CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 19 Of 25 · Legacy Algorithms

Pfitzner Method — 33-Pass Data Erasure & Secure Disk Wiping

33-Pass Random-Data Overwrite For Professional Data Sanitization

Legacy research33 PassesVerification Available
Hard drive under a long multi pass Pfitzner wipe

At A Glance

Published By
Roy Pfitzner
Reference
Legacy multi pass method
Region
Legacy research
Passes
33
Verification
Available On Every Run
Relative Run Time
33× a single pass

What The Software Writes

33 passes: 33 random and 0 fixed patterns.

The Pfitzner Method is a historical multi-pass data wiping methodology associated with Roy Pfitzner. The commonly referenced implementation performs 33 sequential overwrite passes using random data across the target storage area. Technical references and sanitization-method catalogs commonly identify Pfitzner as a 33-pass random-overwrite method.

Data Sanitization Pro (DSP) provides a dedicated Pfitzner Sanitization Method through the DSP Sanitization Engine, allowing the configured method to be executed, monitored, verified and documented with an audit-ready sanitization certificate.

  1. 01Select Method
  2. 02Select Device
  3. 03DSP Sanitization Engine
  4. 04Execute 33 Passes
  5. 05Verify
  6. 06Document
  7. 07Certify
01

What Is The Pfitzner Method?

The Pfitzner Method is a 33-pass random-data overwrite methodology.

Its defining characteristic is straightforward:

Pass 1–33Overwrite With Random Data

Unlike methods that alternate fixed values such as 0x00 and 0xFF, the Pfitzner approach uses random data throughout the overwrite sequence.

The method is therefore commonly categorized as a multi-pass secure data wiping technique rather than as a current government or international storage-sanitization standard.

02

Important Classification

Pfitzner should not be represented as:

  • A Current NIST Standard
  • An IEEE Storage-Sanitization Standard
  • A Current U.S. Department Of Defense Standard
  • A Government Certification
  • An International Standards-Body Certification

It is a historical data-wiping methodology that can be implemented by data-erasure software.

03

Pfitzner 33-Pass Data Wiping

The traditional Pfitzner process is based on repeated random-data overwriting.

Pass RangeOperation
Pass 1Random data
Pass 2Random data
Pass 3Random data
Pass 4–32Random data
Pass 33Random data

The defining feature is therefore not a changing pattern sequence but the use of random data across all 33 passes.

This makes Pfitzner fundamentally different from methods such as:

  • Schneier
  • Gutmann
  • DoD 5220.22-M
  • HMG IS5
  • VSITR
  • Write Zero
  • Random Data

Each uses a different sequence, pass structure or sanitization concept.

04

Pfitzner Method With Data Sanitization Pro

DSP implements Pfitzner as a dedicated sanitization option within the DSP Sanitization Engine.

The complete workflow is designed around controlled execution rather than simply launching a sequence of writes.

05

1. Select Pfitzner Method

The operator selects:

Pfitzner Method — 33 Pass

from the available DSP sanitization methods.

Identify The Device

DSP records relevant storage-device information, including where supported:

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type
  • Firmware
  • Device status

Assess The Storage Device

Before execution, the available device-health information can be reviewed.

DSP can provide information such as:

  • SMART status
  • Temperature
  • Power-on hours
  • Storage errors
  • Device health
  • Logical bad sectors
  • Physical bad-sector indicators
06

4. Execute 33-Pass Pfitzner Sanitization

The DSP Sanitization Engine performs the configured Pfitzner process:

  1. 01Random
  2. 02Random
  3. 03Random
  4. 04…
  5. 05Random

through all 33 passes.

07

5. Monitor Execution

DSP can display operational information such as:

  • Current Pass
  • Overall Progress
  • Processing Rate
  • Elapsed Time
  • Estimated Remaining Time
  • Device Status
  • Errors
  • Events
  • Verification State
08

6. Verify

DSP performs the configured post-sanitization verification process and records the result.

09

7. Certify

DSP generates an audit-ready sanitization certificate documenting the method actually executed on the target device.

10

Pfitzner vs File Deletion

A file deletion operation and a storage sanitization operation are fundamentally different.

Deleting a file generally changes filesystem metadata and makes the space available for reuse. It does not inherently overwrite every underlying storage location containing the previous data.

Pfitzner instead performs repeated overwriting of the targeted storage area.

OperationPrimary Function
File DeletionRemoves filesystem reference
Quick FormatRecreates/modifies filesystem structures
Factory ResetDevice-dependent reset
Write ZeroOverwrites with zero values
Random DataOverwrites with random data
Pfitzner33-pass random-data overwrite
Gutmann35-pass historical methodology
Schneier7-pass historical methodology
PurgeSanitization intended to make recovery infeasible for the specified level of effort
DestroyPhysical destruction of media
11

Pfitzner Method For HDD Data Erasure

The Pfitzner method is primarily understood in the context of traditional magnetic storage and addressable disk wiping.

For a compatible HDD, repeated overwriting can replace the data contained in addressable sectors with newly generated values.

DSP can combine the wiping process with device identification, health assessment, error monitoring and post-process verification.

12

Professional HDD Use Cases

  • Hard-Drive Retirement
  • IT Asset Disposition
  • Enterprise HDD Wiping
  • Computer Refurbishment
  • Data-Center Decommissioning
  • Secure HDD Reuse
  • Storage Recycling
  • Corporate Equipment Disposal
13

Pfitzner For SSD And NVMe

Modern SSD and NVMe storage requires a different technical assessment.

Flash-based storage can use:

  • Flash Translation Layers
  • Wear Leveling
  • Garbage Collection
  • Spare Cells
  • Over-Provisioning
  • Remapped Physical Locations

Because the host normally interacts with a logical address space rather than directly controlling every physical flash location, repeated host-level overwriting does not necessarily guarantee coverage of every previous physical storage location.

Current NIST SP 800-88 Rev. 2 specifically recognizes this limitation for flash-based media and explains that conventional overwrite techniques may not be appropriate for sanitizing all previous data on such devices.

Therefore:

A 33-pass Pfitzner overwrite should not automatically be treated as a universal SSD or NVMe sanitization solution.

For modern flash storage organizations should evaluate device-specific sanitization capabilities and applicable Clear or Purge techniques.

14

Pfitzner And Modern Media Sanitization

Historical multi-pass algorithms were developed around storage technologies and threat models that differ substantially from today's SSD, NVMe and controller-managed flash devices.

Current media sanitization programs should consider:

15

Storage Technology + Data Sensitivity + Device Capability + Sanitization Objective + Verification + Validation

This is more appropriate than assuming that a higher number of overwrite passes automatically provides a stronger result.

For modern devices, dedicated device sanitization commands or other technology-appropriate methods may be preferable where supported and required.

16

Pfitzner vs Schneier vs Gutmann

Pfitzner is frequently grouped with other historical multi-pass wiping methodologies, but their structures are different.

FeaturePfitznerSchneierGutmann
Common Passes33735
Main Data PatternRandomFixed + randomFixed patterns + random
Random Data Throughout✓ YesNoNo
Historical Methodology✓ Yes✓ Yes✓ Yes
Current NIST StandardNoNoNo
Dedicated DSP Method✓ Yes✓ Yes✓ Yes
Audit-Ready DSP Certificate✓ Yes✓ Yes✓ Yes

The pass count alone should not be used as a universal measurement of sanitization assurance.

Modern storage architecture is an important factor in selecting the appropriate sanitization technique.

17

Pfitzner vs DoD 5220.22-M

Pfitzner and DoD 5220.22-M represent different historical approaches to data wiping.

FeaturePfitzner MethodDoD 5220.22-M
Common Implementation33 random-data passesHistorical multi-pass approach
Main TechniqueRandom overwritingPattern/complement/random overwriting
OriginPfitzner methodologyFormer U.S. DoD NISPOM policy
Current NIST StandardNoNo
Current DoD RequirementNoNo
DSP ImplementationDedicated methodDedicated method
Audit-Ready DSP Certificate✓ Yes✓ Yes

The historical DoD methodology should not be presented as interchangeable with Pfitzner merely because both are used in data-wiping software.

18

Pfitzner vs NIST SP 800-88 Rev. 2

NIST SP 800-88 Rev. 2 is the current NIST publication for media sanitization.

Pfitzner is a historical overwrite methodology.

They serve different purposes.

19

Pfitzner

A defined:

33-PASS Random-Data Overwrite Method

20

NIST SP 800-88 Rev. 2

A modern media-sanitization framework that emphasizes selecting an appropriate sanitization technique according to factors such as:

  • Information Sensitivity
  • Storage Technology
  • Device Capability
  • Sanitization Objective
  • Reuse Or Disposal
  • Verification
  • Validation

Consequently, Pfitzner can be offered as a specific sanitization method, while the broader sanitization decision should remain technology-aware.

21

Pfitzner And Bad-Sector Conditions

A complete storage sanitization process must account for device condition.

A drive may contain:

  • Logical Bad Sectors
  • Physical Media Defects
  • Read Errors
  • Write Errors
  • Remapped Sectors
  • Unstable Storage Areas

If the storage device cannot successfully write to an addressable location, the software should not simply assume that the corresponding data was overwritten.

DSP can record relevant error and device-health information as part of the sanitization workflow.

This helps distinguish:

22

Process Completed

from:

23

All Required Storage Areas Successfully Sanitized

01

Verification & Validation

02

Verification

Verification evaluates whether the selected sanitization operation completed successfully.

DSP can record:

  • Pass completion
  • Write status
  • Verification status
  • Device errors
  • Process events
  • Final result
24

Validation

Validation determines whether the completed operation satisfies the intended sanitization requirement.

This distinction is important:

A completed 33-pass process does not automatically establish that every storage architecture has been completely sanitized.

The result must be considered in relation to the device technology, condition and applicable sanitization requirements.

25

Audit-Ready Pfitzner Certificate

DSP can generate an audit-ready sanitization certificate documenting the operation actually performed.

The report can include:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type
  • Firmware

Sanitization Information

  • Selected method
  • Pfitzner Method
  • 33-pass configuration
  • Start time
  • Completion time
  • Duration
  • Sanitization result
  • Verification result

Operator & System Information

  • Operator
  • Workstation/system
  • DSP software version
  • Execution metadata

Audit Information

  • Case/reference information where configured
  • Date/time
  • Result
  • Verification information
  • Certificate identification

The certificate documents the sanitization operation performed by DSP.

It is not certification issued by Roy Pfitzner, NIST, IEEE, DoD or another external standards organization.

26

Offline Pfitzner Data Erasure

DSP can support offline sanitization workflows for environments where internet connectivity is restricted.

This can be useful for:

  • Government Organizations
  • Enterprise IT Departments
  • Secure Facilities
  • ITAD Operations
  • Data Centers
  • Air-Gapped Environments
  • Restricted Networks

The sanitization process can therefore be performed locally without requiring continuous internet connectivity.

27

Multi-Device Data Sanitization

DSP can support professional multi-device sanitization workflows according to the configured licensing and available hardware.

Typical applications include:

  • HDD Batch Wiping
  • Enterprise Storage Retirement
  • ITAD Processing
  • Refurbishment Operations
  • Data-Center Decommissioning
  • Removable-Media Sanitization
  • Corporate Asset Disposal

Each device can maintain its own sanitization and verification record.

28

When Should The Pfitzner Method Be Used?

Pfitzner can be selected when an organization specifically requires or chooses a 33-pass random-data overwrite methodology for compatible storage.

However, the method should not be selected simply because it has 33 passes.

For modern storage, especially SSD and NVMe, the more important questions are:

  • What type of storage technology is being sanitized?
  • Can the selected technique address the relevant storage locations?
  • Is the device healthy enough to complete the operation?
  • What level of sanitization is required?
  • What verification is required?
  • Does organizational policy require a specific methodology?
  • Is the device intended for reuse, transfer or disposal?

This technology-aware approach is more appropriate for professional data erasure than relying solely on pass count.

29

Why Use DSP For Pfitzner Data Erasure?

Dedicated Pfitzner Method

DSP provides a dedicated implementation of the Pfitzner methodology.

33-Pass Execution

The configured 33-pass random-data process can be executed through the DSP Sanitization Engine.

Verification

The completed operation can be verified and documented.

Device Intelligence

DSP can provide device identification and available health information.

Bad-Sector Awareness

Storage errors and bad-sector conditions can be detected and reported where supported.

Audit-Ready Reporting

Generate professional documentation of the actual sanitization operation.

Offline Operation

Suitable for restricted or air-gapped environments where offline operation is required.

Enterprise & ITAD Workflows

Designed for professional storage sanitization, IT asset disposition and enterprise media-retirement processes.

30

25 Sanitization Methods In Data Sanitization Pro

Data Sanitization Pro provides a dedicated sanitization-method library covering established, historical and technology-specific methodologies.

For the Pfitzner method, DSP provides a dedicated:

33-PASS Random-Data Sanitization Method

The selected method is executed through the DSP Sanitization Engine, followed by verification and audit-ready documentation.

Method selection should be based on the storage technology organizational policy and intended sanitization objective.

FAQ

Pfitzner 33 pass Questions

What Is The Pfitzner Method?

The Pfitzner Method is a historical data-wiping methodology commonly implemented as **33 passes of random-data overwriting**.

How Many Passes Does Pfitzner Use?

The commonly referenced Pfitzner implementation uses **33 overwrite passes**. Each pass writes random data.

Is Pfitzner A NIST Standard?

No. Pfitzner is a historical wiping methodology, not a current NIST media-sanitization standard.

Is Pfitzner A DoD Standard?

No. It should not be represented as a U.S. Department of Defense sanitization standard.

Is Pfitzner The Same As Gutmann?

No. Pfitzner is commonly implemented as 33 random-data passes, while the Gutmann methodology uses a 35-pass sequence containing defined patterns and random passes.

Is Pfitzner The Same As Schneier?

No. Schneier is commonly implemented as seven passes using fixed values followed by random-data passes, while Pfitzner uses random data across all 33 passes.

Can Pfitzner Be Used On HDDs?

It can be used as a multi-pass overwrite methodology on compatible addressable storage, subject to device condition and successful write coverage.

Can Pfitzner Be Used On SSDs?

A Pfitzner option can be available in sanitization software, but conventional host-level repeated overwriting should not automatically be considered sufficient for every SSD or NVMe device because flash architecture can prevent direct coverage of all physical storage locations.

Does 33 Passes Make Pfitzner Stronger Than A One-Pass Method?

The number of passes alone does not establish universal sanitization strength. Storage technology, device architecture, sanitization technique and the required security outcome must be considered.

Does DSP Provide A Pfitzner Certificate?

Yes. DSP can generate an audit-ready certificate documenting the Pfitzner method executed, device information, sanitization result and verification information.

Is The DSP Certificate An Official Pfitzner Certification?

No. It documents the operation performed by DSP and is not an external certification issued by Roy Pfitzner or a standards organization.

Pfitzner Method For Professional Data Sanitization

Data Sanitization Pro runs all 25 standards offline and verifies the result.