Microchip Technology CEC1736-S0-I/2HW
- Part No.:
- CEC1736-S0-I/2HW
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 64-VFBGA
- Datasheet:
-
CEC1736-S0-I/2HW.pdf
- Description:
- 1-CHANNEL PFR WITH 2MB FLASH AND
- Quantity:
- Payment:

- Shipping:

Inventory:2,391
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2HW from Microchip Technology is a Real Time Platform Root of Trust Controller implementing hardware-based secure boot (P-384), AES256, SHA-384, ECDSA, and True Random Number Generation (SP800-90B) for server, telecom, and industrial embedded systems. It features SPI Boot Flash monitoring with real-time intervention, hardware PUF, lifecycle management, and operates in 64-pin VFBGA (5.5×5.5×0.92 mm) at 96 MHz ARM Cortex-M4F core.
For engineers reviewing the CEC1736-S0-I/2HW datasheet, CEC1736-S0-I/2HW pinout, CEC1736-S0-I/2HW application, or CEC1736-S0-I/2HW equivalent, this page delivers verified technical context, secure boot flow details, QSPI0-only interface mapping, Soteria-G3 firmware integration, and validated alternative options for platform root-of-trust deployment.
Technical Context
The CEC1736-S0-I/2HW implements an immutable Boot ROM that authenticates and loads Soteria-G3 firmware from internal flash before enabling AP reset release. Its single QSPI0 port supports up to two external SPI flash devices for one Application Processor, with real-time SPI monitor intervention on illegal opcodes or unauthorized erase/write commands.
Hardware security primitives include CNSA-compliant P-384 secure boot, SP800-90B TRNG, lockable OTP memory for keys, and fused lifecycle states governing access to cryptographic resources. The device enforces NIST 800-193 and OCP Security Project compliance via SPDM-based attestation, firmware rollback protection, and transfer-of-ownership protocols executed by Soteria-G3 firmware.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core | 32-bit ARM Cortex-M4F @ 96 MHz - enables deterministic real-time execution of Soteria-G3 security services. |
| Secure Boot | P-384 ECDSA + SHA-384 - provides CNSA-aligned cryptographic strength for immutable Boot ROM and AP image authentication. |
| SPI Monitor | QSPI0-only real-time intervention - blocks illegal flash operations (e.g., chip erase) on one host interface without requiring external logic. |
| Package | 64-pin VFBGA (5.5×5.5×0.92 mm) - optimized footprint for space-constrained server and telecom control boards. |
| Internal Flash | 2 MB or 4 MB options - stores signed/encrypted Soteria-G3 images, customer certificate chains, and runtime data blocks. |
| Power Options | User-configurable 1.8 V or 3.3 V I/O - supports interoperability with diverse host processor voltage domains. |
| Crypto Engine | AES256 + ECDSA + DRNG - accelerates cryptographic operations for secure boot, attestation, and firmware updates without CPU overhead. |
Pinout & Package
CEC1736-S0-I/2HW uses a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package measuring 5.5 mm × 5.5 mm × 0.92 mm, designed for high-density PCB layouts in server and networking equipment.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO020/QSPI0_IN_CS0# | QSPI0 Chip Select 0 | Enables communication with first external SPI flash device attached to QSPI0 bus. |
| GPIO021/QSPI0_IN_CS1# | QSPI0 Chip Select 1 | Enables communication with second external SPI flash device on same QSPI0 bus. |
| GPIO055/QSPI0_CS0#/SPIMON_QSPI0_CS0# | QSPI0 Monitor CS | Triggers SPI Monitor hardware intervention when illegal access occurs on CS0-selected flash. |
| GPIO106/AP0_RESET# | Application Processor Reset | Holds AP0 in reset until Soteria-G3 completes secure boot and validates all critical firmware images. |
| GPIO003/I2C00_SDA(FATAL_ERROR#) | I2C Data / Fault Indicator | Provides status reporting to AP0 over I2C; asserts FATAL_ERROR# on unrecoverable security violation. |
| GPIO004/I2C00_SCL | I2C Clock | Supports run-time status queries and crisis recovery commands from AP0 via I2C interface. |
Key Features
| Feature | Design Value |
|---|---|
| Hardware-Based PUF | Generates unique, unclonable device identity for key binding and anti-counterfeiting without storing secrets in nonvolatile memory. |
| SPI Monitor Intervention | Real-time hardware blocking of illegal SPI commands (e.g., chip erase) on QSPI0 bus - works with standard 8-pin NOR flash. |
| Soteria-G3 Firmware | Pre-provisioned, MISRA-compliant, third-party penetration-tested firmware enabling SPDM attestation, secure firmware updates, and crisis recovery. |
| Lifecycle Management | Fused state machine controlling access to OTP, crypto engines, and debug interfaces across development, test, and production phases. |
| Differential Power Analysis Countermeasures | Hardware-level protections against side-channel attacks during cryptographic operations - certified per industry evaluation standards. |
Applications
| Server Secure Boot | Telecom Baseband Control |
|---|---|
Use Scenario: Ensuring integrity of BIOS and BMC firmware in dual-socket x86 servers prior to CPU initialization. IC Role / Device Role / Timing Role: Platform Root of Trust enforcing authenticated boot chain and runtime flash access control for primary AP. Use Value: Prevents persistent firmware implants by validating hash-matched AP images and blocking unauthorized flash writes via QSPI0 monitor. | Use Scenario: Securing baseband processor firmware in 5G radio units where remote update integrity is mission-critical. IC Role / Device Role / Timing Role: Real-time attestation agent providing SPDM-compliant measurement reports over I2C to host DSP/FPGA. Use Value: Enables zero-touch firmware validation and rollback protection using Soteria-G3's PLDM-based secure update and golden image recovery. |
| Industrial Edge Gateway | Network Switch Trusted Control Plane |
Use Scenario: Protecting Linux kernel and device driver images in ruggedized edge gateways deployed in unattended locations. IC Role / Device Role / Timing Role: Hardware-enforced secure boot controller managing single AP boot sequence and runtime I2C status reporting. Use Value: Delivers NIST 800-193 platform resiliency through automatic crisis recovery and authenticated firmware rollback prevention. | Use Scenario: Securing switch ASIC firmware and configuration tables in enterprise layer-3 switches with redundant control processors. IC Role / Device Role / Timing Role: Dual-role security controller performing AP image authentication and transfer-of-ownership handoff between active/standby control planes. Use Value: Guarantees firmware authenticity across failover events using Soteria-G3's ownership transfer and key revocation capabilities. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar platform root-of-trust applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2ZW | 84-pin WFBGA (7×7×0.8 mm); dual QSPI ports supporting two APs with independent flash monitoring. | Required for multi-AP systems (e.g., dual-CPU servers) needing isolated SPI monitor per host. | Select when system architecture requires concurrent monitoring of two independent SPI flash buses. |
| STM32H563VI | ARM Cortex-M33 @ 250 MHz; TrustZone-based secure boot; no integrated SPI monitor or SPDM attestation stack. | Used in cost-sensitive industrial controllers where software-defined security suffices and external flash protection is handled separately. | Choose only if full Soteria-G3 feature set (SPDM, crisis recovery, PUF) is not required and custom firmware development is acceptable. |
Compared with CEC1736-S0-I/2HW, the CEC1736-S0-I/2ZW adds dual-QSPI monitoring capability but increases board area and BOM cost, while the STM32H563VI lacks hardware-enforced SPI intervention and pre-certified Soteria-G3 firmware-requiring significant security validation effort for equivalent platform resiliency.
Availability
CEC1736-S0-I/2HW is available at Aetrix Electronics and suitable for server motherboard design, telecom baseband control, and industrial edge gateway development requiring stable component supply, long-term lifecycle support, and NIST 800-193 compliance.
Supply support for CEC1736-S0-I/2HW includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology Inc. is a U.S.-based semiconductor manufacturer specializing in microcontrollers, analog devices, and security ICs with global design and manufacturing infrastructure.
The CEC173x-TFLX product line delivers pre-provisioned, NIST 800-193-compliant platform root-of-trust controllers targeting server, telecom, and industrial embedded systems requiring hardware-enforced firmware integrity and attestation.
FAQ
What security certifications apply to the CEC1736-S0-I/2HW?
The CEC1736-S0-I/2HW implements CNSA Suite algorithms (P-384, AES256, SHA-384) and meets NIST SP 800-90B for TRNG entropy. Its Soteria-G3 firmware is MISRA-compliant, Coverity® and CERT® C-analyzed, and certified by third-party penetration tests. The device supports NIST 800-193 platform resiliency and Open Compute Project Security Project requirements - all verified in DS00005397A.
Does the CEC1736-S0-I/2HW support dual Application Processors?
No, the CEC1736-S0-I/2HW supports only one Application Processor via its single QSPI0 interface, as confirmed in Section 5.1 of DS00005397A. Dual-AP capability requires the 84-pin CEC1736-S0-I/2ZW variant with two independent QSPI ports and SPI monitors. This distinction is explicitly stated in the packaging options table and pinout documentation.
How does the SPI Monitor function on the CEC1736-S0-I/2HW?
The CEC1736-S0-I/2HW SPI Monitor observes QSPI0 traffic in real time and intervenes on illegal commands (e.g., chip erase) by asserting hardware control over flash signals before the operation completes. It operates with standard 8-pin NOR flash and supports both pre-boot signature verification and runtime access rule enforcement - detailed in Sections 6.2 and Figure 6-1 of DS00005397A.
What firmware is pre-installed on the CEC1736-S0-I/2HW?
The CEC1736-S0-I/2HW ships pre-provisioned with Soteria-G3 firmware, which implements secure boot, SPDM attestation, secure firmware updates via PLDM, crisis recovery, transfer of ownership, and key revocation. This firmware is immutable in Boot ROM and loaded from internal flash - as specified in Section 1.0 General Description of DS00005397A.
Can the CEC1736-S0-I/2HW operate at both 1.8 V and 3.3 V I/O levels?
Yes, the CEC1736-S0-I/2HW supports user-configurable 1.8 V or 3.3 V power specification for I/O interfaces, enabling direct interfacing with APs and flash devices operating at either voltage. This dual-voltage capability is documented in the Hardware Features list on page 1 of DS00005397A and confirmed in electrical characteristics tables.
CEC1736-S0-I/2HW Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 64-VFBGA
- Packaging:
- Tray
- Product Status:
- Discontinued at Digi-Key
- Programmable:
- Not Verified
- Applications:
- Real Time Platform Root
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, PWM, SMBus, SPI, UART
- Number of I/O:
- 52
- Voltage - Supply:
- 3.135V ~ 3.465V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 64-VFBGA (5.5x5.5)
CEC1736-S0-I/2HW FAQ
1.How can I place an order for CEC1736-S0-I/2HW through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2HW reliable?
The price and inventory of CEC1736-S0-I/2HW are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2HW?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2HW?
CEC1736-S0-I/2HW orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2HW order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW?
For technical support, including CEC1736-S0-I/2HW datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW requirements.
6.How does Aetrix verify that CEC1736-S0-I/2HW is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2HW products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2HW?
All CEC1736-S0-I/2HW units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2HW part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2HW:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2HW Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
