Buying guide

Hard drive & SSD destruction, explained

Which method suits which drive, what the standards actually say, and how to pick equipment that matches your volume and risk. Written for IT teams and IT asset disposal firms.

Updated October 2026 · Sources listed at the end

1. Clear, purge or destroy?

The US National Institute of Standards and Technology (NIST) publishes the most widely cited framework for media sanitisation, SP 800-88. Its second revision, published in September 2025, keeps three levels:

LevelWhat it meansDrive reusable?
ClearLogical techniques (typically overwriting or a factory reset) that protect against simple recovery through the normal interface.Yes
PurgePhysical or logical techniques that make recovery infeasible even with state-of-the-art lab methods, for example a drive's built-in sanitise command or cryptographic erase. NIST says purge should be used instead of clear when possible.Often
DestroyMakes recovery infeasible and leaves the media unable to store data. NIST lists disintegrating, incinerating, melting, pulverising and shredding.No

Two points in the 2025 revision matter if you're buying destruction equipment:

  • Partial damage isn't destruction. NIST says bending, cutting or drilling a hole through a device may only partly damage it, leaving portions accessible with laboratory techniques. That's exactly what a hard drive punch does.
  • Shredding has limits too. NIST notes that as data density increases, some destructive techniques become less effective, and states that "pulverize and shred techniques for ISM should be avoided for anything but the lowest security categories of data" (ISM meaning information storage media). Its preferred route is a verified purge, with destruction where the media can't be purged or must never leave your control.

The practical takeaway: for anything sensitive, wipe (purge) first, then physically destroy. The wipe protects the data, and the destruction gives you visible proof and stops the drive being reused. That's why this site lists drive erasers alongside shredders and punches.

2. Hard drives vs SSDs

Most mistakes come from treating an SSD like a hard drive.

Hard drive (HDD)SSD, M.2, USB, SD
Stores dataMagnetically, on spinning plattersElectrically, in flash memory chips
OverwritingEffective across the whole driveUnreliable: NIST says wear levelling and spare cells make it infeasible to reach all previous data by overwriting
DegaussingWorks if the degausser is strong enough for the driveDoesn't work: NIST warns it "can complete successfully, but no sensitive data is sanitized"
PunchingDeforms platters, but leaves much of the surface intactCan miss the memory chips entirely
ShreddingEffective at a suitable particle sizeNeeds a much finer cut: chips are small enough to survive a coarse shred
Best wipeVerified overwrite or the drive's sanitise commandThe drive's sanitise / secure erase command, or cryptographic erase

3. DIN 66399 / ISO/IEC 21964 security levels

The German standard DIN 66399, now also published internationally as ISO/IEC 21964 (BS ISO/IEC 21964 in the UK), grades destruction by how small the pieces are. Manufacturers quote these levels, so it helps to know what they mean. The letter tells you the media type: H for hard drives and E for electronic media such as SSDs, USB sticks and memory cards.

LevelHard drives (H)Electronic media (E)
1Mechanically / electronically inoperableMechanically / electronically inoperable
2DamagedDivided
3DeformedParticles ≤ 160 mm²
4Particles ≤ 2,000 mm²Particles ≤ 30 mm²
5Particles ≤ 320 mm²Particles ≤ 10 mm²
6Particles ≤ 10 mm²Particles ≤ 1 mm²
7Particles ≤ 5 mm²Particles ≤ 0.5 mm²

Notice how much smaller the E-level particles are at the same number. A shredder rated H-5 for hard drives can still leave SSD chips intact, so check the E-level if you shred SSDs. Punches and crushers that deform a drive correspond to the lower H-levels (H-2 or H-3) at best, and many don't quote a level at all.

4. What UK guidance says

NCSC: secure sanitisation of storage media

  • The National Cyber Security Centre's guidance (last reviewed February 2025) covers hard drives, SSDs and flash media such as USB drives and SD cards.
  • For devices with encryption, the manufacturer's factory reset normally deletes the encryption keys, making the data unreadable. For unencrypted devices, it describes overwriting all user-accessible memory and then checking it worked.
  • For higher-risk cases, it describes physically destroying media to particles of 6mm or less, and verifying the particle size afterwards.
  • Degaussing should only be used on exclusively magnetic media, with a degausser confirmed strong enough for the device.
  • If you use a disposal company, check for recognised certifications such as the NCSC's CAS-S (Sanitisation Assurance) scheme or ADISA.

ICO and UK GDPR

  • The Information Commissioner's Office warns that personal data not destroyed securely may be recoverable, which may breach UK GDPR Articles 5(1)(f) and 32.
  • Its audit toolkit tells organisations to use and document secure disposal methods, such as device wiping, degaussing or hardware shredding.
  • Store devices awaiting destruction securely, for example in a locked area with restricted access, and keep a log of each device and its location.
  • If a third party destroys drives for you, your contract should cover security, accountability and audit rights, and someone should check that destruction certificates match what was sent.

5. Choosing equipment

A few drives a month (small business, IT team)

A screwdriver kit to remove drives, a single-bay drive eraser with Secure Erase support, and a manual punch or crusher for visible destruction is a proportionate, low-cost setup.

Regular batches (IT asset disposal, refurbishers)

Multi-bay SATA/SAS erasers that print or log results, plus M.2 and NVMe erasers for modern laptops, let you wipe at volume and resell drives that still have value. Add physical destruction for failed drives that can't be wiped.

High-risk data or no reuse allowed

Purge first, then destroy to a small particle size, either in-house with an industrial shredder rated for the right H and E levels, or through a certified destruction provider. Industrial drive shredders are mostly sold through specialist dealers rather than Amazon.

6. Keep records

Whatever method you use, write down what you did. A simple log should record:

  • drive serial number and asset tag
  • where it came from, and where it was stored while waiting
  • method used (wipe type and/or destruction method), date, and who did it
  • the eraser's report or printout, and a photo of destroyed drives
  • for third-party destruction, the certificate, checked against your list

Numbered tamper-evident bags and a lockable drive case make the chain of custody easier to prove.

Common questions

Is a punched hard drive "destroyed"?

It's unusable, but not necessarily unrecoverable. NIST notes that bending, cutting or drilling may only partly damage a drive, leaving portions readable with laboratory techniques. Wiping before punching closes that gap.

What particle size does the NCSC recommend?

For higher-risk cases, the NCSC's guidance describes physically destroying media to particles of 6mm or less, and checking the particle size afterwards.

Can I degauss an SSD?

No. NIST says degaussing should not be used on non-magnetic media such as SSDs: the process can appear to complete while no data is actually removed.

Sources

This guide summarises public guidance to help you choose equipment. It isn't legal or compliance advice.