System Control Register (EL2)
Provides top-level control of the system, including its memory system, at EL2.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, these controls also apply to execution at EL0.
This register is present only when FEAT_SCTLR2 is implemented and FEAT_AA64 is implemented. Otherwise, direct accesses to SCTLR2_EL2 are UNDEFINED.
This register has no effect if EL2 is not enabled in the current Security state.
SCTLR2_EL2 is a 64-bit register.
| 63 | 62 | 61 | 60 | 59 | 58 | 57 | 56 | 55 | 54 | 53 | 52 | 51 | 50 | 49 | 48 | 47 | 46 | 45 | 44 | 43 | 42 | 41 | 40 | 39 | 38 | 37 | 36 | 35 | 34 | 33 | 32 |
| 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
| RES0 | |||||||||||||||||||||||||||||||
| RES0 | TLBOSNIS | FDIT | BTD | BTD0 | EnIA2 | EnIB2 | EnDA2 | EnDB2 | RES0 | CPTM0 | CPTM | CPTA0 | CPTA | EnPACM0 | EnPACM | EnIDCP128 | EASE | EnANERR | EnADERR | NMEA | EMEC | RES0 | |||||||||
Reserved, RES0.
TLBI for Outer shareable excludes Inner shareable.
This control applies to TLBI OS instructions executed at EL2.
| TLBOSNIS | Meaning |
|---|---|
| 0b0 |
TLBI OS instructions affect TLBs in the Inner and Outer shareability domains. |
| 0b1 |
TLBI OS instructions affect TLBs in the Outer shareability domain, but not in the Inner shareability domain. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enforce data-independent timing for execution at EL0.
| FDIT | Meaning |
|---|---|
| 0b0 |
This control does not affect data-independent timing of execution. |
| 0b1 |
Data-independent timing of execution is enforced. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
If the Effective value of HCR_EL2.TGE is 0, the field is IGNORED for all purposes other than direct reads and writes of the register.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls the implicit BTI behavior of the following instructions at EL2:
| BTD | Meaning |
|---|---|
| 0b0 |
The implicit BTI behavior of the instructions is unaffected. |
| 0b1 |
When the instructions are executed, they have no implicit BTI behavior. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls the implicit BTI behavior of the following instructions at EL0 in the EL2&0 translation regime:
| BTD0 | Meaning |
|---|---|
| 0b0 |
The implicit BTI behavior of the instructions is unaffected. |
| 0b1 |
When the instructions are executed, they have no implicit BTI behavior. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls enabling of pointer authentication of instruction addresses using the APIAKey_EL1 key, at EL0 in the EL2&0 translation regime. This field is used in conjunction with SCTLR_EL2.EnIA as follows:
| EnIA2 | EnIA | Behavior at EL0 |
|---|---|---|
| 0b0 | 0b0 | Disabled |
| 0b0 | 0b1 | Enabled |
| 0b1 | 0b0 | Enabled |
| 0b1 | 0b1 | Disabled |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls enabling of pointer authentication of instruction addresses using the APIBKey_EL1 key, at EL0 in the EL2&0 translation regime. This field is used in conjunction with SCTLR_EL2.EnIB as follows:
| EnIB2 | EnIB | Behavior at EL0 |
|---|---|---|
| 0b0 | 0b0 | Disabled |
| 0b0 | 0b1 | Enabled |
| 0b1 | 0b0 | Enabled |
| 0b1 | 0b1 | Disabled |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls enabling of pointer authentication of data addresses using the APDAKey_EL1 key, at EL0 in the EL2&0 translation regime. This field is used in conjunction with SCTLR_EL2.EnDA as follows:
| EnDA2 | EnDA | Behavior at EL0 |
|---|---|---|
| 0b0 | 0b0 | Disabled |
| 0b0 | 0b1 | Enabled |
| 0b1 | 0b0 | Enabled |
| 0b1 | 0b1 | Disabled |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls enabling of pointer authentication of data addresses using the APDBKey_EL1 key, at EL0 in the EL2&0 translation regime. This field is used in conjunction with SCTLR_EL2.EnDB as follows:
| EnDB2 | EnDB | Behavior at EL0 |
|---|---|---|
| 0b0 | 0b0 | Disabled |
| 0b0 | 0b1 | Enabled |
| 0b1 | 0b0 | Enabled |
| 0b1 | 0b1 | Disabled |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Reserved, RES0.
This field controls unprivileged Checked Pointer Arithmetic for Multiplication.
| CPTM0 | Meaning |
|---|---|
| 0b0 |
Pointer Arithmetic for Multiplication is not checked. |
| 0b1 |
Pointer Arithmetic for Multiplication is checked. |
If the Effective value of HCR_EL2.TGE is 0, the field is IGNORED for all purposes other than direct reads and writes of the register.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
If the Effective value of SCTLR2_EL2.CPTA0 is 0, then the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
This field controls Checked Pointer Arithmetic for Multiplication at EL2.
| CPTM | Meaning |
|---|---|
| 0b0 |
Pointer Arithmetic for Multiplication is not checked. |
| 0b1 |
Pointer Arithmetic for Multiplication is checked. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
If the Effective value of SCTLR2_EL2.CPTA is 0, then the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
This field controls unprivileged Checked Pointer Arithmetic for Addition.
| CPTA0 | Meaning |
|---|---|
| 0b0 |
Pointer Arithmetic for Addition is not checked. |
| 0b1 |
Pointer Arithmetic for Addition is checked. |
If the Effective value of HCR_EL2.TGE is 0, the field is IGNORED for all purposes other than direct reads and writes of the register.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
This field controls Checked Pointer Arithmetic for Addition at EL2.
| CPTA | Meaning |
|---|---|
| 0b0 |
Pointer Arithmetic for Addition is not checked. |
| 0b1 |
Pointer Arithmetic for Addition is checked. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
PACM Enable at EL0. Controls the effect of a PACM instruction at EL0.
| EnPACM0 | Meaning |
|---|---|
| 0b0 |
The effects of PACM are disabled at EL0. |
| 0b1 |
A PACM instruction at EL0 causes PSTATE.PACM to be set to 1. |
If the Effective value of HCR_EL2.TGE is 0, the field is IGNORED for all purposes other than direct reads and writes of the register.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
PACM Enable at EL2. Controls the effect of a PACM instruction at EL2.
| EnPACM | Meaning |
|---|---|
| 0b0 |
The effects of PACM are disabled at EL2. |
| 0b1 |
A PACM instruction at EL2 causes PSTATE.PACM to be set to 1. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enables access to IMPLEMENTATION DEFINED 128-bit System registers.
| EnIDCP128 | Meaning |
|---|---|
| 0b0 | Accesses at EL0 to IMPLEMENTATION DEFINED 128-bit System registers are trapped to EL2 using an ESR_EL2.EC value of 0x14, unless the access generates a higher priority exception. Disables the functionality of the 128-bit IMPLEMENTATION DEFINED System registers that are accessible at EL2. |
| 0b1 |
No accesses are trapped by this control. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
External Aborts to SError exception vector.
| EASE | Meaning |
|---|---|
| 0b0 |
Synchronous External abort exceptions taken to EL2 are taken to the appropriate synchronous exception vector offset from VBAR_EL2. |
| 0b1 |
Synchronous External abort exceptions taken to EL2 are taken to the appropriate SError exception vector offset from VBAR_EL2. |
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enable Asynchronous Normal Read Error.
| EnANERR | Meaning |
|---|---|
| 0b0 |
External aborts on Normal memory reads generate synchronous Data Abort exceptions in the EL2 and EL2&0 translation regimes. |
| 0b1 |
External aborts on Normal memory reads generate synchronous Data Abort or asynchronous SError exceptions in the EL2 and EL2&0 translation regimes. |
Implementation-specific exceptions to applications of this field are described in 'Taking error exceptions'.
Setting this field to 0 does not guarantee that the PE is able to take a synchronous Data Abort exception for an External abort on a Normal memory read in every case. There might be implementation-specific circumstances when an error on a load cannot be taken synchronously. These circumstances should be rare enough that treating such occurrences as fatal does not cause a significant increase in failure rate.
If FEAT_SVE is implemented, SCTLR2_EL2.EnANERR is 0, and the access generating the External abort is due to any Active element of an SVE Non-fault vector load instruction or an Active element that is not the First active element of an SVE First-fault vector load instruction, then no exception is generated and the External abort is reported in the FFR.
Setting this field to 0 might have a performance impact for Normal memory reads.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
Otherwise, this field is ignored by the PE and treated as one when all of the following are true:
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enable Asynchronous Device Read Error.
| EnADERR | Meaning |
|---|---|
| 0b0 |
External aborts on Device memory reads generate synchronous Data Abort exceptions in the EL2 and EL2&0 translation regimes. |
| 0b1 |
External aborts on Device memory reads generate synchronous Data Abort or asynchronous SError exceptions in the EL2 and EL2&0 translation regimes. |
Implementation-specific exceptions to applications of this field are described in 'Taking error exceptions'.
Setting this field to 0 does not guarantee that the PE is able to take a synchronous Data Abort exception for an External abort on a Device memory read in every case. There might be implementation-specific circumstances when an error on a load cannot be taken synchronously. These circumstances should be rare enough that treating such occurrences as fatal does not cause a significant increase in failure rate.
If FEAT_SVE is implemented, SCTLR2_EL2.EnADERR is 0, and the access generating the External abort is due to any Active element of an SVE Non-fault vector load instruction or an Active element that is not the First active element of an SVE First-fault vector load instruction, then no exception is generated and the External abort is reported in the FFR.
Setting this field to 0 might have a performance impact for Device memory reads.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
Otherwise, this field is ignored by the PE and treated as one when all of the following are true:
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Non-maskable External Aborts. Controls whether physical SError exceptions are masked at EL2 when PSTATE.A is 1 or HCR_EL2.{AMO, TGE} is {0, 0}.
| NMEA | Meaning |
|---|---|
| 0b0 |
The masking of physical SError exceptions at EL2 is unaffected by this mechanism. |
| 0b1 |
Physical SError exceptions are taken at EL2 regardless of whether they are masked by any mechanism, unless they are routed to EL3. |
This field has no effect on the masking of delegated SError interrupts.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
For more information, see 'Asynchronous exception routing'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enables MEC. When enabled, memory accesses to the Realm physical address space are associated with a MECID.
| EMEC | Meaning |
|---|---|
| 0b0 |
MEC is not enabled for the Realm physical address space. |
| 0b1 |
MEC is enabled for the Realm physical address space. |
This bit is permitted to be cached in a TLB.
When EL3 is implemented and SCR_EL3.SCTLR2En == 0, this field is ignored by the PE and treated as zero.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Reserved, RES0.
When the Effective value of HCR_EL2.E2H is 1, without explicit synchronization, accesses from EL2 using the accessor name SCTLR2_EL2 or SCTLR2_EL1 are not guaranteed to be ordered with respect to accesses using the other accessor name.
If FEAT_SRMASK is implemented, accesses to SCTLR2_EL2 are masked by SCTLR2MASK_EL2.
Accesses to this register use the following encodings in the System register encoding space:
MRS <Xt>, SCTLR2_EL2
(op0 = 0b11, op1 = 0b100, CRn = 0b0001, CRm = 0b0000, op2 = 0b011)
if !(IsFeatureImplemented(FEAT_SCTLR2) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif HaveEL(EL3) && PSTATE.EL == EL2 && EL3SDDUndefPriority() && SCR_EL3().SCTLR2En == '0' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else X{64}(t) = SCTLR2_EL2(); end; elsif PSTATE.EL == EL3 then X{64}(t) = SCTLR2_EL2(); end;
MSR SCTLR2_EL2, <Xt>
(op0 = 0b11, op1 = 0b100, CRn = 0b0001, CRm = 0b0000, op2 = 0b011)
if !(IsFeatureImplemented(FEAT_SCTLR2) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif HaveEL(EL3) && PSTATE.EL == EL2 && EL3SDDUndefPriority() && SCR_EL3().SCTLR2En == '0' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else SCTLR2_EL2() = X{64}(t); end; elsif PSTATE.EL == EL3 then SCTLR2_EL2() = X{64}(t); end;
MRS <Xt>, SCTLR2_EL1
(op0 = 0b11, op1 = 0b000, CRn = 0b0001, CRm = 0b0000, op2 = 0b011)
if !(IsFeatureImplemented(FEAT_SCTLR2) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && SCR_EL3().SCTLR2En == '0' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && HCR_EL2().TRVM == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HFGRTR_EL2().SCTLR_EL1 == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && (!IsHCRXEL2Enabled() || HCRX_EL2().SCTLR2En == '0') then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif EffectiveHCR_EL2_NVx() IN {'111'} then X{64}(t) = NVMem(0x278); else X{64}(t) = SCTLR2_EL1(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif ELIsInHost(EL2) then X{64}(t) = SCTLR2_EL2(); else X{64}(t) = SCTLR2_EL1(); end; elsif PSTATE.EL == EL3 then X{64}(t) = SCTLR2_EL1(); end;
MSR SCTLR2_EL1, <Xt>
(op0 = 0b11, op1 = 0b000, CRn = 0b0001, CRm = 0b0000, op2 = 0b011)
if !(IsFeatureImplemented(FEAT_SCTLR2) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && SCR_EL3().SCTLR2En == '0' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && HCR_EL2().TVM == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HFGWTR_EL2().SCTLR_EL1 == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && (!IsHCRXEL2Enabled() || HCRX_EL2().SCTLR2En == '0') then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif EffectiveHCR_EL2_NVx() IN {'111'} then NVMem(0x278) = X{64}(t); else SCTLR2_EL1() = X{64}(t); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && SCR_EL3().SCTLR2En == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif ELIsInHost(EL2) then SCTLR2_EL2() = X{64}(t); else SCTLR2_EL1() = X{64}(t); end; elsif PSTATE.EL == EL3 then SCTLR2_EL1() = X{64}(t); end;
Version 2026.06 — Copyright © 2010-2026 Arm Limited or its affiliates.
This site is provided as a community resource and is NOT affiliated with nor endorsed by Arm Limited.