Skip to content
Nenkin

Smart Card Chip Vendors Compared: ST, NXP, Infineon, Samsung by the Numbers

Procurement teams choosing a secure element ask a small set of repeatable questions. Who has the most CC-certified parts? In which assurance bands? Against which Protection Profiles? In which schemes? This post answers those for the four vendors that dominate the smart card and secure microcontroller market: STMicroelectronics, NXP Semiconductors, Infineon Technologies, and Samsung Electronics.

Numbers come from the NenkinTracker catalogue as of 2026-05-06. NXP appears under several legal-entity names (Germany GmbH, Netherlands N.V., USA Inc., and a few others); we have combined them into a single NXP bucket. Joint listings where an integrator (Idemia, Gemalto/Thales) is co-named with the chip vendor are excluded as integrator-led. Samsung SDS, a separate IT services subsidiary, is excluded.

STMicroelectronics

145 total certifications, 141 active and unexpired, 14 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (80 certifications). EAL5+ is the modal package at 70 of 145; EAL6+ at 16, EAL4+ at 11. The remaining 48 lack a CC EAL package (mostly SESIP and PSA work). Year by year: 6, 16, 14, 32, 45, 14 from 2021 through YTD 2026, the most pronounced upward trajectory of the four. Notable lines: ST33 family secure microcontrollers (ST33K1M5A, ST33K1M5C, ST33G1M2 series), NESLIB cryptographic library, ST33KTPM2X TPM modules, and the ST31P platform. Scheme presence: CCRA 97, PSA 23, SESIP 21, ESA 3, EUCC 1.

NXP Semiconductors (combined entities)

264 total certifications, 230 active and unexpired, 23 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP v1.0 (35).

NXP has the largest combined catalogue, but the headline deserves a caveat: 97 of NXP’s 264 certifications are in MIFARE, NXP’s own scheme and product family. Strip MIFARE out and the NXP CC-style total is 167, second after ST and ahead of Infineon and Samsung. Both numbers are real; which is more useful depends on what you are buying.

150 of NXP’s certifications carry no EAL package (the MIFARE and SESIP/PSA portions). Among CC-style entries, EAL5+ leads at 55, EAL6+ at 30, EAL4+ at 22. Year by year: 20, 53, 50, 46, 27, 23 from 2021 through YTD 2026. NXP peaked in 2022 to 2023 and has trended downward since, the inverse of ST. Notable lines: ChipDoc eID and ePassport applets (22 certifications), the NXP eDoc Suite, JCOP Java Card platforms (JCOP 4 P71, JCOP 4.5 P71, JCOP 8.x/9.x with eUICC extension), and the N7121 and N7122 Secure Smart Card Controllers. Scheme presence: CCRA 114, MIFARE 97, SESIP 26, PSA 23, EUCC 4.

Infineon Technologies

104 total certifications, 103 active and unexpired, 10 YTD 2026, average AVA_VAN 4.75. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (50). EAL6+ is the modal package at 51 of 104, the only vendor of the four where EAL6+ outweighs EAL5+. EAL5+ is second at 26, EAL4+ at 14. The 4.75 AVA_VAN average is the lowest here only because of a tail of AVA_VAN.4 certifications (9 of 36 parsed); the bulk of security IC work is at AVA_VAN.5. Year by year: 20, 9, 7, 24, 31, 10 from 2021 through YTD 2026, with the 2025 spike driven by SECORA ID X applet collections and OPTIGA TPM rollouts. Notable lines: SECORA ID X, the IFX_CCI security controller family, OPTIGA Trusted Platform Modules, and Infineon eID-OS. Scheme presence: CCRA 92, PSA 8, SESIP 3, EUCC 1.

Samsung Electronics

105 total certifications, 100 active and unexpired, 10 YTD 2026, average AVA_VAN 5.0. Most-used PP: Security IC Platform PP with Augmentation Packages v1.0 (80). Samsung’s portfolio is the most concentrated of the four: 80 of 105 certifications conform to that PP, BSI-CC-PP-0084 (the Eurosmart-issued successor to the 2007 BSI-CC-PP-0035 Security IC PP). EAL6+ leads at 49, EAL5+ at 33. All 35 Samsung certifications with a parsed AVA_VAN are at AVA_VAN.5, the cleanest record here. Year by year: 14, 15, 18, 27, 19, 10 from 2021 through YTD 2026. Notable lines: the S3D family (S3D384C, S3D352C, S3D300C, S3D264C, S3D232C and the E variants), S3FT9 and S3FV9 RISC microcontrollers, the S3B512C/SC3512C secure element, and Samsung Knox work. Scheme presence: CCRA 101, EUCC 3, SESIP 1. Samsung has effectively no presence in PSA, ESA, MIFARE, or EMVCo.

Head-to-head

MetricSTNXPInfineonSamsung
Total certs145264104105
Total ex-MIFARE145167104105
YTD 202614231010
Active certs141230103100
Modal EALEAL5+EAL5+EAL6+EAL6+
EAL6+ count16305149
Avg AVA_VAN5.05.04.755.0
Top PP usage80355080
Schemes used5543
EUCC certs1413
2025 volume45273119

A few observations:

  • NXP leads on raw catalogue size, but more than a third of that lead is MIFARE. Ex-MIFARE the gap between NXP (167) and ST (145) narrows considerably.
  • Infineon and Samsung are EAL6+ houses. Their portfolios skew higher than ST or NXP, which lean to EAL5+. If your constraint is the highest CC assurance available off the shelf, those two catalogues are the densest hunting grounds.
  • Samsung is the most CCRA-concentrated. Minimal presence in non-CC schemes. If you need a chip that is also PSA Certified or SESIP attested, you are looking at NXP, ST, or Infineon, in that order.
  • EUCC is still small everywhere. 1 to 4 certificates per vendor. Vendor-level adoption conclusions are premature.
  • 2025 is when ST broke away. Until 2024 all four were in the same range. ST’s 45 in 2025 was nearly double Samsung’s.
  • All four converge on the same PP. Security IC Platform PP with Augmentation Packages v1.0 is the most-used PP for every vendor here. See the most-used Protection Profiles.

Method note

Counts are from the NenkinTracker public bulk SEO manifest as of 2026-05-06. “Active and unexpired” means status is Active or unset and either no expiry is recorded or it lies in the future. “Average AVA_VAN” is the arithmetic mean across certifications whose security level string includes one. This is a comparison piece, not a buying guide: per-part pricing, supply, toolchain quality, second-source policy, and export controls are not in a certificates database.

See also

Frequently asked questions

Who are the largest secure-element vendors?
STMicroelectronics, NXP Semiconductors, Infineon Technologies, and Samsung Electronics are the four chip vendors that dominate the smart card and secure microcontroller market. As of 2026, their Common Criteria certification volumes are: NXP 264 (167 excluding MIFARE), STMicroelectronics 145, Samsung 105, and Infineon 104. NXP leads on raw catalogue size; the gap narrows once MIFARE is excluded.
Which chip vendor has the most Common Criteria certifications?
NXP Semiconductors has the largest combined catalogue at 264 certifications, but 97 of those are in NXP's own MIFARE scheme. Excluding MIFARE, NXP has 167, second to STMicroelectronics at 145, and ahead of Samsung at 105 and Infineon at 104. Both numbers are real; which is more useful depends on what the procurement requires.
Which secure-element vendor has the highest assurance levels?
Infineon Technologies and Samsung Electronics skew highest. EAL6+ is the modal package for both: 51 of Infineon's 104 certifications and 49 of Samsung's 105 are at EAL6+. STMicroelectronics and NXP lean to EAL5+. If procurement constraints require the highest CC assurance available off the shelf, the Infineon and Samsung catalogues are the densest hunting grounds.
Which Protection Profile do most secure-element chips use?
Security IC Platform PP with Augmentation Packages v1.0 (sometimes labelled SECURITY_IC_AUGP_V1.0) is the most-used Protection Profile for every major chip vendor. STMicroelectronics has 80 certifications against it, Samsung 80, Infineon 50, and NXP 35. Convergence on this one PP is the rule, not the exception, in the secure-element corpus.
Do the major chip vendors participate in EUCC?
Yes, but EUCC volume is still small everywhere. NXP has 4 EUCC certifications, Samsung 3, STMicroelectronics 1, and Infineon 1. Across all four vendors combined, that is fewer than 10 certificates. Drawing vendor-level conclusions about EUCC adoption is premature; the scheme is operational but the chip-vendor corpus has only just started landing.
Which non-CC schemes do the top secure-element vendors use?
NXP and STMicroelectronics are present across the broadest set of schemes including CCRA, MIFARE (NXP only), SESIP, PSA Certified, and EUCC. Infineon participates in CCRA, PSA, SESIP, and EUCC. Samsung is the most CCRA-concentrated of the four with minimal presence in non-CC schemes. If procurement requires PSA Certified or SESIP attestation, NXP, STMicroelectronics, or Infineon are the choices.