Snapshot of 8 October 2026 · ICANN APS, public fields

Applications / .sompo / 86302673T-T51999 · published by ICANN 7 October 2026 · snapshot 2026-10-08

.sompo

Brand TLD · Spec 13Active

Sompo Holdings, Inc., JP Q1·Q25

ICANN record ↗

§ 1 — Meaning of the string Q118·Q120

"sompo" is the corporate brand and registered trademark of Sompo Holdings, Inc., derived from the company's own corporate name. It is used as the group's corporate brand across its insurance, nursing-care and digital businesses.

[sompo]

§ 2 — Mission and purpose Q133

Mission and purpose. The .sompo top-level domain provides a dedicated namespace for the official digital touchpoints operated or approved by the SOMPO Group. Its purpose is to help stakeholders worldwide identify the Group's information and services, support consistent brand communication, strengthen domain name governance, and reduce the risk of impersonation, phishing and unauthorised use of the SOMPO brand. Sompo Holdings, Inc. ("The Company"), headquartered at 26-1, Nishi-Shinjuku 1-chome, Shinjuku-ku, Tokyo, Japan, operates in insurance holding under the Insurance Business Act. "sompo" derives from The Company's own corporate name. The TLD is a long-term, group-wide platform supporting the SOMPO purpose "toward a future overflowing with security, safety and health" and the group vision "unleashing the potential of the future".

Intended registrants and users. Registration is limited to the applicant, its Affiliates and, where necessary, Trademark Licensees expressly approved by the applicant, in each case restricted to entities satisfying Specification 13 to the ICANN Base Registry Agreement. Domain names will not be sold or opened to the general public. Intended users are the Group's stakeholders in Japan and overseas: customers, business partners, investors, employees, the media and regulators.

Activities to achieve this purpose. The Group maintains unified brand operations centred on the SOMPO mark, manages its trademarks and domain names, and has established group-wide IT governance and cybersecurity arrangements. Following delegation, The Company will put in place registration and naming rules, eligibility criteria and approval procedures, review standards covering brand, legal and security considerations, procedures for responding to DNS Abuse, and lifecycle management from registration through modification, suspension and deletion. Deployment will be phased, beginning with uses carrying clear value and established operational readiness. The Company does not assume immediate migration from its existing domains; it will combine parallel operation, redirection and user notification.

Sustainability over time. The Company was incorporated on April 1, 2010 and has operated continuously since. The TLD is not intended to generate revenue through short-term campaigns or the sale of domain names to the general public, so its sustainability does not depend on registration volume; it will be run as a group-wide digital asset supporting the SOMPO brand and digital trust over the long term. The Company will maintain a cross-functional governance structure spanning brand, legal, IT and cybersecurity, supported technically by its registry service provider and registrars. Responsible departments and approval authority will be defined at each stage, and The Company will secure the budget, personnel and technical resources required for stable operation. Registered names, policies and security measures will be reviewed periodically, and operations revised as strategy, technology, law and the threat landscape change. The Company will also review its eligibility as a Specification 13 .Brand TLD at least once a year, with the prescribed reporting and certification to ICANN, and will establish measures for business continuity, incident response, data retention and contractor management.

Competition, differentiation and innovation. Because .sompo is closed to third-party registration and no domain names will be sold to the general public, it does not compete with existing generic TLDs for registrations. It differentiates The Company's authentic online presence from look-alike domains in open TLDs and directly reduces the risk of brand abuse. Growth in registrations will not be treated as an achievement in itself; expansion will proceed in stages against user value, brand consistency and security. For each registered name The Company will periodically confirm the responsible manager, the purpose of use and the continuing need for it.

§ 3 — Commitments and safeguards Q164–Q188

More trustworthy, consumer risk, regulated sector, government reporting, harm, government function Q164–Q169No to each
Voluntary Safeguard PICs Q170·Q171None · 90 applications in the round offer some
Registry Voluntary Commitments Q172·Q173None · 5 do
Brand TLD criteria confirmed, trademark certificate attached Q180·Q181Yes · certificate not published
Confirms the string is not a “generic string” Q183Yes
Spec 11 §3(d) statement Q184

The proposed registration policies for .sompo do not conflict with Specification 11.

Specification 11, Section 3(d) applies only where the applied-for string is a "generic string," meaning a word or term that denominates or describes a general class of goods, services, groups, organizations, or things, as opposed to distinguishing a specific brand. .sompo is not such a generic string. It is the applying entity's registered trademark, issued before the filing of this application, and is used by the applying entity and/or its affiliates in connection with the goods and services claimed by that registration. The string functions as a proprietary brand identifier, not as a dictionary or category term.

The applying entity intends to operate .sompo as a single-registrant brand TLD under Specification 13, with domain registrations limited to the applying entity and its affiliates or other authorized brand users. That limitation is a legitimate brand-control and consumer-protection measure. It preserves the trademark's source-identifying function, reduces phishing, impersonation, and other abuse risks, and ensures that names in the TLD are associated with authorized .sompo purposes.

Because .sompo is brand-distinctive and not generic, the exclusive-registration concern addressed by Specification 11, Section 3(d) is not implicated. The applying entity will observe the applicable mandatory Specification 11 safeguard public interest commitments, while relying on the Registry Operator Code of Conduct exemption available to qualifying Specification 13 brand TLDs under Specification 9, Section 6.

§ 4 — All other published answers

Every other answer ICANN published for this application, in the order of the form. Contact details (Q17–Q24) are left to the ICANN record.

Q206Q3.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If the applying entity’s financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC3.2-1.1 - As of the submission date of the application, the applying entity is currently a listed member in one or more of the public stock exchanges identified on ICANN’s list from Market Statistics (https://focus.world-exchanges.org/issue/december-2025/market-statistics, as of December 2025), including information on both the relevant exchange and the current registration ticker symbol. SC3.2-1.2 - The applying entity is in good standing with the public stock exchange in which it is a listed member. SC3.2-1.3 - The applying entity commits to the long-term funding of all applied-for gTLD strings. SC3.2-1.4 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Q3.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If the applying entity’s financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC3.2-1.1 - As of the submission date of the application, the applying entity is currently a listed member in one or more of the public stock exchanges identified on ICANN’s list from Market Statistics (https://focus.world-exchanges.org/issue/december-2025/market-statistics, as of December 2025), including information on both the relevant exchange and the current registration ticker symbol. SC3.2-1.2 - The applying entity is in good standing with the public stock exchange in which it is a listed member. SC3.2-1.3 - The applying entity commits to the long-term funding of all applied-for gTLD strings. SC3.2-1.4 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Answered with a document. Attachments are not published by ICANN.

Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Answered with a document. Attachments are not published by ICANN.

Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Answered with a document. Attachments are not published by ICANN.

Q119Script of String

Script of String

Latin

Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

true

Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true

Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true