Major Revision of SEMI E187: Introducing Tiered Security Levels and Comprehensive Defense Architecture for Fab Equipment
By Nick Chen, SEMI Taiwan
Introduction & Background
Originally published in January 2022, SEMI E187 (Specification for Cybersecurity of Fab Equipment) established fundamental cybersecurity requirements for operating systems, network security, endpoint protection, and logging across semiconductor manufacturing equipment. However, as fab operations and cyber threat landscapes evolve globally, equipment suppliers and chipmakers face distinct operational risks, software lifecycle challenges (such as End-of-Life OS support), and complex supply chain requirements.
To address these global challenges and establish seamless alignment with international OT security standards (notably the IEC 62443 series), the Fab and Equipment Information Security Task Force (under the Information and Control Taiwan TC Chapter) initiated a major revision (SNARF 7317) due to the extensiveness of the updates.
A Tiered Security Approach: Cumulative Security Levels (SL1–SL3)
The core architectural innovation in the revised SEMI E187 is the introduction of three cumulative Security Levels (SL), enabling equipment users (asset owners) and suppliers to jointly select target security profiles based on equipment criticality, connectivity exposure, and risk profile:
- Security Level 1 (SL1) – Baseline Compliance: Defines the mandatory minimum security baseline for all SEMI E187-compliant semiconductor equipment and Automated Material Handling Systems (AMHS). It mandates vendor-supported operating systems, pre-shipment vulnerability and malware scans, encrypted network communications, and basic access control.
- Security Level 2 (SL2) – Enhanced Security: Building on the SL1 baseline, SL2 introduces enhanced security requirements for equipment with higher availability or integrity expectations. It is particularly relevant for systems facing greater exposure through external connectivity, such as remote vendor support conducted over public networks.
- Security Level 3 (SL3) – Comprehensive Protection: SL3 defines the most comprehensive set of security requirements for equipment deployed in high-risk or safety-critical environments. It emphasizes higher assurance through long-term upgrade planning, strong traceability, and complete technical documentation, particularly in settings where operational continuity and the protection of sensitive assets are critical.
Key Highlights Across Core Security Pillars
Computer Operating System and Software Vulnerability Management
Fab equipment frequently relies on computer operating systems and software components that may eventually reach End of Life (EOL) or no longer receive timely security patches. When these vulnerabilities remain unaddressed, they can become entry points for malware or other cyber threats, potentially compromising equipment stability, causing system failures, and disrupting fab operations.
Network Security Requirements
Network security is a critical element of fab equipment cybersecurity because improper configurations, unnecessary services, and unpatched vulnerabilities can expand the equipment's attack surface. The revised SEMI E187 emphasizes systematic hardening of both systems and network environments, including secure configuration practices, removal or disabling of non-essential functions, and timely remediation of supplier-identified vulnerabilities. To support secure deployment and long-term maintainability, equipment suppliers should provide clear and detailed guidance for installation, configuration, operation, and network hardening, enabling equipment users to implement consistent protections across fab environments.
Endpoint Protection Requirements
Endpoint protection is essential for preventing malware infections and unauthorized access to semiconductor equipment. The revised SEMI E187 reinforces the need for pre-shipment malware scanning to ensure that production equipment is delivered in a trusted state before entering fab environments. It also expects equipment suppliers to support endpoint protection mechanisms that can be installed, managed, and maintained by equipment users throughout operation. In addition, robust access control based on authentication and authorization should be implemented to reduce the risk of malicious intrusion or improper equipment access. SEMI E169, Guide for Equipment Information System Security, may be referenced for further guidance on authentication and authorization practices for information assets.
Conclusion and Call for Participation
The revision of SEMI E187 represents an important step toward strengthening cybersecurity resilience across semiconductor manufacturing environments. The task force aims to advance this revision into the balloting stage this year, and continued industry participation will be essential to ensure that the final document reflects practical needs, global alignment, and broad technical consensus. We welcome all committee members to join the discussion through Connect@SEMI or participate in upcoming task force and committee meetings to share valuable input and help shape the next version of SEMI E187.
Get Involved
SEMI Standards development activities take place throughout the year in all major manufacturing regions. To get involved, join the SEMI International Standards Program at: www.semi.org/standardsmembership.
For more information, please visit our main Web site and current events page. If you have any questions regarding SEMI Standards activities, please contact your local SEMI Standards staff.
Standards Watch
SEMI
www.semi.org
August 20, 2026