simpletagASSET TRACKING
Guide · media sanitisation

How to wipe a machine so the certificate means something.

Most people have never done this deliberately, and the advice online is a decade out of date. This walks through what the words mean, how to work out the right method for the machine in front of you, and how to do it on each operating system.

Everything below destroys data and none of it is reversible.Take what you need off the machine first, and confirm you have it somewhere else. If the machine is under lease or belongs to a customer, check who is allowed to authorise this before you start.

First, the three words everyone uses loosely.

NIST SP 800-88 — the document nearly every policy points at — sorts sanitisation into three levels. They are not degrees of thoroughness so much as answers to a different question: who might try to recover this, and with what?

Clear

Overwrite the data using the drive's normal read/write interface. Defeats anyone using ordinary software to undelete files.

Right when the machine stays inside your organisation — reissued to another employee, moved to another site.

Purge

Use a mechanism the drive itself provides — its built-in sanitise command, or destroying the encryption key so the remaining ciphertext is meaningless. Defeats laboratory recovery.

Right when the machine leaves your control — sold, donated, recycled, returned to a lessor. This is the level a disposal certificate should almost always claim.

Destroy

Shred, disintegrate, incinerate. The drive no longer exists as a drive.

Right when the data was sensitive enough that you would rather lose the hardware value than reason about drive firmware, or when the drive is dead and cannot be sanitised at all.

The trap is that a method that achieves Purge on one kind of drive achieves nothing on another. That is the whole of the next section.

Work out what you are holding.

Four questions, in this order. Simpletag already knows the answers for any machine that has been checking in — they are on the asset's record — but here is how to find them by hand.

01

Is it flash, or is it spinning?

This decides more than anything else. Overwriting works on magnetic platters and does not reliably work on flash, because wear levelling and over-provisioning keep spare blocks that the drive's interface never exposes. You can overwrite every sector you are permitted to see and still leave data in sectors you were never shown.

Windows

PowerShell:

Get-PhysicalDisk | Format-List
  FriendlyName,MediaType,BusType

MediaType says SSD or HDD. BusType says NVMe, SATA or USB.

macOS

diskutil info / | grep -E \
  "Solid State|Protocol"

Every Mac shipped in the last decade is flash. Apple silicon machines are also soldered — see step 4.

Linux

lsblk -dno NAME,ROTA,TRAN

ROTA=0 means flash. TRAN gives nvme, sata or usb.

02

Is it already encrypted?

If the whole drive is encrypted and you can destroy the key, you are finished in seconds. That is a legitimate Purge under 800-88, it is what Apple does on every modern Mac, and it is by far the least error-prone route.

Windows

manage-bde -status C:

Look for Protection On and 100% encrypted. Not just "Encryption Method" — a drive can be partially converted.

macOS

fdesetup status

FileVault is on by default on Apple silicon, and the key lives in the Secure Enclave.

Linux

lsblk -o NAME,TYPE,FSTYPE

Look for crypto_LUKS. If the system disk is not LUKS, encryption is not your route.

03

How is it attached?

NVMe and SATA use different sanitise commands, and they are not interchangeable — ATA Secure Erase does not exist on NVMe. If a record says ATA Secure Erase was run on an NVMe drive, either a different command ran or nothing did.

And if the drive is in a USB enclosure, treat any sanitise command with suspicion. USB-to-SATA bridges very commonly swallow the command and report success. Sanitise over a direct connection, or verify afterwards.

04

Can the drive even come out?

On Apple silicon Macs, recent MacBooks and many thin laptops the storage is soldered to the board. Physical destruction of the drive is not an option without destroying the machine, which makes cryptographic erase the only practical Purge — and fortunately the sanctioned one.

Then do it.

Pick the first row that matches. If two apply, the earlier one is simpler and harder to get wrong.

A

Encrypted drive → destroy the key

Purge. Seconds, no special tooling, works on flash and platters alike, and nothing depends on the drive honouring a command correctly.

macOS

  1. System Settings → General → Transfer or Reset
  2. Erase All Content and Settings

Apple's own documented method. It discards the Secure Enclave key.

Windows · BitLocker

  1. Confirm manage-bde -status shows fully encrypted
  2. Settings → System → Recovery → Reset this PC
  3. Remove everything → Clean data

The reset discards the volume key. Delete any escrowed recovery key from Entra/AD afterwards, or you have kept a copy of the thing you just destroyed.

Linux · LUKS

cryptsetup luksErase /dev/nvme0n1p3

Destroys all key slots. Have the header backed up nowhere, or you have not finished.

B

Not encrypted, flash drive → the drive's own sanitise command

Purge. The controller erases every block including the spares you cannot address.

NVMe · Linux

nvme format /dev/nvme0n1 \
  --ses=1

--ses=1 is a cryptographic erase, --ses=2 a full user-data erase. Not all drives support both; nvme id-ctrl shows which.

SATA · Linux

hdparm -I /dev/sda   # check
hdparm --user-master u \
  --security-erase p /dev/sda

Drives are often "frozen" at boot and reject this — a suspend/resume usually clears it. Read the warnings in man hdparm first.

Vendor tools

Dell, HP, Lenovo, Samsung Magician and Intel all ship a sanitise function in their own utility, often from the BIOS or a bootable image. On a fleet of one make this is usually the safest and least surprising route.

An interrupted sanitise can brick the drive.Mains power, not battery. Do not reboot it part way through. This is why the encrypted-drive route above is worth preferring when you have it.
C

Not encrypted, spinning disk → overwrite

Clear, and adequate for a machine that stays in-house. NIST accepts a single pass on modern magnetic media; the 35-pass ritual was designed for encoding schemes no drive has used in decades.

For Purge on a platter drive, use the ATA sanitise command as in B, or degauss it — which also destroys the drive.

D

The drive is dead, or you would rather not reason about it → destroy it

Destroy. A drive that will not power on cannot be sanitised, and "it was broken anyway" is not a defence if it is recoverable. Shred it, or hand it to a processor who will and who gives you a certificate of destruction with serial numbers on it.

Look for R2v3 or e-Stewards certification. Ask for serialised reporting — a certificate that does not name the drives is a receipt, not evidence.

Degaussing does nothing whatsoever to an SSD. It is a magnetic field, and flash memory is not magnetic.

Or let it work out the method for you.

Answer the four questions from above and this gives you the defensible method for that machine and the actual commands. Nothing is sent anywhere — it runs in your browser.

Sanitisation methodfor one machine

Simpletag already knows the first three for any machine that has been checking in — they sit on the asset's own page, so nobody has to look them up by hand.

Check that it worked, then write it down.

800-88 asks for verification, not just execution. For a Purge that usually means sampling: boot the machine from a USB stick and look at the drive. If you see a fresh empty partition table and no recoverable filesystem, that is the result you wanted. Sample more machines when you are doing a batch — spot-checking one in ten catches a bad procedure before it has run fifty times.

Then record it while you still remember: the serial, the make and model, the method, the date, and who did it. That last one matters more than people expect — a certificate records an attestation by a named person, and an unnamed one is worth very little to whoever ends up relying on it.

Simpletag writes that record for you from the register, checks the method against what the drive actually was, and says so on the certificate if the two do not match. More on the certificate →

How to check any of this yourself.

Do not take our word for it, and be equally wary of a forum post from 2011.

We are not a law firm and this is not legal advice.It is a practical guide to a technical procedure. If a regulator, an insurer or a customer contract dictates a method, that beats anything on this page.

Let the register do the paperwork.

Simpletag already knows the make, model, serial, drive type and encryption state of every machine that has checked in — which is most of what a certificate needs. Free for 25 computers, certificates included.

Start free The certificate →