Why overwriting isn't enough
On a hard drive, writing zeros to a block replaces the old data in the same place. An SSD works differently. It writes the new data to a free spot, updates its map and marks the old spot as unused. The old data stays there until the drive clears it later.
Three features of SSDs make this harder:
- Spare space. SSDs keep extra storage your computer can’t see, often 7–28% of the total.
- Wear leveling. The drive spreads writes around to make the flash last longer, so data moves.
- Retired blocks. Worn-out blocks are taken out of use, along with any data still on them.
Overwriting every visible block still counts as Clear under IEEE 2883. Most policies require Purge before a drive leaves your company. Purge needs the drive’s own firmware to do the erase, because only the firmware can reach every cell.
Which method to use
| Drive | Best Purge method | Fallback | Watch out for |
|---|---|---|---|
| NVMe SSD | NVMe Sanitize (crypto erase or block erase) | NVMe Format with secure erase | Older drives without Sanitize; Sanitize keeps running after a restart |
| SATA SSD | ATA Sanitize (block erase or crypto scramble) | ATA Enhanced Secure Erase | Drives frozen by the BIOS; Secure Erase varies by brand |
| Self-encrypting drive (TCG Opal) | Crypto erase using PSID or admin revert | Sanitize block erase | Data saved before encryption was turned on |
| eMMC / UFS (tablets, thin clients) | Device sanitize or secure trim | Overwrite, then mark for destruction | Limited command support; check the maker’s documentation |
| USB stick / SD card | Usually none | Overwrite (Clear only) | Destroy it if you need Purge |
If the drive supports Sanitize, use it. Sanitize covers all user data, including caches and spare space, and reports when it’s finished. Format and Secure Erase are older, and they behave differently from brand to brand.
Doing it yourself on Linux
For a few drives, free Linux tools work. Boot from a Linux USB stick, check the device name carefully, then run the command for your drive. These commands can’t be undone.
NVMe
# Check what the drive supports (look at "sanicap")
nvme id-ctrl /dev/nvme0 -H | grep -i -A4 sanicap
# Sanitize: 4 = crypto erase, 2 = block erase
nvme sanitize /dev/nvme0 --sanact=4
# Check progress until it says it's complete
nvme sanitize-log /dev/nvme0
# Fallback: Format with secure erase (1 = user data, 2 = crypto)
nvme format /dev/nvme0n1 --ses=1SATA SSD
# Check support, and look for "frozen"
hdparm -I /dev/sdX | grep -i -E "frozen|sanitize|erase"
# Best: ATA Sanitize block erase
hdparm --yes-i-know-what-i-am-doing --sanitize-block-erase /dev/sdX
# Fallback: Enhanced Secure Erase (set a temporary password first)
hdparm --user-master u --security-set-pass tmp /dev/sdX
hdparm --user-master u --security-erase-enhanced tmp /dev/sdXIf hdparm shows frozen, the computer locked the drive’s security commands at startup. Putting the computer to sleep and waking it up usually unlocks the drive. Some laptops need a firmware setting changed, such as “Block SID”.
Common reasons SSD erasure fails
- RAID controllers hide the drive’s sanitize commands. Switch the controller to HBA/JBOD (pass-through) mode, or remove the drive and erase it separately.
- Laptop makers’ custom firmware sometimes blocks Sanitize. Use the maker’s BIOS secure erase, and record which method ran.
- Hidden areas (HPA and DCO) on SATA drives can be missed by an overwrite. Remove them first, or use a tool that does.
- Long Sanitize jobs continue after a restart. If someone removes the drive halfway, the erasure is incomplete.
Check the result and keep a record
A command that finishes without an error isn’t proof. After a Purge, read the drive back. A full read is best. A sample is fine if your policy allows it. After a crypto erase, the data should look random, with no readable files.
Then keep a certificate. It should show:
- the drive’s make, model and serial number, and the asset it came from
- the method used (for example, “NVMe Sanitize, crypto erase”) and the level it reached
- how it was verified and the result, who ran it and when
- a digital signature or hash, so no one can change the record later
Doing this by hand works for a few drives. For hundreds a month, software saves time. VaultRazer’s Drive Eraser picks the right command for each drive, handles frozen drives, checks the result and issues a signed certificate.
Frequently asked questions
Does formatting an SSD erase the data?
A normal format only resets the file system, so the data stays on the drive. The NVMe Format command with secure erase is different: it erases the data at firmware level. Use Sanitize if the drive supports it.
Does TRIM securely erase an SSD?
No. TRIM tells the drive which blocks are no longer used, and the drive may clear them later. There's no guarantee when, or if, the data is removed, and there's no record.
Is crypto erase enough on its own?
Yes, if the drive encrypted all data from the start and handles its keys properly. If you can't confirm that, or the data is very sensitive, run a block erase afterwards and verify.
Can I reuse an SSD after a secure erase?
Yes. Sanitize, Format and crypto erase leave the drive working. That's why erasure is better than shredding if you want to resell or reuse the hardware.