PSA Certified Announces New PSA Certified Level 4 Certification and Continued Partner Growth
PSA Certified, the global security and evaluation framework for the connected device ecosystem, has today announced its highest certification level to date as it accelerates its mission to build assurance in connected devices. The new PSA Certified Level 4 iSE/SE certification offers enhanced protection of high value assets that can secure valuable AI models, future-proofing systems against new attack methods and rising security threats linked to the rapid adoption of edge AI. Its launch follows a period of strong momentum for PSA Certified which has become a trusted route for demonstrating security best practice and the assurance of connected devices.
David Maidment, Senior Director, Secure Devices Ecosystem at Arm (a PSA Certified co-founder):
“As the world embraces a new set of AI-enabled use cases, the value of data and assets has never been higher; nor has the importance of protecting them. The launch of PSA Certified Level 4 iSE/SE is testament to our commitment to helping the industry deploy security features that will protect devices and models from malicious changes and theft now, as well as over the next decade.”
As security cements its position as a business imperative, forward-looking companies are uplevelling their investment in security-by-design. PSA Certified has now surpassed the milestone of 200 certifications from nearly 90 technology providers, making it one of the most successful schemes to address connected device security.
The newly launched PSA Certified Level 4 Integrated Secure Enclave / Secure Element (iSE/SE) certification, already available at PSA Certified Labs, builds on the scheme’s momentum further and underpins a step change that can be used to protect valuable models and data during device boot and at rest (when models reside in secure storage). The level recognizes the use of a highly robust integrated Secure Enclave (iSE) or Secure Element (SE) - that acts as a trusted subsystem to the full Root of Trust (PSA RoT). By safeguarding critical cryptographic functions and key storage, OEMs can now ask for a RoT with a trusted subsystem that offers a ‘high’ level of attack resistance.
Benefits of PSA Certified Level 4 iSE / SE Certification include:
Protecting ML models at rest with highly robust crypto and key storage
- PSA Certified Level 4 iSE/SE considers more sophisticated attack methods in scope. Chips that achieve this new level could be used in an AI context to help protect valuable models and data at boot and rest: some chips will need protection from advanced fault injection and differential power analysis (up to and including EMFI, single laser and multi-glitching). PSA Certified Level 4 iSE/SE chips will also benefit from stronger cryptography of at least 128-bit strength. The new level offers a “high” level of protection of the PSA-RoT assets from physical or software attack.
- A trusted subsystem that achieves PSA Certified Level 4 iSE/SE can be used through composition in a PSA Certified Level 3+SE certification of the full PSA RoT security functionality. The PSA Certified Level 3 document has been updated to allow this new certification level.
PSA Certified Level 4 iSE/SE will help protect emerging use cases from sophisticated security attacks
- PSA Certified Level 4 iSE/SE offers additional security against more advanced attacks. Chips that offer this RoT provide a strong trust anchor that could be used to decrypt and verify OTA updates which help protect models in high-value systems.
- Industrial and safety-critical use cases need to support system recovery and stronger authentication: re-establishing integrity, confidentiality and availability are fundamental when rebooting systems and deploying OTA updates when faults are found, or upgrades are required. PSA Certified iSE/SE also mandates higher strength cryptography, which protects against more sophisticated attacks.
- Trust anchor for Edge AI and infrastructure chips, providing a “High” level of protection against physical and software attacks on critical assets that require a more robust Root of Trust to maintain system integrity.
A transparent certification scheme with a route to High, Substantial, and Basic levels of robustness and assurance, purpose-built for the SoC market
- PSA Certified offers a variety of robustness levels to match the market’s needs, all specifically designed for the electronics industry. By allowing a trusted subsystem to be certified as a component, and that certificate reused as part of a complete PSA RoT many times, chip vendors benefit from significant time and cost savings.
The first partner to aim for the PSA Certified Level 4 iSE/SE standard is Infineon, showcasing its commitment to developing IoT devices to the highest security-by-design standards.
Erik Wood, Senior Director, IoT Secure MCU Products at Infineon comments:
“In the age of AI, the risks of insecurity are immense and increasing. I’ve backed PSA Certified since launch and I am impressed by its success in uniting the technology ecosystem around the common goal of improving trust and security within the connected device ecosystem, while aligning to emerging government standards and legislation. The launch of PSA Certified Level 4 iSE/SE takes that one step further. With this new level, the electronics industry is better able to protect against the growing advancement of attack methods driven by the explosion of machine learning, generative AI and LLM.”
About PSA Certified
PSA Certified is a global partnership of security-conscious companies who are proactively building security best practices into devices at scale. Our security framework and independent third-party evaluation scheme was originally spearheaded by Arm and six other security ecosystem leaders (and now maintained by Applus+ Laboratories, CAICT, ECSEC Laboratory, ProvenRun, Riscure, SGS Brightsight, Serma, TrustCB, and UL) providing the resources needed to build upon the Root of Trust.
PSA Certified has scaled to become one of the fastest growing, most valued security ecosystems, globally. Being awarded ‘Ecosystem of the Year’ in the IoT Global Awards 2021 is testament to the role it has played in uniting industry, standards bodies, regulators and insurers together under one initiative. In doing so it’s accelerating the cross-industry collaboration required to untap the full potential of the IoT.
With 200 certifications from 88 partners, PSA Certified has democratized the adoption of security across the electronics industry, giving the ecosystem the confidence to innovate, while protecting consumers from the most common hacks.
Find out more: psacertified.org
1 A Certified Security Report 2023
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240404517921/en/
Contact information
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Outpost24 Acquires Infinipoint to Power Its Entry into the Zero Trust Workforce Access Market9.12.2025 09:00:00 EET | Press release
Outpost24, a leader in exposure management and identity security, today announced the acquisition of Infinipoint, a specialist in device identity, posture validation, and secure workforce access. The acquisition marks Outpost24’s entry into the Zero Trust Workforce Access market and enhances its identity security division, Specops, by laying the foundation for a unified approach that evaluates both the user and the device before access is granted. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251208750630/en/ Ido Erlichman, Chief Executive Officer of Outpost24. As organizations advance their Zero Trust strategies, authentication alone is no longer enough. MFA and SSO confirm who the user is, but they do not validate the security of the device being used. In hybrid environments where employees, contractors, and partners rely on a mix of corporate and unmanaged devices, this gap has become a significant source of risk. Ensuri
VSO Submits VCP v1.0 to Nineteen Regulatory Authorities Across Thirteen Jurisdictions and Completes First Integrated Evaluation in a Production-Like Environment9.12.2025 09:00:00 EET | Press release
The VeritasChain Standards Organization (VSO) announced today that it has submitted the VeritasChain Protocol (VCP) v1.0 to nineteen regulatory authorities across thirteen jurisdictions, including the United States, United Kingdom, European Union, Singapore, Hong Kong, United Arab Emirates (DIFC), Australia, India, South Korea, Switzerland, Brazil, Liechtenstein, and Saudi Arabia. The submissions present VCP v1.0 as a cryptographic audit framework designed to address emerging supervisory requirements under the EU AI Act Article 12 for logging and traceability, and MiFID II / RTS 25 for timestamp integrity and event ordering in AI-driven and algorithmic trading systems. VSO also confirmed the first completed integration of VCP v1.0 within a controlled, production-like evaluation environment operating under its Early Access Program. The environment successfully generated cryptographically linked event chains, immutable hashing, and verifiable proofs using RFC-aligned structures, demonstr
ENGIE and NHOA Energy Expand Their Partnership in Belgium to Build a New 320 MWh Battery Energy Storage System9.12.2025 09:00:00 EET | Press release
NHOA Energy, global provider of utility-scale energy storage systems, has been awarded by ENGIE the contracts for the Supply, Commissioning and the Long-Term Service of a new 80 MW / 320 MWh Battery Energy Storage System (BESS) to be installed at the site of ENGIE’s Drogenbos power station, near Brussels. The Drogenbos BESS represents ENGIE’s third large-scale battery asset in Belgium and was selected in the country’s fifth Capacity Remuneration Mechanism (CRM) auction, securing a 15-year contract starting in November 2027. Designed to deliver essential flexibility services to the Belgian grid, enabling greater integration of renewable energy and supporting grid stability at national level, the BESS will be based on NHOA Energy’s NHEXUS platform, including 88 battery containers capable of providing up to 4 hours of discharge, corresponding to the average daily electricity demand of over 38,000 households. The project marks a significant new milestone in expanding the collaboration betw
2025 Sees Double-digit Increase in Tourists' Spending via Alipay+ in South Korea as Travellers Seek More Local Experiences9.12.2025 08:55:00 EET | Press release
Alipay+, Ant International’s global wallet gateway services, revealed an 18% increase in Alipay+-supported QR code payment transactions, with total payment volume (TPV) growing 16% year-on-year in South Korea, as more tourists use Alipay+ partner wallets and bank apps to make digital payments for a range of services, from beauty clinic treatments and transportation to night market food stalls. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251208351936/en/ Weixiao Jiang, General Manager North Asia and North America, Alipay+, Ant International South Korea is among the top destinations for tourists from regions such as Southeast Asia and the Chinese mainland, with the greatest number of tourists making transactions supported by Alipay+ in cities like Seoul, Jeju Island and Busan. In 2025, Alipay+ transactions for beauty clinic treatments, transportation and F&B were among the fastest-growing categories for tourists. Apart from
Interactive Brokers Expands Market Access with United Arab Emirates Equities9.12.2025 08:00:00 EET | Press release
Interactive Brokers (Nasdaq: IBKR), an automated global electronic broker, today announced the introduction of United Arab Emirates (UAE) equities through two leading exchanges in one of the world’s fastest-growing economic regions. Clients of Interactive Brokers worldwide can now access the Abu Dhabi Securities Exchange (ADX) and the Dubai Financial Market (DFM). This enables investors in the region to trade both local and international markets from a single platform while investors worldwide can build diversified portfolios across asset classes and geographies, including countries in the growing Gulf Cooperation Council (GCC). Interactive Brokers serves a global client base and is uniquely equipped to advance the financial goals of individual and institutional investors worldwide, including those in the Middle East. Adding UAE stocks further expands Interactive Brokers’ market access and enhances the investment opportunities available to local and global investors. Interactive Broker
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
