Cybersecurity risk within the semiconductor supply chain is drawing increased attention as chip manufacturing expands across defense, automotive, energy, and critical infrastructure sectors.
To address that exposure, SEMI’s Semiconductor Manufacturing Cybersecurity Consortium (SMCC) has introduced the Standardized Semiconductor Cyber Assessment (SSCA) — a sector-specific cybersecurity framework designed to streamline how suppliers demonstrate risk management maturity.
Swansea University’s Systems Security Group (SSG), working under the UKRI-funded Security Assurance of Semiconductor Manufacturing (SASM) project, is collaborating with SMCC to define the evidence requirements that underpin SSCA assessments. The effort focuses not just on questionnaire responses, but on what constitutes verifiable proof of security controls.
Semiconductor manufacturing environments combine:
Cyber incidents can disrupt production, compromise product integrity, or expose design IP — risks that extend well beyond traditional IT environments.
SSCA focuses on three core areas:
The framework aligns with NIST Cybersecurity Framework (CSF) 2.0 and incorporates maturity-based evaluation concepts drawn from CMMI. It also builds on lessons from ISO 27001 and automotive-sector standards, while adapting to semiconductor-specific operational realities.
One of the central goals of SSCA is to reduce redundant supplier questionnaires. Instead of responding to multiple, inconsistent assessments from different customers, suppliers can complete a standardized evaluation and share results across buyers.
For procurement and supply chain leaders, that offers efficiency — but also raises the bar.
Standardization increases comparability, and evidence-based assurance strengthens accountability. As semiconductor supply chains are increasingly treated as national infrastructure, cybersecurity posture is becoming part of vendor qualification.
The international collaboration behind SSCA — including partners in the UK, Germany, and the U.S. — reflects growing recognition that semiconductor cybersecurity is a shared supply chain risk, not an isolated IT issue.