NSA/CSS - National Security Agency - Central Security Service

08/25/2026 | Press release | Distributed by Public on 08/25/2026 08:06

NSA Releases Best Practices to Mitigate Threats in Development of ASICs

FORT MEADE, Md. - The National Security Agency (NSA) today released two technical reports addressing threats to application specific integrated circuits (ASICs) during the design and manufacturing process. The reports - ASIC Best Practices Threat Catalog and the Application Specific Integrated Circuit (ASIC) Level of Assurance 1 (LoA1) Best Practices - explain the threats against ASICs and recommend mitigations to reduce risk.

ASICs Best Practices Threat Catalog
The ASIC Best Practices Threat Catalog includes threat descriptions in 18 categories of adversary compromise based on common characteristics and mitigations. These categories include design requirements, information technology (IT) systems, electronic design automation (EDA) software, and third-party intellectual property (3PIP). Read the full ASIC Best Practices Threat Catalog for all the descriptions.

ASICs Level of Assurance
The ASIC Level of Assurance 1 (LoA1) Best Practices is the first of three technical reports focused on the detection and prevention of intentional threats to ASICs. Together, these reports will establish three "Levels of Assurance" for custom microelectronic hardware. NSA developed the reports in collaboration with the Department of War's Joint Federated Assurance Center Hardware Assurance (JFAC HwA) Laboratories.

Each LoA technical report will provide characteristics for the threats described in the Threat Catalog to determine appropriate mitigations. These characteristics are:

  • Access: the level of access required to conduct an attack
  • Technology: the level and complexity of technology required to conduct an attack
  • Investment: the cost of resources necessary to carry out an attack
  • Value of Effect: the measure of effectiveness of an effective attack by an adversary
  • Targetability: the measure of the attack's ability to reliably and predictably be directed to a specific target for a specific effect at a specific time

The LoA1 report is designed for stakeholders in custom microelectronic hardware and applies to ASIC-based designs where system failure could potentially reduce U.S. Government (USG) capabilities. Created using public use cases and input from JFAC HwA subject matter experts in the areas of ASIC design, hardware security, wafer manufacturing, and supply chain assurance, the LoA1 technical report provides multiple mitigation options, allowing users to tailor the best solutions for their needs.

Additional Resources:

Visit our full library for more cybersecurity information and technical guidance.

NSA Media Relations
[email protected]
443-634-0721

About the National Security Agency

Founded in 1952, NSA is a U.S. Department of War combat support agency and element of the U.S. Intelligence Community. The Agency's mission is to provide foreign signals intelligence to policy makers and our military, and to prevent and eradicate cybersecurity threats to U.S. National Security Systems, with a focus on the Defense Industrial Base and the improvement of U.S. weapons' security. From protecting U.S. warfighters around the world to enabling and supporting operations on land, in the air, at sea, in space, and in the cyber domain, NSA is committed to building public trust through transparency and protecting civil liberties and privacy consistent with our nation's values.

###

NSA/CSS - National Security Agency - Central Security Service published this content on August 25, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 25, 2026 at 14:06 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]