Pass 3 — Zero Pattern
The zero pattern is written again.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
Canadian RCMP TSSIT OPS-II Data Erasure Method

RCMP TSSIT OPS-II is a historical Canadian media sanitization and secure data erasure methodology associated with the Royal Canadian Mounted Police (RCMP). It is widely recognized in data wiping software as a structured multi-pass overwrite profile designed primarily for magnetic storage media.
The method is commonly represented as a seven-pass overwrite sequence, using alternating binary patterns followed by a final random-data pass and verification.
For organizations that specifically require the historical RCMP TSSIT OPS-II methodology, Data Sanitization Pro (DSP) provides a dedicated RCMP TSSIT OPS-II Sanitization Method through the DSP Sanitization Engine, with execution monitoring, verification and audit-ready documentation.
Important: RCMP TSSIT OPS-II should not be represented as the current Government of Canada media-sanitization standard. Canada's current federal IT-media sanitization guidance is issued through the Communications Security Establishment (CSE), including ITSP.40.006 v2 – IT Media Sanitization.
RCMP TSSIT OPS-II is a historical Canadian secure data wiping profile designed around repeated overwriting of addressable storage locations.
The commonly implemented sequence is:
| Pass | Data Pattern |
|---|---|
| Pass 1 | 0x00 |
| Pass 2 | 0xFF |
| Pass 3 | 0x00 |
| Pass 4 | 0xFF |
| Pass 5 | 0x00 |
| Pass 6 | 0xFF |
| Pass 7 | Random data |
| Verification | Verify the completed sanitization |
The exact implementation of historical RCMP TSSIT OPS-II profiles can vary between software products. DSP should therefore document the actual method configuration executed, rather than treating the name alone as proof of a particular implementation.
The seven-pass profile is primarily associated with conventional magnetic storage and historical secure overwriting practices.
RCMP TSSIT OPS-II belongs to an earlier generation of software-based media sanitization methods that relied heavily on repeated overwriting.
Its fundamental concept is straightforward:
The method was designed around the principle that repeated alteration of the storage surface would reduce the ability to reconstruct previously stored information.
Today, storage technology has evolved substantially. Modern SSDs, NVMe drives and flash media use controllers, wear leveling, spare areas and other mechanisms that can make conventional multi-pass overwriting unsuitable as a universal sanitization strategy.
Consequently, the RCMP TSSIT OPS-II method should be selected based on the storage technologyorganizational policy, sensitivity of information and intended disposition of the media.
DSP includes a dedicated RCMP TSSIT OPS-II Sanitization Method within the DSP Sanitization Engine.
SELECT RCMP TSSIT OPS-II ↓ IDENTIFY STORAGE DEVICE ↓ ASSESS MEDIA TYPE & HEALTH ↓ EXECUTE 7-PASS SANITIZATION ↓ MONITOR WRITE PROCESS ↓ VERIFY RESULT ↓ DOCUMENT OPERATION ↓ GENERATE AUDIT-READY CERTIFICATE
The selected method is executed as a defined DSP sanitization operation rather than simply providing a generic overwrite function.
The target addressable storage area is overwritten with a zero-value pattern:
The storage area is overwritten with:
The zero pattern is written again.
The 0xFF pattern is written again.
The zero pattern is repeated.
The 0xFF pattern is repeated.
The final overwrite uses random data.
The completed operation is checked according to the configured verification procedure.
This structure is the commonly documented RCMP TSSIT OPS-II seven-pass profile. Commercial software implementations may differ in their exact treatment of patterns and verification, so the DSP certificate should identify the actual operation performed.
RCMP TSSIT OPS-II is most naturally associated with traditional magnetic hard disk drives.
DSP can use the method for applicable HDD sanitization workflows while simultaneously recording device information such as:
This creates a detailed operational record around the historical wiping methodology.
A seven-pass overwrite profile should not automatically be treated as equivalent to complete physical sanitization of modern flash storage.
SSDs and NVMe devices can contain:
A conventional host-level overwrite may therefore not provide equivalent coverage of every physical flash location.
For this reason, RCMP TSSIT OPS-II should be treated as a method-specific historical overwrite profile, not a universal sanitization technique for every modern storage architecture.
For modern SSD/NVMe sanitization, the applicable device capabilities and organizational requirements should be assessed before selecting the sanitization technique.
Current Canadian federal guidance recognizes multiple sanitization approaches, including overwriting, Secure Erase (SE), Cryptographic Erase (CE)anddestruction, depending on media type and sensitivity.
Successful completion of a wiping operation does not automatically mean that every physical storage location was successfully sanitized.
DSP can assess storage conditions before and during sanitization, including:
If portions of a device cannot be reliably addressed or verified, the sanitization result should be evaluated against the organization's media-disposition requirements.
This is particularly important for damaged HDDs, SSDs and flash storage where unsuccessful sanitization may require a stronger disposal or destruction procedure.
Verification is a critical part of a professional data erasure workflow.
DSP records the result of the sanitization operation and can identify:
The purpose is to distinguish between:
and
Canadian federal IT-media guidance emphasizes verification of sanitization results and recognizes that media which cannot be satisfactorily sanitized or verified may require additional handling or destruction depending on sensitivity.
RCMP TSSIT OPS-II should be understood as a historical Canadian overwrite methodology.
The current Government of Canada IT-media sanitization framework is ITSP.40.006 v2, issued under the authority of the Chief of the Communications Security Establishment. It provides a broader risk-based approach to media sanitization rather than prescribing one universal seven-pass overwrite method.
Current Canadian guidance recognizes:
It also recognizes that modern media can be more difficult to reliably sanitize and that encryption can facilitate lifecycle sanitization.
| Area | RCMP TSSIT OPS-II | ITSP.40.006 V2 |
|---|---|---|
| Origin | Historical Canadian RCMP methodology | Current CSE guidance |
| Approach | Defined overwrite profile | Risk- and media-based sanitization |
| Typical Historical Profile | 7-pass overwrite | Multiple applicable techniques |
| HDD | Primarily applicable | Applicable with media-specific assessment |
| SSD/NVMe | Conventional overwrite limitations | Device-appropriate methods |
| Secure Erase | Not the core method | Supported where applicable |
| Cryptographic Erase | Not the core method | Supported |
| Destruction | Separate consideration | Included where sanitization is insufficient |
| Verification | Method verification | Verification is part of sanitization |
| Modern Applicability | Historical/method-specific | Current Canadian federal guidance |
RCMP TSSIT OPS-II and DoD 5220.22-M are often grouped together because both are historical multi-pass overwrite methodologies.
However, their historical pattern sequences are different.
| Method | Commonly Represented Profile |
|---|---|
| RCMP TSSIT OPS-II | 00 → FF → 00 → FF → 00 → FF → Random |
| DoD 5220.22-M | Historical multi-pass DoD overwrite profile |
| HMG IS5 Enhanced | Historical UK multi-pass profile |
| Gutmann | Historical 35-pass methodology |
| Schneier | Historical 7-pass methodology |
The number of passes alone should not be used as a universal measure of sanitization strength. Media architecture, addressability, sanitization technique, verification and disposition requirements are also relevant.
Historical overwrite methods continue to appear in:
For organizations whose internal procedure specifically calls for RCMP TSSIT OPS-II, DSP can provide a dedicated method, execution tracking and audit-ready documentation.
For modern media organizations should select the appropriate sanitization technique based on their current security policy and media architecture.
DSP can support controlled offline sanitization environments where devices must be processed without Internet connectivity.
This is useful for environments such as:
The sanitization operation can be performed locally while maintaining method, device and verification records.
For professional ITAD and enterprise environments, DSP can process multiple supported storage devices while maintaining individual device-level records.
Each device can retain its own:
This makes the RCMP TSSIT OPS-II workflow suitable for controlled batch-processing environments where individual device traceability is required.
After the sanitization operation, DSP can generate an audit-ready sanitization certificate documenting the actual operation performed by the software.
Certificate information can include:
The certificate is evidence of the sanitization operation performed by DSP. It is not an RCMP-issued certificate, Government of Canada certificationorendorsement by the RCMP.
DSP's implementation provides a controlled workflow around the historical methodology:
IDENTIFY Identify the target storage device.
CLASSIFY Determine media type and relevant device characteristics.
ASSESS Evaluate health, accessibility, errors and addressable storage.
SELECT Select RCMP TSSIT OPS-II.
EXECUTE Run the configured seven-pass sanitization process.
VERIFY Check the operation and recorded results.
VALIDATE Determine whether the result satisfies the applicable organizational requirement.
DOCUMENT Record device, method, operator and verification information.
CERTIFY Generate an audit-ready sanitization certificate documenting the operation.
A dedicated method is useful when an organization's procedure, contract or legacy asset-disposal workflow specifically identifies RCMP TSSIT OPS-II.
DSP provides:
The method can therefore be selected as a documented sanitization profile rather than relying on an unspecified generic disk wipe.
The historical seven-pass approach remains relevant where a documented legacy method must be reproduced.
However, modern storage sanitization requires technology awareness.
For:
HDD Traditional overwrite techniques can be applicable when the entire addressable area can be reliably written and verified.
SSD / NVMe Device-specific sanitization capabilities, Secure Erase, Cryptographic Erase or other approved techniques may be more appropriate depending on the device and security requirement.
Flash / USB / Memory Media Controller behavior, spare cells and wear leveling must be considered.
Damaged Media If complete sanitization and verification cannot be achieved, the appropriate organizational disposal policy may require controlled destruction.
This media-specific approach is consistent with current Canadian federal guidance, which distinguishes sanitization techniques according to media type and sensitivity.
RCMP TSSIT OPS-II represents an important historical Canadian approach to secure data wiping.
DSP preserves that methodology as a dedicated, documented sanitization method for organizations that specifically require it, while providing modern operational capabilities around device identification, monitoring, verification and reporting.
RCMP TSSIT OPS-II Seven-Pass Canadian Data Erasure Method Executed through the DSP Sanitization Engine Verified and Documented with an Audit-Ready Sanitization Certificate
No. It should be treated as a historical RCMP overwrite methodology. Current Government of Canada IT-media sanitization guidance is provided through CSE's **ITSP.40.006 v2 – IT Media Sanitization**.
The commonly documented profile uses **seven passes**: alternating 0x00 and 0xFF patterns for the first six passes, followed by random data on the seventh pass and verification.
A conventional multi-pass overwrite should not automatically be treated as complete sanitization of SSD or NVMe physical storage because flash devices use controller-managed architectures such as wear leveling and spare areas.
DSP can generate an audit-ready certificate documenting the RCMP TSSIT OPS-II operation actually performed by DSP. This is **not an RCMP or Government of Canada-issued certificate**.
No. Both are historical multi-pass wiping methodologies, but their documented overwrite profiles differ.
Yes, where the organization's documented sanitization procedure specifically requires the historical method and the target media is appropriate for the technique.
The result should be assessed against the applicable security and disposition policy. Current Canadian guidance recognizes that media that cannot be adequately sanitized or verified may require destruction or additional controls depending on information sensitivity.
Data Sanitization Pro runs all 25 standards offline and verifies the result.