NXP puts secure Ethernet into MCX A5

NXP puts secure Ethernet into MCX A5

NXP has launched MCX A5 microcontrollers for secure industrial Ethernet. The Cortex-M33 family integrates 10BASE-T1S digital PHY capability, topology discovery, and post-quantum security while targeting long-life industrial edge nodes.


IN Brief:

  • MCX A5 integrates a 10BASE-T1S digital PHY and topology discovery for distributed industrial Ethernet endpoints.
  • Devices use a Cortex-M33 core running to 240MHz, with up to 2MB flash, 640KB RAM, and post-quantum security support.
  • Samples are available now, with wider availability expected in Q4 2026 and support through MCUXpresso, Zephyr, and selected Rust-enabled devices.

NXP Semiconductors has introduced the MCX A5 microcontroller family with an integrated 10BASE-T1S Ethernet digital PHY, topology discovery, and support for post-quantum cryptography. The devices are sampling now, with broader availability expected in the fourth quarter of 2026.

MCX A5 is built around an Arm Cortex-M33 core running at up to 240MHz, with configurations offering up to 2MB of flash and 640KB of RAM. Interfaces include a 10/100 Ethernet MAC, 10BASE-T1S digital PHY, UART, I2C, I3C, SPI, CAN FD, high-speed USB, FlexSPI, and FlexIO.

The integrated digital PHY is intended to reduce the amount of external circuitry required to add single-pair Ethernet to distributed industrial nodes. Developers still need an external 10BASE-T1S Physical Medium Dependent transceiver, with NXP positioning its TJF1410 alongside MCX A5 as a complete IEEE 802.3cg-compliant implementation.

10BASE-T1S provides 10Mbit/s Ethernet over a single pair and supports multidrop operation, making it suitable for networks where sensors, actuators, and controllers do not require the bandwidth of conventional switched Ethernet. Integrating more of the communications function into the MCU can reduce component count in those endpoints while bringing them onto the same IP-based architecture used elsewhere in the installation.

NXP has added topology discovery to help identify how devices are connected across the network. In distributed systems, that can simplify commissioning and maintenance by providing a view of connected endpoints rather than relying entirely on manually maintained network documentation.

The security architecture targets PSA Certified Level 3 and includes post-quantum cryptography support, an EdgeLock accelerator, secure boot with a PQC hybrid mode, secure firmware updates, attestation, debug authentication, and additional monitoring functions. Those capabilities are aimed at equipment that may remain deployed long enough for both attack methods and regulatory expectations to change.

Industrial product lifecycles make that an unusually relevant constraint. A connected sensor or controller entering production in 2026 may remain in operation for many years, so secure boot and update mechanisms have to support maintenance well after the hardware architecture has been fixed. Cryptographic agility is similarly easier to design into the platform at launch than retrofit to installed equipment later.

The European Cyber Resilience Act adds another reason for manufacturers to consider lifecycle security earlier in product design. An MCU cannot make a complete product compliant by itself, but hardware-backed boot, authentication, update, and attestation functions provide mechanisms on which an OEM can build its wider vulnerability and maintenance process.

Software support includes NXP’s MCUXpresso environment, SDKs, middleware, security software, Visual Studio Code integration, and long-term-support releases. Zephyr RTOS is also planned, while selected devices are expected to support Rust for teams seeking a memory-safe language alongside established C and C++ embedded development.

The family will be supported by the FRDM-MCXA577 development board, which provides Arduino, mikroBUS, and PMOD expansion options for prototyping. That gives developers a route to evaluate the networking architecture before committing it to a controller or edge node with application-specific analogue circuitry, I/O, and mechanical constraints.

MCX A5’s engineering proposition is less about raw processor performance than consolidation. Bringing the 10BASE-T1S digital PHY, network discovery, security functions, and MCU software environment into one platform reduces the number of separate design decisions around a connected industrial endpoint while retaining an external analogue transceiver where the physical network requires it.

Whether that translates into broader 10BASE-T1S adoption will depend on the complete system cost and the availability of software, cabling, diagnostics, and compatible infrastructure. With samples available now and volume availability expected in Q4, industrial developers can begin testing whether the architecture provides a practical replacement for the mixture of legacy serial links and discrete networking components still common at the edge.


Stories for you


  • Aetina launches palm-sized four-camera edge AI systems

    Aetina launches palm-sized four-camera edge AI systems

    Aetina has launched palm-sized edge AI systems for mobile deployments. The Jetson Orin platforms combine four GMSL2 camera links, up to 100 TOPS, and rugged vehicle-oriented power and environmental features.


  • Avicena ships 1Tbps microLED optical evaluation kits

    Avicena ships 1Tbps microLED optical evaluation kits

    Avicena is now shipping 1Tbps LightBundle kits for customer evaluation. The microLED platform combines 335 optical channels at up to 3Gbps each, giving AI hardware developers a laboratory route to test short-reach optical links.