes in the regulatory environment, such as increasing cybersecurity risks and amendments to personal information protection laws, are also tailwinds. Executives are being forced to strongly recognize that IT procurement is not merely a “cost” or a “convenient tool,” but a subject of “risk management” and “compliance.”
In this context, the emergence of SCS evaluation support services forces executives to make one critical decision: “Should we build the functions of ‘quality control’ and ‘risk assessment’ for IT procurement in-house, or purchase them as an external service?”
Developing/hiring personnel with specialized knowledge in-house and building a continuous evaluation system requires considerable time and cost. On the other hand, using an external service requires an initial investment of several thousand to tens of thousands of dollars, plus renewal fees. This means the classic “Make or Buy” decision in resource allocation has now extended to the new domain of IT procurement quality management.
The Pitfall of Using Support Services: Shifting Goals
However, when utilizing such external services, there is a pitfall that executives must be clearly aware of: “shifting goals.”
There is a danger that obtaining SCS ★3 itself becomes the goal, and the essential purpose of “making the company’s IT procurement process healthy and reducing risk” is lost. Service providers ultimately deliver the outcome of “certification acquisition.” They do not take care of the subsequent, sustained maintenance and management of IT procurement quality within the company after acquisition.
Falling into this pitfall means the investment ends up as merely “a superficial certification requiring large payments again at each three-year renewal.” The “review results” and “corrective proposals” obtained through the support service must not be just a checkpoint for certification but must be utilized as valuable “blueprints” to strengthen the company’s IT procurement governance.
The stance executives should take is not “buy the service and finish,” but to simultaneously design “how to incorporate the insights gained through the service into the company’s decision-making process.” For example, creating a checklist for introducing new SaaS based on SCS evaluation items. Or, formalizing the security settings pointed out in corrective proposals as a company-wide IT policy. These next-step actions are the key to transforming the investment in external services into true management value.
Three Questions to Return IT Procurement to a “Management Decision”
Using this news as a trigger, executives, CTOs, and IT managers should ask the following three questions about their company’s IT procurement process.
First Question: Does our company’s IT procurement have clear “decision criteria” and an “approval process”?
Who approves the introduction of new tools, and based on what criteria? Are introductions progressing based on vague reasons like “seems convenient,” “it’s cheap,” or “another department uses it”? External standards like SCS can be used as an initial framework for building these “decision criteria.”
Second Question: Can we visualize the “Total Cost of Ownership” and “potential risks” associated with IT procurement?
The monthly SaaS fee is not the only cost. Hidden costs and risks are diverse, including the man-hours for data migration, integration costs with other tools, response costs in case of security incidents, and reputation damage risk. The SCS evaluation process is an opportunity to have these risks scrutinized by expert eyes.
Third Question: Should the IT procurement quality control function be built in-house or outsourced?
This is the core question posed by this news. It must be judged in light of the company’s scale, growth stage, IT literacy, and, above all, the vision of “how IT should be positioned within management.” External services are a quick solution but create dependencies. In-house development takes time but accumulates proprietary knowledge.
Summary: Redesigning IT Procurement Beyond Certification Acquisition
The emergence of SCS evaluation system support services is a sign that SME IT procurement has entered a new phase. IT is no longer merely a “tool for operational efficiency”; it is a “subject of risk management” and “infrastructure that influences business opportunities.”
Support services like these provide a valuable opportunity to temporarily “visualize” and “structure” that complex IT environment through external experts. The executive’s role is not to let that opportunity end with mere “certification acquisition,” but to use the gained insights as a foundation to redesign the company’s “management process of IT procurement” itself.
To elevate IT procurement from a departmental chore to a “mainstream management decision” where management defines standards, assesses risks, and allocates resources. The perspective to strategically utilize services like external certification acquisition support as a first step is what is needed now.


Comments