Embedded security for every engineer
Supporting your journey toward secure, CRA compliant embedded designs.
Security is no longer optional, but it doesn't need to be complicated. Whether you are retrofitting an existing design or building a new product from scratch, Microchip provides the hardware security features, development tools, and resources to help you strengthen your design and meet evolving cybersecurity/CRA requirements.
- Support CRA requirements with security documentation and risk assessment resources
- Protect keys, data, and device identity
- Enable secure boot and secure firmware updates
- Implement hardware-enforced security operations
Security starts with understanding your product requirements, risk profile, and regulatory obligations. A cybersecurity risk assessment helps identify vulnerabilities and determine the right approach.
For existing designs, security can be strengthened without a complete redesign. Depending on security measures sufficiency, accomplishing a risk assessment and submitting appropriate security documentation will be enough to demonstrate compliance. In case of known vulnerabilities, software updates or external secure elements like the ATECC608 family can help add secure key storage, device identity, and authentication to the design. Secure gateway solutions can extend protection to more complex connected systems.
For building a new, higher-assurance design: Secure MCUs like the PIC32CM SG00 is purpose-built for security from the ground up - Arm® TrustZone® for ARMv8-M plus an on-chip HSM-Lite, delivering hardware-enforced Secure/Non-Secure partitioning, anti-tamper detection, TrustRAM key storage, and cryptographic acceleration for secure boot, TLS, and encryption.
Microchip and DigiKey support your security journey with security-enabled devices, development resources, documentation, and tools to help accelerate secure embedded design.
- Your solution
- Understand your security requirements
- Develop with your preferred ecosystem
- Learning resources
Extend security in existing designs
Add security capabilities without starting over
For existing products, Microchip enables a practical path to strengthen security without requiring complete hardware redesign. For designs where existing security measures are sufficient, requirements can be addressed through technical documentation, risk assessments, and supporting evidence. For vulnerabilities that can be addressed through firmware improvements, software-based security measures such as secure firmware updates, authentication mechanisms, and vulnerability fixes can strengthen existing designs.
Standalone secure element devices and secure gateway solutions help add trusted device identity, key protection, authentication, and secure connectivity to existing systems. Access and find Microchip security solutions through DigiKey for fast product availability.
Secure element integration options:
- ATECC608 CryptoAuthentication™ devices supported with select Microchip MCUs.
- For more complex connected systems, add a secure element to MCUs, processors, and networking solutions to build a secure gateway design
Hardware Root of Trust: Higher-Assurance Architectures
Security-enabled MCUs with built-in security capabilities including secure boot, hardware cryptographic acceleration, key storage and protection, TrustZone®, secure firmware update support, device identity and authentication.
PIC32CM SG00 family
Designed and built for essential security
Cortex-M23, 72 MHz, 512 KB Flash, 32 KB SRAM
- Hardware Security Module Lite (HSM-Lite)
- Arm TrustZone secure / non-secure partitioning
- TrustRAM for tamper-resistant key storage
- TRNG + crypto acceleration
- Anti-tamper detection
- CAN-FD + USB FS
SAM L11 family ultra-low power with TrustZone
Chip-level security on ultra-low power
Cortex-M23 with Arm TrustZone
- Secure and Non-Secure partitioning
- Built-in cryptographic accelerator
- Secure communication channels through Secure pin multiplexing
- Integrated secure key storage
- Ultra-low power designs
Understand your security requirements
Security starts with understanding your product's risks and regulatory requirements. Your cybersecurity risk assessment determines what security features your product needs, while your CRA classification determines how compliance is demonstrated. Microchip provides the products, tools, and resources to help support both efforts.
Find Your Starting Point
Three questions, in order: what are the threats and risks surrounding my product, how serious are these threats to the operation of my product, what can I do to mitigate them reasonably?
Step 1: What does your product need to cover?
Every connected product needs to cover some version of these, from basic to advanced:
- Knowing your device is genuine
- Protecting your keys and secrets
- Making sure only real, unmodified firmware runs
- Locking down debug access after manufacturing
- Securing how your device talks to the outside world
- Detecting physical tampering
- Keeping it all secure over the product's life
How much you need of each one depends on your end design and its intended and foreseeable use.
Step 2: What's your CRA class?
Understand Your CRA Classification
Your CRA class determines how you demonstrate compliance.
CRA Classification
Default
Important Class I
Important Class II
Critical
Conformity Assessment
Self-assessment (~90% of products)
Self-assessment using harmonized standards
Mandatory third-party conformity assessment
Mandatory EUCC certification
Step 3: Now that you know what you need, here's how to get there.
Choose the Right Security Strategy/ Which Security Approach Fits Your Product?
Your CRA class determines how you demonstrate compliance.
Factor
Available Resources
Security Scope
Solution Sustainability
Time to Market
Choose Retrofit If...
Sufficient hardware and software headroom for modifications
Targeted vulnerabilities need to be addressed
A faster, short-term solution is needed
Existing designs need rapid security enhancements
Choose Secure-by-Design If...
Existing resources are limited or redesign is preferred
Complex, system-level security features are required
A long-term, future-proof approach is preferred
New product development timelines allow redesign
Understand More: MCUs With Integrated Security | Microchip Technology
MPLAB® Tools for VS Code and Trust Platform Design Suite (TPDS) provide a complete development environment to simplify secure embedded design. MPLAB Tools for VS Code brings the Microchip development workflow into a modern coding environment with streamlined setup, debugging, and software development capabilities. TPDS helps developers configure, provision, and integrate security devices with secure provisioning packages, example code, documentation, and learning resources. Together, these tools help accelerate the implementation of hardware-backed security from development through production.
|
Lightweight & fast LSP-based code intelligence, real-time error checking, go-to-definition, and smart autocomplete. No heavy IDE overhead. |
Full debug support PICkit™ 5, ICD 5, SNAP, and CMSIS-DAP integrated into the native VS Code debug toolbar. |
|
MPLAB AI coding assistant A free, Microchip-trained build of the Continue extension. Fewer hallucinations than generic AI tools, in-editor datasheet access, autocomplete, and code generation. |
Import in 5 clicks Already have an MPLAB X project? Import into VS Code using the MPLAB Project Importer Extension, no manual migration needed. |
|
MPLAB code configurator Graphical peripheral config and Harmony v3 support, set up TrustZone and peripherals without low-level register code. |
Cross-platform Windows, macOS, and Linux; the same free toolchain on every workstation. No per-seat licensing complexity. |
Complete security workflow
Configure, provision, and manage Microchip security devices through a single, intuitive platform- from evaluation to production.
Ready-to-use examples
Access example code, configuration guides, and resources to accelerate security integration into your application.
Production-ready security support
Streamline device personalization, certificate management, and secure provisioning processes for scalable deployment. Connect with Microchip experts Access technical resources and support to help address security implementation challenges throughout development.Secure provisioning made simple
Generate provisioning packages, configure security settings, and prepare devices for secure deployment with guided workflows.
Built-in learning resources
Explore Chiptorials, documentation, and training materials to understand security concepts and implementation steps.
Connect with Microchip experts
Access technical resources and support to help address security implementation challenges throughout development.

