PEmicro's development tools and production programmers support life-cycle management with readout protection (RDP) on STM32C5 devices. This article explains the STM32C5 security model and walks through provisioning regression passwords and performing RDP regression using PROGACMP and related PEmicro utilities. Tool support note: PEmicro tools support OEMKEY-based RDP regression from RDP2 to RDP0. Boundary scan operations are not currently supported — this includes the BSKEY transition from RDP2 with boundary scan to RDP2, and OEMKEY regression from the RDP2 with boundary scan state. If you use PEmicro tools for life-cycle management, plan to transition directly between RDP0 and RDP2. For background on STM32 families that support OEM-password RDP regression, see our earlier article on [STM32U-series RDP regression]. The STM32C5 workflow is similar, but there are important differences in RDP levels, key sizes, and tool configuration that are covered below. The STM32C5 series introduces a simplified but hardened product life cycle focused on secure boot and password-protected regression. Unlike many other STM32 families, the STM32C5 does not have an RDP level 1. The device operates in one of three readout protection states set by the RDP value in the FLASH_OPTSR option byte. The following states are listed below with their correlating RDP values: The STM32C5 device supports two password keys, provisioned while the device is in RDP0: For full technical details, refer to: - [ST Wiki: How to set the RDP password keys and levels on STM32C5 MCUs] - [ST Wiki: Getting started with STM32C5 security] - [RM0522 STM32C5 Series Reference Manual] — Chapter 3, Product Life CycleSTMicroelectronics: Securing and Recovering STM32C5 Devices with RDP Regression
STM32C5 Security Background
RDP State Value Debug Access RDP0 (open) 0xED Full debug access RDP2 with Boundary Scan 0xD1 Boundary scan only; OEMKEY can regress to RDP0 (not supported by PEmicro tools) RDP2 (closed) 0x72 No debug access; OEMKEY can regress to RDP0 (supported by PEmicro tools) 
Important warnings
PEmicro has launched the Cyclone MultiChannel Programmer, a new production programming platform capable of simultaneously programming up to 16 devices in a compact, modular form factor. Designed for manufacturing environments where throughput, reliability, automation, and form factor are critical, the Cyclone MultiChannel combines true independent-channel programming with a single point of control, enabling production teams to manage parallel programming operations without increased complexity. Built on programming technology refined by PEmicro over decades and redesigned for today's automated manufacturing environments, the Cyclone MultiChannel represents a new generation of PEmicro production programming tools. Fixture and benchtop space are at a premium. The Cyclone MultiChannel packs a high channel count into an exceptionally compact footprint, making it ideal for fixture integration, benchtop operation, automated test systems, and scalable manufacturing environments. Its modular architecture is built around quad-channel blocks that can be snapped together, mounted, or DIN-railed to fit the production environment. Standard configurations include 4-, 8-, 12-, and 16-channel systems, with even larger programming installations possible through SDK-based control of multiple units. The result is a programming platform that scales with production requirements while minimizing fixture space and cabling complexity. Built to Meet Production Challenges Some production environments program large volumes of a single product, while others support a continually changing mix of devices each with their own programming requirements. The Cyclone MultiChannel was designed to meet these challenges. The platform supports thousands of ARM and non-ARM devices and a broad range of programming protocols including SWD, JTAG, Secure JTAG, BDM, DAP, Nexus, and more. The Cyclone MultiChannel has a robust and varied set of capabilities including: Whether the requirement is high-throughput programming, serialization, traceability, device testing, automation, or support for multiple device architectures, the Cyclone MultiChannel provides the flexibility needed to support a wide range of programming applications. Designed for Automation Manufacturing often depends on automation, and the Cyclone MultiChannel was built with that reality in mind. Comprehensive SDK and console tools enable seamless integration into custom manufacturing applications, command-line interfaces, fixture controllers, Manufacturing Execution Systems (MES), and Automated Test Equipment (ATE). Integration support includes: Whether integrating a single fixture or deploying a fully automated production line, the Cyclone MultiChannel provides the flexibility and control needed to fit into existing manufacturing infrastructure. Available for ordering now, ships June 30th 2026.
Ultra-Compact Design Without Sacrificing Capability
Production programming requirements vary widely.
Learn more about the new Cyclone MultiChannel Programmer and explore available configurations, features, and supported architectures.
With the release of Cyclone software v11.70 and PROG-HL-ARM software v10.00, the following support for STMicroelectronics has been added:
With the release of Cyclone software v11.70 and PROG v10.00, PEMicro’s development and production tools now support additional Wireless Stack features for the STM32WB5x, STM32WB3x, and STM32WB1x devices. The latest PROG and Cyclone support now enables selecting .BIN files for the FUS Operator, Wireless Stack, or the FUS FW. A new command has been added to start the wireless stack in case the FUS begins running. In PROGACMP, there is an additional command to read the FUS FW version from the target to determine which FUS FW version to upgrade.
PEmicro's development tools and production programmers now support Life-cycle management with readout protection (RDP) for STM32 device families. STM32 families that include this feature: STM32U5, STM32U3, STM32U0, & STM32WBA. The RDP mechanism enables secure protection over the devices memory and debug access varying by the RDP level. The protections provided by each RDP level is described in the Table below: The RDP level can be transitioned to a higher level by programming the RDP value in the user area of the option bytes. Regression of the RDP level can be accomplished by provisioning the OEM password to verify access. This article will explore how this process is handled with our tools.
PEmicro's development tools and production programmers now support Debug Authentication provisioning with a password configuration for STMicroelectronics' STM32H7S3, STM32H7S7, STM32H7R3, and STM32H7R7 products.
PEmicro's development tools and production programmers now support OBK programming for STMicroelectronics' STM32H573 series product line. With all the features of the STM32H563 line, including enhanced performance, better power efficiency and more embedded peripherals, STM32H573 devices also include a secure key storage mechanism which adds another layer of security for OBKeys.
PEmicro's programming tools support provisioning and securing of STMicroelectronics' STM32H563 devices in both TrustZone enabled and TrustZone disabled configurations. This tutorial demonstrates a sequence for programming the device into a secure, TrustZone enabled state. Secure and non-secure code and data images are programmed, Debug Authentication is enabled with certificate access, and the OEM-iRoT is provisioned.
STMicroelectronics' STM32H503 devices are based on the ARM Cortex M33 and offer high performance and power efficiency suitable for a wide range of applications. In addition, the STM32H5 product life-cycle adds a layer of security, allowing the user to secure/unsecure a device by moving it through product states. The following example details how to step through a simple product lifecycle.
PEmicro's PROGACMP and Cyclone software have a set of "user options" commands: These commands allow the developer to individually program user options through the use of an IDE.
PEmicro's programming tools support provisioning and securing STMicroelectronics STM32H563 devices in both TrustZone enabled and TrustZone disabled configurations. This article gives an example of how to program the device in the TrustZone disabled configuration. A password is programmed which allows the device to be regressed to the Open (non-secure) state.
The process of setting up Cyclone programmers to perform production programming at a local or remote facility is simple and straightforward. PEmicro's Cyclones support programming of STMicroelectronics' popular STM32 and Bluetooth Low-Energy (BlueNRG) devices, as well as the SPC5 automotive and STM8 8-bit families. In addition, Cyclone programmers leverage PEmicro's ProCryption Security to use industry-standard RSA/AES cryptography to safeguard programming images containing valuable IP. The IP owner also gains added control over factors like when and how many devices can be programmed, and how many errors are allowed. This article will provide an overview of Cyclone programming - what the various components are and how they interact - and then explore the security aspect of the production programming process, in order to show that IP security does not need to be unduly complicated or expensive to be effective.
PEmicro tools can be used to update the current flash memory of STMicroelectronics' STM32WB Wireless MCUs with wireless stack information. Deleting current wireless stacks allows for more available flash memory in the processor, while upgrading wireless stacks allows the processor to perform desired wireless functions out of the otherwise inaccessible second core.
STM32CubeIDE from STMicroelectronics is an Eclipse-based enablement platform which supports development and debugging of code on STM32 ARM microprocessors. PEmicro's Multilink debug probes and Cyclone programmers can be leveraged for advanced debug capabilities via an Eclipse GDB plugin installed into any Eclipse IDE. This blog demonstrates the steps needed to install and configure PEmicro Multilink and Cyclone debug support in STM32CubeIDE to the point of launching a debug session.
Article updated Aug. 2021 to describe automatic fuse generation for NXP i,MX RT devices. Some ARM devices have areas of flash memory dedicated to programming user configuration data. Writes to such areas can be sensitive or permanent for some devices, so it is important that the developer is able to write these options in an intuitive way in order to minimizes human error. PEmicro's PROGACMP v7.78 and Cyclone software installer v10.41 introduce a set of new "user options" commands: These commands allow the developer to individually program user options through the use of an IDE.
Note: As of January 2020, PEmicro now offers a new method of programming user configuration data through the new Program User Options command. Click here for more details about this command. PEmicro supports a wide selection of STMicroelectronics' STM32 device families. Many STM32 devices include a set of user configurable option bytes that can control features such as HW/SW watchdog, read protection, and write protection. These options give users a convenient way of changing the settings of their device. Configuring option bytes of a STM32Fx or STM32Lx device is made easy with our PROG software and Cyclone Image Creation Utility software.
Download the Installer for PEmicro support under Keil uVision IDE PEmicro's run control and FLASH programming support is fully integrated into ARM's MDK-ARM Keil uVision Integrated Development Environment v5.25 for ARM microcontrollers. This provides debug capabilities via PEmicro's Multilink, Cyclone and embedded OpenSDA debug interfaces for a broad range of ARM devices from NXP, STMicroelectronics, Atmel, Cypress, Infineon, Silicon Labs and many others. For complete list of ARM devices that PEMicro supports, please visit the following page: http://www.pemicro.com/arm/.
A volume production solution often relies on simultaneous gang programming of different target boards to meet speed and throughput requirements. This programming scenario may integrate Cyclone programmers into a fixture which interfaces to a panel of boards to be programmed. Programming is commonly controlled and monitored from a local computer, especially when customized dynamic data is being added to the main binary image that is being programmed into each target. PEmicro’s gang programming solution is to control many Cyclone programmers simultaneously via the Cyclone Control Suite. A mix of programming images, targets, and data can be simultaneously programmed into many devices while maintaining a high level of performance because each Cyclone is itself an independently operating programmer.