Trusted Firmware Project
Trusted Firmware Project is an open governance community providing reference implementations of secure firmware for Arm processors, including TF-A, TF-M, MCUboot, and cryptographic libraries. It serves SoC developers, OEMs, and IoT manufacturers seeking PSA Certified-compliant security foundations.
- Company typePrivate
- Founded2018
- Headquarters—
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Trusted Firmware Project does
Trusted Firmware Project is an open governance community project that provides reference implementations of secure firmware for Arm-based processors and devices. Founded in 2018 and hosted by Linaro Limited's Community Projects Division, the project delivers a portfolio of eight software products covering trusted boot, Trusted Execution Environments (TEEs), Secure Processing Environments (SPEs), cryptographic libraries, and continuous integration infrastructure. The portfolio includes Trusted Firmware-A (TF-A) for Armv8-A/Armv9-A application processors, Trusted Firmware-M (TF-M) for Armv8-M/Armv8.1-M microcontrollers, MCUboot secure bootloader, OP-TEE TEE, Hafnium Secure Partition Manager, Mbed TLS and TF-PSA-Crypto cryptographic libraries, TF-RMM Realm Management Monitor for Confidential Computing, Trusted Services framework, and Rusted Firmware-A (RF-A) — a Rust-based implementation of TF-A BL31 for Armv9-A.
The project serves SoC developers, OEMs, embedded/IoT device manufacturers, and mobile/automotive/server OEMs who need specification-compliant secure firmware for Arm-based platforms. TF-M is specifically designed to enable PSA Certified Level 1 and Level 2 security certification, making it the de facto reference for IoT security compliance. The codebase is deployed in billions of devices across mobile, IoT, automotive, and server markets.
The project operates as a member-driven, member-funded nonprofit with no commercial revenue from the software itself. Organizations join at Diamond, Platinum, or General tiers to fund development, contribute code, and influence governance. The 10 current members include Arm and Google (Diamond); Linaro, STMicroelectronics, Renesas, NXP, and Qualcomm (Platinum); and Futurewei, Provenrun, Nordic Semiconductor, and Texas Instruments (General). Distribution is entirely through open source channels (Git/Gerrit repositories, GitHub mirrors, ReadTheDocs documentation) with free Open CI infrastructure for hardware validation.
Trusted Firmware Project firmographics
Firmographics- Name
- Trusted Firmware Project
- Legal name
- Linaro Limited
- Website
- https://trustedfirmware.org
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Trusted Firmware Project is an open governance community providing reference implementations of secure firmware for Arm processors, including TF-A, TF-M, MCUboot, and cryptographic libraries. It serves SoC developers, OEMs, and IoT manufacturers seeking PSA Certified-compliant security foundations.
- Ownership category
- akta.pro rank
Trusted Firmware Project industry classification
Industry- Product category
- Embedded Systems Security Software
- NAICS
- Software Publishers (51321)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
- akta.pro secondary industries
- Secure Elements & Trusted Execution Processors (TPM/TEE/Crypto MCUs) (HDAHAJAK), Security & Trusted Hardware ICs (Secure Element/TPM/Crypto) (HDAHABAF), Key Management, Encryption & Secrets Management (KMS/HSM/Vault) (HDABAHAG), Quantum-Safe Hardware & Embedded Security (TPM/secure elements/firmware) (HDAGAGAJ), Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
Keywords
Trusted Firmware Project business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Others
Revenue model
- Membership Funding: The project is member-driven and member-funded. Organizations join at different tiers (Diamond, Platinum, General) to fund development and gain governance influence. No direct product revenue is generated from the open source code.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Trusted Firmware Project product offering
Product offeringCore offering
Trusted Firmware Project provides open source reference implementations of secure firmware for Arm-based processors and devices. Its portfolio includes Trusted Firmware-A (TF-A) for A-profile/Armv8-A/Armv9-A application processors, Trusted Firmware-M (TF-M) for M-profile/Armv8-M microcontrollers, Hafnium Secure Partition Manager, OP-TEE Trusted Execution Environment, MCUboot secure bootloader, Mbed TLS, TF-PSA-Crypto, Trusted Services framework, TF-RMM Realm Management Monitor, Rusted Firmware-A (RF-A), and Open CI infrastructure. These reference implementations serve as the foundation of Trusted Execution Environments (TEE) and Secure Processing Environments (SPE), enabling PSA Certified security compliance for SoC developers, OEMs, and embedded device manufacturers.
Product overview
The Trusted Firmware Project provides a suite of open-source reference implementations of secure software for Arm processors. The portfolio includes Trusted Firmware-A (TF-A) for application processors supporting A-Profile Armv8-A/Armv9-A architectures, and Trusted Firmware-M (TF-M) for microcontroller processors supporting M-Profile Armv8-M/Armv8.1-M architectures. Supporting products include TF-RMM for Realm Management in Confidential Computing, Hafnium as Secure Partition Manager for Secure-EL2, OP-TEE as Trusted Execution Environment, MCUboot as secure bootloader, and Mbed TLS with TF-PSA-Crypto for cryptographic services. Additional offerings include Trusted Services for secure partition deployment, Open CI for continuous integration infrastructure, and Rusted Firmware-A (RF-A) as a Rust-based implementation of TF-A. The projects form the foundations of Trusted Execution Environments (TEE) on application processors or Secure Processing Environments (SPE) on microcontrollers, enabling PSA Certified security for Arm-based devices.
Differentiator
Problem solved
Functional benefit
Brands
- TF-A (Trusted Firmware-A): Reference implementation of secure software for Armv8-A and Armv9-A application processors, providing trusted boot and EL3 runtime firmware.
- TF-M (Trusted Firmware-M)
- MCUboot
- Hafnium
- OP-TEE
- Mbed TLS
- TF-PSA-Crypto
- Trusted Services
- RF-A (Rusted Firmware-A)
- TF-RMM (Realm Management Monitor)
- Open CI
Products and services
- Trusted Firmware-A (TF-A) Reference implementation of secure software for A-Profile Armv8-A and Armv9-A application processors providing trusted boot and runtime services at EL3, forming the foundation of Trusted Execution Environments (TEE) on application processors.
- Trusted Firmware-M (TF-M) Reference implementation of Platform Security Architecture (PSA) Secure Processing Environment (SPE) for Armv8-M and Armv8.1-M architectures (Cortex-M23, M33, M55, M85), enabling PSA Certified compliance for microcontrollers and IoT devices.
- MCUboot Secure bootloader for 32-bit microcontrollers supporting image signing, encryption, and swap/update strategies, providing a common foundation for building secure bootloader applications on embedded systems.
- TF-RMM (Realm Management Monitor) Reference implementation of the Arm Realm Management Monitor (RMM) specification for Realm Management Extension (RME) in Armv8-A and Armv9-A systems, enabling Confidential Computing with isolated Realm worlds.
- Hafnium Reference Secure Partition Manager (SPM) for systems implementing the Armv8.4-A Secure-EL2 extension, enabling multiple isolated Secure Partitions to run at Secure-EL1 with hypervisor-level security isolation.
- OP-TEE Trusted Execution Environment designed as companion to non-secure Linux kernel on Arm Cortex-A cores using TrustZone technology, implementing TEE Internal Core API v1.1.x and TEE Client API v1.0 per GlobalPlatform specifications.
- Mbed TLS Comprehensive cryptographic library and TLS 1.3 protocol stack implementing PSA Crypto APIs, providing cryptographic primitives, TLS/DTLS protocols, and X.509 certificate handling for secure communications.
- TF-PSA-Crypto Reference implementation of PSA Cryptography API specifications providing portable interfaces to cryptographic operations and key storage following PSA Certified framework requirements.
- Trusted Services Framework for developing and deploying device root-of-trust services for A-profile devices as Firmware Framework-A Secure Partitions, providing PSA Crypto, Storage, and Attestation Secure Partitions plus UEFI SMM services for Cortex-A devices.
- Open CI Cloud-based continuous integration infrastructure leveraging Gerrit, Jenkins, and LAVA for end-to-end integration and testing, validating code changes on physical hardware platforms and Arm Fixed Virtual Platforms in a dedicated hardware lab.
- Rusted Firmware-A (RF-A) Rust-based implementation of EL3 runtime firmware (BL31) for Armv9-A and later systems, providing a modern, memory-safe alternative to C-based TF-A BL31 with full architectural feature support.
Quantifiable outcome
- Trusted Firmware-A and TF-M are deployed in billions of devices across mobile, IoT, automotive, and server markets
- +1 more outcomes
Companies that use Trusted Firmware Project
Customer profileSegments3 records
Ideal customer profiles2 records
Trusted Firmware Project technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
Feature10 records
Trusted Firmware Project partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered core, general and project_partner.
- Qualcomm TechnologiescoreJoined as Platinum member in March 2026. Qualcomm contributes platform expertise for mobile, automotive, IoT, and compute markets. Focus on advancing open collaboration in secure firmware and platform security standards.
- ArmcoreDiamond member and founding contributor to Trusted Firmware. Arm provides specification input, architectural guidance, and engineering contributions to TF-A, TF-M, Hafnium, and other projects. The project implements Arm's security specifications as preferred reference implementations.
- GooglecoreDiamond member providing strategic direction and engineering contributions. Focus on Android ecosystem security requirements and platform security alignment.
- LinarocorePlatinum member and host of Linaro Community Projects Division which provides administrative infrastructure, Open CI systems, and engineering coordination for Trusted Firmware. Linaro employees serve as project maintainers and contributors.
- STMicroelectronics (ST)corePlatinum member contributing STM32 platform support, extensive TF-M and TF-A validation, and product integration work for ST's STM32 microcontrollers.
- Renesas ElectronicscorePlatinum member contributing R-Car automotive processor support for TF-A and RZ embedded processor enablement.
- NXP SemiconductorscorePlatinum member providing LPC and i.MX platform support for TF-M, extensive validation on NXP Cortex-M microcontrollers.
- FutureweigeneralGeneral member contributing to project development and ecosystem expansion.
- ProvenrungeneralGeneral member providing security expertise and contributions to secure firmware implementations.
- Nordic SemiconductorgeneralGeneral member and contributor to MCUboot project. Nordic contributes nRF connectivity MCU platform support and bootloader expertise.
- Texas InstrumentsgeneralGeneral member contributing TI K3 platform support for TF-A including initial support for AM62L and expanded ARM64 processor enablement.
- BUGSENGproject_partnerProject partner providing ECLAIR code verification tools for static analysis and safety compliance (MISRA) across Trusted Firmware projects.
- CloudBeesproject_partnerProject partner providing CI/CD infrastructure tools supporting the Open CI build and test systems.
Scale indicators3 records
Recent moves7 records
Expansion highlights5 records
Trusted Firmware Project competitors and assessment
Company assessmentBroad incumbents
- Arm Holdings: Spec owner and Diamond member of Trusted Firmware. Comparable as the upstream architecture authority whose specifications Trusted Firmware implements; not a direct competitor but a broader incumbent shaping the same security ecosystem.
- Green Hills Software: Commercial vendor of INTEGRITY RTOS and secure development tools for safety- and security-critical embedded systems. Comparable as a broader incumbent in the secure embedded/IoT firmware space competing for high-assurance deployments.
- Wind River Systems: Commercial embedded software vendor offering VxWorks and Wind River Linux with security/certification offerings for aerospace, automotive, and industrial. Comparable as a broader incumbent offering secure embedded software stacks that overlap with Trusted Firmware deployments.
Others
- Linaro: Host organization of the Trusted Firmware Project via its Community Projects Division. Comparable as the parent/effective operator providing administrative, CI, and engineering infrastructure; Linaro is Platinum member and the day-to-day steward of the project.
- PSA Certified: Industry certification scheme for secure silicon, RTOS, and devices. Comparable as the ecosystem enabler whose certification levels are implemented by Trusted Firmware, and whose adoption drives demand for TF-M across IoT vendors.
Emerging players
- Zephyr Project: Open source RTOS for connected, resource-constrained devices. Integrates with TF-M and shares overlapping members (Linaro, Nordic, NXP); comparable as Linux Foundation-hosted open governance project for embedded/IoT with secure firmware ambitions.
- Apache NuttX: Open source RTOS targeting resource-constrained environments with growing Arm ecosystem support. Comparable as an open-governance embedded OS project that increasingly integrates with Trusted Firmware for secure boot and PSA-level features.
Direct peers
- coreboot: Open source firmware project providing alternative boot firmware for x86 and Arm platforms. Comparable as a community-maintained reference firmware project serving silicon vendors and OEMs across architectures.
- OpenTitan: Open source project for silicon root of trust, with lowRISC as host. Directly comparable as an open-governance community delivering secure silicon/firmware foundations backed by major industry members (Google, NXP, Western Digital, etc.).
- EDK II / TianoCore: Open source reference implementation of UEFI firmware. Highly comparable as a vendor-neutral community project providing reference firmware for major hardware ecosystems, with similar open governance and corporate member sponsorship model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Trusted Firmware Project social profiles
Digital presenceTrusted Firmware Project compliance and trust
Trust signalCompliance1 record
Trusted Firmware Project financial estimates
Financial estimateRevenue estimate
Valuation estimate
Trusted Firmware Project leadership team
Management profileNumber of profiles
Trusted Firmware Project funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Trusted Firmware Project M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Trusted Firmware Project
What does Trusted Firmware Project do?
Trusted Firmware Project provides open source reference implementations of secure firmware for Arm-based processors and devices. Its portfolio includes Trusted Firmware-A (TF-A) for A-profile/Armv8-A/Armv9-A application processors, Trusted Firmware-M (TF-M) for M-profile/Armv8-M microcontrollers, Hafnium Secure Partition Manager, OP-TEE Trusted Execution Environment, MCUboot secure bootloader, Mbed TLS, TF-PSA-Crypto, Trusted Services framework, TF-RMM Realm Management Monitor, Rusted Firmware-A (RF-A), and Open CI infrastructure. These reference implementations serve as the foundation of Trusted Execution Environments (TEE) and Secure Processing Environments (SPE), enabling PSA Certified security compliance for SoC developers, OEMs, and embedded device manufacturers.
Is Trusted Firmware Project a public or private company?
Trusted Firmware Project is a private company. It is classified as corporate owned and is currently operating.
When was Trusted Firmware Project founded?
Trusted Firmware Project was founded in 2018. It employs 1 to 10 people.
How does Trusted Firmware Project make money?
One revenue line is on record: membership Funding.
Who are Trusted Firmware Project's main competitors?
Broad incumbents on record are Arm Holdings, Green Hills Software and Wind River Systems. Others are Linaro and PSA Certified. Emerging players are Zephyr Project and Apache NuttX. Direct peers are coreboot, OpenTitan and EDK II / TianoCore.
Does Trusted Firmware Project have an API?
No public API is recorded for Trusted Firmware Project.
What industry is Trusted Firmware Project in?
Trusted Firmware Project's product category is Embedded Systems Security Software. Its primary akta.pro industry code is HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM), with a secondary code of HDAHAJAK, Secure Elements & Trusted Execution Processors (TPM/TEE/Crypto MCUs). Its NAICS code is 51321 and its SIC code is 7370.