Intel and TSMC suppliers in the Phoenix metro get a spreadsheet and a clock, not a security department. Here is how to name the packet, tell the truth, and sign it yourself — without fake certificates.
If you run a 20–75 person shop in the East Valley, the “cybersecurity” problem that actually shows up is not a hoodie in a movie.
It is an email from a buyer or a supplier portal: complete this packet in about 30 days or the PO stalls.
Intel’s Ocotillo campus and TSMC Arizona Fab 21 did not invent paperwork. They did make it local. The same week a quality manager is releasing a job, they are asked questions written for a company that has a CISO. You do not.
This is the lane Arcane Digital Shield is taking: prepare the questionnaire. You sign it. We do not.
Name the packet before you write a word
People say “the Intel cert” or “the TSMC plaque.” Those names are usually wrong. Different files mean different work.
TSMC supplier information-security assessment. TSMC’s own ESG pages describe supplier standards covering 12 categories and 135 inspection items, training on Supply Online 360, and (since 2022) a mix of self-assessment plus third-party evaluation. You do not get a plaque. You get a portal and a spreadsheet. Source: TSMC ESG article on fab-equipment cybersecurity and 135 items.
SEMI E187 / E188. These are fab-equipment specs, not a general machine-shop diploma. E187 is a baseline for equipment computers (OS, network, endpoint, monitoring). E188 is malware-free delivery, install, service, restore. If you do not ship tools that sit on a fab network, do not volunteer “we’re E187.” If the purchase order names the spec, that is a different project. SEMI E187 store listing. SEMI E188 store listing.
Intel Information Security Addendum (ISA). That is a contract addendum for suppliers who touch Intel systems, facilities, or data. Intel may send a due-diligence questionnaire and expect an officer to attest. Intel supply-chain security.
RBA SAQ. The Responsible Business Alliance questionnaire is mostly labor, safety, environment, ethics. Intel still expects in-scope suppliers to complete it in RBA-Online. It is not your firewall diagram. Do not mash it into the ISA answers.
SIG-Lite vs full SIG. Shared Assessments’ Lite form is the short screening version. Full SIG / Core is the long one. Shorter is not “optional truth.” An officer still attests. SIG FAQ.
NIST SP 800-171 vs CMMC Level 1. If you also touch defense work: Level 1 is 15 basic safeguarding requirements in FAR 52.204-21 (Federal Contract Information). 800-171 is 110 requirements for CUI — the CMMC Level 2 neighborhood. DoW paused CMMC Phase II in July 2026; Phase I self-assessments remain. We are not a C3PAO and will not sell a certification. DoW CMMC About.
If you cannot name which of those you were sent, stop typing yes/no. Forward the first page.
How a 40-person shop is supposed to relate
You already have an MSP, or a “computer guy,” or a plant manager with a Microsoft 365 login.
The prime is not asking you to staff a SOC. They are asking whether:
- →MFA is enforced (usually already in the Microsoft or Google license you pay for — that is a setting, not a new SKU; Conditional Access is a different, paid feature — do not mix them up).
- →Laptops have real endpoint protection, not “whatever came with Windows.”
- →Shop-floor machines are not sitting on the same flat network as office email — or you have an honest plan if they still are.
- →Backups exist and someone has restored a file this year.
- →You can name who you call at 2 a.m.
That is a 20–75 person operation talking like an adult. It is not ISO 27001. If you do not have ISO 27001, do not write that you do.
Arizona MEP (NIST MEP via the Arizona Commerce Authority) can subsidize operations and sometimes a cyber overview. Use that money. They are not sitting in your conference room mapping 135 TSMC rows for 30 days. That is the gap we are offering to fill. Arizona MEP.
What “good” looks like (without lying about certs)
Good is:
- →True answers. A dated “no” plus an owner and a date (a POA&M) is something a prime can live with. A false “yes” is how you get a follow-up visit or a score that will not move.
- →Evidence that matches the sentence. Screenshot of MFA enforced. Last backup restore date. Vendor list for EDR.
- →The officer signs. The consultant does not. If a firm offers to “sign it for you,” hang up.
- →Scope honesty. SEMI E187 for a fixture shop is usually the wrong badge. CMMC Level 2 for a shop that only has FCI is the wrong mountain.
Credentials on this practice, said once: eJPT, ICCA, Google Cybersecurity Professional Certificate. Not CISSP. Not CISA. Not a CMMC assessor.
What we sell (and what we will not call it)
- →Free External Security Health Check — what a scanner already sees from the internet. Not a certification. Not an audit.
- →$250 Gap Assessment — we map your questionnaire to your reality and name the gaps.
- →$2,800 full engagement — drafted answers, missing short policies, POA&M. First three founding seats at $1,960 in exchange for a candid testimonial and an anonymized write-up. Remaining seats are the number on the site, not a fake countdown.
We do not sell an “audit.” Live operational technology (the line itself) is out of scope. You keep your MSP.
If the portal email is already in the inbox, start on the supplier questionnaire page or with the free External Security Health Check. Phone (480) 788-5419.
Sources (primary)
TSMC ESG — 12 categories / 135 items, Supply Online 360
TSMC ESG — supplier assessment + third-party evaluation
SEMI E187 store page · SEMI E188 store page
Intel ISA / supply-chain security
Ready to strengthen your security posture?
Get a professional assessment tailored to your business.