High-Tech PCB Reverse Engineering Serices PCB Clone & IC Unlock

PCB Reverse Engineering Cost: What Actually Drives It

Sep 5, 2026  /  PCB COPY

PCB reverse engineering cost is driven by six things: layer count, board size, component count, whether there are BGAs or blind/buried vias, which deliverables you need, and whether firmware is involved. Nobody can quote a board from a description alone. Send clear photos of both sides plus the board dimensions, and you get feasibility, lead time, and a price back — usually within a day.

If you’re collecting quotes and the numbers you’re getting back vary by 5x, that’s normal. It usually means the vendors are quoting different deliverable sets. This page explains what you’re actually paying for.

Why one board costs more than another

Reverse engineering is engineer-hours, not material. The board is consumed as a reference; what you pay for is the time someone spends tracing nets, identifying parts, and verifying the result. So every cost driver is really a proxy for hours.

Layer count is the biggest single factor

A two-layer board can often be traced optically from both sides with good lighting and a microscope. Nothing has to be destroyed. Once you go past two layers, the inner copper has to be imaged, and that means controlled removal of the outer layers — grinding or chemical stripping down one plane at a time, scanning each one, then registering all the images to the drill pattern so the vias line up.

That work scales roughly with layers, but not linearly. Going from four to six layers adds two scans. Going from eight to twelve adds four scans plus a much harder registration problem, because small errors in alignment compound and every misregistered via becomes a net error you have to chase down later. A twelve-layer telecom board is not three times a four-layer board — it’s more.

Component count and density

Every part on the board needs a footprint, a value, and a line in the BOM. A 200-part board with a mix of 0402 passives, a couple of QFNs, and a linear regulator is straightforward. A 900-part board with unmarked SOT-23s, remarked house-numbered ICs, and three different crystal packages costs more, because each ambiguous part becomes a measurement or a datasheet hunt.

Passives with no visible marking — most ceramic caps and small inductors — have to be measured off the board or inferred from the circuit. That’s cheap per part and expensive in aggregate.

BGAs, fine pitch, and hidden vias

A BGA hides its entire connection pattern under the package. To get the ball map and the escape routing you generally need X-ray imaging, and often controlled removal of the device so you can see the pads underneath. Blind and buried vias make it worse: a via that only spans layers 3 to 5 doesn’t show on either outer surface, so the only way to find it is layer-by-layer imaging with careful registration.

HDI boards with microvias and stacked vias sit at the top of the difficulty range. They’re doable, but budget accordingly.

Deliverables — this is where quotes diverge most

“Reverse engineer this board” means four different things to four different vendors. Gerber-level copy files are the cheapest output because you never have to understand the circuit — you just reproduce the copper. A full schematic costs more because someone has to read the design, group the nets into recognizable blocks, and make it human-readable. A verified BOM with second sources costs more again.

Deliverable What it takes Relative cost
Gerber + drill files Layer imaging, net cleanup, no circuit analysis Lowest
Gerber + BOM Above, plus part ID and measurement of unmarked passives Low to moderate
Netlist Full connectivity extraction, pin-level mapping Moderate
Editable schematic (Altium/KiCad/OrCAD) Connectivity plus circuit interpretation and readable sheet layout Higher
Schematic + editable PCB source + BOM Everything above, re-entered as a real design database Highest non-firmware tier
Any of the above + firmware recovery Separate chip-level work, quoted separately Depends entirely on the part

Be specific about what you’ll do with the files. If you only need to build spares, Gerbers and a BOM may be enough. If you plan to modify the design — swap an obsolete regulator, add a connector, meet a new EMC requirement — you need the schematic and an editable layout, and paying for the cheap tier first means paying twice.

Board condition

Cost goes up when the board fights back. Conformal coating has to be removed without lifting silkscreen. Potting compound and epoxy blobs over die-on-board parts are slow and sometimes destructive. A board that arrived burnt, water-damaged, or with sections already cut out means missing information that has to be reconstructed from the circuit’s own logic — and sometimes can’t be.

Whether firmware is in scope

Copper and firmware are separate jobs with separate cost structures. Board-level work is predictable; chip-level work depends on the exact part and the protection state it was shipped in. An STM32 at RDP Level 1 is a very different conversation from the same die at Level 2, and an MSP430 with a blown JTAG fuse is different again from one with only a BSL password set. Old 8051 and AVR parts with simple lock bits sit at the easy end. None of that is knowable until we see the marking.

How much does PCB reverse engineering cost in practice?

We don’t publish a price list, and you should be skeptical of anyone who does for this kind of work. What we can tell you is how the ranges relate to each other, which is usually what you need for a budget conversation:

  • A small two-layer control board with under 100 parts, Gerbers only, sits at the bottom of the range — the kind of number you can approve without a purchase order in most companies.
  • A four-layer board with a few hundred parts and a full schematic deliverable is a mid-range project. This is the most common request we see.
  • A dense six- to twelve-layer board with BGAs, impedance-controlled routing, and full editable source is a genuine engineering project with a proportional price.
  • Adding firmware recovery adds a line item that can be small or can exceed the board work, depending on the chip.

Two things reduce your cost more than negotiating does. First, send two identical boards if you have them — one to sacrifice for layer separation, one to keep intact as a reference. That avoids reconstruction work. Second, send whatever partial documentation exists. An old BOM, a pinout note, even a photo of a hand-drawn block diagram removes hours of guessing. Our breakdown of what drives reverse engineering cost across service types goes further into how these levers interact.

What to send for a real quote

Rough descriptions produce rough numbers. Here’s what makes a quote accurate:

  1. Photos of both sides, on a dark, non-reflective background, whole board in frame and in focus. Straight-on, not at an angle. Diffuse light beats flash.
  2. Board dimensions in mm or inches, plus thickness if you have calipers handy.
  3. Layer count if you know it. If you don’t, say so — we can usually estimate from the photos and the via pattern.
  4. Close-ups of the main ICs so we can read the markings. Any part with a sanded-off or house-numbered top, flag it.
  5. One line on deliverables. “Gerbers to build spares” or “full schematic, we need to redesign the power stage” is enough.
  6. Whether firmware matters. If a programmed MCU has to work in the copy, tell us up front — it changes the whole scope.

What comes back is a feasibility assessment, a lead time, and a price. If something on the board looks like a problem, you’ll hear about it before you commit, not after. The step-by-step walkthrough of the process shows what happens to your board once the quote is accepted.

Where the honest limits are

Some cases are hard and a few aren’t worth doing:

  • Full-custom ASICs and mask ROM parts. We can identify them and map their connections, but we can’t reproduce the silicon. If a board depends on a discontinued custom chip, reverse engineering the PCB doesn’t solve your problem by itself.
  • Heavily damaged boards. Burnt traces and delaminated regions leave real gaps. We’ll tell you how much is unrecoverable before quoting.
  • Secure elements and hardened MCUs. Some parts are designed so that stored code cannot be read out. Nobody should promise you otherwise.
  • High-speed and RF sections. Copper geometry copies fine, but matching the original’s impedance behavior depends on the stackup and the dielectric material, which we characterize rather than assume. Expect discussion, not a silent copy.
  • Ancient boards with no surviving reference. Single copy, missing parts, no schematic anywhere — sometimes a partial recovery plus a redesign of the missing block is cheaper than a full trace-out.

On the legal side: we work on boards and firmware you have the rights to — recovering your own lost design files, keeping out-of-production equipment running, dealing with obsolete parts, failure analysis. You’re responsible for holding those rights; every project runs under NDA.

FAQ

How much does it cost to reverse engineer a 4-layer PCB?

It depends mostly on part count and deliverables, not the layer count alone. A four-layer board with 150 parts and Gerber-only output is a modest job. The same board with 600 parts, two BGAs, and a full editable schematic can be several times that. Send photos and dimensions and you’ll get a firm number, not a range.

Why do vendors quote such different prices for the same board?

Almost always because they’re quoting different deliverables. One vendor prices copper-level copy files; another prices a verified schematic plus BOM plus editable layout. Ask each one to list exactly which files you receive and in which CAD format. Once that’s f

Working on a board like this?

Send the chip marking or two photos. You get feasibility, lead time and price within 24 hours, and the check costs nothing.

Get a free quote

Related reading

WhatsApp Send board details