High-Tech PCB Reverse Engineering Serices PCB Clone & IC Unlock

PCB Reverse Engineering: Recover Schematic, Netlist, BOM

Aug 11, 2026  /  PCB COPY

pcb reverse engineering: Desoldered PCB on a flatbed scanner with components sorted in labeled trays on a lab bench

Why PCB Reverse Engineering Exists

Every year, thousands of electronic products reach a point where the original design files are no longer available. The OEM may have closed, the engineer who created the board may have moved on, or the files were simply never archived. When that happens, the only source of truth is the physical board itself. PCB reverse engineering is the disciplined process of extracting every piece of design information—copper layers, component values, net connectivity, and mechanical dimensions—from that hardware and rebuilding it into editable, manufacturable documentation.

The need spans industries. Defense contractors face obsolescence in aerospace and defense electronics, medical OEMs must maintain traceability for legacy devices, and industrial equipment owners simply need spare boards for machines that still have decades of service life. In each scenario, the goal is the same: produce a complete data package that lets you fabricate, assemble, and test an identical or improved board.

What You Get: The Four Core Deliverables

Cross-section of a delayered multilayer PCB showing inner copper traces under a microscope

A professional PCB reverse engineering project typically produces four primary outputs. Understanding each one helps you set expectations and evaluate the quality of the work.

1. Schematic

The schematic is the logical blueprint of the circuit. It shows every component, its reference designator, its value, and how it connects to every other component. A well-recovered schematic is hierarchical, readable, and annotated—not just a flat rat’s nest. Engineers use it to understand circuit function, make design changes, and perform failure analysis. Learn more about turning a bare board into a hierarchical schematic.

2. Netlist

The netlist is the connectivity database that ties the schematic to the physical layout. Every pad, via, and trace belongs to a named net. Without a verified netlist, a schematic is just a picture—it cannot drive DRC or be used for automated layout. The process of netlist extraction involves tracing every copper connection across all layers and cross-referencing it against the schematic.

3. Bill of Materials (BOM)

The BOM lists every component on the board: manufacturer, part number, package, value, tolerance, and reference designator. Recovering it requires reading SMD markings, cross-referencing datasheets, and sometimes sourcing alternatives for discontinued parts. A complete BOM is a buildable parts list ready for procurement, not just a list of descriptions.

4. Gerber and Fabrication Data

Gerber files (or ODB++ archives) define every copper layer, solder mask opening, silkscreen marking, and drill hole. They are what the PCB fabricator actually uses to manufacture the bare board. Gerber file extraction rebuilds this data from scanned images and physical measurements, producing output that passes any fab house’s DFM check.

For a deeper look at the full package—including fabrication notes, stack-up specifications, and impedance tables—see our overview of PCB reverse engineering deliverables.

The Step-by-Step Process

PCB reverse engineering is not a single action; it is a sequence of carefully ordered steps, each building on the last. Below is the workflow used in a professional lab.

Step 1: Sample Intake and Photography

The board is received, logged, and photographed from every angle. High-resolution images of both sides capture component placement, silkscreen text, and any visible damage. If you are preparing to ship a board for the first time, review the guidelines for sending your PCB sample safely.

Step 2: Component Removal and Identification

Every component is desoldered, catalogued, and identified. Standard parts with clear markings are straightforward. Chips with sanded tops, custom house numbers, or faded ink require cross-referencing pin counts, package dimensions, and functional testing. When a part is truly obsolete, the engineer flags it for form-fit-function replacement.

Step 3: Outer Layer Scanning

With components removed, the bare board’s top and bottom copper layers are scanned at 1200 DPI or higher. The scans are imported into CAD software, scaled to true dimensions, and converted into vector artwork. Pad shapes, trace widths, and clearances are captured at this stage.

Step 4: Delayering Inner Layers

For multi-layer boards (4, 6, 8, 10+ layers), the inner copper must be exposed. This is done through controlled mechanical grinding or chemical etching—one layer at a time. Each exposed layer is scanned and registered to the outer layers using fiducial marks and via locations. The precision required in PCB delayering is what separates amateur attempts from professional results.

Step 5: Via and BGA Inspection

Buried vias, blind vias, and BGA solder joints cannot always be seen by optical scanning alone. X-ray inspection reveals their exact positions, diameters, and layer connections. This data is critical for boards with high-density interconnect (HDI) structures or fine-pitch BGA packages.

Step 6: CAD Reconstruction

All scanned layers are imported into PCB design software—typically Altium Designer, Cadence Allegro, or KiCad—and rebuilt as editable copper, mask, and drill layers. The engineer places every pad, draws every trace, and defines every via to match the original board. Design rules are set to match the measured trace widths and clearances.

Step 7: Netlist Generation and Schematic Drawing

Once the layout is complete, the software generates a netlist. The engineer then draws the schematic, organizing it by functional blocks (power supply, microcontroller, analog front end, connectors) and verifying that the schematic netlist matches the layout netlist with zero errors.

Step 8: Verification

The rebuilt data is verified against the original board through continuity testing, visual overlay comparison, and—where possible—powered bring-up of a fabricated copy. This stage catches the errors that cost money if missed.

Tools and Technology Behind the Work

A reverse engineering lab relies on a combination of hardware and software. The table below summarizes the most common tools and their roles.

Tool Category Examples Role in the Process
Flatbed / Optical Scanner Epson V850, custom rigs High-resolution layer imaging
X-Ray System Nikon XT H 225, Nordson DAGE Buried via and BGA inspection
Microscope Keyence VHX, Olympus SZX SMD marking reading, trace measurement
PCB Design Software Altium Designer, Cadence Allegro, KiCad Layout reconstruction, netlist, Gerber output
Reverse Engineering Software EasyLogic, PCBI, custom scripts Bitmap-to-vector conversion, auto-trace
LCR Meter / Multimeter Keysight U1733C, Fluke 87V Passive component value verification
Soldering / Rework Station Hakko, JBC, Weller Component removal and reattachment

No single piece of software can complete the entire job. Each tool handles a specific phase, and experienced engineers know where automation helps and where manual judgment is essential. For a candid look at what each application can and cannot do, see our article on the software used in PCB reverse engineering and where each tool stops working.

Accuracy: How Errors Enter and How They Are Caught

The value of a reverse-engineered data package depends entirely on its accuracy. Below are the most common sources of error and the countermeasures used to prevent them.

  • Registration drift during delayering. If inner-layer scans shift even 2 mils relative to outer layers, vias will appear to connect to the wrong nets. Solution: use at least four fiducial points per layer and verify via alignment before proceeding.
  • Misidentified components. A 10 kΩ resistor read as 10 Ω will cause circuit failure. Solution: measure every passive with an LCR meter; cross-reference every IC against its datasheet pinout.
  • Trace width rounding. Scanning resolution limits how precisely trace widths can be measured. Solution: scan at 2400 DPI for boards with traces below 4 mil; use a calibrated microscope for critical nets.
  • Missing connections on inner layers. Copper that is corroded, delaminated, or poorly exposed during delayering can cause open nets. Solution: compare the extracted netlist against the physical board using continuity testing on every net.

A rigorous lab performs multiple verification passes before releasing data. Read about the full verification workflow—continuity, ICT, powered bring-up, and golden-board comparison—to understand what “verified” really means.

Common Use Cases

Legacy Equipment Maintenance

Industrial controllers, CNC machines, and HVAC systems often outlive the companies that designed their electronics. Reverse engineering the PCB lets the equipment owner produce spare boards without depending on the original supplier. This is especially critical for obsolete equipment that no one supports anymore.

Product Redesign and Improvement

Sometimes the goal is not an exact copy but a starting point for redesign. An editable schematic and layout let engineers swap obsolete parts, add new features, or reduce cost—all without starting from scratch.

Second-Source Qualification

Companies that depend on a single supplier for a critical board sometimes reverse engineer it to qualify a second fabrication and assembly source. The deliverables give the second source everything needed to build and test the board independently.

Failure Analysis and Root Cause Investigation

When a board fails in the field and no schematic exists, reverse engineering provides the circuit documentation needed to trace the fault, simulate the circuit, and identify the root cause.

Medical and Defense Compliance

Regulated industries require complete design documentation for every board in a fielded system. When that documentation is lost, reverse engineering is often the only compliant path to recovery. Medical device PCB reverse engineering demands additional traceability and change-control rigor.

Timeline and Cost Factors

Project duration and cost depend on several variables:

Factor Impact on Time Impact on Cost
Layer count (2 vs 12+) High High
Component count Medium Medium
Board size Medium Low–Medium
BGA / fine-pitch density High High
Obsolete or unmarked parts Medium–High Medium
Deliverable scope (Gerber only vs full package) Low–Medium Medium

A simple 2-layer board with 50 components might take 3–5 business days. A 10-layer board with 800 components and multiple BGAs could take 3–5 weeks. For a detailed breakdown of where your budget goes, see our guide to PCB reverse engineering cost.

Intellectual Property and Confidentiality

PCB reverse engineering touches sensitive territory. Reputable labs protect client data through non-disclosure agreements, encrypted file transfer, restricted lab access, and documented sample handling procedures. Before engaging any provider, confirm that they offer a formal NDA and clear data-retention policies.

Choosing the Right Provider

Not all reverse engineering services are equal. Use the checklist below to evaluate a potential partner:

  • Layer capability: Can they handle your board’s layer count? Ask for examples of similar complexity.
  • Verification method: Do they perform continuity testing, or do they simply hand over unverified files?
  • Output format: Can they deliver in Altium, Allegro, KiCad, or ODB++ format—not just Gerber?
  • Component identification depth: Do they measure passives and verify IC pinouts, or just read markings?
  • Confidentiality: Do they offer a signed NDA before receiving your sample?
  • Communication: Will you receive progress updates and have a named engineer as your point of contact?
  • Track record: Ask for case studies or references in your industry.

Frequently Asked Questions

Can any board be reverse engineered?

In principle, yes. In practice, severely damaged boards, boards with epoxy-potted sections, or boards with intentional anti-tamper measures require extra effort and may yield incomplete results. Read about twelve measures used to protect boards from reverse engineering and how labs work around them.

Do I need to send multiple samples?

One sample is usually sufficient for non-destructive work (outer layers, X-ray). If the board has more than two layers, at least one sample will be consumed during delayering. Sending two samples is ideal—one for destructive analysis, one as a golden reference.

Will the copy work exactly like the original?

When the reverse engineering is performed correctly and verified against the original, the fabricated copy should be functionally identical. Verification is the step that guarantees this—skip it at your own risk.

What file formats will I receive?

Most labs deliver Gerber RS-274X, Excellon drill files, a BOM spreadsheet, a schematic PDF, and native CAD project files. If you need ODB++ or IPC-2581 instead of Gerber, specify that at the start of the project.

How is this different from simply copying a board?

A PCB copy reproduces the physical layout without necessarily recovering the schematic or understanding the circuit. Reverse engineering goes deeper—it produces editable, annotated design data that supports redesign, analysis, and long-term maintenance.

Getting Started

If you have a board that needs its design data recovered, the first step is straightforward: photograph both sides, note the approximate layer count and component count, and reach out for a quote. A competent lab will review your images, ask clarifying questions, and provide a timeline and cost estimate before you ship anything.

PCB reverse engineering is not magic—it is methodical, tool-intensive work performed by experienced engineers. When done right, it gives you complete ownership of a design that was previously locked inside a piece of hardware.

Working on a board like this?

Send the chip marking or two photos. You get feasibility, lead time and price within 24 hours, and the check costs nothing.

Get a free quote

Related reading

WhatsApp Send board details