How PCB Reverse Engineering Works: Our Seven-Stage Process

Reverse engineering a circuit board is often described as “scanning” a board, which makes it sound like a single automated step. It is not. It is a sequence of seven stages, and the sequence matters: every stage consumes the output of the one before it, so an error introduced early does not stay small — it propagates into the schematic, the netlist, and eventually the manufactured board. This page walks through the process we actually run, in the order we run it.

Why the sequence matters

Two things can only happen in one direction. Layer exposure is destructive — once a layer is milled away it cannot be recovered, so imaging has to be complete and verified before the next layer is touched. And component values often have to be measured before the board is sectioned, because some parts do not survive the process. A workflow that skips or reorders these stages does not save time; it simply moves the cost to a later phase where it is harder to fix.

The seven stages, in order

Stage 1 — Intake and assessment

The board is photographed, measured and inspected before any work begins. We record length and width to ±0.01 mm, thickness, substrate material and surface finish, and we look for damage: corrosion, scorching, delamination, missing or previously replaced components. Layer count is confirmed by edge inspection or X-ray cross-section. The output of this stage is a project scope document that states what is recoverable, what is at risk, and what will be flagged rather than guessed.

This is also where we decide whether a second sample board is needed. Any board with four or more layers benefits from having an intact reference, because that is what later stages use for continuity verification.

Stage 2 — Component cataloguing

Every component is logged: package type, marking code, orientation, and reference designator position. On a dense board with 200 or more components this stage alone takes four to eight hours, because it is manual work done under magnification.

Marked parts are straightforward — the marking identifies the part. Unmarked, house-marked or proprietary devices are measured electrically: resistance, capacitance and inductance are taken directly, and the values are cross-referenced against candidate parts. The deliverable of this stage is the basis of the bill of materials, and its accuracy determines whether the reproduced board can actually be assembled.

Stage 3 — Layer exposure and imaging

For single- and double-sided boards this stage is non-destructive: both copper layers are visible and are imaged directly at high resolution.

Multilayer boards are different. Each internal copper layer has to be exposed before it can be imaged. For rigid FR-4 we use controlled micro-milling; for flex and polyimide substrates, chemical etching. Each exposed layer is scanned, labelled and archived before the next is removed. This stage is irreversible — there is no undo — which is why we X-ray every multilayer board before any material is removed, so the internal structure is at least documented before it is consumed.

Stage 4 — Vectorisation and netlist extraction

Bitmap scans are imported into CAD and traced into vector geometry. Pads are snapped to grid, vias are mapped across layers, and copper pours are reconstructed. The result is the netlist: the electrical connectivity of every node on the board.

The netlist is then compared against physical continuity measurements taken from the intact reference board. This cross-check is what catches a misread trace before it reaches the schematic — a single missed connection at this stage is far cheaper to fix than the same error found after fabrication.

Stage 5 — Schematic reconstruction

The netlist drives schematic capture, but a netlist is not a schematic. A raw connectivity dump shows which pins connect to which; it does not group circuits by function or present them in a form an engineer can read and maintain. Our engineers restructure the capture by function — power supply, digital logic, analog front end, interfaces, connectors — and reference component datasheets to confirm pin assignments and typical application circuits.

The goal is a schematic that somebody can actually work from, not a flat rat’s nest that happens to be electrically correct. This distinction is what separates usable deliverables from technically compliant ones, and it is covered in more detail under schematic recovery.

Stage 6 — Verification and design rule checks

A second engineer reviews the complete package. This is deliberate: if the person who traced the board also signs it off, their misreadings survive. Independent review catches a meaningful share of first-pass trace errors before they reach the client.

Design rule checks and electrical rule checks are run on the layout. The Gerber output is loaded into an independent viewer and overlaid against the original scans at 1:1 scale, so geometry errors show up as visible mismatches. Our target on every project is zero unresolved net errors at handover.

Stage 7 — Deliverable packaging

The client receives the finished set: Gerber files in RS-274X or ODB++ on request, a schematic in both PDF and native CAD format, a BOM in spreadsheet form with manufacturer part numbers and suggested alternates for obsolete parts, and a pick-and-place centroid file if SMT assembly is planned. Everything ships in a single archive so nothing is lost between handoffs.

What we need from you

  • The board itself, populated or bare, in the best condition available.
  • Two samples where possible for multilayer boards — one for sectioning, one as an intact reference.
  • Any documentation you have, even partial: an old manual, a connector pinout, a photograph of the assembled unit. Fragments reduce inference work.
  • Your intended use, so the deliverable matches it. Reproducing a bare board and understanding a circuit are different projects.
  • Signed NDA before work starts, which we provide.

Timeline by board complexity

Board typeLayersStandard lead timeRush option
Simple consumer board1–23–6 working days2 days
Industrial control board46–10 working days4 days
Networking / telecom board6–810–18 working days7 days
HDI / high-speed board10–1615–25 working daysby assessment

Rush work carries a premium because it compresses scheduling rather than the work itself; the stages cannot be skipped, only overlapped. The full cost implications are set out in our pricing guide.

What can go wrong, and how we handle it

Three problems recur often enough to be worth naming.

Buried vias and inner traces. Where X-ray CT is available we map inner layers non-destructively first. Where it is not, we accept destructive delayering and work from the resulting images, which is slower but reliable.

Conformal coating. Acrylic and urethane coatings are removed with chemical strippers; silicone and parylene coatings are harder and sometimes require mechanical removal under magnification, which adds time.

Custom ASICs and potted modules. Where a proprietary device has no public datasheet and cannot be characterised externally, part of the design intent is not recoverable. We report these limits upfront rather than delivering a plausible guess, because a guessed pinout is worse than a known gap.

Frequently asked questions

Can you reverse engineer a board without removing its components?

Partly. Surface traces and component markings can be read in place. Inner layers cannot — they require either X-ray tomography or destructive layer removal. Where the board must stay intact we rely on X-ray and electrical probing, which works for many four-layer boards but has limits on dense, high-layer-count designs.

How accurate is the reconstructed netlist?

On boards within our stated capability, netlist accuracy after verification is effectively complete — we do not release a project with unresolved net errors. That said, accuracy applies to the copper geometry we can observe. Any area of destroyed copper is reconstructed by inference and is flagged as such in the delivery notes.

Do you need the original firmware to reproduce a board?

For the bare board, no. For a working unit, yes — a reproduced board with no program will not run. Firmware recovery is a separate service and depends on the protection mechanism of the specific device.

How do you handle boards with obsolete components?

We document them in the BOM with suggested modern equivalents. Where no drop-in replacement exists, we flag it as a small redesign rather than pretending a substitution will work. This is covered in our guide to obsolete component sourcing.

Is the process different for a single-sided board?

It is simpler, not different. Stages 1, 2, 4, 5, 6 and 7 are identical. Only stage 3 changes: a single-sided board needs no layer removal, which is why it sits at the low end of both cost and lead time.

If you want to see how this process applies to your board, send us photographs and a short description and we will return a scope assessment within one business day.

Related reading