
A deleted file is not a removed file, and a factory reset is not sanitisation. The federal standard recognises three levels: Clear, which overwrites accessible storage; Purge, which reaches hidden areas or destroys the encryption keys; and Destroy, which physically reduces the drive to approved particle size. Solid state drives cannot be reliably overwritten because of wear levelling and hidden over-provisioned capacity, so they need cryptographic erasure or physical destruction. Drilling a hole and hitting it with a hammer are not on the approved list.
Once the data is dealt with, the machine itself is straightforward, and in more than 25 states it cannot go in a bin.
The three levels, and which one you need
| Clear | Purge | Destroy | |
|---|---|---|---|
| Measurement | What it does and when it is enough | Same | Same |
| Method | Overwrite user-accessible storage with a data pattern | Remove hidden areas, firmware block erase, or destroy encryption keys | Disintegrate, pulverise, melt, shred or incinerate |
| Verification | Software logs confirming completion | Forensic-level verification | Particle size confirmed, destruction logged |
| Media stays reusable | Yes | Yes | No |
| Works on hard drives | Yes | Yes | Yes |
| Works on solid state drives | Not reliably | Only via crypto erase or firmware erase | Yes |
| Right for | A personal machine being passed on | Business equipment being resold | Regulated data, or a drive that failed |
Most households need Clear. Most businesses need Purge or Destroy with paperwork behind it.
Why a solid state drive is the problem
Overwriting works on a spinning disk because you can address every sector. On flash storage you cannot, for three reasons.
- Wear levelling spreads writes across the chip to prolong its life, which leaves copies of data in areas the operating system cannot reach.
- Over-provisioning reserves extra capacity that never appears to the operating system and may hold old data.
- Block remapping retires failed blocks, which can still contain readable data.
So the standard recommends cryptographic erasure where the drive supports it, or physical destruction where it does not.
Cryptographic erasure is elegant: the drive encrypts everything as it writes, and sanitisation means irreversibly destroying the key. It is faster and far less wasteful than shredding, and it only works if the encryption was native and properly managed, and if the key destruction is verified.
Degaussing does not work on solid state drives at all. A magnetic field erases magnetic media; flash memory is electronic. Degaussers used on hard drives are specified to produce fields of at least 20,000 Gauss and must match the drive’s recording type.
One awkward case is worth knowing. Where a drive is soldered directly to the motherboard, as with many modern laptops, reaching destruction level can require destroying the whole board.
What does not count
This matters because the internet is full of confident advice that falls outside the standard.
Acceptable destruction methods are disintegration, pulverising, melting, shredding and incineration, each to a defined particle size.
Not included: shooting the drive, running it over with a vehicle, drilling through it, or dropping it from a height. Those may satisfy you. They do not satisfy an auditor, and on a solid state drive a drill hole leaves most of the flash chips intact.
If you are doing this at home for a personal machine, removing the drive and keeping it is simpler, cheaper and more certain than any of the above.
What changed in the standard
The guidance was rewritten recently, and the change is worth understanding if you are setting policy rather than clearing a desk.
Revision 1 dated from 2014 and prescribed techniques by device type. Revision 2, published in September of last year, moves to a programme-driven, risk-based approach and defers technique selection to a separate storage sanitisation standard written specifically for modern media.
It also expands guidance on cryptographic erasure and raises the emphasis on validating that sanitisation actually worked, rather than assuming it did.
The practical translation: the question is no longer which wipe tool to run, it is whether your process is documented, verified and appropriate to the sensitivity of the data.
A household computer, step by step
- Move what you want to keep to an external drive or cloud storage.
- Sign out of every account and deauthorise the machine from any service that limits device count, because that is easy to forget and awkward to undo later.
- Sanitise. Use the manufacturer’s secure erase for a solid state drive, or an overwrite tool for a spinning disk.
- Or simply remove the drive and keep it. This is the most certain option available to a household and costs nothing.
- Take out the battery where it is removable, and declare it where it is not, for the reasons set out on our electronics hub.
- Choose a route. Retailer drop-off, manufacturer take-back or a municipal event, compared on our page about where to take old electronics.
A machine that still works is worth far more passed on than recycled, so do this in the order above rather than reaching for a hammer first.
Business equipment is a different job
If the machine held customer, patient, payment or employee data, the standard is documentary rather than technical.
- A serialised certificate of destruction naming each asset, not a general receipt.
- An unbroken chain of custody from collection to destruction, with real-time tracking where possible.
- Vendor certification. Data destruction providers are audited under a specialist scheme, and environmental handling under two recycling standards. Ask which the vendor holds and check it is current.
- On-site destruction where the data cannot leave the premises.
- Reuse first where regulation allows, because it recovers value that shredding destroys.
The federal standard is mandatory for federal agencies and defence contractors handling controlled information, and it has been adopted as the reference point by healthcare, payment and financial reporting regimes. A municipal drop-off gives you none of the documentation those require.
The battery and the metal
Portable devices carry lithium cells, and specialists recommend dedicated vendors for destruction precisely because of the fire risk during processing.
As for the machine itself: a desktop tower holds roughly $15 of sorted metal, which our teardown sets out component by component. That figure is the reason to be relaxed about the hardware and careful about the drive.
Common mistakes
- Believing a factory reset is sanitisation. It is closer to Clear than to Purge, and on some devices it is neither.
- Overwriting a solid state drive and assuming it is done. Wear levelling and over-provisioning defeat it.
- Degaussing an SSD. It has no effect whatsoever.
- Drilling or hammering a drive and calling it destruction. Not an approved method, and ineffective on flash.
- Accepting a generic receipt as proof. Certificates should be serialised and name the asset.
- Skipping account sign-out before wiping, which locks you out of services later.
- Leaving the battery in. The single most damaging habit in electronics recycling.
- Binning the machine. More than 25 states plus the District of Columbia ban covered electronics from landfill.
How we produced this
The sanitisation levels, approved and excluded destruction methods, degausser field strength and the description of solid state drive limitations are drawn from the federal media sanitisation standard, related national security guidance and specialist provider documentation summarising both. We have described the standard rather than reproducing it.
The revision date and the shift to a risk-based approach deferring to a separate storage standard are as published. Certification schemes for destruction vendors and for environmental handling are named generically because their scope and holders change; verify any claim directly with the issuing body.
This is general information rather than a compliance opinion. Regulated organisations should work from the standard itself and their own regulator’s requirements.
Frequently asked questions
Is a factory reset enough before recycling a computer?
For a personal machine with nothing sensitive on it, usually. It sits closer to the Clear level than to Purge, and on some devices it is neither. Anything that held business, customer or payment data needs a verified sanitisation with documentation.
Why can a solid state drive not be wiped like a hard drive?
Because you cannot address every location. Wear levelling spreads writes across the chip and leaves data in areas the operating system cannot reach, over-provisioning hides capacity that never appears to the system, and retired blocks can still hold readable data.
What is cryptographic erasure?
The drive encrypts everything as it writes, and sanitisation means irreversibly destroying the encryption key so the data becomes unreadable. It is faster and less wasteful than shredding, but only works where encryption is native, properly managed and key destruction is verified.
Does degaussing work on an SSD?
No. Degaussing uses a magnetic field, and flash memory stores data electronically rather than magnetically, so it has no effect. Degaussers used on hard drives are specified to produce fields of at least 20,000 Gauss and must match the drive's recording type.
Can I just drill a hole in the drive?
Not as a recognised method. Approved destruction is disintegration, pulverising, melting, shredding or incineration to a defined particle size. Shooting, driving over, drilling and dropping from height are explicitly outside the guidance, and a drill hole leaves most flash chips on an SSD intact.
What is the simplest secure option for a home computer?
Remove the drive and keep it. That is more certain than any home destruction method, costs nothing, and lets the rest of the machine go to a normal recycling route. Sign out of your accounts first so you are not locked out of services.
What has changed in the sanitisation standard?
The revision published in September of last year moved from prescribing techniques by device type to a programme-driven, risk-based approach, deferring technique selection to a separate storage sanitisation standard, expanding cryptographic erase guidance and raising the emphasis on validating that sanitisation worked.
What should a business ask a disposal vendor for?
A serialised certificate of destruction naming each asset rather than a general receipt, an unbroken chain of custody with tracking, current certification for both data destruction and environmental handling, and on-site destruction where data cannot leave the premises.
What if the drive is soldered to the motherboard?
Reaching destruction level can require destroying the whole board, which is increasingly common on thin laptops. Where the machine is being passed on rather than destroyed, a verified firmware or cryptographic erase is the practical route instead.
Can I put the computer in the bin once the data is handled?
No in most of the country. More than 25 states plus the District of Columbia ban covered electronics from landfill, and any remaining battery makes it a fire risk in a collection truck. Use a retailer, manufacturer or municipal route instead.