<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Clarification on nRF54L15 ERASEPROTECT</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/128778/clarification-on-nrf54l15-eraseprotect</link><description>Hi Nordic Support, 
 I have a question regarding the nRF54L15 security features. 
 If APPROTECT, SECUREAPPROTECT, and ERASEPROTECT are enabled (with ERASEPROTECT.LOCK set), is it still possible for someone with physical SWD access (using J-Link or nRF</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 23 Jul 2026 12:11:52 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/128778/clarification-on-nrf54l15-eraseprotect" /><item><title>RE: Clarification on nRF54L15 ERASEPROTECT</title><link>https://devzone.nordicsemi.com/thread/569400?ContentTypeID=1</link><pubDate>Thu, 23 Jul 2026 12:11:52 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:58de7b09-0548-4572-acf9-2ea05c92b232</guid><dc:creator>Bipinv2000</dc:creator><description>&lt;p&gt;ok thanks for the information&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Clarification on nRF54L15 ERASEPROTECT</title><link>https://devzone.nordicsemi.com/thread/569398?ContentTypeID=1</link><pubDate>Thu, 23 Jul 2026 11:47:41 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:2a234db0-c611-46a7-8a1b-d2355e476c27</guid><dc:creator>Adam Le</dc:creator><description>&lt;p&gt;Essentially yes. If you lose the mechanism to&amp;nbsp;provide ERASEPROTECT.DISABLE, there will be no method to recover the chip. This is a deliberate security design. That is why you should ensure you have a reliable way to write to the register before enabling both APPPROTECT and ERASEPROTECT simultaneously.&lt;/p&gt;
&lt;p&gt;Br,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Adam&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Clarification on nRF54L15 ERASEPROTECT</title><link>https://devzone.nordicsemi.com/thread/569396?ContentTypeID=1</link><pubDate>Thu, 23 Jul 2026 11:26:02 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:48d78294-b42f-4b2f-90c3-d3dc74ffe391</guid><dc:creator>Bipinv2000</dc:creator><description>&lt;p class="isSelectedEnd"&gt;&lt;span&gt;Hi,&lt;/span&gt;&lt;/p&gt;
&lt;p class="isSelectedEnd"&gt;&lt;span&gt;Just to confirm my understanding:&lt;/span&gt;&lt;/p&gt;
&lt;p class="isSelectedEnd"&gt;&lt;span&gt;If I enable &lt;/span&gt;&lt;strong&gt;&lt;span&gt;APPPROTECT + ERASEPROTECT&lt;/span&gt;&lt;/strong&gt;&lt;span&gt; (and optionally &lt;/span&gt;&lt;strong&gt;&lt;span&gt;SECUREAPPPROTECT&lt;/span&gt;&lt;/strong&gt;&lt;span&gt;), and later lose the firmware or key/mechanism required to disable ERASEPROTECT, does that mean the device is permanently locked? In that case, would there be &lt;/span&gt;&lt;strong&gt;&lt;span&gt;no method&lt;/span&gt;&lt;/strong&gt;&lt;span&gt; to recover the chip or program new firmware again&amp;mdash;not even through Nordic support or factory tools?&lt;/span&gt;&lt;/p&gt;
&lt;p class="isSelectedEnd"&gt;&lt;span&gt;I just want to be absolutely sure before enabling these protections, since an incorrect configuration could make the device unrecoverable.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Thank you.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Clarification on nRF54L15 ERASEPROTECT</title><link>https://devzone.nordicsemi.com/thread/569379?ContentTypeID=1</link><pubDate>Thu, 23 Jul 2026 07:41:37 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:abe68ba0-b2d7-4be9-9232-452d382d998e</guid><dc:creator>Adam Le</dc:creator><description>&lt;p&gt;Hi Bipin,&lt;/p&gt;
&lt;p&gt;If all three are enabled, it should not be possible for someone with SWD access to perform an Erase All and then reprogram. &lt;a href="https://docs.nordicsemi.com/r/bundle/ps_nrf54l15/page/ctrl-ap.html-ctrlap_unlocking"&gt;ERASEPROTECT&lt;/a&gt; requires both the debugger and the on-board firmware to disable it, just physical SWD access isn&amp;#39;t enough. You can read more about each &lt;a href="https://docs.nordicsemi.com/r/bundle/nan_047/page/app/nan_production_programming/nrf54l/nrf54l_device_protection.html"&gt;Device Protection method&lt;/a&gt; in our technical documentation.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;As for what configuration, at minimum use APPPROTECT and ERASEPROTECT.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Just be very careful when enabling the two together as if you do not have a &lt;/strong&gt;&lt;span&gt;&lt;strong&gt;firmware running on the nRF to unlock the ERASEPROTECT or APPROTECT you will no longer be able to reprogram your chip&lt;/strong&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;SECUREAPPPROTECT adds another layer of security on top in case APPPROTECT is not fully locked, also does not cost extra as it is just one more UICR write. If you also use ERASEPROTECT.LOCK, that means NOTHING, not even your own firmware can disable erase protection until a hardware reset. If you wish to use that as well, we recommend you call it as early in your start up code as possible, &lt;span&gt;once the firmware has determined it does not need to communicate with a debugger over the CTRL-AP mailbox&lt;/span&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Best regards,&lt;/p&gt;
&lt;p&gt;Adam&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>