There are twenty-five erasure standards in the software. Most of the difference between them is not strength — it is who published them and what their procedure requires. A single verified pass and a thirty-five pass sequence leave a modern drive in the same state; one takes minutes and the other takes days.
The table below is generated from the erase engine's own catalogue, so the pass counts are what the software runs rather than a figure written for a brochure. Where a standard's published procedure includes a verification read, the software performs it and the option cannot be turned off.
The Risks This Removes
Picking by Pass Count
More passes is not more erased. Overwriting was defeated on 1990s encodings by residual magnetism; on a current drive one verified pass leaves nothing behind. Thirty-five passes buys days of runtime and no additional certainty.
Overwriting Flash
An SSD's controller decides where writes land. Overwrite passes cannot reach blocks the controller has retired, so a standard written for spinning media does not do on flash what it does on a hard drive. The device's own sanitize command does.
A Standard Named but Not Followed
Most standards define verification as part of the procedure. A run that skipped it is not that standard, and a certificate claiming it would be false. That is why verification is locked on where the procedure requires it.
Every Standard the Software Runs
Passes are what the engine performs. Verification is marked where the published procedure itself requires the read — on those standards it cannot be switched off.
| Standard | Passes | Region | Verification | What it does |
|---|---|---|---|---|
| Data Sanitization Pro — DPDP Compliance | 1 | India | Optional | Single-pass overwrite with a verification read, aligned to India's Digital Personal Data Protection Act. |
| NIST 800-88 Clear | 1 | United States | Optional | One overwrite pass across every addressable block. The NIST baseline for media that stays inside the organisation. |
| NIST SP 800-88 Rev. 1 Purge | 3 | United States | Optional | Three passes with a verification read, for media leaving the organisation's control. |
| NIST SP 800-88 Rev. 2 Clear | 1 | United States | Optional | Revision 2 single-pass clear, with the revised addressing rules for flash media. |
| NIST SP 800-88 Rev. 2 Purge | 3 | United States | Optional | Revision 2 purge — three passes plus verification, for media leaving the organisation. |
| DoD 5220.22-M | 3 | United States | Optional | Zeroes, complement, then a random pattern with verification. The long-standing US defence baseline. |
| DoD 5220.22-M ECE | 7 | United States | Optional | Extended DoD sequence: seven passes with verification between them. |
| IEEE 2883-2022 | 1 | International | Required | Single-pass logical sanitize as defined for modern storage, verification mandatory. |
| Gutmann Method | 35 | Legacy | Optional | Thirty-five patterns designed for 1990s MFM and RLL encodings. Offered for policies that still name it; it has no advantage on current drives. |
| Schneier Algorithm | 7 | Legacy | Required | Two fixed passes followed by five random ones, with verification. |
| Pfitzner | 33 | Legacy | Optional | Thirty-three random passes. Very slow, and no stronger than a single verified pass on modern media. |
| AFSSI-5020 (US Air Force) | 3 | United States | Required | US Air Force sequence: zeroes, ones, then random, verified. |
| AR 380-19 (US Army) | 3 | United States | Required | US Army sequence: random, its complement, then random, verified. |
| VSITR (German Federal) | 7 | Germany | Required | German federal seven-pass alternating sequence with a final verification read. |
| BSI-GSE (German Extended) | 7 | Germany | Required | German BSI extended seven-pass profile with verification. |
| GOST R 50739-95 | 1 | Russia | Optional | Russian state standard: a single pass of zeroes or random data. |
| HMG IS5 Baseline | 1 | United Kingdom | Required | UK baseline: one pass of zeroes with a verification read. |
| HMG IS5 Enhanced | 3 | United Kingdom | Required | UK enhanced: zeroes, ones, then random, all verified. |
| ISO/IEC 27040:2024 | 1 | International | Required | Single verified pass as defined for modern storage devices. |
| NAVSO P-5239-26 (US Navy) | 3 | United States | Required | US Navy sequence: a character, its complement, then random, verified. |
| NZISM | 1 | New Zealand | Optional | New Zealand government single verified overwrite pass. |
| RCMP TSSIT OPS-II (Canada) | 7 | Canada | Required | Canadian police seven-pass alternating sequence with verification. |
| NSA/CSS Policy Manual 9-12 | 3 | United States | Optional | Three-pass sequence to the NSA/CSS storage device declassification manual. |
| CSEC ITSG-06 (Canada) | 3 | Canada | Required | Canadian ITSG-06 three-pass sequence with verification. |
| Random Overwrite | 1 | — | Optional | A single pass of cryptographically random data. Fast, and sufficient on any drive that reports its writes honestly. |
How to Choose One
- Staying inside the organisation: a single verified pass — NIST SP 800-88 Rev. 2 Clear — is the baseline and is enough.
- Leaving the organisation, being resold or returned: use a purge profile, NIST SP 800-88 Rev. 2 Purge or your own regulator's equivalent.
- SSD, NVMe or a self-encrypting drive: the drive's sanitize or crypto-erase command, then verify. Overwriting alone cannot reach retired blocks.
- Working to a policy that names a standard: pick that standard. It is in the list, and the certificate will name it.
- In India and working to the DPDP Act: the DPDP profile is a single verified pass aligned to that Act.
- A drive that refuses to sanitize, or fails verification: it is flagged for physical destruction rather than passed.
Frequently Asked Questions
Which standard should we use by default?
NIST SP 800-88 Rev. 2 — Clear for media staying inside the organisation, Purge for media leaving it. It is the most widely accepted baseline and it is written for current storage rather than for 1990s drives.
Is DoD 5220.22-M still required?
Rarely by name, but many internal policies still cite it and some customers ask for it, so it is implemented. It runs three passes with verification. NIST superseded it as the reference standard.
Why offer Gutmann at all if it adds nothing?
Because policies still name it. Where a policy says Gutmann, the run has to say Gutmann. The description in the table says plainly that it has no advantage on current drives.
Can verification be turned off to save time?
Not where the standard requires it. On those methods the option is locked and the reason is shown to the operator. Turning it off would mean the run was no longer that standard.
What happens on a self-encrypting drive?
Cryptographic erase destroys the key rather than overwriting sectors. There is no plaintext left to hash, so hash verification is locked off for that method rather than on.
Not Sure Which One Applies to You
Tell us the regulator you answer to and the media you are retiring, and we will tell you which profile to run.
See Sample Certificates
