October 2, 2026
What the SSCA Actually Asks Semiconductor Suppliers For
The Standardized Semiconductor Cyber Assessment is one security questionnaire for semiconductor supply chain suppliers: 165 questions…
By Consilien
3 min read
The Standardized Semiconductor Cyber Assessment is one security questionnaire for semiconductor supply chain suppliers: 165 questions across the 6 NIST CSF 2.0 functions. SEMI released it in September 2025. It is free, and results can be shared with multiple customers.
The problem it was built to solve
Before the SSCA, every fab and every OEM sent its own questionnaire. The questions covered similar ground, but the scoping differed, the maturity models differed, and the formats differed. A supplier serving six customers answered six versions of the same assessment, and spent dozens of hours a year doing it.
SEMI's Semiconductor Manufacturing Cybersecurity Consortium built the SSCA to collapse that into one. The practical change for a supplier is that the work becomes reusable. The strategic change is less comfortable: your security posture is now recorded in a common format that buyers can compare.
The assessment is not pass/fail. It measures maturity. But customers use the result to decide whether your posture meets their requirements, and a weak score means remediating on someone else's timeline or losing the contract.
How the 165 questions are organised
The six activity areas map directly to NIST CSF 2.0.
Govern asks whether cybersecurity is a real organisational priority. Who owns it, does it have a budget, does it reach the board. This section is difficult for any company where security is one person doing their best without formal policies or executive backing.
Identify asks what you have and what depends on it. Asset inventory, risk assessment, supply chain dependencies. Asset inventory sounds elementary until you try to produce a complete, current list for a few hundred endpoints.
Protect covers access controls, data protection, security awareness training, and information protection processes. It maps closely to NIST SP 800–171 and to SEMI E187's endpoint requirements, so companies already working toward CMMC or ISO 27001 tend to have much of it in place.
Detect asks whether you can see something happening. Security monitoring, anomaly detection, processes for unauthorised access. Checking firewall logs when something seems wrong is not detection. It is investigation after the fact.
Respond asks for an incident response plan, evidence that it has been tested, and communication procedures for notifying affected parties. Most mid-market manufacturers have never written one. Fewer have tested one.
Recover asks whether you can restore operations. Backups, validation, business continuity. This is where the most common gap sits, and it is a quiet one.
The evidence is the hard part
The questions themselves are answerable. Producing evidence for the answers is where suppliers lose points.
Answering yes to a question about access controls is not sufficient. The assessment process expects the access control policy, the configuration that implements it, and a record showing it was reviewed within the last 12 months. The same standard applies across all six functions.
For Govern, that means a written cybersecurity policy, risk management framework documentation, executive review records, and named role assignments. For Identify, a current asset inventory, a dated risk assessment, network diagrams, and data flow maps. For Protect, access control policies and configurations, encryption settings, training records, and patch management logs. For Detect, deployment documentation for your monitoring stack, coverage maps, and alert response procedures. For Respond, a written and dated incident response plan plus tabletop exercise records. For Recover, backup configurations and restore test records.
Read that list against your own environment and a pattern usually emerges. The controls exist. The documentation does not. That gap is the single most common reason a technically competent company scores poorly.
I know a manufacturer running nightly backups on a well-configured system that had not attempted a restore in two years. The backups were fine. The evidence that they worked did not exist, and under the assessment an untested backup counts as an assumption rather than a control.
A sequence that works better than answering cold
Trying to answer all 165 questions in one sitting produces guesswork and an incomplete evidence package. A more useful order looks like this.
Start with a gap assessment against NIST CSF 2.0. Because the SSCA maps to the same six functions, knowing your gaps against the framework tells you where the assessment will hurt. The initial review takes a few hours and produces a prioritised list.
Build the evidence library before the questionnaire arrives. Collect policies, configurations, logs, training records, and test results now, organised by NIST function so they map directly onto the assessment structure.
Close documentation gaps first, because they are the cheapest to fix. If access controls are running without a written policy, write the policy. If backups run without a restore test, run the test and record the result.
Then take on the structural gaps. Missing security monitoring, no incident response plan, no risk assessment. These need budget and time, which is exactly why finding them early matters.
The questionnaire is publicly available from SEMI. Download it and score yourself honestly before a customer sends it. The self-assessment tells you which sections will be difficult while there is still room to do something about it.
Consilien runs compliance readiness engagements for electronics and semiconductor manufacturers covering the SSCA, SEMI E187, NIST SP 800–171, CMMC, and ISO 27001.