In the rapidly expanding Internet of Things (IoT) landscape, ensuring robust security is paramount. Two prominent frameworks addressing this need are the Security Evaluation Standard for IoT Platforms (SESIP) and Platform Security Architecture (PSA) Certified. While both aim to streamline security evaluations and enhance trust, they cater to distinct aspects of IoT product security. Their synergies provide manufacturers with effective solutions to meet diverse regulatory and industry-specific requirements.
SESIP: Developed by GlobalPlatform, SESIP is a modular security evaluation standard tailored for IoT platforms. It focuses on the reuse of certified components, reducing redundancy and streamlining evaluations. SESIP’s alignment with international standards such as ISO/IEC and regional regulations makes it a versatile tool for compliance.
PSA Certified: Led by Arm and industry partners, PSA Certified offers a comprehensive security framework that integrates security from the design stage. It provides structured guidelines for threat analysis, secure design, and independent evaluation. Notably, PSA Certified incorporates SESIP protection profiles for Levels 2, 3, and 4, enabling a cohesive evaluation process. At Level 1, PSA Certified addresses the fragmentation of IoT security standards by aligning with key global regulations.
The following table highlights the key differences and synergies:
Aspect | SESIP | PSA Certified |
Focus | Modular platform evaluations | Comprehensive IoT device security, utilizing SESIP profiles for advanced levels |
Evaluation Levels | Five levels aligned with ISO/IEC standards | Four levels: Level 1 (basic) to Level 4 (advanced, SESIP-based) |
Protection Profiles | Industry can create specific profiles for specific needs. E.g. Automotive | Only PSA profiles accepted (root of trust for IOT chips) |
Certification Synergy | Independent but aligns with global standards | PSA Level 2–4 certifications include SESIP certification without extra costs or testing |
Market Target | Broad platform-based reuse | Holistic device-level assurance for IoT products |
The market targets for SESIP and PSA Certified reflect their distinct approaches to IoT security, addressing different stages of the product lifecycle and catering to varied security needs.
SESIP is designed for IoT platforms and modules that serve as foundational building blocks for multiple devices. Its modular approach emphasizes component reuse, allowing manufacturers to certify core security features of platforms or subsystems and reuse these certifications across a wide range of end products. This makes SESIP particularly suited for:
PSA Certified provides comprehensive device-level security assurance, guiding manufacturers from the initial design phase to final product evaluation. It ensures that IoT devices, whether consumer-facing or industrial, meet robust security requirements. PSA Certified is ideal for:
Fragmentation of standards and regulations is one of the biggest challenges in IoT security. PSA Certified Level 1 directly addresses this by aligning with major global guidelines and legislation, including ETSI EN 303 645, NIST 8259A, and Californian State Law SB-327. Additionally, PSA Certified is actively tracking and aligning with emerging regulations such as UK PSTI, European Cyber Resilience Act (CRA), RED Directive, IEC 62443 4-2, and CSA-311.
By maintaining alignment with current and upcoming standards, PSA Certified provides a flexible framework that reduces complexity and enhances regulatory adherence for IoT manufacturers.
SESIP and PSA Certified are complementary frameworks that create powerful pathways for IoT manufacturers to achieve efficient, cost-effective, and globally recognized security certifications. SESIP’s modularity supports platform-based reuse and and it is flexible to adapt to new market needs in different industries, while PSA Certified ensures device-level security. Together, they reduce complexity, streamline compliance, and foster innovation and resilience in the IoT ecosystem, enabling manufacturers to meet diverse market and regulatory needs.
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.