Smart Card Chip Vendors Compared: ST, NXP, Infineon, Samsung by the Numbers
Procurement teams choosing a secure element ask a small set of repeatable questions. Who has the most CC-certified parts? In which assurance bands? Against which Protection Profiles? In which schemes? This post answers those for the four vendors that dominate the smart card and secure microcontroller market: STMicroelectronics, NXP Semiconductors, Infineon Technologies, and Samsung Electronics.
Numbers come from the NenkinTracker catalogue as of 2026-05-06. NXP appears under several legal-entity names (Germany GmbH, Netherlands N.V., USA Inc., and a few others); we have combined them into a single NXP bucket. Joint listings where an integrator (Idemia, Gemalto/Thales) is co-named with the chip vendor are excluded as integrator-led. Samsung SDS, a separate IT services subsidiary, is excluded.
STMicroelectronics
145 total certifications, 141 active and unexpired, 14 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (80 certifications). EAL5+ is the modal package at 70 of 145; EAL6+ at 16, EAL4+ at 11. The remaining 48 lack a CC EAL package (mostly SESIP and PSA work). Year by year: 6, 16, 14, 32, 45, 14 from 2021 through YTD 2026, the most pronounced upward trajectory of the four. Notable lines: ST33 family secure microcontrollers (ST33K1M5A, ST33K1M5C, ST33G1M2 series), NESLIB cryptographic library, ST33KTPM2X TPM modules, and the ST31P platform. Scheme presence: CCRA 97, PSA 23, SESIP 21, ESA 3, EUCC 1.
NXP Semiconductors (combined entities)
264 total certifications, 230 active and unexpired, 23 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP v1.0 (35).
NXP has the largest combined catalogue, but the headline deserves a caveat: 97 of NXP’s 264 certifications are in MIFARE, NXP’s own scheme and product family. Strip MIFARE out and the NXP CC-style total is 167, second after ST and ahead of Infineon and Samsung. Both numbers are real; which is more useful depends on what you are buying.
150 of NXP’s certifications carry no EAL package (the MIFARE and SESIP/PSA portions). Among CC-style entries, EAL5+ leads at 55, EAL6+ at 30, EAL4+ at 22. Year by year: 20, 53, 50, 46, 27, 23 from 2021 through YTD 2026. NXP peaked in 2022 to 2023 and has trended downward since, the inverse of ST. Notable lines: ChipDoc eID and ePassport applets (22 certifications), the NXP eDoc Suite, JCOP Java Card platforms (JCOP 4 P71, JCOP 4.5 P71, JCOP 8.x/9.x with eUICC extension), and the N7121 and N7122 Secure Smart Card Controllers. Scheme presence: CCRA 114, MIFARE 97, SESIP 26, PSA 23, EUCC 4.
Infineon Technologies
104 total certifications, 103 active and unexpired, 10 YTD 2026, average AVA_VAN 4.75. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (50). EAL6+ is the modal package at 51 of 104, the only vendor of the four where EAL6+ outweighs EAL5+. EAL5+ is second at 26, EAL4+ at 14. The 4.75 AVA_VAN average is the lowest here only because of a tail of AVA_VAN.4 certifications (9 of 36 parsed); the bulk of security IC work is at AVA_VAN.5. Year by year: 20, 9, 7, 24, 31, 10 from 2021 through YTD 2026, with the 2025 spike driven by SECORA ID X applet collections and OPTIGA TPM rollouts. Notable lines: SECORA ID X, the IFX_CCI security controller family, OPTIGA Trusted Platform Modules, and Infineon eID-OS. Scheme presence: CCRA 92, PSA 8, SESIP 3, EUCC 1.
Samsung Electronics
105 total certifications, 100 active and unexpired, 10 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (80). Samsung’s portfolio is the most concentrated of the four: 80 of 105 certifications conform to that PP, BSI-CC-PP-0084 (the Eurosmart-issued successor to the 2007 BSI-CC-PP-0035 Security IC PP). EAL6+ leads at 49, EAL5+ at 33. All 35 Samsung certifications with a parsed AVA_VAN are at AVA_VAN.5, the cleanest record here. Year by year: 14, 15, 18, 27, 19, 10 from 2021 through YTD 2026. Notable lines: the S3D family (S3D384C, S3D352C, S3D300C, S3D264C, S3D232C and the E variants), S3FT9 and S3FV9 RISC microcontrollers, the S3B512C/SC3512C secure element, and Samsung Knox work. Scheme presence: CCRA 101, EUCC 3, SESIP 1. Samsung has effectively no presence in PSA, ESA, MIFARE, or EMVCo.
Head-to-head
| Metric | ST | NXP | Infineon | Samsung |
|---|---|---|---|---|
| Total certs | 145 | 264 | 104 | 105 |
| Total ex-MIFARE | 145 | 167 | 104 | 105 |
| YTD 2026 | 14 | 23 | 10 | 10 |
| Active certs | 141 | 230 | 103 | 100 |
| Modal EAL | EAL5+ | EAL5+ | EAL6+ | EAL6+ |
| EAL6+ count | 16 | 30 | 51 | 49 |
| Avg AVA_VAN | 5.0 | 5.0 | 4.75 | 5.0 |
| Top PP usage | 80 | 35 | 50 | 80 |
| Schemes used | 5 | 5 | 4 | 3 |
| EUCC certs | 1 | 4 | 1 | 3 |
| 2025 volume | 45 | 27 | 31 | 19 |
A few observations:
- NXP leads on raw catalogue size, but more than a third of that lead is MIFARE. Ex-MIFARE the gap between NXP (167) and ST (145) narrows considerably.
- Infineon and Samsung are EAL6+ houses. Their portfolios skew higher than ST or NXP, which lean to EAL5+. If your constraint is the highest CC assurance available off the shelf, those two catalogues are the densest hunting grounds.
- Samsung is the most CCRA-concentrated. Minimal presence in non-CC schemes. If you need a chip that is also PSA Certified or SESIP attested, you are looking at NXP, ST, or Infineon, in that order.
- EUCC is still small everywhere. 1 to 4 certificates per vendor. Vendor-level adoption conclusions are premature.
- 2025 is when ST broke away. Until 2024 all four were in the same range. ST’s 45 in 2025 was nearly double Samsung’s.
- All four converge on the same PP. Security IC Platform PP with Augmentation Packages v1.0 is the most-used PP for every vendor here. See the most-used Protection Profiles.
Method note
Counts are from the NenkinTracker public bulk SEO manifest as of 2026-05-06. “Active and unexpired” means status is Active or unset and either no expiry is recorded or it lies in the future. “Average AVA_VAN” is the arithmetic mean across certifications whose security level string includes one. This is a comparison piece, not a buying guide: per-part pricing, supply, toolchain quality, second-source policy, and export controls are not in a certificates database.
See also
- The Most-Used Protection Profiles: what every chip vendor here is converging on
- Common Criteria in 2026 So Far: the broader context for the YTD numbers above