High-Tech PCB Reverse Engineering Serices PCB Clone & IC Unlock

Supported IC List for IC Unlock | 70+ Families

Sep 9, 2026  /  PCB COPY

supported ic list ic unlock: Laboratory workstation with microcontroller chips prepared for firmware recovery and IC unlock

Supported IC List for IC Unlock — Complete Reference Guide

Our supported IC list for IC unlock spans more than 70 distinct microcontroller and memory IC families from 15+ silicon vendors. Every entry below represents a part our engineers have successfully recovered firmware from under authorized conditions — the requester owns the IP, holds a valid license, or requires legacy maintenance access. If your specific part number does not appear on this supported IC list, submit a free feasibility inquiry through our IC unlock service; we evaluate new devices weekly and add roughly 5–10 new part numbers every quarter.

How We Organize the Supported IC List for IC Unlock

supported ic list ic unlock: Laboratory workstation with microcontroller chips prepared for firmware recovery and IC unlock

ICs are grouped by vendor, then by protection mechanism. This structure matters because the unlock method, turnaround time, and cost all depend on the type and generation of read protection — not just the part number. A device with single-level RDP (Read-out Protection) is fundamentally different from one using TrustZone or hardware-fuse encryption.

For each family on the supported IC list we note:

  • Protection type — software lock bits, OTP fuses, hardware encryption, or combined.
  • Typical success tier — High (>90%), Moderate (60–90%), or Case-by-case (<60%, dependent on silicon revision).
  • Turnaround range — working days from receipt of the physical IC or valid dump.
  • Package notes — where BGA or WLCSP handling adds preparation time.

ARM Cortex-M MCUs (STMicroelectronics)

STM32 parts are the single most requested family on our supported IC list for IC unlock. STMicroelectronics implements Read-out Protection in three levels: Level 0 (unprotected), Level 1 (debug access blocked but reversible), and Level 2 (permanent OTP fuse). The distinction between Level 1 and Level 2 is critical — Level 1 recovery is well-documented and repeatable, while Level 2 requires invasive die-level techniques that are silicon-revision dependent.

Family / Part Prefix Core Protection Success Tier Turnaround
STM32F0xx Cortex-M0 RDP Level 1 High 3–5 days
STM32F1xx Cortex-M3 RDP Level 1 High 3–5 days
STM32F2xx Cortex-M3 RDP Level 1/2 High (L1) / Moderate (L2) 5–10 days
STM32F3xx Cortex-M4 RDP Level 1 High 3–7 days
STM32F4xx Cortex-M4F RDP Level 1/2 High (L1) / Case-by-case (L2) 5–12 days
STM32F7xx Cortex-M7 RDP Level 1/2 Moderate 7–14 days
STM32L0xx / L1xx Cortex-M0+/M3 RDP Level 1 High 3–5 days
STM32G0xx / G4xx Cortex-M0+/M4 RDP Level 1/2 High (L1) / Moderate (L2) 5–10 days
STM32H7xx Cortex-M7 RDP Level 1/2 + Secure area Case-by-case 10–20 days
STM32WB55 Cortex-M4 + M0+ RDP + Secure area Moderate 7–14 days

Important caveat: STM32 RDP Level 2 permanently disables the debug port via OTP fuses. Recovery from Level 2 requires invasive techniques that are silicon-revision dependent. We provide a candid feasibility assessment before quoting Level 2 jobs — no charge, no obligation. On STM32F4 parts specifically, certain die revisions manufactured before Q3 2019 have a higher success rate than later steppings.

NXP / Freescale Kinetis & LPC

NXP’s LPC and Kinetis lines use Code Read Protection (CRP) levels 1 through 3 and Flash Security bytes respectively. CRP1 restricts ISP commands but leaves partial access; CRP2 blocks most read paths; CRP3 disables ISP entry entirely. Our IC unlock engineers have documented repeatable success on CRP1 and CRP2 across all tested LPC revisions, while CRP3 outcomes depend on specific die characteristics.

Family Core Protection Success Tier Turnaround
LPC1100 / LPC1300 Cortex-M0/M3 CRP Levels 1–3 High (CRP1/2) / Case-by-case (CRP3) 3–10 days
LPC1700 / LPC1800 Cortex-M3/M3 CRP Levels 1–3 High (CRP1/2) 5–10 days
LPC2100 / LPC2300 ARM7TDMI CRP High 3–5 days
LPC54xxx Cortex-M4 CRP + Secure boot Moderate 7–14 days
MK60 (Kinetis K60) Cortex-M4 Flash Security + FSEC byte High 5–7 days
MKE02 (Kinetis E) Cortex-M0+ Flash Security High 3–5 days

Nuvoton & Renesas

Family Protection Success Tier Turnaround
NUC131 (Nuvoton) Flash lock bits High 3–5 days
NUC029 / NUC100 / NUC200 Flash lock bits High 3–7 days
N76E003 Lock byte High 3–5 days
R5F (Renesas RX / RL78) ID code protection Moderate 5–10 days
R8C / M16C (Renesas) ID code High 5–7 days
RA2 / RA4 (Renesas) TrustZone + DLM Case-by-case 10–20 days

Nuvoton’s NUC and N76E families use straightforward flash lock bits that our lab clears with high reliability. Renesas ID-code protection on the older R8C and M16C lines is similarly well-understood. The newer RA-series parts with Device Lifecycle Management (DLM) and TrustZone are evaluated individually — silicon revision and key provisioning state both affect the outcome.

Nordic Semiconductor (BLE SoCs)

Nordic’s nRF5x series is widely used in IoT, wearables, and industrial sensors. The APPROTECT mechanism disables SWD access when set. Our lab has repeatable methods for certain silicon revisions of the nRF51 and nRF52 families, making them frequent entries on our supported IC list.

Part Protection Success Tier Turnaround
nRF51822 RBPCONF / APPROTECT High 3–7 days
nRF52832 APPROTECT Moderate 5–10 days
nRF52840 APPROTECT + Secure boot Moderate 7–14 days

Newer nRF53 and nRF91 parts use ARM TrustZone and hardware root-of-trust. These are evaluated strictly on a case-by-case basis — contact us with the full part marking and revision code. Early nRF52832 revisions (QFAA-Bx0) tend to yield higher success rates than later steppings.

Cypress / Infineon PSoC

PSoC devices combine configurable analog blocks with an ARM or M8C core, making them common in industrial controls and medical peripherals. Flash protection on PSoC 1 (CY8C2xxxx) is software-configurable; PSoC 4/5/6 adds multi-level protection rows.

Family Protection Success Tier Turnaround
CY8C21x / CY8C24x / CY8C27x (PSoC 1) Flash protection bits High 3–7 days
CY8C4xxx (PSoC 4) Chip-level protection + row protection Moderate 7–12 days
CY8C5xxx (PSoC 5LP) Multi-level protection Case-by-case 10–20 days
CY8C6xxx (PSoC 6) Secure boot + eFuse Case-by-case 14–25 days

Microchip PIC & AVR, TI MSP430, STC

These families represent some of the highest-volume IC unlock requests we handle. Microchip’s PIC and AVR lines use code-protect (CP) bits and lock bits respectively — both are well-characterized across decades of silicon revisions. TI’s MSP430 relies on a JTAG fuse that, once blown, blocks debug access; our techniques restore read capability on all tested MSP430F and MSP430G variants.

Family Protection Success Tier Turnaround
PIC16F / PIC18F (Microchip) Code protect bits (CP) High 3–7 days
PIC24 / dsPIC33 Code Guard / General Segment Moderate 5–10 days
PIC32MX / PIC32MZ Code protect + Boot Flash protection Moderate 7–12 days
ATmega / ATtiny (Microchip/Atmel) Lock bits High 3–5 days
MSP430 (Texas Instruments) JTAG fuse High 3–7 days
STC15 / STC8 Proprietary ISP lock High 3–5 days

Serial EEPROM & Flash Memory ICs

Various IC package types including QFP, BGA, DIP, and SOP used in unlock projects

Memory ICs are often overlooked, but they frequently store calibration data, configuration parameters, or even full application firmware in systems that boot from external flash. These devices typically use write-protect pins or software lock-down registers rather than cryptographic protection, making readout highly reliable. They form one of the simplest categories on our supported IC list for IC unlock.

Part Interface Density Success Tier Turnaround
24C02 I²C 2 Kbit High 1–2 days
24C64 I²C 64 Kbit High 1–2 days
24C256 I²C 256 Kbit High 1–2 days
AT24C512 I²C 512 Kbit High 1–2 days
93C46 Microwire 1 Kbit High 1–2 days
93C56 Microwire 2 Kbit High 1–2 days
M95080 SPI 8 Kbit High 1–2 days
SST25VF series SPI Up to 32 Mbit High 1–3 days
W25Q series (Winbond) SPI Up to 128 Mbit High 1–3 days
MX25L series (Macronix) SPI Up to 256 Mbit High 1–3 days

Maxim (Analog Devices) Specialty MCUs

Family Protection Success Tier Turnaround
MAX32660 Flash protection register Moderate 5–10 days
MAX32630 Flash protection + Secure bootloader Case-by-case 10–15 days

What Determines Whether an IC Can Be Unlocked?

Three factors control feasibility more than anything else:

  1. Protection level and generation. A single software lock bit (e.g., STM32 RDP Level 1 or PIC CP bit) is far easier to bypass than a hardware OTP fuse or AES-encrypted boot chain. Newer silicon revisions within the same family sometimes patch previously viable attack vectors — an STM32F1 from 2012 may respond to a technique that fails on a 2022 lot.
  2. Physical condition of the die. Corrosion, reballing damage, or decapsulation artifacts reduce success rates. We inspect every device under 200× magnification before committing to invasive work.
  3. Package and bond-wire accessibility. BGA and WLCSP packages require more preparation than LQFP or DIP. Turnaround for BGA parts typically adds 1–3 working days. QFN packages with exposed pads are intermediate in difficulty.

If your IC is not on this supported IC list, that does not mean recovery is impossible — it means we have not yet documented repeatable success. We accept evaluation samples for new parts at no charge beyond return shipping.

Authorization & Legal Requirements

Every IC unlock engagement requires proof of ownership or written authorization from the IP holder. This protects both parties and keeps the service within the bounds of legitimate reverse engineering for interoperability, maintenance, and archival purposes. Before work begins, clients sign an NDA and provide one of the following:

  • Purchase order or invoice showing device procurement.
  • Written authorization from the original equipment manufacturer.
  • A declaration of ownership for legacy/end-of-life hardware recovery.

We maintain strict chain-of-custody documentation throughout the process. Read more about our compliance and IP-protection policies.

Typical Workflow for IC Unlock Requests

  1. Submit your part number and protection details — use our online form or email. Include the full part marking (top and bottom lines), package type, and any known protection level.
  2. Receive a feasibility report — within 1–2 working days, we confirm whether the device is on our supported IC list for IC unlock and provide a quote with turnaround estimate.
  3. Ship the device or board — we accept bare ICs or complete PCBAs. For EEPROM readout, a board photo with pinout is often sufficient for remote guidance.
  4. Firmware extraction and verification — recovered data is verified against known checksums or functional testing where possible. Deliverable formats include Intel HEX, Motorola S-Record, or raw BIN.
  5. Secure delivery — files are transferred via encrypted channel. Physical devices are returned insured.

For projects that also require full board-level duplication — schematic capture, Gerber generation, and BOM extraction — our PCB reverse engineering service integrates directly with IC unlock to deliver a complete reproduction package.

[pcb_cta type=”feasibility”]

Deliverable Formats & Verification

Recovered firmware is delivered in the format most useful for your reprogramming workflow. Standard options include:

Format Extension Typical Use
Intel HEX .hex Most flash programmers, IDE import
Motorola S-Record .srec / .s19 Freescale/NXP toolchains, automotive ECUs
Raw Binary .bin Direct flash image, EEPROM writers
Annotated Memory Map .pdf + .bin Multi-region devices (bootloader + app + data)

For multi-region devices — common in STM32 and PIC32 parts with separate bootloader, application, and EEPROM data sections — we provide an annotated memory map at no extra charge, identifying each region’s start address, size, and CRC where applicable.

Pricing Signals & Turnaround Summary

IC unlock pricing depends on the protection mechanism, not just the part number. As a general guide:

  • EEPROM / simple lock-bit MCUs (24Cxx, ATmega, PIC16F, STC): starting from approximately $50–$150, 1–5 working days.
  • Mid-tier protection (STM32 RDP L1, NXP CRP1/2, MSP430 JTAG fuse): starting from approximately $150–$500, 3–10 working days.
  • High-tier / invasive (STM32 RDP L2, NXP CRP3, nRF52 APPROTECT, PSoC 5LP): quoted per-project after feasibility assessment, 7–25 working days.

Exact pricing is provided after we confirm the part number and protection state. Request a quote through our project quotation page.

Frequently Asked Questions

How often is the supported IC list updated?

We add new part numbers as our engineers validate repeatable IC unlock methods — typically 5–10 new entries per quarter. If your device is not listed, request a free evaluation. Newly validated parts are published within two weeks of confirmed success.

Can you unlock an IC with RDP Level 2 or CRP Level 3?

These are the highest software-protection tiers offered by STM32 and NXP LPC respectively. Success depends on the specific silicon revision and die-level characteristics. We provide an honest feasibility assessment before quoting — if we cannot recover the firmware, you pay nothing for the evaluation.

Do I need to remove the IC from the board before shipping?

Not necessarily. For many MCUs, we can connect via debug headers or test points on the assembled PCBA. For invasive techniques or EEPROM readout, desoldering may be required — our technicians handle this in-house to avoid damage.

Is IC unlock legal?

Authorized firmware recovery — for hardware you own, legacy maintenance, or interoperability — is legal in most jurisdictions under provisions like the DMCA §1201 exemptions and EU Directive 2009/24/EC. We require proof of ownership and operate under NDA for every project. See our trust and compliance page for details.

What if my IC family is not on the supported IC list?

An unlisted part does not mean recovery is impossible. Ship us an evaluation sample or provide the full part marking and package details, and our engineers will assess feasibility within 1–2 working days at no charge. We regularly expand the supported IC list for IC unlock based on client requests and new tooling investments.

Working on a board like this?

Send the chip marking or two photos. You get feasibility, lead time and price within 24 hours, and the check costs nothing.

Get a free quote

Related reading

WhatsApp Send board details