In a previous era, tech leaders could stay focused on the application layer and not pay too much attention to the layers below. The pace of change with AI and machine learning now means forward-thinking leaders have to pay attention to their compute and infrastructure. I write about companies across the full enterprise stack, from application software down through compute and infrastructure, because the constraint that decides what an AI system can actually do increasingly sits in the layers most executives never look at.
A $12 billion supplier nobody outside engineering has heard of
NXP Semiconductors is a Dutch chipmaker headquartered in Eindhoven, spun out of Philips in 2006 and now trading on Nasdaq as NXPI. The company builds the connectivity, security, and processing silicon that sits underneath automotive, industrial, mobile, and communications systems, largely invisible to the end customers who buy the branded products on top of it. It posted $12.27 billion in revenue in 2025 across operations in more than 30 countries.
Rafael Sotomayor took over as president and CEO in October 2025, after running the company's Secure Connected Edge business, the same unit responsible for this week's announcement. That background matters. NXP's new CEO came up through the part of the company betting hardest on pairing connectivity with embedded security, and the MCX A5 family is that bet made into a shipping product line.
What's inside the MCX A5 family
NXP introduced the MCX A5 family of microcontrollers, built on an Arm Cortex-M33 core running up to 240 MHz, with up to 2 MB of flash and 640 KB of RAM. The headline feature is what NXP calls the industry's first wired MCU with topology discovery built on 10BASE-T1S Ethernet, a low-cost, twisted-pair Ethernet standard designed for exactly this kind of distributed industrial wiring. Topology discovery means the chip automatically identifies and maps connected devices on the network, eliminating the manual configuration work that is the unglamorous part of industrial deployment and actually determines how long a rollout takes.
Security is baked in at the silicon level. The family carries PSA Certified Level 3 status and support for post-quantum cryptography, including a hardware root of trust covering secure boot, secure firmware updates, secure attestation, and secure debug authentication. Selected devices support Rust, and the family runs on both NXP's own MCUXpresso tooling and Zephyr RTOS. Paired with NXP's TJF1410 transceiver, which handles the analog front end, the combination gives a manufacturer a complete single-pair Ethernet path from a $12 billion supplier's roadmap down to a single chip. Devices are sampling now, with volume availability expected in the fourth quarter of 2026, and NXP is shipping FRDM development boards alongside it so engineering teams can start building before the parts hit volume production.
NXP is not alone in this race
Every major microcontroller vendor is moving on post-quantum security at roughly the same time, which tells you the driver is regulatory pressure and the quantum threat timeline, playing out across the industry at once. Infineon has built PQC support into its PSOC Control C3 industrial microcontrollers and has publicly stated it is future-proofing its wider portfolio for the same requirements. STMicroelectronics introduced the ST54M, which combines a PQC hardware accelerator with NFC and an embedded secure element for mobile and connected-device use cases. Microchip released the PIC64HX family of microprocessors supporting the NIST-standardized ML-KEM and ML-DSA algorithms for defense-grade edge designs, and Samsung has shown its own S3SSE2A security chip built around the same standards.
NXP's angle in that field is the combination it is selling. Competing announcements pair post-quantum cryptography with a secure element or an NFC radio aimed at mobile and consumer designs. NXP is pairing it with 10BASE-T1S Ethernet and topology discovery on a general-purpose industrial MCU. That combination targets a more urgent industrial problem: getting a device onto the network at all, with security built in from the moment it connects.
The real bottleneck: legacy wiring, not compute
Most industrial edge devices today are still on legacy point-to-point links such as RS-232 and RS-485, or not networked at all. That is the real constraint behind every conversation about industrial AI and predictive maintenance. A model can only act on data it receives, and legacy serial links deliver nothing in real time. The strategic move here is not the clock speed or the flash size. It is that NXP is trying to make Ethernet connectivity cheap and simple enough, at the microcontroller level, to become the default choice over legacy serial for the next generation of sensors, actuators, and controllers going into new designs.
The security piece is timed to a specific regulatory clock, and it is not the only one running. The EU Cyber Resilience Act requires manufacturers to begin reporting actively exploited vulnerabilities and severe incidents starting September 11, 2026, with full compliance and CE marking requirements applying from December 11, 2027. Every connected industrial device NXP's customers ship into Europe after that date needs a documented, auditable security posture. Putting a PQC-based root of trust into a general-purpose MCU, the low-margin commodity part of NXP's lineup, is how NXP makes that requirement affordable at the volumes industrial customers actually need.
The United States is running a parallel clock on the same threat. Executive Order 14409, signed June 22, 2026, requires federal agencies to designate a post-quantum cryptography migration lead within 30 days and submit migration plans against a 2030 deadline for high-value assets. Between the EU's device-level mandate and the federal government's infrastructure-level one, any vendor selling connected industrial or government hardware now has two separate compliance calendars converging on the same cryptographic transition, on two different continents, with two different enforcement mechanisms.
"Industrial edge AI cannot realize its full potential without access to real-time data."— Charles Dachs, EVP and GM, Secure Connected Edge, NXP
Why this belongs below the application layer
This is the second time in a few months NXP has shown up in this space with a chip aimed at a constraint most application-layer conversations skip past entirely. In June, the company's SAF8444 radar chip targeted the mainstream automotive safety segment, on the logic that regulatory mandates hit the cheapest cars first. The MCX A5 family follows the same pattern one layer down. NXP is building post-quantum security and real Ethernet connectivity into its general-purpose MCU line, the parts every customer buys by default, aiming to make both features unremarkable and standard. Together, the two announcements describe a company betting that the compute and infrastructure layers decide the next several years of industrial AI adoption.
There is a genuine tension worth naming here, and CAREL's chief technology officer gestured at it directly when he called connectivity, cybersecurity, and AI capabilities that now have to work together seamlessly. Post-quantum cryptography is being deployed years before a cryptographically relevant quantum computer exists, as a hedge against adversaries harvesting encrypted data now to decrypt later. That is a defensible bet for a chip with a decade-long product lifecycle in industrial equipment. It is also an unproven one. Nobody has field experience with PQC key management failures at the scale of millions of deployed industrial MCUs, because nobody has run PQC at that scale for more than a couple of years.
If your organization is planning industrial edge AI deployments that will still be running hardware in 2030, who on your team owns the decision to trust a cryptographic standard that has never been attacked at scale, embedded in a chip you cannot easily replace once it is in the field?
NXP Semiconductors. "NXP Introduces MCX A5 Family." Press release, Aug. 2026.
"NXP Semiconductors." Wikipedia, 2026.
"Cyber Resilience Act." European Commission, Shaping Europe's Digital Future, 2026.
"The Safety Mandate Hits the Cheapest Car First." shashi.co, 11 June 2026.
"AWS Summit Washington D.C. 2026: The Post-Quantum Clock Started Last Monday." shashi.co, 28 June 2026.
"New PQC Security Chips from STMicroelectronics, Samsung, Infineon, and Microchip Target Quantum-Ready Devices." IndexBox, 2026.
Image is not a representation of NXP or it's products
