Open data on the ModRetro M64 (Artix UltraScale+) and the MiSTer DE10-Nano (Cyclone V SoC) compared: what is published, what is still "Comin…
What makes an FPGA space-grade: package, qualification, radiation, TMR (XQRVC1902)
Space-grade combines package, qualification to MIL-PRF-38535 and radiation data, plus design-level TMR and configuration scrubbing. Analysis based on AMD XQRVC1902 and NASA sources.
Summary
Space-grade is a combination of package, MIL-PRF-38535 qualification status, radiation characterization and design-level protection; the XQRVC1902 case shows where each piece is documented.
Overview
Package. "Space-grade" is not a single parameter: it combines package construction, a qualification programme and radiation characterization. AMD Versal AI Core XQRVC1902 is a convenient example. AMD's space page lists the XQR Versal AI Core XQRVC1902 among its space-grade Versal devices, and the 1 October 2026 AMD release says the new package is pin-compatible with existing Versal AI Core VC1902 commercial, defense-grade and space-grade devices in the 2197 ball grid array package.
Package construction. The release describes the new variant as an organic lidless design developed by AMD for missions up to 15 years. It uses conservative design rules, an enhanced organic substrate material to mitigate thermal and mechanical stress, and space-grade chip capacitors with established flight heritage; AMD says the lidless design improves thermal performance. AMD datasheet DS946 describes XQR Versal AI Core devices in ruggedized organic packaging intended for launch vibration and orbital thermal cycling, with production testing in AMD Class B or Class Y flows.
Ceramic versus organic. For comparison, a 2020 NASA JPL presentation at the NEPP Electronics Technology Workshop describes the first Class Y parts as ceramic single-die system-on-chip devices with non-hermetic flip-chip construction in high-pin-count ceramic column grid array packages, using base-metal-electrode capacitors and vented packages for thermal management; Xilinx Virtex-4 is given as an example. The same presentation reports that a task group for organic-substrate Class Y was created in September 2018. None of the sources we read compares cost, mass or reliability of organic and ceramic packages, so we make no such comparison.
Qualification classes. MIL-PRF-38535 is the performance specification for microcircuits. According to the NASA JPL presentation, it offers traditional hermetic Class Q and Class V (class level B and S) and non-hermetic Class N and Class Y. Class Y requirements came with a major overhaul of the standard covering flip-chip, underfill, CSAM and column grid arrays; revision K was released in December 2013, and a Package Integrity Demonstration Test Plan (PIDTP) gives manufacturers flexibility. AMD says it is testing XQRVC1902 to Class Y and expects Class Y flight-qualified units in the second half of 2027, so the samples are not described as qualified. AMD also uses its own "Class B" and "Class Y" flows (DS946); how they map to the QML classes is not explained on the pages we read.
Effects named by the vendor. The AMD space page gives, for Versal XQR adaptive SoCs, values for TID (total ionizing dose), SEL (single event latch-up immunity), SEU (single event upset) in configuration RAM and block RAM, and SEFI (single event functional interrupt) for configuration RAM. AMD states that it performs and reports radiation characterization, including TID and single event effects in proton and heavy ion environments, and points to a secure site for detailed reports.
Numbers on the AMD page. For Versal XQR adaptive SoCs (GEO) the table lists, in the Typ column: TID 100 krad(Si) with a maximum of 120 krad(Si); SEL immunity 80 MeV-cm2/mg; SEU in configuration RAM 6.5e-12 upsets per bit per day; SEU in block RAM 9.4e-10 upsets per bit per day; SEFI in configuration RAM 1.3e-5 per device per day. These are family-level figures from AMD's page, not figures for the new lidless package: the release has no radiation numbers, so check DS946 and AMD radiation reports before designing around them.
Why this matters for SRAM-based FPGAs. In a NASA GSFC presentation (Berg and Campola, SERESSA 2018), the configuration of a non-mitigated SRAM FPGA is named the most susceptible part of the circuitry, while antifuse configuration is designated hard against single event effects; the presentation stresses that one configuration bit flip can cause significant malfunction. A NASA JPL paper comparing hardening approaches states that upset hardening of both anti-fuse and SRAM-based parts is limited by SEFI rates. These materials cover earlier device families, so we use them to explain mechanisms, not as Versal data.
Triple modular redundancy. The NASA GSFC presentation lists global, local, distributed and block variants of TMR, and a general set of mitigation options: replication with correction, replication with detection (which requires a recovery plan), filtration and masking. The JPL paper describes the Xilinx approach as design-level triplication of both functional blocks and voters, in contrast to triplication inside each flip-flop. On its space page AMD says it offers TMR technology and an architecture designed to mitigate radiation effects.
Checking that TMR is really there. A NASA GSFC paper on TMR insertion verification states that improper insertion can jeopardize reliability and security, and that at the time no available technique could completely and reliably confirm TMR insertion; the authors propose combining existing formal analysis tools with a search-detect-and-verify tool. Editorial conclusion: confirming that the tool tripled what you expected is a separate verification step, not a by-product of synthesis.
Configuration scrubbing. The GSFC presentation defines scrubbing as writing into configuration memory while the functional logic is operating, with the intent of correcting configuration bit errors, and notes that it applies only to SRAM-based configuration. An internal scrubber is built from hard cores or user fabric inside the FPGA; an external scrubber is a separate device. The JPL paper adds that SRAM-based Xilinx parts of the Virtex and Virtex-2 era needed additional functionality and external circuitry (PROMs and at least a watchdog timer) for configuration and scrubbing.
SEM and XilSEM at AMD. Soft errors are defined in AMD guide PG036 as unintended changes to values stored in state elements caused by ionizing radiation. The LogiCORE IP Soft Error Mitigation (SEM) Controller is described there as an automatically configured, pre-verified solution to detect and correct soft errors in configuration memory of AMD FPGAs; AMD adds that it does not prevent soft errors but helps manage their system-level effects. The open AMD embeddedsw repository (MIT licence) contains the XilSEM library; its client API header defines commands to start and stop CRAM and NPI scans, inject errors, read frame ECC and register for CRAM error events. PG036 covers the SEM Controller for AMD FPGAs, and the XilSEM documentation page was not extractable from the docs.amd.com portal, so we do not retell how XilSEM works.
Editorial conclusion. Read "space-grade" as three separate questions, each answered by a different document: package and environment (DS946), qualification (Class Y status and the manufacturer's test evidence), and radiation (AMD reports and the family table). In a project schedule, samples and flight units are different lines: AMD itself separates sampling now from flight-qualified units expected in the second half of 2027.
Editorial hypothesis. Protection works in layers: TMR guards design logic, scrubbing and SEM guard configuration, and a detected but uncorrected failure needs a pre-written recovery scenario. NASA GSFC states directly that replication with detection requires recovery, for example switching to another device, trying to recover state, starting over or alerting. We have not measured any of this.
Experiment protocol (not performed by us). On commercial VC1902 or on samples: (1) inject configuration errors using the available tooling (the XilSEM client header defines error injection commands) and record detection, correction and function recovery times; (2) compare a baseline design with a TMR design by LUT, register and memory block counts and by achievable clock frequency; (3) check at netlist level or formally that the intended blocks and voters were tripled; (4) list failures the scrubber does not correct and write down what the system does.
Verified facts
AMD says the new organic lidless package is pin-compatible with VC1902 devices in the 2197 BGA and that Class Y testing is under way. Source: https://newsroom.amd.com/news/amd-sampling-versal-ai-core-adaptive-soc/. Checked: 2026-10-02. Confidence: 5/5.
The AMD space page lists TID, SEL, SEU and SEFI values for Versal XQR adaptive SoCs and states that AMD offers TMR technology. Source: https://www.amd.com/en/solutions/aerospace-and-defense/space.html. Checked: 2026-10-02. Confidence: 4/5.
MIL-PRF-38535 offers hermetic Class Q and V and non-hermetic Class N and Y; revision K, December 2013, reflected Class Y changes (NASA JPL presentation). The claim comes from the presentation or paper text behind this NASA NTRS record; the record page shows only title and abstract (if any). The devices discussed are older families. Source: https://ntrs.nasa.gov/citations/20220001378. Checked: 2026-10-02. Confidence: 4/5.
Scrubbing is writing into configuration memory during operation to correct bit errors and applies only to SRAM-based configuration (NASA GSFC presentation). The claim comes from the presentation or paper text behind this NASA NTRS record; the record page shows only title and abstract (if any). The devices discussed are older families. Source: https://ntrs.nasa.gov/citations/20180007760. Checked: 2026-10-02. Confidence: 4/5.
The Xilinx approach is design-level triplication of functional blocks and voters (NASA JPL paper). Source: https://ntrs.nasa.gov/citations/20090007932. Checked: 2026-10-02. Confidence: 4/5.
Improper TMR insertion can jeopardize reliability, and complete verification of TMR insertion was not available at the time (NASA GSFC paper). Source: https://ntrs.nasa.gov/citations/20160001756. Checked: 2026-10-02. Confidence: 4/5.
The SEM Controller detects and corrects soft errors in configuration memory of AMD FPGAs and does not prevent them (AMD PG036). Source: https://docs.amd.com/r/en-US/pg036_sem/Introduction. Checked: 2026-10-02. Confidence: 4/5.
The XilSEM client API header defines CRAM and NPI scan control, error injection, frame ECC read and CRAM error events. Source: https://raw.githubusercontent.com/Xilinx/embeddedsw/master/lib/sw_services/xilsem/src/client/xsem_client_api.h. Checked: 2026-10-02. Confidence: 4/5.
Engineering benefit
The article separates four checkable layers (package, qualification, radiation data, design-level mitigation) and ties each to a primary or NASA source, which gives engineers a checklist for reading a space-grade datasheet. Inference: the checklist is an editorial synthesis of the cited sources. Source: https://www.amd.com/en/solutions/aerospace-and-defense/space.html. Checked: 2026-10-02. Confidence: 4/5.
NASA GSFC states that one configuration bit flip can cause significant malfunction and defines scrubbing as correcting configuration errors during operation, which explains why SRAM-based designs need it. Source: https://ntrs.nasa.gov/citations/20180007760. Checked: 2026-10-02. Confidence: 4/5.
Commercial benefit
AMD states a schedule marker (Class Y flight-qualified units expected in the second half of 2027), which lets programme managers keep sampling and flight qualification as separate milestones. The release gives no price or lead time. Source: https://newsroom.amd.com/news/amd-sampling-versal-ai-core-adaptive-soc/. Checked: 2026-10-02. Confidence: 5/5.
Community benefit
Open NASA NTRS records and AMD documentation are cited with links, so students and small teams can follow the same chain of evidence without a vendor non-disclosure agreement. AMD says detailed radiation reports are on a secure site, so that part is not open. Source: https://ntrs.nasa.gov/citations/20180007760. Checked: 2026-10-02. Confidence: 4/5.
Critical review
The radiation table on the AMD page is family-level for Versal XQR; the release about the new lidless package contains no radiation numbers, so the figures must not be attributed to the new package. Source: https://www.amd.com/en/solutions/aerospace-and-defense/space.html. Checked: 2026-10-02. Confidence: 4/5.
NASA sources on QML classes, scrubbing and TMR date from 2009 to 2020 and describe earlier families (Virtex, Virtex-2, Virtex-4, Actel); they explain mechanisms but are not Versal measurements. Source: https://ntrs.nasa.gov/citations/20180007760. Checked: 2026-10-02. Confidence: 4/5.
The organic Class Y requirements were still under development in the 2020 presentation; the current status of the standard for organic substrates is not confirmed by the sources read. Source: https://ntrs.nasa.gov/citations/20220001378. Checked: 2026-10-02. Confidence: 4/5.
DS946 is a dynamic portal page whose content could not be extracted by the snapshot tool; statements attributed to it should be checked against the datasheet PDF. Source: https://docs.amd.com/r/en-US/ds946-xqr-versal-ai-core/General-Description. Checked: 2026-10-02. Confidence: 3/5.
Mechanisms (SRAM configuration upsets, scrubbing, TMR, SEFI limits) are architecture-level and are described in the vendor documentation as well, so the older NASA sources remain relevant for explanation. Source: https://docs.amd.com/r/en-US/pg036_sem/Introduction. Checked: 2026-10-02. Confidence: 4/5.
Practical recommendations
Before reusing the experiment protocol above, write down the pass criteria first; a scrubber that "mostly works" is the kind of result that looks fine until the first SEFI.
Keep "samples", "qualified" and "flight units" as separate columns in the schedule. A press release is not a flight certificate, and the radiation environment does not read schedules.
Ask the vendor for the radiation report that covers your exact package and speed grade, not the family table.
Official links
AMD release: XQRVC1902 sampling (1 Oct 2026)
AMD space solutions (radiation table)
PG036, Soft Error Mitigation Controller
XilSEM client API header (AMD embeddedsw)
NASA NTRS: MIL-PRF-38535 (JPL, NEPP ETW 2020)
NASA NTRS: FPGA mitigation strategies (GSFC, 2018)
NASA NTRS: hardened-by-design vs design-level hardening (JPL)
NASA NTRS: verification of TMR insertion (GSFC)
Evidence
AMD Versal AI Core XQRVC1902 in the new organic lidless package is pin-compatible with VC1902 commercial, defense-grade and space-grade devices in the 2197 BGA package. Source: https://newsroom.amd.com/news/amd-sampling-versal-ai-core-adaptive-soc/. Checked: 2026-10-02.
AMD is testing XQRVC1902 to MIL-PRF-38535 Class Y; Class Y flight-qualified units are expected in the second half of 2027. Source: https://newsroom.amd.com/news/amd-sampling-versal-ai-core-adaptive-soc/. Checked: 2026-10-02.
The new package uses conservative design rules, an enhanced organic substrate material and space-grade chip capacitors with established flight heritage; AMD says the lidless design improves thermal performance. Source: https://newsroom.amd.com/news/amd-sampling-versal-ai-core-adaptive-soc/. Checked: 2026-10-02.
AMD space page: radiation table for Versal XQR adaptive SoCs (GEO): TID typ 100 / max 120 krad(Si); SEL immunity typ 80 MeV-cm2/mg; SEU CRAM typ 6.5e-12 upset/bit/day; SEU BRAM typ 9.4e-10 upset/bit/day; SEFI CRAM typ 1.3e-5 SEFI/device/day. Source: https://www.amd.com/en/solutions/aerospace-and-defense/space.html. Checked: 2026-10-02.
AMD says it performs and reports radiation characterization including TID and SEE in proton and heavy ion environments, and offers TMR technology and an architecture designed to mitigate radiation effects. Source: https://www.amd.com/en/solutions/aerospace-and-defense/space.html. Checked: 2026-10-02.
DS946 describes XQR Versal AI Core devices in ruggedized organic packaging, with production testing in AMD class B or class Y flows. Source: https://docs.amd.com/r/en-US/ds946-xqr-versal-ai-core/General-Description. Checked: 2026-10-02.
PG036: the SEM Controller detects and corrects soft errors in configuration memory of AMD FPGAs; it does not prevent soft errors. Source: https://docs.amd.com/r/en-US/pg036_sem/Introduction. Checked: 2026-10-02.
The AMD embeddedsw XilSEM client header (MIT licence) defines CRAM and NPI start/stop scan, error injection, frame ECC read and CRAM error event commands. Source: https://raw.githubusercontent.com/Xilinx/embeddedsw/master/lib/sw_services/xilsem/src/client/xsem_client_api.h. Checked: 2026-10-02.
NASA JPL NEPP ETW 2020 presentation: MIL-PRF-38535 offers hermetic Class Q and V (class level B, S) and non-hermetic Class N and Y; first Class Y parts are ceramic single-die SoCs with non-hermetic flip-chip construction in CGA packages; revision K released December 2013; organic Class Y task group created September 2018. Source: https://ntrs.nasa.gov/citations/20220001378. Checked: 2026-10-02.
NASA GSFC SERESSA 2018 presentation: SRAM configuration is the most susceptible part of a non-mitigated SRAM FPGA; scrubbing definition; internal versus external scrubbers; replication with correction or detection as mitigation options. Source: https://ntrs.nasa.gov/citations/20180007760. Checked: 2026-10-02.
NASA JPL paper: Xilinx approach is design-level triplication of functional blocks and voters; SRAM Xilinx parts of the Virtex and Virtex-2 era need PROMs and at least a watchdog timer for configuration and scrubbing; hardening of both approaches is limited by SEFI rates. Source: https://ntrs.nasa.gov/citations/20090007932. Checked: 2026-10-02.
NASA GSFC paper: improper TMR insertion can jeopardize reliability and security; no technique then available could completely and reliably confirm TMR insertion. Source: https://ntrs.nasa.gov/citations/20160001756. Checked: 2026-10-02.
More from this section
In AI servers the FPGA acts as a control and security device beside the compute: I/O aggregation, firmware protection and recovery, DC-SCM i…