diff --git a/arm-env.sh b/arm-env.sh
index 9d80736..11c7967 100644
--- a/arm-env.sh
+++ b/arm-env.sh
@@ -1,6 +1,6 @@
 #!/usr/bin/env bash
 #
-# Copyright (c) 2020-2021, Arm Limited. All rights reserved.
+# Copyright (c) 2020-2022, Arm Limited. All rights reserved.
 #
 # SPDX-License-Identifier: BSD-3-Clause
 #
@@ -24,8 +24,8 @@
 scp_tools_src_repo_url="${scp_tools_src_repo_url:-http://$arm_gerrit_url/scp/tools-non-public}"
 tf_for_scp_tools_src_repo_url="https://gerrit.oss.arm.com/scp/test-framework"
 
-# If not set, the OpenCI would download the tarball from Github every time.
-mbedtls_archive="${mbedtls_archive:-$tfa_downloads/mbedtls/mbedtls-2.26.0.tar.gz}"
+# If not set, the scripts would download the tarball from Github every time.
+mbedtls_archive="${mbedtls_archive:-$tfa_downloads/mbedtls/mbedtls-2.28.0.tar.gz}"
 
 # Arm Coverity server.
 export coverity_host="${coverity_host:-coverity.cambridge.arm.com}"
diff --git a/script/tf-coverity/common-def.sh b/script/tf-coverity/common-def.sh
index 09b03b0..5d2cf13 100644
--- a/script/tf-coverity/common-def.sh
+++ b/script/tf-coverity/common-def.sh
@@ -1,6 +1,6 @@
 #!/usr/bin/env bash
 #
-# Copyright (c) 2019-2021 Arm Limited. All rights reserved.
+# Copyright (c) 2019-2022 Arm Limited. All rights reserved.
 #
 # SPDX-License-Identifier: BSD-3-Clause
 #
@@ -77,9 +77,9 @@
 MBED_TLS_DIR=mbedtls
 MBED_TLS_URL_REPO=https://github.com/ARMmbed/mbedtls.git
 
-# mbed TLS source tag to checkout when building Trusted Firmware with Trusted
-# Board Boot support.
-MBED_TLS_SOURCES_TAG="mbedtls-2.26.0"
+# mbed TLS source tag to checkout when building Trusted Firmware with
+# cryptography support (e.g. for Trusted Board Boot feature).
+MBED_TLS_SOURCES_TAG="mbedtls-2.28.0"
 
 ARMCLANG_PATH="$(set_armclang_toolchain)"
 
diff --git a/utils.sh b/utils.sh
index 48dab67..20ee96f 100644
--- a/utils.sh
+++ b/utils.sh
@@ -340,10 +340,10 @@
 
 linaro_2001_release="${linaro_2001_release:-$tfa_downloads/linaro/20.01}"
 linaro_release="${linaro_release:-$linaro_2001_release}"
-mbedtls_version="${mbedtls_version:-2.26.0}"
+mbedtls_version="${mbedtls_version:-2.28.0}"
 
 # mbedTLS archive public hosting available at github.com
-mbedtls_archive="${mbedtls_archive:-https://github.com/ARMmbed/mbedtls/archive/mbedtls-${mbedtls_version}.tar.gz}"
+mbedtls_archive="${mbedtls_archive:-https://github.com/Mbed-TLS/mbedtls/archive/refs/tags/v${mbedtls_version}.tar.gz}"
 
 coverity_path="${coverity_path:-${nfs_volume}/tools/coverity/static-analysis/2020.12}"
 coverity_default_checkers=(
