CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 22 Of 25 · Government And Defence

GOST R 50739-95 — Russian Data Erasure & Secure Disk Wiping

Russian GOST R 50739-95 Data Sanitization Method

Russia2 PassesVerification Available
Storage media prepared for a GOST R 50739-95 wipe

At A Glance

Published By
Gosstandart of Russia
Reference
GOST R 50739-95, 1995
Region
Russia
Passes
2
Verification
Available On Every Run
Relative Run Time
2× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Pass 2 Fixed pattern 0x00
  3. Verify Read back of the final pass, available on every run.
  4. Certify Signed certificate with device, method, result and operator

GOST R 50739-95 is a Russian Federation standard titled “Computers Technique. Information Protection AgainstUnauthorizedAccess to Information. General Technical Requirements.” It establishes functional requirements for protecting computer systems and information against unauthorized access, including requirements relating to access control, security mechanisms, event registration and protection assurance. The standard was approved in 1995 and entered into force on January 1, 1996. Rosstandart currently lists it as in force.

In the data-erasure software industry, GOST R 50739-95 is also commonly used as the name of a software-based disk wiping profile, typically implemented as a one- or two-pass overwrite process. However, this software profile should not be confused with the complete scope of the official GOST standard itself.

Data Sanitization Pro (DSP) provides a dedicated GOST R 50739-95 Sanitization Method through the DSP Sanitization Engine, enabling controlled execution, verification, device monitoring and audit-ready certification.

01

GOST R 50739-95 — Russian Data Erasure, Verified Sanitization & Audit-Ready Certification

02

What Is GOST R 50739-95?

GOST R 50739-95 is a Russian national standard concerning protection of computer technology and information against unauthorized access.

Its official title is:

“Средства вычислительной техники. Защита от несанкционированного доступа к информации. Общие технические требования”

or:

“Computers Technique. Information Protection Against Unauthorised Access to Information. General Technical Requirements.”

The standard defines requirements for computer systems, protection mechanisms, access control and security assurance. It is not, by its full official scope, simply a hard-drive wiping specification.

Nevertheless, the GOST R 50739-95 name is widely used in commercial disk-wiping software to identify a Russian-associated overwrite profile.

That distinction is important when documenting compliance, sanitization methodology and audit evidence.

03

GOST R 50739-95 Data Wiping Profile

In commercial data-erasure implementations, GOST R 50739-95 is commonly represented as a one- or two-pass overwrite profile.

A frequently used implementation is:

04

Pass 1

05

Overwrite With Zeros

Pass 2

Overwrite With Random Data

The second pass is sometimes treated as an optional extended operation, resulting in either a one-pass or two-pass implementation depending on the software and selected profile. This software-industry interpretation is documented by multiple data-erasure products and technical references.

DSP should therefore identify the actual configured sanitization profile in its certificate rather than implying that every implementation of GOST R 50739-95 uses exactly the same pass sequence.

GOST R 50739-95 With DSP

DSP provides a dedicated GOST R 50739-95 Sanitization Method through the DSP Sanitization Engine.

06

DSP Workflow

  1. 01Select GOST R 50739-95
  2. 02Identify
  3. 03Assess
  4. 04Execute
  5. 05Verify
  6. 06Document
  7. 07Certify

The operator selects the GOST R 50739-95 method and target storage device.

DSP then identifies the device, assesses available device information and executes the selected sanitization profile.

07

GOST R 50739-95 Sanitization Engine

During the sanitization process, DSP can monitor and record:

  • Manufacturer
  • Model
  • Serial Number
  • Capacity
  • Storage Interface
  • Device Type
  • Current Operation
  • Sanitization Progress
  • Processing Rate
  • Elapsed Time
  • Estimated Completion
  • Verification Status
  • Device Errors
  • Process Events
  • Completion Result

This provides a traceable workflow from device identification to verified sanitization.

08

One-Pass And Two-Pass GOST Profiles

The GOST R 50739-95 name is commonly encountered in data-wiping software with two related configurations.

ProfileOperation
GOST R 50739-95 — 1 PassOverwrite with zeros
GOST R 50739-95 — 2 PassOverwrite with zeros followed by random data

The important technical point is that these are software sanitization profiles associated with the GOST designation, rather than claiming that the official GOST standard itself is a dedicated two-pass disk-erasure specification.

DSP can document the exact profile executed on the target device.

09

GOST R 50739-95 For HDD Data Erasure

The overwrite interpretation of GOST R 50739-95 is most naturally applicable to rewriteable magnetic storage, particularly traditional HDDs.

A software overwrite replaces data in addressable storage locations with new values.

For supported HDDs, DSP can execute the selected GOST profile while recording:

  • Drive Identity
  • Capacity
  • Serial Number
  • Sanitization Method
  • Pass Configuration
  • Progress
  • Completion Status
  • Verification Result
  • Device Health Information
  • Errors And Exceptions

This makes the method suitable for controlled:

  • HDD Data Erasure
  • Hard Drive Wiping
  • IT Asset Disposition
  • Computer Refurbishment
  • Enterprise Hardware Retirement
  • Storage-Device Reuse
  • Secure Media Disposal Workflows
10

GOST R 50739-95 And SSD / NVMe

Modern solid-state storage requires special consideration.

SSDs and NVMe devices use architectures such as:

  • Flash Translation Layers
  • Wear Leveling
  • Garbage Collection
  • Over-Provisioning
  • Spare NAND Blocks
  • Controller-Level Remapping

Consequently, repeatedly overwriting logical sectors through a normal interface does not necessarily guarantee that every historical physical NAND location has been addressed.

Therefore, the historical/software GOST overwrite profile should not automatically be represented as universal physical sanitization for SSD or NVMe media.

For modern flash storage, the sanitization technique should be selected according to the actual storage architecture and applicable current media-sanitization guidance.

Where supported, device-native sanitization techniques may provide more appropriate coverage than repeated logical overwriting.

11

GOST R 50739-95 vs File Deletion

GOST-associated disk wiping is fundamentally different from ordinary file deletion.

OperationResult
File DeletionRemoves filesystem references
Quick FormatRecreates filesystem structures
Factory ResetReinitializes data according to device implementation
One-Pass OverwriteReplaces addressable storage with a defined value
Two-Pass GOST ProfileZero overwrite followed by random-data overwrite
Physical DestructionMakes media physically unusable

Deleting a file or formatting a drive does not by itself establish that previously stored information has been securely sanitized.

12

GOST R 50739-95 And Verification

A professional data erasure workflow should not stop when the final write operation completes.

DSP records the sanitization outcome and verification status.

The audit record can include:

  • Device Identification
  • Selected GOST Method
  • Selected Pass Configuration
  • Execution Status
  • Verification Status
  • Errors
  • Exceptions
  • Start Time
  • Completion Time
  • Operator
  • System Information

This provides evidence of what operation was actually performed on the target device.

13

Bad Sectors And Device Health

Storage-media condition can directly affect software sanitization.

DSP can provide available information relating to:

  • SMART Health
  • Temperature
  • Power-On Hours
  • Firmware
  • Model
  • Serial Number
  • Read/write Errors
  • Logical Bad Sectors
  • Physical Media Errors
  • Device Performance

If portions of a drive cannot be reliably accessed or overwritten, the sanitization result should identify those conditions rather than treating the device as equivalent to a completely processed drive.

This is particularly relevant to:

  1. 01ITAD
  2. 02Refurbishment
  3. 03Resale
  4. 04Redeployment
  5. 05Disposal
14

GOST R 50739-95 For ITAD

A GOST-associated sanitization profile can be incorporated into structured ITAD workflows where a customer, contract or organizational policy specifically requires it.

DSP can connect:

  1. 01Physical Device
  2. 02Device ID
  3. 03GOST Method
  4. 04Sanitization Result
  5. 05Verification
  6. 06Certificate

This provides a documented relationship between the storage device and the sanitization operation.

Typical applications include:

  • Enterprise ITAD
  • Refurbishment centers
  • Data-center decommissioning
  • Computer recycling
  • Corporate hardware retirement
  • Secure storage-device processing
  • Government and regulated environments where the methodology is specifically required
15

Audit-Ready GOST Sanitization Certificate

DSP generates an audit-ready sanitization certificate documenting the GOST R 50739-95 sanitization operation actually performed.

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Device/interface information

Sanitization Information

  • GOST R 50739-95 method
  • Selected pass configuration
  • Sanitization start time
  • Completion time
  • Process result

Verification Information

  • Verification status
  • Verification result
  • Errors
  • Exceptions

Operator & System Information

  • Operator
  • Workstation/system
  • DSP software information
  • Relevant audit metadata

The certificate documents the operation performed by DSP.

It is not a certificate issued byRosstandart, the Russian government or another external standards organization.

GOST R 50739-95 — Standard vs Sanitization Profile

This distinction should remain visible on a professional data-erasure website.

Official GOST R 50739-95

The official standard addresses:

Protection of computer technology and information against unauthorized access.

Its scope includes security requirements, access control, event registration and protection mechanisms.

GOST R 50739-95 In Data-Wiping Software

The designation is also commonly used by disk-wiping software for a one- or two-pass overwrite profile, generally involving zero and/or random-data overwriting.

DSP treats the sanitization operation as a specific executable method and records the actual profile used.

This avoids conflating a broad information-security standard with a particular commercial disk-wiping algorithm.

16

GOST R 50739-95 vs Modern Sanitization Standards

Method / StandardGeneral ContextSanitization Approach
GOST R 50739-95Russian information-security standardBroad information-security requirements; GOST-associated wiping profiles are used by erasure software
VSITRHistorical German methodologyMulti-pass overwrite
DoD 5220.22-MLegacy U.S. methodologyHistorical overwrite profile
GutmannHistorical methodology35-pass overwrite
SchneierHistorical methodology7-pass overwrite
NIST SP 800-88 Rev. 2Current NIST guidanceMedia-specific Clear, Purge and Destroy
IEEE 2883-2022Active IEEE standardTechnology-specific storage sanitization

The number of overwrite passes should not by itself be treated as proof that one method is universally more appropriate than another.

Modern sanitization decisions should consider:

  • Storage Technology
  • Information Sensitivity
  • Device Condition
  • Intended Reuse Or Disposal
  • Organizational Policy
  • Applicable Standards
  • Available Device-Native Sanitization Capabilities
17

GOST R 50739-95 vs NIST SP 800-88 Rev. 2

These are not equivalent documents.

GOST R 50739-95 is a Russian information-security standard addressing protection against unauthorized access.

NIST SP 800-88 Rev. 2 is current U.S. NIST guidance specifically addressing media sanitization programs and the selection of appropriate sanitization techniques.

A GOST-associated overwrite profile should therefore not be marketed as simply being "the Russian equivalent of NIST 800-88."

Instead, DSP can provide both methodologies as separate selectable sanitization methods where supported.

18

GOST R 50739-95 For Offline Data Erasure

DSP supports offline sanitization workflows for environments where internet connectivity is restricted.

This can be useful for:

  • Government Facilities
  • Secure Environments
  • Air-Gapped Networks
  • Enterprise ITAD Centers
  • Data Centers
  • Sensitive Media-Processing Facilities

The sanitization operation can be performed locally while the resulting audit documentation remains available for reporting.

19

Multi-Device GOST Sanitization

Enterprise and ITAD environments may process multiple storage devices in a single workflow.

DSP can provide structured device-level processing with visibility into:

  • Individual Device Identity
  • Sanitization Status
  • Progress
  • Processing Rate
  • Verification
  • Errors
  • Completion Status

The operational workflow becomes:

  1. 01Identify
  2. 02Select GOST Profile
  3. 03Sanitize
  4. 04Verify
  5. 05Certify

Why Use DSP For GOST R 50739-95?

Dedicated GOST Method

DSP provides a dedicated GOST R 50739-95 sanitization method.

Defined Profile

The selected one-pass or two-pass configuration can be explicitly documented.

Device Identification

Target-device information is recorded for traceability.

Process Monitoring

Progress, rate, elapsed time and status can be monitored.

Verification

The completed operation can be verified and documented.

Health Assessment

Available SMART and media-health information can be assessed.

Error Visibility

Bad sectors and device errors can be reported.

Audit Documentation

DSP generates an audit-ready sanitization certificate.

Offline Operation

Suitable for disconnected and restricted environments.

Enterprise & ITAD

Designed for structured storage-device processing.

20

GOST R 50739-95 And Secure Data Erasure

GOST R 50739-95 has an important place in Russian information-security history and remains listed by Rosstandart as an active Russian Federation standard.

For data-erasure applications, the GOST R 50739-95 name is also used for software wiping profiles, commonly represented by one or two overwrite operations.

With Data Sanitization Pro, the selected GOST sanitization profile is executed through the DSP Sanitization Engine, monitored during processing, verified after execution and documented through an audit-ready certificate.

  1. 01Select GOST R 50739-95
  2. 02Identify
  3. 03Assess
  4. 04Execute
  5. 05Verify
  6. 06Document
  7. 07Certify
FAQ

GOST Questions

What Is GOST R 50739-95?

GOST R 50739-95 is a Russian Federation standard concerning protection of computer technology and information against unauthorized access.

Is GOST R 50739-95 A Disk-Wiping Standard?

Not in its complete official scope. The official standard addresses broader information-security requirements. The name is also commonly used by data-erasure software for a one- or two-pass wiping profile.

How Many Passes Does GOST R 50739-95 Use?

Commercial data-wiping implementations commonly describe one-pass or two-pass profiles, typically using zero and/or random-data overwriting. These should be treated as software implementations rather than claiming that the complete official GOST standard mandates a universal disk-wiping pass count.

Is GOST R 50739-95 Still Active?

Yes. Rosstandart currently lists GOST R 50739-95 as **in force**.

Is GOST R 50739-95 Suitable For HDDs?

The GOST-associated overwrite profile is primarily relevant to software-based wiping of addressable rewriteable storage, particularly traditional HDDs.

Can GOST R 50739-95 Be Used For SSDs?

A traditional logical overwrite profile should not automatically be treated as complete physical sanitization of modern SSD/NVMe media because of flash translation, wear leveling, over-provisioning and controller-level remapping.

Does DSP Support GOST R 50739-95?

Yes. DSP provides a dedicated GOST R 50739-95 Sanitization Method through the DSP Sanitization Engine.

Does DSP Generate A GOST Certificate?

Yes. DSP generates an audit-ready certificate documenting the actual sanitization operation performed by DSP.

Is The DSP Certificate Issued By Rosstandart?

No. The certificate is generated by DSP and documents the operation performed by the software. It is not an external Rosstandart-issued certification.

GOST R 50739-95 — Russian Data Erasure, Verified & Documented

Data Sanitization Pro runs all 25 standards offline and verifies the result.