We start with a joint workshop to map your architecture, target markets, and threat landscape. Together we define the Target of Evaluation (ToE), select the right SESIP assurance level, and identify which SESIP profile fits your product category.
SESIP workshops bring your engineering, product, and security teams onto the same page: how the SESIP catalogue works, what evaluators will actually look for, and how SESIP relates to Common Criteria, PSA Certified, and the regulations on your roadmap.
The Security Target is where most SESIP projects succeed or stall. We help you select security functional requirements from the SESIP catalogue, write claims that are precise and testable, and assemble the architecture descriptions, threat models, and developer evidence your assurance level requires.
Before the clock starts on formal evaluation, our experts run vulnerability analysis and penetration testing against your product. You get findings and remediation guidance while there is still time to act on them.
As a licensed lab under the TrustCB SESIP scheme, we conduct the independent evaluation in our labs, perform the required testing for your assurance level, and deliver the Evaluation Technical Report to TrustCB for certificate issuance.
A TrustCB SESIP certificate is valid for five years from the issue date of the ETR. We help you plan for product updates, derivative certifications, higher assurance levels, and the reuse of your evidence in adjacent schemes and regulatory submissions.
SESIP was built for platforms and their parts — which means it applies at every layer of a connected product, from a software library to a finished device. Because certified components can be composed into higher-level products, SESIP is especially valuable to anyone building on top of someone else's silicon or stack.
SESIP defines five assurance levels. Each represents a step up in evaluator effort and in the attack potential your product is expected to resist. The right level is the one that matches your product's real threat model and your customers' expectations.
SESIP 1 is based on self-assessment. Evaluators do not independently verify that the platform implements the claimed security functional requirements, so the level provides a basic degree of assurance. It suits software components and platforms entering the market for the first time, low-risk consumer products where physical attack is implausible, and teams who want to establish a documented, structured security baseline before committing to independent testing.
SESIP 2 adds independent black-box penetration testing. It is the highest level that can be applied to a closed-source platform without developer cooperation, which makes it valuable when evaluating third-party or acquired components. Typical products include connected consumer devices, home hubs, routers and gateways, and closed-source platforms that need credible independent evidence for network-facing threats.
SESIP 3 is a traditional white-box vulnerability analysis, structured around time-limited source code review combined with time-limited penetration testing. It is the level most commonly requested by commercial customers and regulators. Typical products include secure microcontrollers and wireless SoCs, smart meters and grid devices, industrial controllers, automotive ECUs and gateways, and any platform where an attacker may have extended physical access to the device.
SESIP 4 was originally designed for the reuse of SOG-IS certified platforms and parts, allowing those platforms to draw on SESIP's mappings into specific commercial domains. That reuse path remains available, including for EUCC certification. CEN/CENELEC has since added a standalone evaluation methodology to EN 17927, so a SESIP-only SESIP 4 evaluation is now possible. It suits high-value components where sophisticated logical and physical attacks are in scope.
SESIP 5 shares the same origin as SESIP 4 — reuse of SOG-IS certified platforms and parts by licensed laboratories — and, with the CEN/CENELEC standalone methodology, can now also be pursued as a SESIP-only evaluation. It targets components that must withstand attackers with high attack potential, such as secure elements, secure enclaves, and Root of Trust implementations protecting cryptographic keys and other high-value assets.
Focus on advancing your product while Keysight guides you through SESIP preparation and evaluation.
Our team has spent decades finding real weaknesses in real embedded products, using side-channel analysis, fault injection, and hardware and firmware reverse engineering. That experience shapes how we scope, test, and advise — so your certificate reflects genuine resistance to attack, not just a completed checklist.
Most delays in SESIP projects trace back to an imprecise Security Target or evidence that does not match the claims. Our readiness assessments, training, and documentation support surface those gaps before the formal evaluation begins, which keeps timelines and budgets predictable.
We plan your SESIP work alongside the other schemes and regulations on your roadmap — CRA, RED, PSA Certified, IEC 62443, Common Criteria — so one body of evidence serves several obligations, and each new product or derivative costs less to certify than the last.
SESIP — the Security Evaluation Standard for IoT Platforms — is a security evaluation methodology for connected platforms and their components, published by GlobalPlatform and standardized by CEN/CENELEC as EN 17927. It defines a catalogue of security functional requirements and a set of assurance levels tailored to IoT products.
TrustCB operates the TrustCB SESIP scheme and issues certificates in accordance with GlobalPlatform SESIP (GP_FST_070) and CEN/CENELEC EN 17927. Evaluation itself is performed by licensed laboratories such as Keysight, which deliver an Evaluation Technical Report to TrustCB.
SESIP requirements are derived from Common Criteria (ISO/IEC 15408) but restructured for IoT platforms. The result is a lighter, faster evaluation with a reusable requirements catalogue and assurance levels calibrated to typical IoT deployment contexts — while keeping the methodological rigor that makes Common Criteria credible.
Platforms and parts of platforms: chips, secure elements, Roots of Trust, RTOSes and software stacks, connectivity and cryptographic components, and complete devices. Because SESIP supports composition, products built on a certified platform can reuse that platform's evidence.
It depends on your product's threat model, your customers' requirements, and any regulation you need to satisfy. SESIP 2 suits network-facing consumer products and closed-source components; SESIP 3 is the most common commercial level for devices exposed to physical access; SESIP 4 and 5 apply to high-value components facing sophisticated attackers. Our scoping workshop is designed to settle this question early.
Timelines depend on the assurance level, the complexity of the Target of Evaluation, and the maturity of your documentation. Levels 2 and 3 are structured around time-limited testing efforts, which makes them comparatively predictable. The largest variable is usually evidence readiness — which is why we recommend a pre-certification assessment.
A TrustCB SESIP certificate is valid for five years from the issue date of the Evaluation Technical Report, as defined in the scheme procedure.
Not automatically. SESIP certification produces strong, structured security evidence that supports CRA technical documentation and conformity assessment, but the CRA also imposes obligations around vulnerability handling, reporting, and product lifecycle that sit outside a SESIP evaluation. We can help you map what SESIP covers and what still needs addressing.
Yes. SESIP 4 and SESIP 5 provide a defined route for reusing SOG-IS or EUCC certified platforms and parts, allowing them to draw on SESIP's mappings into commercial product domains.
Yes. The TrustCB scheme supports both GlobalPlatform SESIP and CEN/CENELEC EN 17927, and we scope evaluations against whichever version fits your market and customer requirements.
A SESIP profile is a published set of commonly provided security functionality for a particular product category, defined using the SESIP catalogue. Profiles have been published by organizations including GlobalPlatform and PSA Certified, and using one shortens the work of writing a Security Target from scratch.
Our experts regularly share practical insights in our blog. Explore the latest developments in device security.
This certification is a major milestone for Silicon Labs and a testament to the strength of our collaboration with Keysight. Achieving PSA Certified Level 4 required more than just technical readiness—it demanded a testing partner with deep expertise, flexible processes, and a shared commitment to security excellence. Keysight played a critical role not only in guiding us through the evaluation but in pushing the limits of what we could achieve. Their rigorous approach and hands-on support made it possible to reach this advanced level of assurance.
Product Manager for IoT Security, Silicon Labs
What are you looking for?