prEN 40004-3:2026

Cybersecurity requirements for Field Programmable Gate Arrays and Application Specific Integrated Circuits with security-related functionalities

General information

40.10   harmonizedStageCodeLabel.40.10   Aug 26, 2026

CENELEC

CLC/TC 47X

European Norm

31.200   Integrated circuits. Microelectronics | 35.030   IT Security

Scope

This document specifies the technical requirements for general-purpose Application Specific Integrated Circuits (ASICs) and Field Programmable Gate Arrays (FPGAs) with security features, related to cybersecurity. The products with digital elements in scope, thereafter "platforms":
— are specified within the "technical description" of the "category of product" number "NN" by the Commission Implementing Regulation (EU) 2025/2392 [16] as:
• “Application specific integrated circuits (ASIC) with security-related functionalities are products with digital elements that are integrated circuits, fully or partially custom-designed to perform a specific function or implement a specific application, and which additionally provide security-related functionalities that aim to secure other products, networks or services beyond the ASIC itself, such as trusted execution environments or secure communication interfaces.”

• “Field-programmable gate arrays (FPGA) with security-related functionalities are products with digital elements that are integrated circuits characterized by a matrix of configurable logic blocks designed to be reprogrammable after manufacturing to perform a specific function or implement a specific application, and which additionally provide security-related functionalities that aim to secure other products, networks or services beyond the FPGA itself, such as trusted execution environments or secure communication interfaces.”

— are only covered within the product context described in Clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 [16] Annex I Part I under the conditions identified in Annex ZZ.
ASICs and FPGAs additionally provide security-related functionalities, such as encryption, authentication, secure key storage, random number generation, trusted execution environment, or other hardware- based protection mechanisms, that aim to secure other products, networks or services beyond the ASIC or FPGA itself, such as secure boot chain, virtualization or secure communication interfaces
Such ASICs and FPGAs are intended to be integrated in a larger system, complemented by application software, and optionally by additional hardware components by integrators to build a device corresponding to a given intent of use. The intent of use of the platform integrated into a device is likely be known to the manufacturer of the ASIC with security-related functionalities, while the intent of use of the platform integrated into a device may not be known to the manufacturer of the FPGA with security-related functionalities.
The ASICs and FPGAs in scope are designed for deployment in environments where the security features of the product integrating the platform are of importance, and where the threat landscape includes attackers with low/medium attack potential.

Related legislation

Legislation related to this standard

2024/2847

Life cycle

NOW

IN_DEVELOPMENT
prEN 40004-3:2026
40.10 harmonizedStageCodeLabel.40.10
Aug 26, 2026