ASIC/FPGA Manufacturing

Custom application-specific integrated circuits (ASICs) should be fabricated through accredited trusted foundries, and field-programmable gate array (FPGA) devices should be procured through trusted suppliers with documented fabrication provenance, to reduce the risk of hardware Trojan insertion or unauthorized modification. Unlike software, hardware trojans embedded during semiconductor manufacturing are extremely difficult to detect through functional testing alone, as they may be designed to activate only under specific operational conditions or remain dormant indefinitely; the integrity of the fabrication source is therefore a primary defense. Trusted foundry accreditation provides assurance that the accredited fabrication activities are subject to security controls intended to reduce the risk of unauthorized modification. Assurance for design, intellectual property, aggregation, packaging, assembly, testing, and distribution must be addressed through trusted suppliers or other controls applicable to those lifecycle stages. This requirement applies to custom ASICs and to the base silicon used in FPGA implementations. The programmable design loaded onto an FPGA requires separate protection because trusted fabrication of the device does not establish the integrity or authenticity of the configured bitstream.

ID: CM0027
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate that all ASICs and FPGAs incorporated into spacecraft and mission-critical ground systems be fabricated by foundries that hold recognized trusted foundry accreditation, with the accreditation basis documented and subject to government verification before components are accepted into the program. Requirements should define the minimum accreditation criteria acceptable for the program, based on the mission's classification, criticality, and threat environment, and should specify that waivers to trusted foundry requirements require approval at a defined authority level with documented risk acceptance. Contract language should flow trusted foundry requirements to all subcontractors and suppliers providing ASIC or FPGA components, and should require contractors to maintain and submit documentation of foundry accreditation status for each custom or programmable device incorporated into the deliverable system. Evaluation criteria should assess offerors' established relationships with accredited trusted foundries, their experience managing trusted foundry requirements across complex supply chains, and their proposed approach to verifying foundry accreditation currency throughout the development lifecycle. Verification should include review of foundry accreditation documentation and component traceability records at relevant integration milestones, confirming that all ASIC and FPGA devices are traceable to an accredited manufacturing source.

Pre-Operations Developer/Supplier

Custom ASIC programs should identify an accredited trusted foundry early enough to incorporate foundry capabilities, eligibility requirements, availability, and fabrication schedules into design and tape-out planning. FPGA programs should identify trusted device manufacturers and approved sourcing channels early in component selection. The selection of a fabrication partner should be treated as a security-critical decision documented through the program's supply chain governance process, with foundry accreditation status verified at the time of selection and again at the time of each fabrication order to confirm that accreditation remains current. For FPGA-based designs, assurance of the base silicon must be supplemented by controls protecting the configured design. FPGA bitstreams should be authenticated and integrity-verified before configuration, with encryption and readback restrictions applied when protection of design confidentiality is required. Programming interfaces and processes should prevent unauthorized bitstream loading or modification. Post-fabrication verification should be selected based on component criticality, threat assessment, and available test capability. Verification may provide additional confidence that delivered devices conform to expected characteristics, but it should not be treated as proof that a device is free of malicious functionality. Component traceability records linking each ASIC or FPGA device to its specific fabrication lot, foundry accreditation documentation, and any post-fabrication verification results should be retained as controlled program records.