Korea Semiconductor Manufacturing Cybersecurity Consortium (SMCC) Updates
At the end of June, SEMI Korea held a Standardized Semiconductor Cyber Assessment (SSCA) webinar. Since it was the first SSCA meeting, its purposes and related information were introduced. The last session of the meeting featured a Q&A discussion between industry participants and the presenters on the practical implementation of SSCA. The questions raised were highly specific and practical in nature, covering real-world adoption and operational considerations. This interactive discussion significantly enhanced the value of the session by providing useful insights and clarifying key aspects of SSCA implementation.
Session 1 – Introduction of Korea SSCA
The first presentation by Suk Won Kang, Director of Information Security at Applied Materials, introduced the Semiconductor Manufacturing Cybersecurity Consortium (SMCC) and its South Korea cybersecurity working group (WG9), highlighting the semiconductor industry’s effort to improve cyber resilience across factories and supply chains. SMCC’s mission is to promote industry-wide, standards-based cybersecurity practices, support implementation of SEMI cybersecurity standards (E187, E191), and help companies address evolving regulatory requirements such as the EU Cyber Resilience Act (CRA). The presentation outlined the origins and growth of SMCC, its organizational structure, leadership, and global participation, which currently includes more than 80 organizations spanning device manufacturers, equipment suppliers, solution providers, academia, and industry groups. WG9 specifically focused on increasing awareness and adoption of cybersecurity standards in Korea, facilitating collaboration among semiconductor companies, and representing regional cybersecurity concerns within the broader SMCC community.
The second half of the presentation focused on the Standardized Semiconductor Cyber Assessment (SSCA) initiative, a common cybersecurity assessment framework designed to reduce the burden of multiple supplier audits and improve supply chain security. Inspired by the automotive industry’s TISAX model, SSCA introduced a shared questionnaire covering Cyber Resilience, IP Protection, and Product Security, aligned with NIST CSF 2.0 principles. The framework aimed to replace numerous customer-specific assessments with a standardized approach that could be shared across the semiconductor ecosystem, improving efficiency, reducing costs, and driving measurable security improvements. The presentation described the development journey of SSCA, its scoring methodology, and its planned industry-wide adoption, emphasizing that the questionnaire was freely available in multiple languages, including Korean, to encourage broad participation and strengthen cybersecurity maturity throughout the global semiconductor supply.
Session 2 – Introduction of Korea SSCA Assessment
The second presentation provided a detailed introduction to the Standardized Semiconductor Cyber Assessment (SSCA) framework developed by the Semiconductor Manufacturing Cybersecurity Consortium (SMCC) to standardize cybersecurity assessments across the semiconductor supply chain. It explained the SSCA maturity-based assessment methodology using 44 CMMI questions scored from Level 0 to Level 5, aligned with NIST CSF functions and mapped to common security certifications such as ISO 27001 and ISMS-P. The presentation walked through all major assessment domains including governance, supply chain risk management, security policies, business continuity, cloud security, asset management, physical security, security awareness, access control, network and email security, endpoint protection, data protection, software and product security, monitoring, incident response, and recovery. For each domain, it identified key evaluation criteria, required evidence, maturity expectations, and practical controls organizations should implement to improve their cybersecurity posture and demonstrate compliance during SSCA assessments.
At the end of this session, we had detailed questions and answers because these were new and advanced requirements for the Korean industry; most vendors wanted detailed information to prepare better services.
Here are a few examples of questions and responses that were exchanged.
- If a company had headquarters and branches in Korea, how could it prepare?
A. The company’s headquarters had priority, and each branch could add more localized information required by manufacturers. - What impact would this certification have on future business?
A. SSCA was expected to become a standard cybersecurity assessment framework within the semiconductor industry. With accredited assessors and a centralized data-sharing platform established, companies would be able to leverage SSCA assessment results instead of conducting separate cybersecurity audits for each supplier. SSCA was expected to become an important factor in supplier qualifications. It would be like how TISAX had become a prerequisite for participation in the automotive supply chain. - How would the certification body and governance structure for SSCA be organized? Also, was SSCA primarily intended to assess companies or products?
A. The long-term goal was to establish a model like TISAX in the automotive industry, where an independent assessment and governance ecosystem supported standardized cybersecurity evaluations across the supply chain. However, SSCA was still in its early stages. At that time, there was no established mechanism for broadly sharing assessment results with customers, and there were no officially certified companies yet. In Korea, SK hynix had begun conducting pilot assessments based on the SSCA framework in 2026, representing an important first step toward broader industry adoption. - What is the plan for product security, such as semiconductor equipment, materials, components, or end products?
A. Product security was also an area of active discussion within the industry. Secure SDCIM and dynamic scanning technologies were being explored and debated. SEMI E187 was being driven primarily by TSMC, which had taken a leading role in its development and adoption. Meanwhile, E188 might eventually be merged into other related standards and potentially phased out as a standalone standard. Since many of these initiatives had originated in Taiwan and had gained significant momentum there, it was expected that the broader semiconductor market would gradually align with these standards and practices in the near future.
The inaugural Korea SSCA webinar marked an important step in bringing standardized cybersecurity assessment to the region’s semiconductor industry. With SK hynix already piloting the framework and strong vendor interest evident in the Q&A, SSCA looks poised to follow TISAX’s path from voluntary standard to de facto supply chain requirement. Key questions—governance structure, assessor accreditation, product-level security standards like E187 and E188—remain open, but the momentum and level of engagement suggest Korea’s semiconductor ecosystem is preparing early for what may become the industry norm.