← Blog ·

How to destroy an SSD securely

Destroying an SSD securely requires either certified software commands specific to flash memory — such as ATA Secure Erase or NVMe sanitise — or physical shredding, because SSDs store data in NAND flash chips that are unaffected by the magnetic fields used in degaussing and cannot be reliably overwritten by standard hard drive tools.

Why SSDs are different from hard drives

A traditional hard drive stores data as magnetic patterns on spinning platters. Overwriting those patterns with new data — or demagnetising the platters with a degausser — destroys the original data. An SSD stores data in NAND flash memory cells. There are no magnetic fields, no platters, and no heads.

This difference has three important implications for data destruction:

Degaussing is useless. A degausser generates a magnetic field. NAND flash memory has no magnetic properties to disrupt. Running an SSD through a degausser has zero effect on the data it contains. The drive emerges intact, data fully readable. Any organisation that degausses SSDs believing this constitutes data destruction is not protected.

Standard overwrite tools may not reach all data. Because SSDs use a technique called wear levelling — distributing writes across all flash cells to extend the drive’s life — a conventional overwrite command may not address every cell that has held data. Over-provisioned cells (spare capacity maintained by the drive’s firmware) may be inaccessible to host-level write commands.

Specific firmware commands are required for reliable software sanitisation. The ATA Secure Erase command (for SATA SSDs) and the NVMe Sanitise command (for NVMe drives) instruct the drive’s own firmware to cryptographically or physically erase all cells, including over-provisioned areas. These are the correct software-based methods for SSD data destruction.

Method 1: ATA Secure Erase or NVMe Sanitise

For SSDs that will be reused or donated, firmware-level commands are the appropriate method. The process works as follows:

  1. Check compatibility: Confirm that the SSD supports ATA Secure Erase (SATA drives) or NVMe Sanitise (NVMe M.2 drives). Most modern SSDs do, but older or budget models may not. Consult the manufacturer’s documentation.

  2. Use certified software: Tools such as Blancco Drive Eraser and similar enterprise-grade products support these commands and produce a per-drive verification report. The report confirms that the command completed successfully and is the evidence needed for a certificate of data destruction.

  3. Verify completion: The tool should confirm that the Secure Erase or Sanitise command was accepted by the drive and completed without errors. A failed or unsupported command must be treated as incomplete — the drive should then be physically shredded.

  4. Document the result: The verification report should record the drive make, model, serial number, firmware version, the command issued, and the outcome. This feeds into the certificate of data destruction.

Note that NIST Special Publication 800-88 (“Guidelines for Media Sanitisation”) addresses flash-based media and recommends Secure Erase or Sanitise commands for the “purge” level of sanitisation.

Method 2: Encryption then wipe

Some SSD manufacturers implement hardware-based encryption that encrypts all data on the drive at rest. Cryptographic erase — destroying the encryption key — renders all data permanently unreadable because the ciphertext cannot be decrypted without the key.

Where a drive supports this (known as a Self-Encrypting Drive, or SED), the process is to enable encryption from the outset and then issue a cryptographic erase command at disposal. NIST SP 800-88 accepts cryptographic erase as a “purge”-level method for supported drives.

This method requires planning ahead: the drive must have been operating in encrypted mode from the start. An SSD that was not encrypted during use cannot be retrospectively made secure by enabling encryption — the existing data was written in plaintext.

Method 3: Physical shredding

Where certified software sanitisation cannot be confirmed — because the drive does not support the required commands, the firmware is unresponsive, or the drive is faulty — physical shredding is the reliable alternative.

Industrial shredders reduce the SSD to fragments that destroy the NAND flash chips. Once shredded, data recovery is not possible regardless of what data was present or how it was stored. Shredding is also the right choice when:

  • The SSD is at end of life and has no residual value
  • The data held was of the highest sensitivity
  • The device type is a smartphone, tablet, or other device where the storage is integral and firmware-level commands are not accessible
  • You need absolute certainty without reliance on firmware behaviour

For more on shredding as a method, see our guide to hard drive shredding explained.

What does not work on SSDs

The following methods are commonly misunderstood or misapplied to SSDs and should not be relied upon:

  • Degaussing: Has no effect on NAND flash memory. Zero protection.
  • Standard disk overwrite (e.g. DoD 5220.22-M applied to SSDs via host-level writes): May not reach all storage cells due to wear levelling and over-provisioned areas.
  • Factory reset: A factory reset on a laptop or phone does not constitute a secure wipe of the SSD. It removes the operating system’s access to the data but does not overwrite or sanitise the flash cells.
  • Drilling or hammering: Damaging one area of an SSD does not destroy the flash chips elsewhere. Data recovery laboratories can retrieve data from physically damaged SSDs.

UK GDPR obligations

Under UK GDPR and the Data Protection Act 2018, personal data held on an SSD must be destroyed securely when it is no longer needed. The method must be appropriate to the device type and the sensitivity of the data, and destruction must be evidenced by a certificate of data destruction.

The ICO does not prescribe specific technical methods, but it expects organisations to follow recognised standards. For SSDs, that means either certified firmware-level sanitisation or physical shredding.

Recycle4Charity provides certified SSD data destruction for London businesses — using certified software tools where supported or physical shredding where not — and issues a certificate of data destruction with every collection. Visit our hard drive and media destruction page, or contact us to arrange a collection.

Blog

Frequently asked questions

No. Degaussing generates a magnetic field that disrupts magnetic storage, but SSDs store data in NAND flash memory, which is not magnetic. A degaussed SSD is physically unchanged and the data remains fully readable. Never use degaussing as a method of data destruction for SSDs.

Standard host-level overwrite tools designed for magnetic hard drives may not reach all storage locations on an SSD due to wear levelling and over-provisioning. For reliable software sanitisation of an SSD, use firmware-level commands — ATA Secure Erase for SATA drives or NVMe Sanitise for NVMe drives — through certified software that produces a verification report.

No. A factory reset reinstalls the operating system and removes user data from the file system, but it does not issue the firmware-level commands needed to sanitise an SSD. Data can often be recovered from a factory-reset device. Use certified software wiping or have the device shredded.

ATA Secure Erase is a firmware-level command built into the SATA specification. When issued, it instructs the SSD's own controller to erase all storage cells — including over-provisioned areas inaccessible to normal write commands. It is one of the two accepted methods for software sanitisation of SATA SSDs under NIST SP 800-88.

If the laptop is going to a certified ITAD provider, they will destroy the SSD as part of the service. If you are managing the process in-house, use certified software with ATA Secure Erase or NVMe Sanitise support, or remove the SSD and have it physically shredded. Never simply delete files or reset the operating system and assume the data is gone.

Need secure IT disposal in London?

Certified data destruction and WEEE recycling — with refurbished devices going to people who need them.