Silicon Labs’ Series 3 Secure Vault security subsystem, associated with the SiXG301 wireless SoC family, achieved PSA Certified Level 4. The certification indicates that this subsystem was evaluated for high resistance to sophisticated physical and software attacks. It strengthens the security foundation available to products built around the SiXG301, but it does not certify every Silicon Labs chip, complete device, or deployed IoT system.
What was certified
The certified product is Series 3 Secure Vault, associated with Silicon Labs’ SiXG301 SoC family. PSA Certified’s product listing records the following certificate details:
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
XG22-EK8200A, Development Tools - 802.15.1 EFR32xG22E Energy Harvesting Explorer Kit | $559.99 | Buy on Amazon |
| Field | Recorded value |
|---|---|
| Certified product | Series 3 Secure Vault |
| Associated SoC family | SiXG301 |
| Certificate number | 6327935204051-0001 |
| Certificate issue date | July 31, 2025 |
| Test laboratory | Keysight Riscure |
| Certification designation | PSA Certified Level 4 iSE/SE v2.0 BETA REL 03 |
Silicon Labs announced the achievement on August 4, 2025. The company described it as the world’s first PSA Certified Level 4 certification for a wireless SoC security subsystem; that “world’s first” wording is Silicon Labs’ announcement claim, not an independently established market audit.
What PSA Certified Level 4 evaluates
PSA Certified introduced Level 4 iSE/SE in April 2024. The designation is intended for an integrated secure enclave or an external secure element that must withstand highly capable physical and software attacks.
#1 Best Overall
- USHTS: 8517620090 CNHTS: 8543709990 JPHTS: 851762090
In its announcement, Silicon Labs says the Level 4 evaluation validates resilience to:
- Laser fault injection
- Side-channel attacks
- Microprobing
- Voltage manipulation
Those attack categories describe the threat scope named by Silicon Labs. The available certification record identifies the level, specification release and test laboratory, but does not publish detailed procedures or results for each attack class.
How this can improve IoT security
Stronger protection for high-value secrets
A certified secure subsystem can provide a more rigorously evaluated place to protect device keys and other security-sensitive operations than relying only on application software. For an IoT product, that can make extraction or manipulation of secrets more difficult when an attacker has physical access to hardware.
More resistance to physical tampering
Level 4 is aimed at threats that go beyond ordinary remote exploitation. Fault injection, probing and side-channel analysis attempt to observe or alter a chip’s behavior directly. Evaluation against those classes is particularly relevant to devices deployed in exposed locations or handled by untrusted parties.
A clearer security baseline for product teams
Engineers selecting the SiXG301 can use the named Secure Vault certification as evidence about the security subsystem’s assessed design and testing scope. It is a component-level assurance point that can support a broader threat model, security architecture and procurement review.
What the certification does not prove
- It does not certify every Silicon Labs SoC or every product branded with Secure Vault.
- It does not automatically certify a finished thermostat, sensor, gateway or other IoT device that uses the SiXG301.
- It does not guarantee that an application, firmware update process, cloud service or manufacturing process is secure.
- It is not, by itself, proof of regulatory compliance or immunity from every attack.
System security still depends on how a manufacturer configures the chip, manages credentials, validates firmware, controls debug access, updates software and protects backend services.
How to interpret the announcement dates
The certificate listing gives July 31, 2025 as the issue date. Silicon Labs’ public announcement came four days later, on August 4, 2025. These are separate milestones: the first is the certification record’s date, while the second is the vendor’s communication date.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for IoT developers
- Confirm the exact certified component. Verify that your design uses the Series 3 Secure Vault implementation associated with the SiXG301 family, rather than assuming the certification covers another Silicon Labs device.
- Map the subsystem to your threat model. Consider whether your product faces physical access, invasive analysis, fault injection or side-channel risks.
- Keep system controls in scope. Pair hardware protection with secure boot, authenticated updates, key provisioning, access control and service-side security appropriate to the product.
- Document the certification boundary. In compliance and procurement records, identify the subsystem, certificate number, certification designation and issue date instead of describing the entire product as PSA Level 4 certified.
Bottom line for buyers and engineers
Silicon Labs’ SiXG301-associated Series 3 Secure Vault has a PSA Certified Level 4 iSE/SE certificate, issued July 31, 2025 and tested by Keysight Riscure. That is meaningful evidence that the security subsystem was assessed against sophisticated physical and software threats. The practical benefit is a stronger, independently evaluated hardware security foundation—not a blanket security guarantee for every IoT device built with the SoC.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

