SCI Semiconductor has raised an oversubscribed £5 million round, led by PXN Ventures and Mercia Ventures, to ramp ICENI chip production and build a next generation device. The Sheffield based company says it has fabricated its first devices, secured more than £2 million in orders and won £7.7 million in government c...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How has Sheffield-based SCI Semiconductor raised a heavily oversubscribed £5 million round—led by NPIF II fund managers PXN Ventures and Mer. Article summary: SCI Semiconductor’s £5 million oversubscribed growth round gives it capital to move ICENI from initial silicon and orders into scaled production, while funding a next-generation chip. It is a bet that preventing a major . Topic tags: general, general web, government, news, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermar
SCI Semiconductor’s new £5 million growth round is a commercial test for a long-running cybersecurity idea: prevent certain memory errors in the processor architecture rather than trying to find and patch every instance in software. The Sheffield-based company will use the capital to increase production of its ICENI chips and develop a next-generation product. 3
6
The oversubscribed financing was led by PXN Ventures and Mercia Ventures, the managers of the relevant Northern Powerhouse Investment Fund II equity funds. Specialist cybersecurity investor Osney Capital, US-based Black Opal Ventures and private investors also participated. 3
6
SCI says the immediate priority is scaling production in response to demand for ICENI, alongside further chip development. The company has already fabricated its first devices and reports more than £2 million in orders. It also reports £7.7 million in government contracts and partnerships with Google Research and Microsoft. 6
12
Those figures indicate early market activity, but the larger challenge is converting interest into sustained product adoption: customers need hardware, software toolchains and applications that can work together in deployed systems.
ICENI is based on CHERI, a capability-based computer architecture developed through UK-backed research. CHERI uses memory-safe pointers and secure compartmentalisation to control how software accesses memory. The UK government describes it as a security-by-design approach intended to strengthen system security and remove many common memory-security vulnerabilities.
In practical terms, this is designed to make classes of failures such as invalid or out-of-bounds memory access harder to exploit. That is materially different from relying only on software checks after code has been written and deployed.
The potential is significant because memory-safety bugs remain a persistent source of security defects. UK government material cites Google and Microsoft research estimating that memory-safety bugs account for 70% of ongoing cyber vulnerabilities.
Memory errors are not only a theoretical security concern; they can also become reliability incidents. CrowdStrike’s July 2024 outage was not a cyberattack, but the company’s technical root-cause analysis found that a latent out-of-bounds read in its Content Interpreter contributed to system crashes after a problematic update.
That does not mean a CHERI-based design would have prevented every factor behind that outage. It does illustrate why organisations increasingly care about reducing entire bug categories rather than depending solely on detection and remediation after release.
The NCSC makes a similar strategic argument: memory-safety vulnerabilities are prevalent, and secure-by-design development could reduce the continuing burden of patch management and incident response. At the same time, the NCSC stresses that patching remains necessary, particularly for exposed and critical systems.
Hardware-enforced memory boundaries can reduce the likelihood or impact of some memory-corruption flaws. That can be especially valuable in products with long support lifecycles or in environments where failures have high operational consequences.
But memory safety is only one layer of security. CHERI-based hardware does not eliminate identity and access-control failures, insecure update processes, misconfiguration, social engineering, supply-chain risk or application logic errors. Organisations still need secure software practices, testing, monitoring, vulnerability management and timely updates.
The commercial question for SCI is therefore broader than chip performance: customers will need a credible path to integrate CHERI-aware hardware and software into real products without unacceptable cost, compatibility or development trade-offs.
The EU Cyber Resilience Act’s reporting obligations apply to manufacturers of products with digital elements. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security. An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours. 17
18
A memory-safe architecture may help manufacturers reduce exposure to some reportable memory-corruption vulnerabilities and demonstrate a stronger secure-by-design posture. However, it does not create automatic compliance. CRA obligations still require product-security governance, incident detection, vulnerability handling, reporting processes and the other applicable requirements.
SCI, founded in 2022, is also reported to be a core supplier to the UK Accelerated CHERI Adoption Programme and plans to add 15 roles to its 35-person Sheffield-and-Cambridge team. 11
14
The £5 million round gives the company runway to move from initial silicon and orders toward production scale. Its central proposition is straightforward: if memory-access rules can be enforced in hardware, some vulnerabilities can be prevented before they become a patching, outage or disclosure problem. Whether that proposition becomes a widely deployed product category will depend on customer integration, developer tooling and demonstrated performance in production systems.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
SCI Semiconductor has raised an oversubscribed £5 million round, led by PXN Ventures and Mercia Ventures, to ramp ICENI chip production and build a next generation device.
SCI Semiconductor has raised an oversubscribed £5 million round, led by PXN Ventures and Mercia Ventures, to ramp ICENI chip production and build a next generation device. The Sheffield based company says it has fabricated its first devices, secured more than £2 million in orders and won £7.7 million in government contracts.
For EU products with digital elements, actively exploited vulnerabilities and severe security incidents must now be reported with an early warning within 24 hours and a fuller notification within 72 hours.