Who Verifies the Chip That Verifies Everything Else?
Intel and Fortinet just co-designed purpose-built security processor that does the security work that general purpose chips can’t. But if it isn’t verified on the line, it can’t do its job.
By: Tyler York, CBO, Cybord
On July 21, Intel and Fortinet announced they are jointly developing Fortinet’s next generation security processor, SP6. Fortinet brings more than two decades of purpose built ASIC design. Intel brings its packaging and foundry capacity, including the Intel 4 process, and this marks the first publicly named cybersecurity chip customer for Intel’s foundry business. Intel CEO Lip-Bu Tan framed the deal in two parts: performance for a harder threat landscape, and, in his words, a more resilient and diversified global supply chain.
That second half of the sentence is the one worth sitting with.
A security chip is still a chip
SP6 is meant to sit inside firewalls, switches, and network appliances that customers buy specifically because they are supposed to be trustworthy. Fortinet has built its reputation on the idea that purpose built silicon does security work that general purpose chips can’t. That’s a real advantage. But it also means the entire security promise of the appliance now rests on one more physical part, made in one more factory, and eventually placed on one more board.
Intel and Fortinet are already thinking about the supply chain angle for the chip itself, diversifying where and how SP6 gets fabricated. That’s the right instinct. Component shortages, geopolitical sourcing pressure, and the same gray market dynamics that hit every other class of semiconductor apply here too. A purpose built security processor isn’t exempt from any of it.
The blind spot sits after the chip leaves the fab
Here is the part that rarely gets discussed in announcements like this one. Once SP6 leaves Intel’s fab, it still has to move through distribution and onto a board, whether by a contract manufacturer or an internal assembly line. That’s where much of the electronics industry’s trust gap actually exists.
In the first six months of this year alone, Cybord identified more than thirty major events in which an authentic, non-AVL component was placed on a board. None were counterfeits, but every one represented the wrong part. If SP6 itself were substituted, would incoming inspection or sampling-based AOI catch it? Probably not.
Standard practice relies on supplier documentation, batch traceability, and sampling-based AOI. Those methods confirm what should have been assembled – not that the specific component installed on a specific board is the genuine, approved device. For a passive component, that’s a quality risk. For a security processor, it’s a security risk.
Verification has to reach the placement step
Zero Trust assumes nothing is trusted until it’s verified. Hardware deserves the same discipline.
Documentation remains essential, but it establishes intent, not proof. Verification has to happen where trust is ultimately decided: at placement.
Visual AI closes that gap by inspecting every installed component rather than relying solely on paperwork or sampling. It compares what the camera actually sees – markings, lot and date code, country of origin, and physical characteristics – against the approved BOM and AVL, providing evidence that the component assembled is the one that was specified.
Why this matters more for telecom and datacom infrastructure
Network security appliances sit in a category where the cost of an undetected substitution isn’t a warranty claim. It’s a network operator, a data center, or a telecom carrier trusting a piece of hardware to be exactly what it claims to be, down to the silicon. Supply chain and compliance leaders in this vertical are already being asked to prove country of origin and component provenance for CHIPS Act and related procurement requirements, including DFARS Case 2022-D011, the rule published July 2, 2026 tightening printed circuit board acquisition restrictions and requiring provable, imagery backed traceability rather than paperwork alone.
A jointly developed security processor from two well known suppliers doesn’t remove that obligation. If anything, it raises the bar, because the part in question is the one meant to be the last line of defense.
For OEMs specifying SP6 or any comparable security processor, one question matters: how do you prove the security chip on the board is the genuine, approved device? If the answer ends with incoming inspection or supplier certificates, the verification chain still has a gap.
Intel and Fortinet are right to frame SP6 as both a performance and supply-chain story. But resilience can’t stop at the fab gate. It has to extend to the moment a genuine part becomes a placed part – on every board, every time.
The chip built to verify everything else deserves the same standard of verification.
# # #
Questions worth asking
Q1: Doesn’t Intel’s role in fabricating SP6 already guarantee its authenticity?
Intel’s fab controls what happens during manufacturing. It has no visibility into what happens after SP6 ships, through distribution, and onto a board at assembly, where substitution and counterfeiting risk actually lives.
Q2: Isn’t automated optical inspection already catching this?
Most AOI systems check placement and solder quality, not component identity. They can confirm a chip is present and aligned without confirming it’s the specific, genuine and approved part the BOM calls for.
Q3: What would it actually take to verify a component like SP6 at assembly?
Visual AI uses existing imaging devices on the SMT line, namely AOI. It acquires high resolution imaging of every component as it’s placed, cross-checked against the marking, lot and date code, and country of origin data in the approved vendor list, at line speed, on every unit built, not a sample.