Hardware · Concept · 9 min read

What Is ROM, and Why Read Only Is No Longer Accurate

The definition made sense when the contents were fixed during manufacture. The ROM in a current computer is flash, writable in place, and the useful modern reading of the term is non-volatile rather than unchangeable.

Written by Marko Ristic, Editor Updated Sep 17, 2026
5Generations, of which two were genuinely read only
0Modern firmware roles that use a chip nobody can rewrite
2Boot stages a clean install of the operating system never reaches
MBThe unit firmware is measured in, against GB of RAM
Short answer

ROM stands for read-only memory: computer memory that keeps its data when the power goes off, holding the code a machine needs before it can load anything else. The name describes the original technology, not what is in machines now.

The ROM in a current computer, phone or switch is flash, it is writable by design, and that is exactly why firmware can be updated and exactly why firmware can be attacked.

  • Non-volatile memory that stores firmware and boot code
  • The name describes the original technology, not what ships today
  • Modern ROM is flash, writable in place, which is what makes updates possible
  • RAM is fast, volatile and large; ROM is slower, persistent and small
  • Because it is writable, firmware integrity is a security problem
On this page

The jobWhat ROM is for

Every computer has a bootstrap problem. The processor starts, and there is nothing in RAM because that memory lost all of its data when the power went off. Something has to already be there, at a known address, containing enough code to find and load the rest.

That something is ROM, read-only memory. On a computer it stores the firmware, the low level software instructions that initialize the memory controller, enumerate devices and hand over to a boot loader.

On a network switch it holds the image that brings up the ports and the management interface, and the switch reads it on every boot. On a printer, a camera or a thermostat it holds most of what the device is.

Two properties make ROM fit that job. It is non-volatile memory, so the data is there at power-on with nothing having loaded it. And the CPU can access it very early, before any driver or file system exists, which no other storage on the machine allows.

Size is deliberately modest. Firmware in ROM is measured in megabytes where RAM is measured in gigabytes, because the job is to get the computer to the point where it can load something larger.

Where the chip is, and how the processor reaches it

On a desktop or server board the memory in question is usually a single SPI flash chip somewhere near the chipset, eight pins and a few megabytes, often in a socket so it can be replaced.

On a laptop or a switch it is soldered. Either way it is one component, and it is the component a hardware technician clips a programmer onto when a board will not post.

The processor reaches it without any help. At reset the CPU begins executing at a fixed address burned into its design, the reset vector, and the platform arranges for that address to land in the firmware chip rather than in main memory.

Nothing has configured anything at that moment: no memory controller, no bus enumeration, no disk. That is the whole reason a machine needs memory that is already populated before it starts.

The five typesThe types of ROM, and why the name is a fossil

The history explains the term and the term has outlived it. There are five types of ROM, from mask ROM through PROM, EPROM and EEPROM to flash memory, and each one made the stored data easier to change.

TypeWrittenErasedWhere you meet it
Mask ROMAt manufactureNeverGenuinely read only, high volume parts
PROMOnce, by the buyerNeverOne shot programmable devices
EPROMBy a programmerUltraviolet lightOld boards, chips with a quartz window
EEPROMElectrically, in circuitElectrically, per byteSmall settings stores
FlashElectrically, in circuitElectrically, per blockEvery modern firmware role

Read the second and third columns down the table. Read only is true of the first two rows and of nothing since.

Mask ROM had its data built into the silicon during manufacture. Genuinely read-only memory: the stored contents were a physical property of the chip and changing them meant a new chip. Cheap in volume, useless for anything that might need a correction.

PROM, programmable read-only memory, shipped blank and the data could be written once, by blowing fuses inside it. One chance, permanent result.

EPROM could be erased, by exposing the die to ultraviolet light through a quartz window in the package. Those windows are the reason old boards have chips with stickers over them. Erasing meant removing the chip and putting it under a lamp.

EEPROM, electrically erasable programmable read-only memory, removed the lamp and the removal. The stored data could be rewritten in place, in circuit, by the computer itself. That is the point at which read-only stopped describing the behavior, and the term stuck anyway.

Flash is EEPROM refined for speed and density, erasing in blocks rather than byte by byte. Flash memory is what the word ROM now means in practice, in every firmware role on modern computer systems and devices.

So a current machine's ROM is writable, and the industry kept a name that says the opposite. That is a harmless piece of jargon right up until somebody reasons about security from the name.

UsesWhere ROM is used today

The practical answer to what is ROM is the chip that stores the instructions a device needs before anything else can run. Almost every piece of electronics has at least one, and most computer systems have several.

  • Computers and servers. The BIOS or UEFI firmware, plus smaller ROM chips on graphics cards, network cards and storage controllers. Those are called option ROMs, and they store the instructions each card needs at startup.
  • Network devices. Switches, routers, firewalls and access points store a boot loader in ROM, usually with the operating system image in flash memory beside it.
  • Phones and tablets. A small boot ROM inside the processor is the first code to run, and it is one of the few types of ROM still fixed at manufacture. It checks the boot loader held in flash storage.
  • Embedded systems. Printers, cars, washing machines, microwave ovens, medical devices and industrial controllers run a fixed program from ROM. Many of these devices have no other storage at all.
  • Game cartridges. Older consoles read each game from a mask ROM inside the cartridge, which is why copies of those games are still called ROMs.

Trade offsAdvantages and disadvantages of ROM

People who ask what is ROM usually also ask why a computer needs more than one type of memory. The answer is that each of the types of memory is a trade, and ROM gives up speed and size to get permanence.

Advantages of ROM

  • It is non-volatile. The data stays in the chip for years with no power applied.
  • The instructions are available to the processor the moment it starts, with no software loaded.
  • Programs and users cannot overwrite it by accident, the way they overwrite data in RAM or files on a disk.
  • It is cheap in volume, uses little power and has no moving parts.

Disadvantages of ROM

  • Writing is slow, and the oldest types cannot be rewritten at all.
  • Capacity is small next to RAM and disk storage.
  • Reading is slower than RAM, so many computer systems copy firmware from ROM into RAM at startup and run it from there.
  • An error in mask ROM means replacing the chip, and an interrupted flash update can leave a device unable to start.

ROM against a hard drive or SSD

Both keep data without power, so the difference is the role. Storage holds the operating system, software and files, and the computer needs a driver and a file system to access it. ROM sits at a known address the processor can read directly, and it stores only the instructions that start the system.

SecurityWhy writable firmware is a security question

If the data can be rewritten in place by software, then firmware is code that can be modified by anything that gets write access to the chip, and it runs before the operating system exists.

That ordering is what makes it valuable to an attacker. Code stored in firmware executes on the CPU before the kernel, before any security agent, and it survives reinstalling the operating system and replacing the disk, because neither of those touches the memory chip.

The defenses follow from the same fact. Signed firmware means the machine checks a signature before accepting an update, so a modified image is refused. Secure Boot extends the idea upward, with each stage verifying the next.

Write protection, in hardware or through a lock bit, prevents rewriting outside a controlled update. And a firmware version is a version like any other, which means it belongs in the same patching conversation as the operating system rather than in a separate category nobody owns.

The practical asymmetry is worth stating. The data in ROM is not secret and was never meant to be; anybody can read a firmware image. What matters is integrity, whether the image on the chip is the one the vendor signed, and that is a different property with different controls.

PitfallsWhere the confusion shows up

Treating ROM as unchangeable. The most common error, and the one with consequences. A firmware image is not a fixed property of the hardware, and a device that has been running for six years is running whatever was last written to it.

Confusing ROM with mass storage. A phone advertised with 128 GB of ROM is using the word for flash storage, which is technically the same memory family and a different job entirely. The firmware on that phone is a few megabytes.

Assuming reinstalling the operating system clears everything. It clears the disk. It does not touch the firmware chip, which is precisely why firmware is a persistence mechanism worth understanding.

Ignoring firmware in the patch process. Motherboards, drives, network cards and management controllers all store firmware in memory of this kind, and most estates patch the operating system diligently and the firmware never.

Reading the acronym as a security guarantee. Read-only is a name. Write protection is a configuration, and the two are not the same thing.

WHAT A CLEAN INSTALL DOES NOT REACHThe five stages of starting a computer, in execution order.Power on, CPU jumps to the reset vectorFirmware: BIOS or UEFIin the flash chip, this is the ROMBoot loaderon the diskOperating system kernelon the diskDrivers, services, security agenton the diskA clean installreplaces theseSurvives areinstall anda disk swapFirmware runs before the kernel and before any security agent.Reinstalling does not touch the chip it is stored in. That is why the signature check matters.
The two stages outside the bracket are the reason firmware is worth patching. Neither a reinstall nor a new disk goes anywhere near them.

ComparisonROM and RAM, and the row everyone forgets

CriterionROMRAM
Survives power lossYesNo
WritableYes, but slowly and in blocksYes, freely
SpeedMuch slowerNanoseconds
Typical sizeMegabytesGigabytes
HoldsFirmware and boot codeThe running system
Wears outYes, limited erase cyclesNo
Cost per byteHigher for the same speedLower

The row people forget is the sixth. Flash cells wear out after a finite number of erase cycles, which is irrelevant for firmware that is rewritten twice a year and very relevant for the same technology used as a disk, where wear leveling exists specifically to spread the damage.

It is the same underlying storage in an SSD, managed very differently because the write pattern is completely different. The second row is the one that surprises people who learned the definition and not the history. Both are writable now. What separates them is persistence and speed, not permission.

FAQFrequently asked questions

What is ROM?

Read-only memory: non-volatile memory that keeps its contents without power and holds the firmware and boot code a machine needs before it can load anything else.

What does ROM stand for?

Read-only memory. The name describes the original technology, where the contents were fixed during manufacture, rather than what is in a modern machine.

Is ROM really read-only?

Not any more. The ROM in a current computer, phone or network device is flash, which is writable in place. That is what makes firmware updates possible, and it is why firmware integrity is a security concern.

What is the difference between RAM and ROM?

Persistence and speed. RAM is fast, large and loses everything when the power goes off. ROM is slower, much smaller and keeps its contents, which is why the machine can start at all.

What are the types of ROM?

Five, in order of how the data gets in and out. Mask ROM, fixed during manufacture. PROM, written once. EPROM, erased with ultraviolet light. EEPROM, erased electrically in circuit. Flash, which is EEPROM refined for speed and density and is what the word means today.

What data is stored in ROM?

Firmware: the BIOS or UEFI on a computer, the boot image on a switch, and on a simple device most of what the device does. Also some device settings that have to survive a power cut.

Can ROM be updated?

Yes, that is what a firmware update is. The machine writes a new image to the flash chip, usually after verifying a signature on it.

Does ROM lose its data when the power is off?

No. That is the defining property of non-volatile memory, and it is the reason the term is better read as non-volatile memory than as read-only memory.

Why is firmware a security concern?

Because it is writable and it runs before the operating system and any security software. A modified firmware image survives reinstalling the operating system and replacing the disk, since neither touches the chip.

How is firmware protected from tampering?

Signature checking before an update is accepted, Secure Boot verifying each stage of startup, and write protection in hardware or through a lock bit outside a controlled update window.

Is the ROM in my phone the same as its storage?

The advertised figure is flash storage rather than firmware. Both are flash and the roles are different: the firmware is a few megabytes and the storage is the rest.

Does ROM wear out?

Flash cells have a finite number of erase cycles. That is irrelevant for firmware rewritten twice a year and very relevant for the same technology used as a disk, which is why solid state drives do wear leveling.

How much ROM does a computer have?

Firmware is typically measured in megabytes of this memory, against gigabytes of RAM. The job is to get the machine to the point where it can load something bigger, so it does not need to be large.

Should firmware be in the patching schedule?

Yes. Motherboards, drives, network cards and management controllers all have updatable firmware, and it is the layer most estates patch least, despite running below everything else.

Is the BIOS chip ROM or flash memory?

Today it is flash memory. Early PCs kept the BIOS in true read only memory that could not be changed. A modern BIOS chip is a small flash memory part, which is why firmware can be updated. It is still called ROM by habit, because it keeps its contents without power.

Read next · Firmware and boot What Is a BIOS? The firmware that actually sits in the chip on a computer, and what it does with the machine before an operating system exists. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.