top of page

Secure Data Destruction Guide

Secure data destruction should match the storage technology, project risk and evidence requirement. Appropriate routes include secure erase, degaussing and physical destruction, supported by the agreed level of audit evidence.

Magnetic hard drives

Traditional hard disk drives can be securely erased when reuse is appropriate, or rendered unreadable by degaussing or physical destruction where the risk or project requirement calls for it.

  • Software overwrite where suitable
  • SDD Master degaussing for compatible magnetic HDDs
  • Additional physical destruction where the agreed process requires it
  • Serial-number and project-level reporting available

Magnetic backup tapes

Match the exact tape format and generation to the degausser and the applicable process. Bioteknik uses an SDD Master with serial-linked cycle records for suitable magnetic media.

  • Identify the tape format, not just its capacity
  • Check the listed media scope and equipment capability
  • Keep the individual media serial and treatment timestamp
  • Agree record delivery and any further destruction before processing

Solid-state storage

Flash-based storage needs methods designed for SSD and NVMe media. Conventional HDD overwrite assumptions should not simply be carried across to flash devices.

  • Secure erase or sanitisation where supported
  • Device health and method suitability checked
  • Per-device wipe evidence available on higher-assurance projects
  • Physical destruction remains an option where required

Phones and tablets

Mobile devices combine encrypted storage with cloud accounts, activation locks and MDM. Data security and successful device release therefore need to be considered together.

  • Factory reset and encryption-aware processing
  • MDM and activation-lock status checked
  • Locked devices can still be securely processed
  • Reuse depends on successful account and management release

Removable and embedded media

USB storage, memory cards and embedded flash require media-appropriate handling. The chosen method should match the storage technology and the evidence the organisation needs.

  • Media identified before processing
  • Appropriate erase or destruction route selected
  • Exceptions recorded where necessary
  • Final outcome documented at the agreed assurance level

Understanding the degaussing evidence

The machine, the medium and the record.

Bioteknik uses the VS Security Products SDD Master. Its July 2026 NSA/CSS EPL model listing is useful equipment evidence, not company certification or government endorsement of Bioteknik.

The manufacturer specifies a 20,000-gauss, triple-discharge system with Data Destruction Auditor reporting. That rated specification is distinct from the field reading recorded for an individual cycle; neither should be treated as a universal guarantee for every storage technology.

Identify the medium

Check the storage technology, exact model or tape format, and applicable requirements. Capacity alone does not establish compatibility. Degaussing applies to suitable magnetic media, not SSDs, NVMe flash or phone memory.

Keep the cycle record

The Media Destruction Record can include the media identity, operator, equipment model and serial, firmware, cycle counter, capacitor voltage, magnetic-field reading and recorded result. Keep the treatment timestamp separate from the later print or export timestamp.

Review the full evidence

A record saying Degaussed reports the cycle result. It does not by itself prove correct media identification, complete custody, additional physical destruction or the absence of all residual data. The final certificate and supporting records serve different purposes.

From the media serial to the client record

Match the media serial number to the correct asset; a report may also contain a separate serial for the degausser itself. A combined PDF can contain several media records, so retain the original and identify any per-media page extracts clearly.

Evidence-file upload is not automatic treatment approval. Bioteknik's client evidence access remains subject to the agreed Level 3 service, authorised company access, and the required file review and release checks. Lower reporting levels do not automatically include every device-level file.

Degaussing a removed drive is not destruction of the entire laptop or server. The parent equipment may be assessed for refurbishment separately; the original medium and any replacement storage must remain distinct in its history.

Discuss the method and evidence for your project →

Illustration only · not a client report

Inside a degaussing record

Media serial number
[individual media serial]
Treatment date and time
[recorded cycle timestamp]
Degausser model
SDD-MASTER
Machine serial / firmware
[recorded equipment details]
Cycle counter
[recorded cycle count]
Magnetic field (gauss)
[recorded field reading]
Result
[recorded cycle result]

Example fields, not evidence that any item has been processed. A processing log supports the audit trail; it is not the final project certificate.

Model listing, media limits and equipment verification

The July 2026 NSA list names VS Security Products — SDD Master on page 2. Its HDD scope is limited to manufacture in 2024 or earlier; HAMR and hybrid drives are outside this magnetic-only route. Supported tape formats are listed individually on page 5.

For a process specified to those NSA requirements, HDD degaussing must be followed by physical destruction deforming all platters. Fit, media compatibility and continued equipment verification also matter. A model listing does not establish the present condition of an individual machine or approve a whole service.

The NCSC storage-media guidance likewise calls for checking degausser capability against the actual magnetic media. SSDs, NVMe flash, USB flash and phone memory need a different sanitisation or destruction route.

The July 2026 document also sets a 30,000-gauss minimum for new degausser evaluations, while continuing to list the SDD Master. Do not confuse continued inclusion with blanket approval for newer media, or with independent verification of a particular unit's present performance.

Equipment-model listing checked 17 September 2026; source edition July 2026. Scope and equipment condition must be reviewed for each project.

Standard: Controlled processing

Suitable for routine business IT retirement where the organisation needs secure processing and clear project records without a large volume of per-device evidence.

  • Serial-number or asset list where agreed
  • Secure erase, degauss or destruction route recorded
  • Certificate of Data Destruction
  • Responsible reuse or recycling outcome

Enhanced: Stronger audit trail

Adds more detailed handling and destruction-point auditing for organisations that need clearer evidence of what happened to each data-bearing asset.

  • Device-level identification
  • Method recorded at destruction or sanitisation point
  • Exception and locked-device handling
  • Expanded project reporting and certificate

Full Assurance: Detailed evidence package

For higher-risk or governance-heavy projects where the evidence package matters as much as the destruction method itself.

  • Multi-stage asset scanning where required
  • Per-device wipe or degauss logs where technically available
  • Chain-of-custody and exception records
  • Detailed final reporting with project certificate

Secure data destruction process

01 Agree the risk and evidence level

Define the storage types, destruction method, audit depth and reporting expectations before processing begins.

02 Identify every data-bearing asset

Record relevant serial numbers, asset tags, make/model and any exceptions that affect processing.

03 Select the correct sanitisation route

Match erase, degauss or destruction to HDD, SSD, NVMe, mobile or removable storage.

04 Process and verify

Complete the agreed method and record the result, including devices that cannot follow the intended route.

05 Separate reuse from recycling

Only equipment that has completed data-security checks proceeds toward refurbishment or value recovery.

06 Issue the agreed evidence

Provide the serial list, method records, logs and Certificate of Data Destruction appropriate to the project tier.

Common secure data destruction mistakes

Using one method for every storage type

HDD, SSD, NVMe and mobile storage do not all respond to the same sanitisation process.

Assuming factory reset equals full offboarding

Cloud accounts, MDM and activation controls can remain even when local user data has been reset.

Specifying shredding before defining the evidence needed

Physical destruction can be appropriate, but it does not automatically provide the detailed audit trail some organisations expect.

Ignoring reuse until after destruction is chosen

Where policy allows, the right sanitisation route can preserve equipment value and reduce unnecessary material destruction.

Secure data destruction FAQs

Is physical shredding always the most secure option?

No. The correct method depends on the storage technology, risk, policy and evidence requirement. Secure erase, degaussing and physical destruction each have appropriate use cases.

Can SSDs be degaussed?

No. Degaussing is for suitable magnetic media such as HDDs and backup tapes. SSD and NVMe devices need flash-appropriate sanitisation or physical destruction.

Do you provide a certificate?

Yes. A Certificate of Data Destruction can be provided. The amount of supporting device-level evidence depends on the agreed project assurance level.

Can locked or MDM-managed devices still be processed?

Yes. They can still be secured, but unresolved management or activation controls can prevent reuse and may require additional administration.

Is onsite data destruction available?

Yes. Onsite processing can be arranged where project requirements call for witnessed or site-based destruction.

Data destruction service · Onsite data destruction · MDM and device offboarding

bottom of page