Fujitsu Limited has begun a post-quantum virtual private network pilot with three Ministry of Defense subcontractors in Kanagawa Prefecture, according to people briefed on the deployment and a technical notice circulated to participating suppliers last week. The trial replaces legacy IKE-based tunnels between plant-floor systems and ministry-facing document exchanges with hybrid key exchange that includes ML-KEM, the lattice scheme Japan’s CRYPTREC added to its recommended ciphers list this year.

What the pilot actually tests

The pilot is narrow by design. Each site runs a pair of Fujitsu-branded VPN appliances that terminate encrypted links to a regional aggregation node Fujitsu operates inside an ISMAP-registered data center in the Keihin industrial belt. Traffic mirrors production flows—controlled technical data, subcontractor status reports, and audit logs—but runs on parallel circuits so a rollback does not interrupt live ministry business.

Engineers at two of the three sites said the appliances negotiate classical ECDH first, then layer ML-KEM as an additional shared secret, matching interim guidance several CRC members have circulated while NEDO’s national implementation program works toward final documents in 2026. The third site is testing a stricter profile that refuses sessions unless post-quantum algorithms succeed end to end, a configuration Fujitsu documentation labels “PQ-only” for future procurement language.

Why Kanagawa and why now

Kanagawa clusters shipbuilding, precision machining, and electronics suppliers that feed Japan’s defense industrial base. Those companies already face NIST SP 800-171-style controls through ministry acquisition reforms and Fujitsu’s newer Trusted Supplychain Service, which pairs Exostar-managed Microsoft 365 enclaves with domestic operations. The VPN pilot sits beside that service rather than inside it: subcontractors that cannot move all collaboration into a SaaS enclave still need encrypted site-to-site links that will survive a future “harvest now, decrypt later” threat model.

Fujitsu joined the Cyber Research Consortium under NEDO’s post-quantum implementation grant alongside NTT, Preferred Networks, and others; the Kanagawa rollout is the first customer-facing VPN artifact attributed to that membership, according to two consortium participants who asked not to be named because they are not authorized to speak for Fujitsu.

Operational constraints suppliers describe

Participants said the hardest work is not the algorithms but clock skew and firmware governance. One machining supplier runs legacy Windows file servers that initiate VPN sessions only during night batches; ML-KEM handshakes added roughly twelve percent latency in initial measurements, within Fujitsu’s stated tolerance but enough to force scheduler changes. Another site must keep a classical fallback path for a U.S. parent company’s remote monitoring tool until the parent completes its own PQC roadmap.

Fujitsu support staff based in Kawasaki are handling configuration; suppliers are not receiving source code. Maintenance windows are coordinated with prefectural cybersecurity drills scheduled for late September, when ministries test continuity plans ahead of Silver Week travel congestion.

Procurement and standards path

Ministry acquisition officials have not published a mandate requiring ML-KEM on contractor VPNs. People familiar with the pilot said Fujitsu is using it to draft procurement annex language—key rotation intervals, allowed hybrid profiles, and logging fields—that could attach to broader defense supply-chain contracts in 2027 if CRYPTREC and NEDO deliverables align.

CRYPTREC’s public materials emphasize that ML-KEM is recommended for key establishment, not a blanket replacement for every legacy system. Fujitsu’s notice to participants explicitly warns that post-quantum VPNs do not fix endpoint malware or stolen credentials, echoing language in the company’s August Trusted Supplychain launch.

What success would look like

Fujitsu aims to complete ninety days of dual-stack operation without session drops attributable to PQC negotiation failures, then publish a sanitized configuration guide through the CRC. Suppliers want clarity on whether ministry auditors will accept hybrid tunnels as compliant or insist on PQ-only profiles that could strand overseas partners.

For Kanagawa plants already juggling foreign ownership rules and ministry documentation burdens, the pilot is less about quantum physics than about predictable upgrade windows. If the appliances ship as a managed service with domestic support, two participants said they would expand beyond the trial; if Fujitsu expects each tier-two supplier to operate PQ policy alone, interest cools quickly.