Shipping Matter
Factory Flashing at Scale: Tooling and Throughput
Factory firmware programming at 100k-unit scale shares nothing with flashing a dev board over USB. The target isn’t speed. It’s zero-defect output at a throughput your contract manufacturer can sustain across multi-week runs.
This is a deep-dive from Provisioning Matter Devices at Scale. That post covers the full manufacturing pipeline. Here we focus on the first step: getting firmware onto the silicon.
flowchart TD
JIG["Device on jig"] --> FLASH["Flash firmware
gang programmer"]
FLASH --> VERIFY["Post-flash verify
checksum + manifest hash"]
VERIFY -->|green| NEXT["Next unit"]
VERIFY -->|red| STOP["Stop. Investigate."]
Tooling
You need three things you probably don’t have yet:
A gang programmer or multi-site programmer. Segger Flasher PRO with multiplexer boards handles up to 8 targets in parallel. PEmicro’s Cyclone FX does 4 simultaneous. For high-volume BLE SoCs, Nordic’s nRF Connect for Desktop has a production programming mode that queues devices. The CM’s existing single-port J-Link is not the answer.
A programming jig. Not just a pogo-pin bed — a fixture that guarantees alignment, controls insertion force, and includes a pass/fail indicator visible to the operator. The jig must survive a production cycle without pin wear causing intermittent contact failures. Spec gold-plated pogo pins with at least 10,000 cycle life ratings (QA Technology, Everett Charles). Budget 4-6 weeks for mechanical design and fabrication. This is not the thing to outsource in week 1 of production ramp.
Post-flash verification firmware. Your production image must include a self-test mode that runs immediately after programming and reports a checksum, MAC address, and factory data validity over a UART or SWD backchannel. The operator flips a switch, sees green, moves to the next unit. Red means stop and investigate. Without this, you are shipping devices that “probably” have valid firmware.
Throughput math
Assume 20 seconds per device for flash and verify on a single programmer. That’s 180 units per hour per station. Three stations: 540/hr. A 100k-unit run at eight-hour shifts: 23 production days. Factor in yield loss, rework, and operator breaks — plan for 35 days. Don’t let your CM’s schedule estimate surprise you two weeks before the purchase order ships.
The “flash and pray” anti-pattern
The most expensive mistake: flashing firmware with no cryptographic integrity check, shipping the device, and discovering in the field that 3% of units have bit flips in the application partition. Your firmware image must include a signed manifest with a SHA-256 hash. The production tester validates the hash before the unit leaves the programming station. This is not optional at scale. Nordic’s nRF Secure Immutable Bootloader and Espressif’s Secure Boot V2 both support this — use them.