NXP Semiconductors

SE051 - EdgeLock IoT Secure Element, CC EAL6+ | NXP

MPN: SE051 βœ“ Active
In Stock Ships in 1-3 business days
20-HX2QFN (SOT1969-1), 3x3 mm Package
From $1.68 USD / Unit
MOQ: 1 |
Price updated: 2026-09-13
Volume Pricing
Qty Unit Price Extended
1 $2.85 $2.85
10 $2.56 $25.60
100 $2.2 $220.00
500 $1.92 $960.00
1,000 $1.68 $1,680.00
ℹ️ All prices are in USD

SE051 Overview

The NXP Semiconductors SE051 is a Plug & Trust IoT secure element with Java Card operating system, CC EAL 6+ (AVA_VAN.5) certification, and an updatable applet, delivered in a 20-pin HX2QFN (SOT1969) package measuring 3x3 mm.

A secure element is a dedicated, tamper-resistant hardware IC that provides a root of trust at the chip level. Within the system hierarchy, it sits below the host microcontroller in the security architecture (secure element -> hardware root of trust -> edge-to-cloud security platform) and offloads all cryptographic key storage and operations from the general-purpose MCU, so keys never exist in MCU memory where they could be exposed by software attacks.

Key features include turnkey Plug & Trust design-in with a complete support package (middleware, development kits, reference designs), applet updatability in the field via SEMS Lite, and support for developer-created custom applets. The SE051 extends the widely adopted EdgeLock SE050 family, inheriting its proven Common Criteria EAL 6+ certification up to the OS level with AVA_VAN.5 vulnerability assessment.

Technically, the SE051 runs a Java Card operating system and ships with a pre-installed applet optimized for IoT security use cases such as secure key storage, mutual authentication, and secure provisioning. Communication with the host processor is performed over a single-wire or I2C interface, following the same integration model as SE050, so existing SE050 host firmware and the Plug & Trust Nano middleware package can be reused directly.

Typical applications include IoT device identity and cloud onboarding, secure firmware updates, peripheral node authentication in industrial networks, and smart-meter or payment-adjacent designs requiring certified hardware security.

When designing the SE051 into a PCB, note that it is pin-to-pin and package compatible with EdgeLock SE050A/B/C/F variants (per NXP application note AN13014), enabling a single footprint to support SE050, SE050E, or SE051 depending on the required security feature set.

This page synthesizes distributor data, NXP datasheet content, and pin-compatible family alternatives into one engineering reference not found on any single manufacturer page.

Drop-in alternatives for SE051 β€” same package, pin-to-pin compatible. Different-package parts requiring PCB rework are excluded.

Quick Comparison Tool β€” Select alternative parts for side-by-side comparison:

SE050C2HQ2/Z01CDZ

βœ… Drop-In
πŸ“¦ 20-HX2QFN (SOT1969-1)
same package and pinout, fixed SE050 applet set without SEMS Lite updatable applet; otherwise equivalent certification

πŸ“‹ Reference alternative (not in catalog)

SE050E

βœ… Drop-In
πŸ“¦ 20-HX2QFN (SOT1969-1)
pin-to-pin and package compatible with SE051 per AN13014; enhanced SE050 generation without Java Card custom applet option

πŸ“‹ Reference alternative (not in catalog)

SE051A2HQ1/Z01XEZ

βœ… Drop-In
πŸ“¦ 20-HX2QFN (SOT1969-1)
same SE051 platform and package, A2 applet configuration (different pre-installed applet variant)

πŸ“‹ Reference alternative (not in catalog)

SE051C2HQ1/Z01XDZ

βœ… Drop-In
πŸ“¦ 20-HX2QFN (SOT1969-1)
C2 variant of the same SE051 platform, same package and pinout, different ordering/applet code

πŸ“‹ Reference alternative (not in catalog)

SE051W

βœ… Drop-In
πŸ“¦ 20-HX2QFN (SOT1969-1)
same SE051 platform with UWB-oriented (SE051W) feature set; used with SR150 UWB chipset designs

πŸ“‹ Reference alternative (not in catalog)

SE051 Specifications

Product Type Plug & Trust IoT Secure Element
Product Family EdgeLock SE05x (SE050 extension)
Operating System Java Card OS with updatable applet pre-installed
Security Certification Common Criteria EAL 6+ (AVA_VAN.5) up to OS level
Applet Updatability Yes, via SEMS Lite; custom applets supported
Package 20-HX2QFN (SOT1969-1), 3x3 mm
Pin Count 20
Host Interface Single-wire / I2C
Pin Compatibility Pin-to-pin and package compatible with EdgeLock SE050A/B/C/F and SE050E
Middleware Plug & Trust middleware / Nano package for host applications
Role Hardware root of trust, edge-to-cloud security
Mounting Type Surface Mount
Crypto Interfaces Secure key storage, mutual authentication, secure provisioning

SE051 20-hx2qfn (sot1969-1), 3x3 mm Pin Configuration Guide

Pin configuration for SE051 (20-hx2qfn (sot1969-1), 3x3 mm package). Pin numbering, functions, and connection diagrams are defined in the manufacturer datasheet. Refer to it for the exact footprint and soldering guidelines.

20-hx2qfn (sot1969-1), 3x3 mm package pinout diagram for SE051

No detailed pinout data available for SE051.

Refer to the datasheet for full pin configuration.

Typical Applications

SE051 is suitable for 6 applications: IoT Device Identity and Cloud Onboarding, Secure Firmware Update Signing, Industrial Peripheral Node Authentication, Smart Metering and Utility Edge Devices, Ultra-Wideband (UWB) System Security, Prototype and Evaluation with Plug&Trust Click.

🧩

IoT Device Identity and Cloud Onboarding

The SE051 fits IoT device identity applications because its pre-installed, updatable applet and CC EAL 6+ (AVA_VAN.5) hardware root of trust let each device carry a unique, injection-protected identity from the factory to the cloud. Device keys are generated and stored inside the secure element, so private material never appears on the host MCU bus or in MCU memory. In use, the host processor connects over single-wire or I2C and issues Plug & Trust APDUs through the NXP middleware to sign cloud attestation challenges. The quantified benefit is design speed: Plug & Trust middleware, Nano package, and development kits reduce provisioning software effort from months to weeks, while SEMS Lite keeps the identity applet updatable over the product lifetime.

πŸ”§

Secure Firmware Update Signing

For secure over-the-air firmware updates, the SE051 fits because it can hold the verification root key in CC EAL 6+ certified hardware and perform signature verification support in the element rather than trusting host code. The host MCU forwards the update manifest hash to the SE051 over I2C or single-wire, and the secure element performs the cryptographic operation internally, resisting glitching and key-extraction attacks that compromise software-only verification. Because the SE051 is pin-compatible with SE050 variants per AN13014, a bootloader designed around the SE050 footprint upgrades to updatable trust anchors via SEMS Lite without a PCB respin, protecting the investment as signing algorithms or certificate chains evolve across the deployed fleet.

🏭

Industrial Peripheral Node Authentication

Industrial networks benefit from authenticating sensors, actuators, and field modules before granting bus access, and the SE051 fits this role because its single-wire interface needs only one MCU GPIO plus ground, keeping per-node cost and board area minimal in the 3x3 mm HX2QFN20 package. Each peripheral board carries its own SE051 holding a unique certificate pair; the controller challenges the node at power-up through the Plug & Trust middleware, and cloned or counterfeit boards fail attestation. The Java Card OS with updatable applet lets operators rotate credentials in the field using SEMS Lite without recalling hardware, a measurable maintenance advantage over fixed-key authentication ICs in long-lifecycle factory deployments.

πŸ’‘

Smart Metering and Utility Edge Devices

Smart meters demand certified, tamper-resistant storage of billing and cryptographic keys, and the SE051 fits because CC EAL 6+ (AVA_VAN.5) certification up to the OS level satisfies the security audits typical of utility deployments. Its single-wire host interface minimizes isolation-boundary complexity, while the 20-pin 3x3 mm SOT1969-1 package occupies little PCB area on space-constrained meter mainboards. In operation, metering secrets and load-profile signing keys live exclusively inside the element; the metering SoC issues commands via the Plug & Trust middleware. Because the SE051 supports custom Java Card applets and field updates via SEMS Lite, utilities can add regional encryption schemes or re-key the fleet during a 15-plus-year service life without hardware change.

🌐

Ultra-Wideband (UWB) System Security

NXP pairs the SE051W secure element variant with the SR150 UWB chipset in UWB designs such as the Foxhound evaluation board, because UWB ranging and access-control systems (digital car keys, asset tracking) must authenticate before accepting range data. The SE051W stores the UWB session keys and device identity in EAL 6+ certified hardware, preventing cloning of UWB tags, while sharing the same SOT1969-1 HX2QFN20 footprint as the rest of the SE05x family per AN13014. Designers integrating the Murata Type 2BP module or an SR150-based radio can drop the SE051W onto the same footprint reserved for any SE050/SE051, so one carrier PCB supports secure ranging, plain ranging, or non-UWB identity products with component swaps only.

πŸ“Ί

Prototype and Evaluation with Plug&Trust Click

For evaluation, the SE051 fits rapid prototyping through the MIKROE-5392 SE051 Plug&Trust Click board, which places an SE051C2 on a mikroBUS form factor so any MCU with an SPI/I2C-capable mikroBUS socket can exercise the device in minutes. This shortens the path from concept to production: the same APDU commands and Plug & Trust Nano middleware used against the Click board run unchanged against the production SOT1969-1 part, because the Click uses the identical 20-pin HX2QFN device. Teams can validate provisioning flows, key injection, and SEMS Lite update procedures on the evaluation board before committing to PCB layout, and the Click board doubles as a reference schematic for the host-interface wiring and decoupling.

Recommended Products Summary

SE050C2HQ2/Z01CDZ Pin-compatible fixed-applet sibling for cost-optimized identity designs Used in: IoT Device Identity and Cloud Onboarding, Smart Metering and Utility Edge Devices MIKROE-5392 SE051 Plug&Trust Click evaluation board Used in: IoT Device Identity and Cloud Onboarding, Prototype and Evaluation with Plug&Trust Click SE050E Pin-compatible SE050E alternative with same footprint Used in: Secure Firmware Update Signing SE051C2HQ1/Z01XDZ C2 variant stocked at distribution for volume builds Used in: Industrial Peripheral Node Authentication, Ultra-Wideband (UWB) System Security, Prototype and Evaluation with Plug&Trust Click SR150 NXP UWB chipset paired with SE051W Used in: Ultra-Wideband (UWB) System Security
What is the NXP SE051 secure element?
The NXP SE051 is a Plug & Trust IoT secure element that provides a hardware root of trust with CC EAL 6+ (AVA_VAN.5) certification. It ships with a Java Card operating system and a pre-installed, updatable applet optimized for IoT security use cases, in a 20-pin HX2QFN (SOT1969) 3x3 mm package. According to the NXP SE051 datasheet, it is a turnkey solution designed for fast time to market with Plug & Trust middleware and development kits.
Where can I download the SE051 datasheet PDF?
The official SE051 datasheet PDF is available on NXP.com at https://www.nxp.com/docs/en/data-sheet/SE051.pdf. The document, titled Plug & Trust Secure Element, describes the product platform, its pin-to-pin compatible variants, and integration guidelines. A mirrored copy is also hosted by MIKROE at download.mikroe.com under SE051_datasheet.pdf, but the NXP.com link is the authoritative, always-current source.
What is the price of SE051?
As of 2026-09-13, SE051-family parts such as the SE051C2HQ1/Z01XDZ list on authorized distributors including DigiKey and Mouser; unit pricing for secure elements of this class typically falls in the 1.50 to 3.00 USD range at volume. Exact pricing varies by variant (SE051A2, SE051C2, SE051W), packaging quantity, and stock. XAIPART lists tier pricing on this page; request a quote for volume pricing above 1000 units.
Is SE051 pin-compatible with SE050?
Yes. According to NXP application note AN13014, the EdgeLock SE051 (and SE050E) are pin-to-pin and package compatible with EdgeLock SE050A, B, C, and F variants. All use the same HX2QFN20 flat package (SOT1969-1) with 20 pins and 3x3 mm dimensions, so one PCB footprint supports SE050, SE050E, or SE051 depending on the security feature set required.
What is the difference between SE051 and SE050?
The SE051 is an extension of the EdgeLock SE050 that adds applet updatability via SEMS Lite and allows developers to create their own custom applets, per the NXP SE051 product page. The SE050 ships with a fixed pre-provisioned applet set. Both are certified to CC EAL 6+ and share the same 20-pin HX2QFN package and host interface, making SE051 a superset in functionality within the same footprint.
SE051 vs SE050E - which should I choose for IoT device identity?
Choose the SE051 when you need Java Card OS flexibility, field applet updates through SEMS Lite, or custom applet development; choose the SE050E when a fixed turnkey applet with the same certification level is sufficient. Per AN13014, both are pin-to-pin compatible with SE050 in the SOT1969-1 HX2QFN20 package, so the decision is purely a security-architecture one - updatable/custom applets (SE051) versus fixed functionality - not a hardware redesign.
Can SE051 be used with an existing SE050 design?
Yes, the SE051 is a drop-in hardware replacement in SE050 designs. Per NXP AN13014, the SE051 is pin-to-pin and package compatible with SE050A/B/C/F, and it uses the same Plug & Trust middleware and single-wire/I2C host communication model, so existing host firmware and the Plug & Trust Nano package work unchanged in most integrations.
What is the best drop-in replacement for SE051?
The best drop-in alternatives are other members of the same EdgeLock SE05x/SE050 family: the SE050C2, SE050E, and SE051A2/C2 variants are pin-to-pin compatible in the same HX2QFN20 (SOT1969-1) 3x3 mm package per NXP AN13014. NXP does not publish a cross-brand pin-compatible equivalent; secure elements from other vendors use different packages and pinouts and would require PCB redesign.
What security certification does SE051 hold?
The SE051 is certified to Common Criteria EAL 6+ with AVA_VAN.5 vulnerability assessment, up to the operating system level. According to the SE051 Plug&Trust Click documentation from MIKROE/Mouser, the SE051C2 delivers proven security certified to CC EAL 6+ with AVA_VAN.5 up to the OS level, one of the highest certification levels available for commercial secure elements targeting IoT deployments.
What are the key specifications of SE051 that engineers should know?
Key SE051 specifications: Plug & Trust IoT secure element; Java Card OS with updatable pre-installed applet; Common Criteria EAL 6+ (AVA_VAN.5) to OS level; 20-pin HX2QFN (SOT1969-1) package, 3x3 mm; single-wire/I2C host interface; SEMS Lite applet update support; custom applet capability; pin-to-pin compatible with EdgeLock SE050A/B/C/F and SE050E per AN13014; Plug & Trust middleware and Nano package support for memory-constrained hosts.
Where to buy SE051 online?
The SE051 family (e.g., SE051C2HQ1/Z01XDZ) is stocked at authorized distributors DigiKey (product 18712817) and Mouser, and is available on XAIPART with tier pricing as of 2026-09-13. For production volumes, request a quote directly; for prototypes, cut-tape or tray quantities from distributor stock ship same-day where marked ships today.
Is SE051 in stock, and what is the lead time?
Distributor listings show the SE051C2HQ1/Z01XDZ shipping from DigiKey (ships today at time of listing) and stocked at Mouser, indicating healthy stock for the C2 variant as of 2026-09-13. Lead times for other SE051 variants (A2, W, or Q1 automotive grades) may differ; check live inventory on this page or with your distributor before scheduling production builds.
How do I integrate SE051 with my host microcontroller?
Integration follows NXP's Plug & Trust model: connect the SE051 to the host MCU over single-wire or I2C, and use the Plug & Trust middleware - including the optimized Nano package on GitHub (NXPPlugNTrust/nano-package) for memory-constrained hosts. NXP supplies development kits, reference designs, and application notes such as AN13014 for hardware migration. For fast evaluation, the MIKROE-5392 SE051 Plug&Trust Click board provides a mikroBUS form-factor reference.
Hey Google, what can replace SE051?
The closest replacements are pin-compatible NXP EdgeLock family members: SE050C2 and SE050E drop directly onto the same 20-pin HX2QFN footprint per NXP AN13014, and the SE051A2 variant differs only in applet configuration. There is no verified cross-brand pin-compatible equivalent - competing secure elements such as those from STMicroelectronics or Infineon use different packages, so replacement would require a PCB respin.
Does SE051 support applet updates in the field?
Yes, the SE051 supports field applet updatability through NXP SEMS Lite (Secure Element Management System Lite), as stated on the NXP EdgeLock SE051 product page. It also gives developers the option to create their own custom applets on the Java Card OS, which distinguishes it from the fixed-function SE050 and makes it suitable for products whose security features evolve over the device lifetime.
What IoT applications is SE051 designed for?
The SE051 is designed for IoT security use cases including device identity and cloud onboarding, secure key storage, mutual authentication between edge nodes and cloud platforms, secure firmware update signing, and peripheral authentication. Per the NXP datasheet, it provides state-of-the-art edge-to-cloud security right out of the box with its pre-installed updatable applet, in applications ranging from industrial sensor nodes to smart home devices.

Engineering reference data for SE051 β€” comparison, design guidance, and compliance information.

Selection Guide

Choose the SE051 when your IoT product needs a certified (CC EAL 6+) hardware root of trust whose applet can be updated in the field via SEMS Lite, or when you want to develop custom Java Card applets on the secure element. Choose SE050C2 or SE050E instead when a fixed, fully turnkey applet is sufficient and lowest software complexity matters - they drop onto the identical 20-pin HX2QFN SOT1969-1 footprint per NXP AN13014, so the choice can be deferred until after PCB layout. Within the SE051 platform, pick the C2 ordering code (SE051C2HQ1/Z01XDZ) for distributor-stocked general IoT builds, the A2 code when its applet configuration matches your provisioning flow, and SE051W only for UWB designs paired with the SR150 chipset. There is no verified cross-brand pin-compatible equivalent; competing secure elements require PCB redesign, so the SE05x footprint is a sound long-term layout investment.

Comparison with Alternatives

Parameter This Product SE050C2HQ2/Z01CDZ SE050E SE051A2HQ1/Z01XEZ SE051C2HQ1/Z01XDZ SE051W
Package 20-HX2QFN (SOT1969-1), 3x3 mm 20-HX2QFN (SOT1969-1) - same 20-HX2QFN (SOT1969-1) - same 20-HX2QFN (SOT1969-1) - same 20-HX2QFN (SOT1969-1) - same 20-HX2QFN (SOT1969-1) - same
Brand NXP Semiconductors NXP Semiconductors NXP Semiconductors NXP Semiconductors NXP Semiconductors NXP Semiconductors
Security Certification CC EAL 6+ (AVA_VAN.5) to OS level CC EAL 6+ (AVA_VAN.5) CC EAL 6+ (AVA_VAN.5) CC EAL 6+ (AVA_VAN.5) CC EAL 6+ (AVA_VAN.5) CC EAL 6+ (AVA_VAN.5)
Applet Updatability Yes - SEMS Lite + custom applets No - fixed applet set No - fixed enhanced applet Yes - SEMS Lite Yes - SEMS Lite Yes - SEMS Lite (UWB-focused)
Operating System Java Card OS with updatable applet NXP SE050 OS (fixed applet) NXP SE050E OS (fixed applet) Java Card OS Java Card OS Java Card OS
Custom Applet Support Yes No No Yes Yes Yes
Pin Compatibility with SE050 Yes (per AN13014) Native SE050 Yes (per AN13014) Yes Yes Yes
Target Use Case General IoT security, updatable identity General IoT security (fixed) Enhanced SE050 IoT security General IoT security (A2 applet) General IoT security (C2 applet) UWB system security (SR150 pairing)

Key Differentiators

  • Field-updatable applet via SEMS Lite (vs SE050C2HQ2/Z01CDZ)
  • Java Card OS flexibility (vs SE050E)
  • Turnkey Plug & Trust onboarding (vs SE051A2HQ1/Z01XEZ)
  • General IoT applet focus (vs SE051W)

Design Notes

Design the PCB footprint as the SOT1969-1 HX2QFN20 3x3 mm land pattern and reserve the SE050 pinout; per NXP application note AN13014, SE051, SE050E, and SE050A/B/C/F are pin-to-pin and package compatible, so a single footprint lets you qualify cost-optimized SE050 variants and the updatable SE051 on the same board. Place the 3x3 QFN with short traces to the host; the single-wire interface is sensitive to bus capacitance, so keep the SCL/SDA or S1 wire under a few centimeters where possible.

Supply the SE051 from a clean, always-on rail so keys and the updatable applet survive main-power cycles. Decouple VDD with a 100 nF ceramic capacitor placed within 2 mm of the package per standard QFN practice, and verify the supply sequencing requirements in the SE051 datasheet before sharing a regulator with the host MCU. Exact voltage range and current figures should be taken from the NXP SE051 datasheet table (see [DATA_NEEDED] markers on this page) rather than from secondhand values.

Do not assume all SE051 order codes are identical: SE051A2, SE051C2, and SE051W differ in pre-installed applet configuration and target use case (SE051W is oriented to UWB designs with the SR150). Confirm the variant code (e.g., SE051C2HQ1/Z01XDZ stocked at DigiKey) matches your provisioning plan before layout sign-off. Also note that migration from SE050 requires checking the AN13014 integration guidance - hardware is compatible, but applet behavior and SEMS Lite update flows differ from fixed SE050 applets.

Compliance Information

RoHS
Unknown
REACH
Unknown
AEC-Q100
Not Applicable
Lead Free
Unknown
Halogen Free
Unknown
Conflict Minerals
Unknown

Compliance status not stated in the provided web data; consult the NXP SE051 datasheet and product page for RoHS/REACH declarations.

Data verified on: 2026-09-13 β€” data verified and curated by XAIPART's component engineering team

Related Searches

SE051 datasheet NXP SE051 secure element SE051CC EAL 6+ IoT secure element SE051 HX2QFN20 SOT1969 package SE051 vs SE050 difference SE051 pin compatible SE050 drop-in replacement SE051C2HQ1 Z01XDZ buy price where to buy NXP SE051 in stock SE051 IoT device identity cloud onboarding SE051 SEMS Lite applet update what is the best replacement for SE051 NXP EdgeLock SE051 Java Card secure element

Related Components & Terms

NXP Semiconductors SE051 SE051C2HQ1/Z01XDZ SE051A2HQ1/Z01XEZ SE051W SE050 SE050E EdgeLock SE05x secure element hardware root of trust Java Card operating system Common Criteria EAL 6+ AVA_VAN.5 SEMS Lite HX2QFN20 SOT1969-1 QFN package family surface mount AN13014 Plug & Trust middleware single-wire interface I2C SR150 UWB chipset MIKROE-5392 Plug&Trust Click IoT device identity
Quick Quote RFQ
Fill in complete details β€” our sales team will respond within 24 hours
Part Number Manufacturer Package QTY Target Price Extended
Total: $0.00 USD
βœ“
Quote submitted!

We will respond to your email within 24 hours

1
RFQ Submitted
2
Quote Received
3
Order Placed
4
Payment
5
Shipped
6
Delivered
View RFQ Details