How to wipe a machine so the certificate means something.
Most people have never done this deliberately, and the advice online is a decade out of date. This walks through what the words mean, how to work out the right method for the machine in front of you, and how to do it on each operating system.
First, the three words everyone uses loosely.
NIST SP 800-88 — the document nearly every policy points at — sorts sanitisation into three levels. They are not degrees of thoroughness so much as answers to a different question: who might try to recover this, and with what?
Overwrite the data using the drive's normal read/write interface. Defeats anyone using ordinary software to undelete files.
Right when the machine stays inside your organisation — reissued to another employee, moved to another site.
Use a mechanism the drive itself provides — its built-in sanitise command, or destroying the encryption key so the remaining ciphertext is meaningless. Defeats laboratory recovery.
Right when the machine leaves your control — sold, donated, recycled, returned to a lessor. This is the level a disposal certificate should almost always claim.
Shred, disintegrate, incinerate. The drive no longer exists as a drive.
Right when the data was sensitive enough that you would rather lose the hardware value than reason about drive firmware, or when the drive is dead and cannot be sanitised at all.
The trap is that a method that achieves Purge on one kind of drive achieves nothing on another. That is the whole of the next section.
Work out what you are holding.
Four questions, in this order. Simpletag already knows the answers for any machine that has been checking in — they are on the asset's record — but here is how to find them by hand.
Is it flash, or is it spinning?
This decides more than anything else. Overwriting works on magnetic platters and does not reliably work on flash, because wear levelling and over-provisioning keep spare blocks that the drive's interface never exposes. You can overwrite every sector you are permitted to see and still leave data in sectors you were never shown.
Windows
PowerShell:
Get-PhysicalDisk | Format-List FriendlyName,MediaType,BusType
MediaType says SSD or HDD. BusType says NVMe, SATA or USB.
macOS
diskutil info / | grep -E \ "Solid State|Protocol"
Every Mac shipped in the last decade is flash. Apple silicon machines are also soldered — see step 4.
Linux
lsblk -dno NAME,ROTA,TRAN
ROTA=0 means flash. TRAN gives nvme, sata or usb.
Is it already encrypted?
If the whole drive is encrypted and you can destroy the key, you are finished in seconds. That is a legitimate Purge under 800-88, it is what Apple does on every modern Mac, and it is by far the least error-prone route.
Windows
manage-bde -status C:
Look for Protection On and 100% encrypted. Not just "Encryption Method" — a drive can be partially converted.
macOS
fdesetup status
FileVault is on by default on Apple silicon, and the key lives in the Secure Enclave.
Linux
lsblk -o NAME,TYPE,FSTYPE
Look for crypto_LUKS. If the system disk is not LUKS, encryption is not your route.
How is it attached?
NVMe and SATA use different sanitise commands, and they are not interchangeable — ATA Secure Erase does not exist on NVMe. If a record says ATA Secure Erase was run on an NVMe drive, either a different command ran or nothing did.
And if the drive is in a USB enclosure, treat any sanitise command with suspicion. USB-to-SATA bridges very commonly swallow the command and report success. Sanitise over a direct connection, or verify afterwards.
Can the drive even come out?
On Apple silicon Macs, recent MacBooks and many thin laptops the storage is soldered to the board. Physical destruction of the drive is not an option without destroying the machine, which makes cryptographic erase the only practical Purge — and fortunately the sanctioned one.
Then do it.
Pick the first row that matches. If two apply, the earlier one is simpler and harder to get wrong.
Encrypted drive → destroy the key
Purge. Seconds, no special tooling, works on flash and platters alike, and nothing depends on the drive honouring a command correctly.
macOS
- System Settings → General → Transfer or Reset
- Erase All Content and Settings
Apple's own documented method. It discards the Secure Enclave key.
Windows · BitLocker
- Confirm
manage-bde -statusshows fully encrypted - Settings → System → Recovery → Reset this PC
- Remove everything → Clean data
The reset discards the volume key. Delete any escrowed recovery key from Entra/AD afterwards, or you have kept a copy of the thing you just destroyed.
Linux · LUKS
cryptsetup luksErase /dev/nvme0n1p3
Destroys all key slots. Have the header backed up nowhere, or you have not finished.
Not encrypted, flash drive → the drive's own sanitise command
Purge. The controller erases every block including the spares you cannot address.
NVMe · Linux
nvme format /dev/nvme0n1 \ --ses=1
--ses=1 is a cryptographic erase, --ses=2 a full user-data erase. Not all drives support both; nvme id-ctrl shows which.
SATA · Linux
hdparm -I /dev/sda # check hdparm --user-master u \ --security-erase p /dev/sda
Drives are often "frozen" at boot and reject this — a suspend/resume usually clears it. Read the warnings in man hdparm first.
Vendor tools
Dell, HP, Lenovo, Samsung Magician and Intel all ship a sanitise function in their own utility, often from the BIOS or a bootable image. On a fleet of one make this is usually the safest and least surprising route.
Not encrypted, spinning disk → overwrite
Clear, and adequate for a machine that stays in-house. NIST accepts a single pass on modern magnetic media; the 35-pass ritual was designed for encoding schemes no drive has used in decades.
For Purge on a platter drive, use the ATA sanitise command as in B, or degauss it — which also destroys the drive.
The drive is dead, or you would rather not reason about it → destroy it
Destroy. A drive that will not power on cannot be sanitised, and "it was broken anyway" is not a defence if it is recoverable. Shred it, or hand it to a processor who will and who gives you a certificate of destruction with serial numbers on it.
Look for R2v3 or e-Stewards certification. Ask for serialised reporting — a certificate that does not name the drives is a receipt, not evidence.
Degaussing does nothing whatsoever to an SSD. It is a magnetic field, and flash memory is not magnetic.
Or let it work out the method for you.
Answer the four questions from above and this gives you the defensible method for that machine and the actual commands. Nothing is sent anywhere — it runs in your browser.
Simpletag already knows the first three for any machine that has been checking in — they sit on the asset's own page, so nobody has to look them up by hand.
Check that it worked, then write it down.
800-88 asks for verification, not just execution. For a Purge that usually means sampling: boot the machine from a USB stick and look at the drive. If you see a fresh empty partition table and no recoverable filesystem, that is the result you wanted. Sample more machines when you are doing a batch — spot-checking one in ten catches a bad procedure before it has run fifty times.
Then record it while you still remember: the serial, the make and model, the method, the date, and who did it. That last one matters more than people expect — a certificate records an attestation by a named person, and an unnamed one is worth very little to whoever ends up relying on it.
Simpletag writes that record for you from the register, checks the method against what the drive actually was, and says so on the certificate if the two do not match. More on the certificate →
How to check any of this yourself.
Do not take our word for it, and be equally wary of a forum post from 2011.
- NIST SP 800-88 Rev. 1 is the source document, it is free, and Appendix A lists the accepted methods per media type. Appendix G is a certificate template — worth reading even if you never use it, because it shows what a complete record contains.
- The drive manufacturer's own documentation beats general advice every time. Search the exact model plus "sanitize" or "secure erase".
- Your own policy or contract may demand a specific level. Defence work, card data and health records all have their own expectations, and "we did a Purge" is a much easier sentence when it is written down beforehand.
Let the register do the paperwork.
Simpletag already knows the make, model, serial, drive type and encryption state of every machine that has checked in — which is most of what a certificate needs. Free for 25 computers, certificates included.