Skip to content
Nenkin

PSA Certified: IoT Security Certification Maintained by GlobalPlatform

PSA Certified is a tiered IoT security certification programme whose seven founding companies are Arm, SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB (the certification body). The scheme was donated to GlobalPlatform in September 2025 and is now maintained there. It defines four assurance levels for chips, software, and devices, ranging from questionnaire-based self-assessment to laboratory evaluation against specified attack potentials.

Key facts

  • Maintaining body: GlobalPlatform (since September 2025)
  • Certification body: TrustCB
  • Founding companies: Arm, SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB
  • Country / region: Global
  • Year established: 2019; transferred to GlobalPlatform in September 2025
  • Product types: chips (silicon vendors), system software (RTOSes, middleware), and finished devices
  • CCRA status: Not a CCRA scheme; Level 4 evaluations use the SESIP methodology and are recognised under EUCC for IoT
  • Canonical portal: https://www.psacertified.org/

Overview

PSA Certified Level 1 is a self-assessment questionnaire reviewed by the certification body. Levels 2, 2 Ready, and 3 introduce laboratory-based robustness evaluation at increasing attack potentials, focusing on the chip’s Root of Trust. Level 4, introduced in 2024, adopts SESIP as its evaluation framework and aligns with the IoT state-of-the-art for EUCC-relevant evaluations.

How evaluations work under this scheme

For Level 1, the vendor completes the PSA Certified questionnaire and supplies evidence; the certification body reviews and issues the certificate. For Levels 2 and above, an accredited laboratory performs the evaluation activities against PSA Certified specifications (including the PSA Root of Trust specification) and produces an evaluation report. TrustCB issues the certificate and the result is published on the PSA Certified website.

Notable product categories

  • IoT microcontroller chips and system-on-chip products (silicon vendor certificates)
  • IoT RTOS and middleware components
  • Integrated IoT devices certified to Level 1 for baseline security labelling
  • Chips targeting Level 4 / SESIP 3 for higher-assurance IoT

Relationship to CC baseline

PSA Certified Levels 1 through 3 are distinct from Common Criteria, though they draw on similar threat-modelling and attack-potential concepts. Level 4, by adopting SESIP, brings the programme into methodological alignment with the CC family, including use of Security Target-style documents and CEM-inspired work units.

Where to find official records

See also: SESIP, Glossary.

Frequently asked questions

What is PSA Certified?
PSA Certified is a tiered IoT security certification programme launched in 2019 by seven founding companies: Arm, SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB (the certification body). The scheme was donated to GlobalPlatform in September 2025 and is now maintained there. It defines four assurance levels for chips, system software, and finished devices, ranging from questionnaire-based self-assessment to laboratory evaluation against specified attack potentials.
What does PSA Certified cover?
PSA Certified evaluates three categories: chips (silicon vendor IoT microcontrollers and system-on-chip products), system software (real-time operating systems, middleware, and secure firmware), and integrated finished devices. Evaluation focuses on the chip's Root of Trust, its isolation properties, and the security functions defined in the PSA Root of Trust specification.
What are the PSA Certified levels?
Level 1 is a self-assessment questionnaire reviewed by the certification body. Level 2 introduces laboratory robustness evaluation; Level 2 Ready is a stepping-stone variant. Level 3 raises the attack-potential coverage in laboratory evaluation. Level 4, introduced in 2024, adopts SESIP as its evaluation framework and aligns with the IoT state-of-the-art for EUCC-relevant evaluations.
How is a PSA Certified evaluation performed?
For Level 1, the vendor completes the PSA Certified questionnaire and supplies evidence; the certification body reviews and issues the certificate. For Levels 2 and above, an accredited laboratory performs evaluation activities against PSA Certified specifications, including the PSA Root of Trust specification, and produces an evaluation report. TrustCB issues the certificate and the result is published on the PSA Certified website.
Is PSA Certified a Common Criteria scheme?
No. PSA Certified is not a CCRA scheme. Levels 1 through 3 use distinct PSA-specific specifications, although they share threat-modelling and attack-potential concepts with Common Criteria. Level 4 brings methodological alignment by adopting SESIP, which uses Security Target-style documents and CEM-inspired work units. Level 4 is recognised under EUCC as state-of-the-art for IoT.
Who is behind PSA Certified?
PSA Certified was originally developed by seven founding companies: Arm, SGS Brightsight, CAICT, Riscure Keysight, UL, Prove & Run, and TrustCB. They governed the scheme through a Joint Stakeholder Agreement until September 2025, when the programme was donated to GlobalPlatform, where it is now maintained. TrustCB continues as the independent certification body that issues the certificates. The technical baseline is rooted in the Arm Platform Security Architecture.