Be the first to know.
Get our Computing weekly email digest.

Secure-control FPGA puts post-quantum root of trust on 215k-logic-cell device

Lattice's Mach-N2 FPGAs pair internal-flash boot with PCIe Gen4 and 16 Gb/s transceivers for compute and communications infrastructure.

author avatar

30 Sep, 2026. 5 minutes read

The Lattice Mach N2 FPGA

The Lattice Mach N2 FPGA

Lattice Semiconductor announced the Mach-N2 Family:

The Mach-N2 is the newest generation of Lattice's secure-control FPGAs, which handle power sequencing, system management and security. Mach-N2 shares Nexus 2, Lattice's 16 nm FinFET platform, with the general-purpose Certus-N2 family, adding internal flash and run-time security. Its five devices span 40k to 135k LUTs, or 65k to 220k system logic cells.[1][2][3]

Lattice says Mach-N2 pairs a hardware root of trust with crypto-agile post-quantum cryptography (PQC) compliant with CNSA 2.0, the NSA's algorithm suite for national security systems. It also claims up to twice the logic density for system control functions and sub-30 ms boot for the 220k-cell device.[1] Hardware PQC sits on one device, the 215k-cell MH21D.[2]

Why it matters

Lattice pitches Mach-N2 as a first-on, last-off device.[4] In NIST's platform firmware resiliency model, SP 800-193, a root of trust protects firmware, detects corruption and restores a known-good image.[5] The NSA prioritises firmware signing, whose algorithms are "frequently locked in for the life of a system". CNSA 2.0 lists hash-based LMS and XMSS for firmware signing, ML-DSA-87 for signatures and ML-KEM-1024 for key establishment, and new national security system acquisitions must comply from January 1, 2027.[6]

The MH21D adds ML-DSA, LMS, XMSS and stateless hash-based SLH-DSA signatures, plus ML-KEM key exchange, to the classical cryptography all five devices share.[2] Lattice's previous PQC-capable parts belong to its MachXO5-NX secure-control family, whose TDQ devices launched in October 2025 on 28 nm FD-SOI and now reach 64k logic cells with PCIe Gen2 x1.[7][8] The MH21D's 132k LUTs are about 2.5 times the largest TDQ device's roughly 53k (author's calculation, 64k cells ÷ 1.2 cells per LUT), and its hard PCIe controller runs Gen4 x4.[2]

The MH21D comes only in an 18 × 18 mm CBG484 package with 236 user I/O and in the two slower speed grades; it needs customer keys and policy provisioned before first use. Mach-N2 tops out at 248 user I/O, 92 of them 3.3 V-capable, where the largest MachXO5-NX packages reach 360 or more, over 300 of them 3.3 V-capable. Mach-N2 also drops the 12-bit SAR ADCs that MachXO5-NX provides for system monitoring.[2][8][9]

Some competing FPGAs already offer post-quantum boot. AMD's cost-optimised Spartan UltraScale+ SU200P targets board management and platform root of trust with up to 572 I/O and up to eight transceivers. The SU200P authenticates boot images with hash-based HSS/LMS signatures or ECDSA P-384 and receives its configuration from external memory or a host at every power-up.[10][11][12] Altera said in September that PQC-enabled Agilex 3 and Agilex 5 FPGAs are shipping.[13] Mach-N2 instead boots from internal flash; Lattice says configuration data is never exposed outside the device while loading.[14]

Technical specifications

Mach-N2 devices

SpecMH06MH10MH16MH20MH21D
System logic cells65k100k160k220k215k
LUTs40k61k98k135k132k
Block RAM (36 kbit blocks)114153228306289
18 × 18 multipliers120240360520520
Hardware PQC and crypto agilityNoNoNoNoYes
Packages (0.8 mm pitch)CBG256 (14 × 14 mm), CBG484 (18 × 18 mm)CBG256, CBG484CBG484CBG484CBG484
User I/O, total (3.3 V-capable wide-range / high-performance)141 (39 / 102) in CBG256; 196 (92 / 104) in CBG484141 (39 / 102) in CBG256; 196 (92 / 104) in CBG484248 (92 / 156)248 (92 / 156)236 (83 / 153)
Transceiver lanes2 in CBG256; 4 in CBG4842 in CBG256; 4 in CBG484444
Speed grades1 to 31 to 31 to 31 to 31 and 2
User flash memory (UFM)not statednot stated105,472 kbit105,472 kbitnot stated
Internal flash, totalnot statednot statednot stated256 Mbitnot stated
Configuration timenot statednot statednot statedunder 30 ms (Lattice claim)not stated
Flash data retention at 100 °C junction20 years20 years20 years20 yearsnot stated
Flash programming cycles within retention spec (write/erase maximum)10,000 (100,000)10,000 (100,000)10,000 (100,000)10,000 (100,000)not stated

Shared by all five Mach-N2 devices

SpecValue
Platform and processLattice Nexus 2, TSMC 16 nm FinFET
Core supply0.82 V
Transceiversup to 16 Gb/s per lane
PCIehard Gen4 (16 GT/s) controller, up to x4, up to eight physical functions
Ethernet10GbE, with PMA and PCS in hardware and the MAC in fabric
External memoryDDR4 and LPDDR4 up to 2400 Mb/s
Configurationboots from internal flash (self-download mode); images programmed over JTAG or target SPI; no boot from external SPI flash
Image fallbackup to three stored images: primary, secondary and golden (Lattice); falls back on a failed authentication or a bitstream revision below the set minimum
Bitstream protectionAES-256-GCM encryption; ECDSA (up to 521-bit) or RSA (up to 4096-bit) authentication
Run-time cryptographyAES-256 engines at up to 2.5 Gb/s and 10 Gb/s; SHA-2, SHA-3 and HMAC up to 512 bits; ECDSA, ECDH and ECIES up to 521 bits; Ed25519; RSA 2048 to 4096; TRNG
Device identityphysically unclonable function (PUF), 256 bits of entropy, stable for more than 20 years; Lattice lists DICE and SPDM attestation on the PUF-derived identity
Anti-tampervoltage and temperature monitor, plus user-triggered responses ranging from zeroising RAM and stored secrets to permanently disabling the device
Temperature gradescommercial 0 to 85 °C; industrial -40 to 100 °C
Power consumptionnot stated

MH21D root-of-trust device: differences from the other four

SpecValue
Post-quantum signaturesML-DSA, LMS, XMSS, SLH-DSA
Post-quantum key exchangeML-KEM
Other additionsEd448; SHAKE128 and SHAKE256; crypto agility with field-updatable algorithms (Lattice)
ML-DSA and ML-KEM parameter setsnot stated (CNSA 2.0 requires ML-DSA-87 and ML-KEM-1024)
Secret storageone-time-programmable memory; the battery-backed RAM option is not available
Provisioningcustomer policy and key files plus an authenticated image, loaded over JTAG or target SPI before the first reboot

Sources: [1][2][3][4][14][15][16]

All Mach-N2 specifications are preliminary. Cell counts do not compare across generations: Nexus 2 system logic cells run about 1.63 per LUT against 1.2 for MachXO5-NX logic cells, so the 220k-cell MH20 has about 1.7 times the LUTs of the largest MachXO5-NX (our calculation).[2][9] Lattice quotes a boot time under 30 ms for the MH20, whose uncompressed bitstreams are 44 Mbit to 64.1 Mbit.[1][14] For CNSA 2.0 designs, the MH21D's parameter sets are a gating item; boot time and power only set budgets. Lattice's evaluation board carries an MH20, which lacks the PQC engines.[17]


Recommended reading: Post-quantum secure boot reaches low-cost and mid-range FPGAs. How Altera placed PQC bitstream authentication in the Agilex 3 and Agilex 5 Secure Device Manager, and where other vendors put it in the boot chain.

References

  1. Lattice Expands Secure Control FPGA Leadership with New Lattice Mach-N2 Family, Lattice Semiconductor via Business Wire, September 16, 2026.
  2. Lattice Nexus 2 Platform: Overview Data Sheet (FPGA-DS-02122, v0.80), Lattice Semiconductor, September 2026. Preliminary vendor datasheet.
  3. Lattice Advances Low Power FPGA Leadership with New Small and Mid-range FPGA Offerings, Lattice Semiconductor via Business Wire, December 10, 2024.
  4. Mach-N2, Lattice Semiconductor product page, accessed September 30, 2026.
  5. Platform Firmware Resiliency Guidelines (NIST SP 800-193), National Institute of Standards and Technology, May 2018.
  6. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ, National Security Agency, December 2024. Cybersecurity Information Sheet, version 2.1.
  7. Lattice Launches Industry-First PQC-Ready FPGA Family: MachXO5-NX TDQ, Lattice Semiconductor via Business Wire, October 13, 2025.
  8. MachXO5-NX Family Root-of-Trust Devices Data Sheet (FPGA-DS-02120, v1.5), Lattice Semiconductor, August 2026. Vendor datasheet.
  9. MachXO5-NX Family Data Sheet (FPGA-DS-02102, v2.3), Lattice Semiconductor, July 2026. Vendor datasheet.
  10. AMD Spartan FPGA Grows Up: Bigger, Smarter, Scalable, More Secure, AMD, June 15, 2026. Vendor blog.
  11. Spartan UltraScale+ Authentication Certificate (Bootgen User Guide, UG1283), AMD, June 2026. Vendor user guide.
  12. Configuration Flow for AMD Spartan UltraScale+ Devices, AMD, 2025. Vendor presentation.
  13. Altera Adds Post-Quantum Security to Agilex 3 and Agilex 5 FPGAs, Altera press release, September 8, 2026.
  14. Lattice Nexus 2 sysCONFIG User Guide (FPGA-TN-02370, v0.82), Lattice Semiconductor, September 2026. Preliminary vendor technical note.
  15. Lattice Nexus 2 Platform: Specifications Data Sheet (FPGA-DS-02121, v0.80), Lattice Semiconductor, September 2026. Preliminary vendor datasheet.
  16. Lattice Nexus 2 Multi-Boot User Guide (FPGA-TN-02385, v0.81), Lattice Semiconductor, September 2026. Preliminary vendor technical note.
  17. Mach-N2 Evaluation Board (FPGA-EB-02078, v0.81), Lattice Semiconductor, September 2026. Vendor board guide.

24,000+ Subscribers

Stay Cutting Edge

Join thousands of innovators, engineers, and tech enthusiasts who rely on our newsletter for the latest breakthroughs in the Engineering Community.

By subscribing, you agree to ourPrivacy Policy.You can unsubscribe at any time.