Pfitzner Method — 33 Pass
from the available DSP sanitization methods.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
33-Pass Random-Data Overwrite For Professional Data Sanitization

33 passes: 33 random and 0 fixed patterns.
The Pfitzner Method is a historical multi-pass data wiping methodology associated with Roy Pfitzner. The commonly referenced implementation performs 33 sequential overwrite passes using random data across the target storage area. Technical references and sanitization-method catalogs commonly identify Pfitzner as a 33-pass random-overwrite method.
Data Sanitization Pro (DSP) provides a dedicated Pfitzner Sanitization Method through the DSP Sanitization Engine, allowing the configured method to be executed, monitored, verified and documented with an audit-ready sanitization certificate.
The Pfitzner Method is a 33-pass random-data overwrite methodology.
Its defining characteristic is straightforward:
Unlike methods that alternate fixed values such as 0x00 and 0xFF, the Pfitzner approach uses random data throughout the overwrite sequence.
The method is therefore commonly categorized as a multi-pass secure data wiping technique rather than as a current government or international storage-sanitization standard.
Pfitzner should not be represented as:
It is a historical data-wiping methodology that can be implemented by data-erasure software.
The traditional Pfitzner process is based on repeated random-data overwriting.
| Pass Range | Operation |
|---|---|
| Pass 1 | Random data |
| Pass 2 | Random data |
| Pass 3 | Random data |
| Pass 4–32 | Random data |
| Pass 33 | Random data |
The defining feature is therefore not a changing pattern sequence but the use of random data across all 33 passes.
This makes Pfitzner fundamentally different from methods such as:
Each uses a different sequence, pass structure or sanitization concept.
DSP implements Pfitzner as a dedicated sanitization option within the DSP Sanitization Engine.
The complete workflow is designed around controlled execution rather than simply launching a sequence of writes.
The operator selects:
from the available DSP sanitization methods.
DSP records relevant storage-device information, including where supported:
Before execution, the available device-health information can be reviewed.
DSP can provide information such as:
The DSP Sanitization Engine performs the configured Pfitzner process:
through all 33 passes.
DSP can display operational information such as:
DSP performs the configured post-sanitization verification process and records the result.
DSP generates an audit-ready sanitization certificate documenting the method actually executed on the target device.
A file deletion operation and a storage sanitization operation are fundamentally different.
Deleting a file generally changes filesystem metadata and makes the space available for reuse. It does not inherently overwrite every underlying storage location containing the previous data.
Pfitzner instead performs repeated overwriting of the targeted storage area.
| Operation | Primary Function |
|---|---|
| File Deletion | Removes filesystem reference |
| Quick Format | Recreates/modifies filesystem structures |
| Factory Reset | Device-dependent reset |
| Write Zero | Overwrites with zero values |
| Random Data | Overwrites with random data |
| Pfitzner | 33-pass random-data overwrite |
| Gutmann | 35-pass historical methodology |
| Schneier | 7-pass historical methodology |
| Purge | Sanitization intended to make recovery infeasible for the specified level of effort |
| Destroy | Physical destruction of media |
The Pfitzner method is primarily understood in the context of traditional magnetic storage and addressable disk wiping.
For a compatible HDD, repeated overwriting can replace the data contained in addressable sectors with newly generated values.
DSP can combine the wiping process with device identification, health assessment, error monitoring and post-process verification.
Modern SSD and NVMe storage requires a different technical assessment.
Flash-based storage can use:
Because the host normally interacts with a logical address space rather than directly controlling every physical flash location, repeated host-level overwriting does not necessarily guarantee coverage of every previous physical storage location.
Current NIST SP 800-88 Rev. 2 specifically recognizes this limitation for flash-based media and explains that conventional overwrite techniques may not be appropriate for sanitizing all previous data on such devices.
Therefore:
A 33-pass Pfitzner overwrite should not automatically be treated as a universal SSD or NVMe sanitization solution.
For modern flash storage organizations should evaluate device-specific sanitization capabilities and applicable Clear or Purge techniques.
Historical multi-pass algorithms were developed around storage technologies and threat models that differ substantially from today's SSD, NVMe and controller-managed flash devices.
Current media sanitization programs should consider:
This is more appropriate than assuming that a higher number of overwrite passes automatically provides a stronger result.
For modern devices, dedicated device sanitization commands or other technology-appropriate methods may be preferable where supported and required.
Pfitzner is frequently grouped with other historical multi-pass wiping methodologies, but their structures are different.
| Feature | Pfitzner | Schneier | Gutmann |
|---|---|---|---|
| Common Passes | 33 | 7 | 35 |
| Main Data Pattern | Random | Fixed + random | Fixed patterns + random |
| Random Data Throughout | ✓ Yes | No | No |
| Historical Methodology | ✓ Yes | ✓ Yes | ✓ Yes |
| Current NIST Standard | No | No | No |
| Dedicated DSP Method | ✓ Yes | ✓ Yes | ✓ Yes |
| Audit-Ready DSP Certificate | ✓ Yes | ✓ Yes | ✓ Yes |
The pass count alone should not be used as a universal measurement of sanitization assurance.
Modern storage architecture is an important factor in selecting the appropriate sanitization technique.
Pfitzner and DoD 5220.22-M represent different historical approaches to data wiping.
| Feature | Pfitzner Method | DoD 5220.22-M |
|---|---|---|
| Common Implementation | 33 random-data passes | Historical multi-pass approach |
| Main Technique | Random overwriting | Pattern/complement/random overwriting |
| Origin | Pfitzner methodology | Former U.S. DoD NISPOM policy |
| Current NIST Standard | No | No |
| Current DoD Requirement | No | No |
| DSP Implementation | Dedicated method | Dedicated method |
| Audit-Ready DSP Certificate | ✓ Yes | ✓ Yes |
The historical DoD methodology should not be presented as interchangeable with Pfitzner merely because both are used in data-wiping software.
NIST SP 800-88 Rev. 2 is the current NIST publication for media sanitization.
Pfitzner is a historical overwrite methodology.
They serve different purposes.
A defined:
A modern media-sanitization framework that emphasizes selecting an appropriate sanitization technique according to factors such as:
Consequently, Pfitzner can be offered as a specific sanitization method, while the broader sanitization decision should remain technology-aware.
A complete storage sanitization process must account for device condition.
A drive may contain:
If the storage device cannot successfully write to an addressable location, the software should not simply assume that the corresponding data was overwritten.
DSP can record relevant error and device-health information as part of the sanitization workflow.
This helps distinguish:
from:
Verification evaluates whether the selected sanitization operation completed successfully.
DSP can record:
Validation determines whether the completed operation satisfies the intended sanitization requirement.
This distinction is important:
A completed 33-pass process does not automatically establish that every storage architecture has been completely sanitized.
The result must be considered in relation to the device technology, condition and applicable sanitization requirements.
DSP can generate an audit-ready sanitization certificate documenting the operation actually performed.
The report can include:
The certificate documents the sanitization operation performed by DSP.
It is not certification issued by Roy Pfitzner, NIST, IEEE, DoD or another external standards organization.
DSP can support offline sanitization workflows for environments where internet connectivity is restricted.
This can be useful for:
The sanitization process can therefore be performed locally without requiring continuous internet connectivity.
DSP can support professional multi-device sanitization workflows according to the configured licensing and available hardware.
Typical applications include:
Each device can maintain its own sanitization and verification record.
Pfitzner can be selected when an organization specifically requires or chooses a 33-pass random-data overwrite methodology for compatible storage.
However, the method should not be selected simply because it has 33 passes.
For modern storage, especially SSD and NVMe, the more important questions are:
This technology-aware approach is more appropriate for professional data erasure than relying solely on pass count.
DSP provides a dedicated implementation of the Pfitzner methodology.
The configured 33-pass random-data process can be executed through the DSP Sanitization Engine.
The completed operation can be verified and documented.
DSP can provide device identification and available health information.
Storage errors and bad-sector conditions can be detected and reported where supported.
Generate professional documentation of the actual sanitization operation.
Suitable for restricted or air-gapped environments where offline operation is required.
Designed for professional storage sanitization, IT asset disposition and enterprise media-retirement processes.
Data Sanitization Pro provides a dedicated sanitization-method library covering established, historical and technology-specific methodologies.
For the Pfitzner method, DSP provides a dedicated:
The selected method is executed through the DSP Sanitization Engine, followed by verification and audit-ready documentation.
Method selection should be based on the storage technology organizational policy and intended sanitization objective.
The Pfitzner Method is a historical data-wiping methodology commonly implemented as **33 passes of random-data overwriting**.
The commonly referenced Pfitzner implementation uses **33 overwrite passes**. Each pass writes random data.
No. Pfitzner is a historical wiping methodology, not a current NIST media-sanitization standard.
No. It should not be represented as a U.S. Department of Defense sanitization standard.
No. Pfitzner is commonly implemented as 33 random-data passes, while the Gutmann methodology uses a 35-pass sequence containing defined patterns and random passes.
No. Schneier is commonly implemented as seven passes using fixed values followed by random-data passes, while Pfitzner uses random data across all 33 passes.
It can be used as a multi-pass overwrite methodology on compatible addressable storage, subject to device condition and successful write coverage.
A Pfitzner option can be available in sanitization software, but conventional host-level repeated overwriting should not automatically be considered sufficient for every SSD or NVMe device because flash architecture can prevent direct coverage of all physical storage locations.
The number of passes alone does not establish universal sanitization strength. Storage technology, device architecture, sanitization technique and the required security outcome must be considered.
Yes. DSP can generate an audit-ready certificate documenting the Pfitzner method executed, device information, sanitization result and verification information.
No. It documents the operation performed by DSP and is not an external certification issued by Roy Pfitzner or a standards organization.
Data Sanitization Pro runs all 25 standards offline and verifies the result.