DATASAN — SSD MEDIA SANITIZATION
Secure SSD Data Destruction: Why Degaussing Fails and What Actually Works
SSDs store data in NAND flash chips, not on magnetic platters — which means degaussing erases nothing on an SSD. Datasan sanitizes SSDs the right way under NIST SP 800-88: cryptographic erase, firmware-level sanitization, and physical destruction, each documented with a per-serial-number certificate of destruction for your audits.
SSD data destruction is one of the most widely misunderstood areas of information security governance. Many organizations still apply legacy hard-drive procedures — degaussing or multi-pass overwriting — to modern SSDs, business laptops, and servers. Physically, however, degaussing works by destroying magnetic patterns on HDD platters and tape; SSDs store nothing magnetically, so a 'degaussed' SSD can be plugged back in and read in full.
This risk is not theoretical. SSD architecture — wear leveling, over-provisioning, and spare blocks invisible to the operating system — means data can survive in areas that software-based erasure never touches. When decommissioned server drives, employee laptops, or leased equipment leave your control without proper sanitization, the personal data, customer records, or medical records they hold can leak — with legal consequences under Indonesia's Personal Data Protection Law (Law No. 27 of 2022) and, for electronic system operators, Government Regulation 71/2019.
NIST SP 800-88 Rev. 1, the most widely referenced international standard for media sanitization, explicitly limits degaussing to magnetic media and defines a separate path for flash memory: Purge techniques such as cryptographic erase and firmware-level sanitize commands, or Destroy via physical destruction. This page explains why legacy methods fail on SSDs, how the correct methods work, and what evidence you need to hold for auditors and regulators.
Why Legacy Destruction Procedures Fail on SSDs
Degaussing has no effect on NAND flash
A degausser destroys magnetic patterns — effective on HDDs and tape, but SSDs store data as electrical charge in NAND cells. An SSD that has passed through a degausser retains all of its data and often still works normally.
Software overwrites cannot reach every cell
Wear leveling and over-provisioning mean the SSD controller writes to physical locations different from what the operating system sees. Software-based overwriting can leave copies of data in spare and remapped blocks.
Formatting and deleting only remove pointers
A quick format or file deletion merely discards file-system references; the contents of the NAND cells remain and can be recovered with fairly common forensic tools.
Without evidence, compliance cannot be proven
Indonesia's PDP Law requires accountable destruction of personal data. Without per-serial-number certificates and a chain of custody, an organization has no proof that this obligation was actually fulfilled.
The Datasan Approach: SSD Sanitization per NIST SP 800-88
Media assessment and method selection
Every unit is identified by media type first — HDD, SATA/NVMe SSD, eMMC, or hybrid — because the correct method differs by technology. SSDs are never routed to a degausser.
Cryptographic erase for encrypted drives
On qualifying self-encrypting drives, the encryption key is destroyed via a crypto-erase command, leaving the entire drive as unrecoverable ciphertext — a Purge technique recognized by NIST SP 800-88.
Firmware-level sanitization with verification
The drive's built-in sanitize commands (block erase/sanitize) are executed at the controller level to reach over-provisioned areas, then verified with sample reads to confirm no data remains.
Physical destruction for the highest-risk media
For drives that fail sanitization, are damaged, or carry the most sensitive classifications, SSDs are physically destroyed with fragment sizes that account for how small NAND chips are — not merely a cracked casing.
Certificates of destruction and audit trail
Every unit is documented: serial number, method, date, operator, and verification result, issued as a certificate of destruction plus formal minutes ready for internal auditors and regulators alike.
Datasan has handled storage-media decommissioning for banking, healthcare, and national enterprise groups with complete per-unit audit documentation.
How the SSD Data Destruction Process Works
Inventory and chain of custody
All media are logged by serial number from handover. Every transfer of possession is documented so no unit ever leaves oversight — whether processed on-site at your premises or at our facility.
Media classification and sensitivity mapping
Our team separates magnetic media from flash, then maps data sensitivity with you to determine the appropriate NIST path: Clear, Purge, or Destroy.
Sanitization or destruction execution
SSDs are processed with crypto-erase or firmware sanitize commands, and physically destroyed where your policy requires it or where sanitization cannot be verified. Magnetic media are handled separately via degaussing or shredding.
Verification, certificates, and reporting
Each unit's result is verified, then a certificate of destruction and a summary report are issued — compliance evidence you can attach to ISO 27001 audits, OJK examinations, or internal reporting.
Frequently Asked Questions about SSD Data Destruction
Why is degaussing ineffective on SSDs?
Degaussing uses a powerful magnetic field to scramble the magnetic patterns on HDD platters or tape. SSDs store data as electrical charge in NAND flash cells — there is nothing magnetic to destroy, so the data remains intact after degaussing. NIST SP 800-88 accordingly recognizes degaussing for magnetic media only.
Are multi-pass software overwrites sufficient for SSDs?
They are not reliable. SSD controllers perform wear leveling and maintain over-provisioned areas that ordinary overwrite software cannot reach, so copies of data can survive in blocks invisible to the operating system. For SSDs, NIST SP 800-88 points to firmware-level Purge techniques or physical destruction instead.
What is cryptographic erase and when is it valid?
Cryptographic erase destroys the encryption key on a drive whose entire contents are encrypted, leaving only ciphertext that can never be decrypted. NIST SP 800-88 recognizes it as a Purge technique, provided encryption was properly enabled and implemented from the start — which is why we verify eligibility per drive before relying on it.
When should an SSD be physically destroyed?
Physical destruction is chosen when logical sanitization cannot be executed or verified — for example, a damaged drive that no longer responds to sanitize commands — or when internal policy for the highest data classifications requires it. Destruction must reach the NAND chips with sufficiently small fragments, because an intact chip can still potentially be read.
What does a certificate of destruction contain and why does it matter?
The certificate records the unit's identity (serial number), the method used, the execution date, the responsible personnel, and the verification result. It is your evidence of accountability when auditors, regulators, or data subjects ask what happened to their data — without it, a destruction claim is difficult to substantiate.
Do Indonesian regulations mandate a specific destruction method?
The PDP Law No. 27/2022 and Government Regulation 71/2019 require deletion and destruction of data under certain conditions, but they do not prescribe detailed technical methods. Common practice is therefore to anchor procedures in international standards such as NIST SP 800-88, so an organization can demonstrate its destruction was performed in a recognized, verifiable manner.
DATASAN — SSD MEDIA SANITIZATION
Make Sure the Data on Your SSDs Is Truly Gone
Talk to the Datasan team about your device decommissioning plan. We help you map media types, select methods under NIST SP 800-88, and produce audit-ready proof of destruction — on-site or at our facility.
