Home / Insights

HDD, SSD and NVMe Destruction: Which Method Should You Use?

Compare secure erasure, cryptographic erase, degaussing and physical destruction for HDD, SSD and NVMe media using a risk-based process.

Choosing how to dispose of a data-bearing drive should not begin with a shredder. It should begin with four questions: what type of media is it, what information did it hold, does the organisation need to reuse or recover value from it, and what evidence will be required to prove the outcome?

Those questions matter because hard disk drives, SATA and SAS solid-state drives, and NVMe devices do not store or manage data in the same way. A method that is suitable for a conventional magnetic HDD may be ineffective, unsupported or unnecessarily destructive for flash-based media. Likewise, an erase command that succeeds on a healthy SSD may not be available when its controller has failed, the device is locked or the drive can no longer be reliably addressed.

The correct objective is therefore not simply to “wipe” or “destroy” a disk. It is to select and verify a sanitisation outcome that makes access to the target data infeasible for the organisation’s assessed threat, while preserving reuse value where that can be done safely.

This guide explains how UK organisations can choose between logical clearing, purge techniques, cryptographic erase, degaussing and physical destruction for HDD, SSD and NVMe media. It also covers failed drives, self-encrypting media, onsite destruction, verification, chain of custody and the evidence that should accompany a defensible data-disposal process.

Important: No single method is appropriate for every drive or every data classification. The organisation that owns the data remains responsible for defining the required outcome, approving the method and retaining evidence. Vendor instructions, contractual duties, regulatory obligations and any sector-specific requirements must be considered alongside general guidance.

Start with the required outcome: Clear, Purge or Destroy

NIST Special Publication 800-88 Revision 2 describes media sanitisation as a process that makes access to target data infeasible for a given level of effort. A practical programme normally distinguishes three broad outcomes.

Clear

Clear applies logical techniques through the normal interface to protect against straightforward, non-invasive data recovery. It may be appropriate when media remains inside organisational control, when the information sensitivity and threat assessment permit it, or when a device is being reassigned under controlled conditions.

Examples can include an approved overwrite process for an addressable magnetic drive or a supported logical reset process. Formatting, deleting files or removing partitions is not, by itself, sanitisation: those actions mainly change file-system metadata and may leave recoverable content behind.

Purge

Purge is intended to provide stronger assurance against advanced recovery while allowing media to remain potentially reusable. The appropriate technique depends on the device and may include a validated device-native sanitise operation or cryptographic erase when its prerequisites have been met.

Purge is not simply “more overwrite passes”. Modern sanitisation focuses on whether the chosen technique reaches the places where data may reside and whether the outcome can be verified for that model and technology.

Destroy

Destroy renders the media unusable and the data infeasible to recover using state-of-the-art laboratory techniques, subject to the selected destruction standard and particle-size requirement. It is appropriate where reuse is not permitted, where media cannot be reliably sanitised, where the device is failed or inaccessible, or where policy requires physical destruction.

Destroying the outer enclosure is not enough. The data-bearing component must be sufficiently damaged: magnetic platters for HDDs and every relevant NAND package or storage component for SSD and NVMe devices.

Why HDD, SSD and NVMe require different decisions

Magnetic HDDs

An HDD stores data magnetically on rotating platters. The host normally addresses sectors through the drive controller. Healthy HDDs can often be sanitised using a validated overwrite or supported firmware-level technique, depending on the required outcome.

Challenges include:

  • remapped or reallocated sectors;
  • inaccessible areas;
  • firmware or interface faults;
  • host-protected or device-configuration regions;
  • incomplete verification; and
  • drives that fail during processing.

Because the data is magnetic, degaussing can also be effective when performed with equipment rated for the media’s coercivity. Degaussing normally makes the drive unusable and does not provide a visual indication that every relevant area was treated, so process control and equipment assurance are important.

SATA and SAS SSDs

An SSD stores data in NAND flash and uses a controller to manage wear levelling, garbage collection, bad-block replacement and over-provisioning. The logical block address visible to an operating system is not a direct map of the physical flash cells.

That means ordinary host overwriting cannot provide the same assurance as it can on conventional magnetic media. The controller may redirect writes to different cells, while retired or spare cells remain outside normal host addressing.

Where supported and validated, device-native sanitise, block erase or cryptographic erase may provide an appropriate non-destructive outcome. Where those features are absent, unreliable or unverifiable, physical destruction may be required.

NVMe devices

NVMe describes a protocol and interface for accessing non-volatile storage, most commonly NAND flash. NVMe drives can appear as removable M.2 modules, U.2 or U.3 devices, add-in cards, enterprise EDSFF media, or soldered components inside a system.

Like other flash media, NVMe devices use controllers, namespaces, over-provisioning and wear-management processes. They may support Format NVM, Sanitize, block erase, overwrite or cryptographic erase capabilities, but support and behaviour vary by model, firmware and implementation.

The word “NVMe” does not itself prove that a particular sanitisation command is supported or suitable. The device’s identify data, vendor documentation, firmware state and command completion must be assessed.

Method 1: deleting, formatting and factory reset

Deleting files, recreating partitions or performing a quick format does not securely remove the underlying information. It generally marks storage locations as available for reuse.

A full format may write across addressable areas on some platforms, but its behaviour is operating-system and media dependent. It should not be accepted as a sanitisation method unless the process has been explicitly approved, technically understood and verified against the required outcome.

“Factory reset” is similarly ambiguous. On a managed laptop or appliance it may invoke a device-specific cryptographic or logical erase, but on another product it may only reinstall an operating system or reset configuration. The evidence must describe what actually happened, not merely record that a menu option was selected.

Suitable for secure disposal? Generally no, unless it invokes an approved underlying sanitisation mechanism and that mechanism is verified.

Method 2: logical overwriting

Overwriting writes a defined data pattern to addressable storage. For a healthy magnetic HDD, a properly controlled overwrite can be an effective Clear technique and may support reuse.

The old belief that every HDD always requires three, seven or 35 overwrite passes should not replace a current risk assessment. Additional passes consume time and energy without necessarily improving assurance if inaccessible sectors or process failures are not managed. The important controls are complete addressable coverage, error handling, verification and escalation of exceptions.

For SSD and NVMe media, ordinary overwrite is less reliable as a complete sanitisation method because the flash translation layer can redirect writes and retain data in over-provisioned, remapped or retired cells. It may reduce recoverability through the normal interface but should not be treated automatically as a Purge technique.

Overwrite controls for HDDs

A defensible workflow should:

  • identify the exact drive by make, model, serial number and capacity;
  • determine whether the full expected capacity is visible;
  • detect interface, SMART or media errors;
  • write across all accessible logical blocks using an approved tool;
  • capture start time, end time, tool version and result;
  • verify the required proportion or all addressable locations according to policy;
  • treat unreadable, inaccessible or failed drives as exceptions; and
  • retain an asset-linked erasure record.

Best fit: Healthy magnetic HDDs intended for reuse, where policy permits a Clear outcome or the approved method achieves the required level of assurance.

Poor fit: Failed HDDs, drives with inaccessible areas, flash media where the controller prevents assurance, or cases requiring mandatory destruction.

Method 3: device-native secure erase or sanitise

Many modern drives implement commands intended to sanitise media internally. Depending on the standard, device and firmware, a command may erase addressable and non-addressable areas more effectively than host writes.

Possible operations include:

  • ATA Security Erase or Enhanced Security Erase;
  • ATA Sanitize operations;
  • SCSI SANITIZE for supported SAS devices;
  • NVMe Sanitize actions;
  • NVMe Format with an appropriate secure erase setting; and
  • vendor-supported block-erase procedures.

These terms are not interchangeable. A utility button labelled “secure erase” may call a different operation on different models. The operator should record the actual command category, device response, completion status and any vendor constraints.

When device-native sanitisation is appropriate

It can be a strong option when:

  • the drive is healthy and remains responsive;
  • the exact model and firmware support the selected operation;
  • the command covers the relevant user, spare and remapped areas as required;
  • the device is connected through an interface that passes the command correctly;
  • power can be maintained throughout the operation;
  • completion status can be independently recorded; and
  • the organisation’s policy accepts the outcome.

Common failure points

  • USB bridges that do not pass ATA, SCSI or NVMe commands;
  • frozen security states;
  • RAID controllers hiding individual device capabilities;
  • namespaces or logical volumes being confused with the whole physical device;
  • firmware bugs or unsupported commands;
  • drives dropping offline during processing;
  • incomplete power-loss recovery; and
  • a tool reporting “success” without confirming the underlying device result.

Best fit: Healthy, supported SSD or NVMe media intended for reuse, and supported HDDs where the approved procedure calls for it.

Poor fit: Failed, locked, counterfeit, unsupported or intermittently accessible devices; media whose command behaviour cannot be validated.

Method 4: cryptographic erase

Cryptographic erase sanitises data by securely deleting or changing the encryption key required to decrypt it. It can complete quickly because the data itself does not need to be overwritten block by block.

However, cryptographic erase is trustworthy only if encryption protected all target data before sensitive information was written and if the relevant key copies can be sanitised effectively.

Preconditions for a defensible cryptographic erase

Confirm:

  • encryption was enabled before the data was stored;
  • the algorithm and implementation meet organisational requirements;
  • keys were generated with sufficient strength and managed correctly;
  • the target data was not also stored unencrypted elsewhere on the device;
  • all relevant keys, including wrapped or escrowed copies, are addressed;
  • the key-sanitisation command is supported and completes successfully;
  • there is no unresolved implementation or firmware concern; and
  • the residual encrypted data is acceptable under the threat model.

Self-encrypting drive capability alone is not proof that all historical data is protected. A drive may encrypt internally with a media encryption key while access controls have never been activated; cryptographic erase can still be effective if implemented correctly, but the organisation must understand the architecture and validate the command rather than rely on a marketing label.

Crypto erase is also unsuitable when the drive no longer accepts commands or when the encryption state cannot be established. In those cases, destruction may be necessary.

Best fit: Supported self-encrypting HDD, SSD or NVMe devices with a verified encryption lifecycle, where rapid sanitisation and reuse are required.

Poor fit: Unknown encryption history, broken controllers, inaccessible devices or environments where policy requires physical destruction.

Method 5: degaussing

A degausser applies a strong magnetic field to disrupt magnetic domains. It can be effective for magnetic HDD platters and magnetic tape when the equipment is correctly rated, maintained and operated.

Degaussing does not sanitise NAND flash. SSDs, NVMe devices, USB flash drives and memory cards are not made safe by exposure to a degausser because their data is stored electrically rather than magnetically.

Modern HDDs may require powerful equipment because of the coercivity of their recording media. An under-rated or poorly maintained degausser can create false assurance. The process should account for:

  • the make and model of degausser;
  • its rating against the media type;
  • maintenance and calibration or performance-assurance records;
  • operator training;
  • cycle completion evidence; and
  • subsequent handling of the unusable drive.

Degaussing often damages servo information and electronics, leaving the HDD unusable. It may therefore satisfy an organisation’s need to prevent reuse, but it should not be selected when value recovery from the drive is desired.

Best fit: Magnetic HDD or tape requiring non-reuse sanitisation under an approved degaussing process.

Not suitable: SSD, NVMe or any other flash media.

Method 6: physical destruction

Physical destruction is appropriate when reuse is prohibited or sanitisation cannot be completed and verified. Methods include shredding, crushing, disintegration and other approved processes that damage the data-bearing material to a specified outcome.

The phrase “physically destroyed” is not sufficiently precise. The effectiveness depends on:

  • media technology;
  • destruction equipment;
  • resulting particle or fragment size;
  • whether every data-bearing component entered the process;
  • the sensitivity and threat model;
  • containment and accounting of fragments; and
  • final recycling or disposal.

HDD destruction

For an HDD, the platters are the primary data-bearing components. Bending the chassis, drilling one hole or striking the enclosure may make normal operation difficult but can leave substantial platter areas intact.

An approved shredder, disintegrator or other process should damage the platters to the required fragment size. Where crushing is used, the organisation should establish whether the resulting deformation satisfies its policy and risk level.

SSD and NVMe destruction

For flash devices, the NAND packages hold the data. Breaking an M.2 PCB in one place or crushing only the controller may leave intact NAND packages that could potentially be removed and examined.

The process must ensure all storage packages are destroyed to the specified particle size. This is why equipment and settings designed only for HDDs may not be adequate for SSDs. Flash media commonly requires a smaller destruction outcome than magnetic drives because data remains concentrated in small semiconductor packages.

Onsite versus offsite destruction

Onsite destruction reduces transport exposure and allows a client representative to witness the process. It is valuable for sensitive projects, failed media and organisations that require destruction before equipment leaves the premises.

Offsite destruction can be appropriate when secure collection, sealed transport, controlled facilities and complete chain-of-custody evidence are in place. The decision should be based on risk and policy rather than convenience alone.

Best fit: Failed or inaccessible drives, high-risk data, mandatory non-reuse requirements, unsupported media and sanitisation exceptions.

Trade-off: The device loses reuse and remarketing value, and unnecessary destruction increases embodied-carbon and material-recovery impacts.

Decision guide: which method should you use?

  • Healthy magnetic HDD intended for reuse: Consider validated overwrite or a supported purge technique. Confirm full capacity, errors, completion and verification.
  • Self-encrypting HDD with a proven encryption lifecycle: Consider validated cryptographic erase. Confirm the encryption preconditions and key sanitisation.
  • Failed or inaccessible HDD: Use approved physical destruction, or degaussing where policy expressly permits it. Account for the drive and damage all platters sufficiently.
  • Healthy SATA or SAS SSD intended for reuse: Consider supported device-native sanitise, block erase or cryptographic erase. Confirm model and firmware support and command completion.
  • Healthy NVMe SSD intended for reuse: Consider supported NVMe Sanitize or an appropriate secure-format or cryptographic operation. Address the complete device and relevant namespaces and validate its capability.
  • SSD or NVMe with unknown command support: Perform a vendor-specific assessment and destroy it if the required assurance cannot be established. Do not substitute ordinary overwrite automatically.
  • Failed, locked or intermittent SSD/NVMe: Use flash-appropriate physical destruction that destroys every NAND package to the required outcome.
  • Any media subject to mandatory destruction policy: Use approved physical destruction and match the equipment and particle size to the media and classification.

This table is a starting point, not an automatic authorisation. Data sensitivity, contractual commitments, device condition, destination and threat must be assessed.

What about multiple overwrite passes?

The number of passes is often treated as a measure of quality, but it can distract from more important questions.

For HDDs, a correctly completed and verified overwrite of accessible areas can be effective for the approved outcome. Repeating it does not resolve inaccessible sectors, a capacity mismatch, an interface error or a failed drive.

For SSD and NVMe devices, additional host overwrite passes do not force the controller to expose every physical flash location. More passes can add wear while still leaving uncertainty in retired or over-provisioned cells.

Ask instead:

  • Was the method appropriate for this media technology?
  • Did it cover the necessary storage areas?
  • Did the device complete the operation without errors?
  • Was the result verified?
  • Were exceptions quarantined and escalated?
  • Is the evidence linked to the correct serial number?

How to handle failed and unreadable drives

Failed media is where weak processes often break down. A drive that is absent from software reports can accidentally disappear from the project record even though it may still contain all its data.

Use an exception workflow:

  1. Record the asset and drive identifiers before removal where possible.
  2. Confirm the drive is not merely hidden by a cable, adapter, RAID configuration or power fault.
  3. Limit troubleshooting to approved actions that do not increase data risk.
  4. Mark the attempted sanitisation as failed or not possible—never as passed.
  5. Quarantine the device in controlled storage.
  6. Authorise an alternative method, normally physical destruction.
  7. Witness or record the destruction event.
  8. Reconcile the destroyed serial number with the original asset register.

Do not send failed drives under ordinary warranty replacement until the data-retention and replacement terms are understood. If the manufacturer will not permit retention of the failed media, the organisation must decide whether the support arrangement is compatible with its security requirements.

Sanitisation verification is not optional

Verification should test the result and the process.

For erasure or device-native sanitisation

Record:

  • asset ID and drive serial number;
  • manufacturer, model, capacity and interface;
  • firmware revision where relevant;
  • selected method and command category;
  • tool name and version;
  • start and completion timestamps;
  • device completion status and errors;
  • verification result;
  • operator or system identity; and
  • final disposition decision.

Where the process samples or reads the media after sanitisation, define the verification scope in policy. A software success flag alone should not be the only evidence when the tool can obtain device health, capacity and command-status information.

For physical destruction

Record:

  • the same asset and media identifiers;
  • destruction method and equipment;
  • location, date and time;
  • operator and witness where required;
  • required and achieved destruction outcome;
  • exceptions or incomplete cycles;
  • photographs or video only where policy permits and they add value;
  • certificate reference; and
  • downstream material-recycling route.

A certificate of destruction should summarise a controlled process; it should not replace the underlying media-level reconciliation.

Chain of custody from collection to outcome

Data risk exists before sanitisation as well as during it. Organisations should maintain custody records from the point equipment is identified until every drive has a verified outcome.

Controls can include:

  • collection lists linked to asset tags and serial numbers;
  • named handover and receipt;
  • tamper-evident containers or numbered seals;
  • vehicle and route controls proportionate to risk;
  • restricted processing areas;
  • CCTV and access records where required;
  • separate quarantine for failed or unidentified media;
  • status changes recorded in an asset system;
  • two-person checks for high-risk batches; and
  • final reconciliation showing erased, destroyed, returned or exceptional items.

Batch totals alone are insufficient if an organisation cannot determine what happened to a particular data-bearing device.

Data classification should drive the method

The choice should be approved through a media-sanitisation policy that considers:

  • information classification and sensitivity;
  • personal, financial, health, defence or commercially sensitive data;
  • regulatory and contractual requirements;
  • the capability of likely adversaries;
  • whether media leaves organisational control;
  • whether the destination is internal reuse, resale, return, recycling or disposal;
  • environmental and financial value of reuse;
  • device condition and sanitisation support; and
  • evidence and assurance requirements.

NCSC guidance advises organisations to plan for sanitisation, reuse and disposal and to ensure data cannot be recovered by unauthorised parties after media leaves their control. The strongest policy therefore defines approved methods by media type and classification, not one universal instruction such as “three-pass wipe everything”.

Reuse versus destruction

Physical destruction is easy to explain, but it is not automatically the best outcome for every working drive.

Securely sanitised media can be reused, redeployed or remarketed, preserving equipment value and avoiding the environmental impact of prematurely replacing serviceable storage. The decision should balance security assurance with circular-economy objectives.

Reuse is appropriate only when:

  • the sanitisation method is suitable for that exact media;
  • the device is healthy enough to complete it reliably;
  • verification passes;
  • policy permits the intended destination; and
  • the evidence is retained.

If any of those conditions fails, the device should enter an exception or destruction route. Sustainability must never be used to justify an unverifiable sanitisation outcome; equally, destroying every functional device by default can waste value without improving security where a validated purge method is available.

Onsite data destruction: when it adds value

Onsite destruction can be appropriate when:

  • drives contain highly sensitive or regulated information;
  • policy prohibits intact media leaving the site;
  • a data centre or office exit must be completed under observation;
  • failed drives cannot be logically sanitised;
  • the client needs immediate witnessed assurance; or
  • transport and intermediate-storage exposure must be minimised.

A proper onsite service should still inventory the media, control the destruction area, match equipment to media type, capture exceptions and remove residual material through an authorised recycling route.

Witnessing a machine process drives is reassuring, but the decisive control remains reconciliation: every expected serial number must have a recorded outcome.

Questions to ask a data-destruction provider

  1. How do you distinguish HDD, SSD, NVMe and other flash media?
  2. Which standards and current guidance inform your methods?
  3. How do you decide between Clear, Purge and Destroy?
  4. What happens when a drive reports errors or disappears during processing?
  5. Can your software identify the actual device command used?
  6. How do you verify cryptographic-erase prerequisites?
  7. Is your physical-destruction equipment appropriate for both platters and NAND packages?
  8. What destruction outcome or particle size is produced?
  9. How are individual serial numbers reconciled?
  10. What evidence appears on the erasure or destruction certificate?
  11. Can the service be performed onsite?
  12. How are fragments and reusable assets handled afterwards?

The provider should explain the technical reason for each method. “We shred everything” and “our software is certified” are not complete answers without scope, media compatibility, verification and evidence.

Common mistakes to avoid

Calling formatting secure erasure

Formatting and file deletion usually leave recoverable data. Record the underlying sanitisation operation, not the user-interface label.

Overwriting SSDs as though they were HDDs

Flash translation, wear levelling and spare areas make ordinary overwrite an unreliable universal answer for SSD and NVMe media.

Degaussing flash storage

Degaussing affects magnetic media. It does not sanitise NAND flash.

Destroying only the controller or casing

For SSD and NVMe devices, every NAND package matters. For HDDs, substantial platter areas must not remain intact beyond the approved destruction outcome.

Assuming encryption without proving its lifecycle

Cryptographic erase depends on effective prior encryption and secure key destruction. A self-encrypting label alone is not enough evidence.

Ignoring media inside appliances

Storage can remain in servers, firewalls, routers, printers, multifunction devices, storage arrays, hyperconverged nodes and industrial equipment. Discovery must extend beyond obvious laptop and server drives.

Issuing batch-only certificates

A certificate stating that “100 drives were destroyed” is weak if the organisation cannot reconcile each serial number to the original inventory.

Compritech media-sanitisation decision checklist

Before processing

  • Identify the asset, media type, interface, serial number and capacity.
  • Confirm the information classification and required outcome.
  • Decide whether reuse, resale or mandatory destruction applies.
  • Check device health, firmware and supported sanitisation capabilities.
  • Record custody and authorisation.

For logical or device-native sanitisation

  • Use a method approved for the exact media technology.
  • Confirm the tool communicates with the physical device, not only a volume.
  • Maintain stable power throughout the operation.
  • Capture command, tool, timestamps, status and errors.
  • Verify the result according to policy.
  • Quarantine every failed or uncertain device.

For cryptographic erase

  • Confirm encryption protected all target data before storage.
  • Validate algorithm, implementation and key-management assumptions.
  • Sanitise all relevant key copies.
  • Record successful command completion.
  • Escalate any uncertain encryption history.

For physical destruction

  • Match equipment and destruction outcome to HDD platter or flash NAND media.
  • Account for every device before and after processing.
  • Destroy all data-bearing components.
  • Record operator, equipment, date, location and exceptions.
  • Recycle residual material through an authorised route.

At project close

  • Reconcile every expected serial number.
  • Issue media-level erasure or destruction evidence.
  • Resolve quarantined and missing items.
  • Retain records for the required period.
  • Report reuse, value recovery and recycling outcomes separately.

Why engineer-led data destruction matters

Storage sanitisation is a technical control, not merely a logistics activity. The engineer must understand whether the host is addressing a logical volume, RAID virtual disk, namespace or physical device; whether the controller exposes the required command; whether encryption prerequisites are credible; and whether an error changes the approved outcome.

At Compritech, the objective is to connect each asset to a technically appropriate, verifiable result. Working media should retain its value when a validated sanitisation method and policy permit reuse. Failed, unsupported or high-risk media should move through a controlled destruction route with serial-level evidence and chain of custody.

That approach supports data protection, auditability and responsible IT lifecycle management without confusing convenience with assurance.

Final takeaway

The right method depends on the media and the risk:

  • Healthy magnetic HDD: validated overwrite or a supported purge method can preserve reuse value; degaussing or destruction is appropriate when reuse is not required.
  • Healthy SSD or NVMe: use a supported, validated device-native sanitise or cryptographic technique when policy permits; ordinary host overwrite is not a universal substitute.
  • Failed or inaccessible media: quarantine and physically destroy it using equipment appropriate to its data-bearing components.
  • High-risk or mandatory-destruction media: use an approved physical-destruction process and reconcile every serial number.

Above all, do not select a method by habit. Define the required outcome, identify the storage technology, verify the process and retain evidence that connects the individual drive to its final disposition.

Authoritative guidance and further reading

Choosing a destruction method for HDD, SSD or NVMe media?

Compritech provides engineer-led onsite and offsite data destruction, secure erasure, serial-level reporting, chain of custody and certificates of destruction.

Secure data destruction servicesExplore onsite data destructionDiscuss your project