For decades, IT asset decommissioning followed a reliable logic.

  1. Overwrite the drive
  2. Document it
  3. Retire it

For spinning hard drives, like a HDD, this was good enough because these data-bearing hard drives were technically physically rewritten, meaning, the data appears gone.

But that logic no longer applies to modern enterprise storage. Applying the old playbook is one of the most quietly dangerous compliance failures in corporate IT today.

Why Overwrites Don’t Work for Flash Storages

NVMe drives and solid-state arrays (SSDs) fundamentally change how data is written, managed and most importantly, how it can be destroyed.

Unlike HDDS, these NAND flash memory cannot overwrite data in place. When new data is written to a cell that already contains data, the drive’s controller must first find an already-erased, vacant page to write the new data, marking the old data as invalid until the entire block can be erased later during physical destruction, like secure shredding.

Let’s simplify this.

Imagine the SSD as a giant notebook, but it has a very strange set of rules.

  • You are allowed to write on the pages with a pencil.
  • You are not allowed to use an eraser on a single page.
  • The only way to erase anything is to use a giant machine that shreds and cleans an entire chapter (a block) all at once.

So, what’s the consequence of issuing an overwrite command to an SSD?

Your tool essentially writes new data to new cells and the original data may remain in other physical cells across the drive. That means they are still physically present and potentially recoverable.

There’s also the matter of over-provisioned capacity.

Enterprise SSDs typically reserve 7-28% of their raw NAND as over-provisioned space, used by the controller for wear-levelling, bad block management and write buffering. This space is invisible to the host Operating System and inaccessible to standard overwrite utilities. While sensitive data may temporarily sit in this pool as it awaits data destruction, it cannot be targeted by basic software-based wiping attempts, meaning a hardware-level NVMe Format or Crypto-Erase is required to guarantee complete sanitisation. 

Multi-pass overwrite standards like DoD 5220.22-M were designed in a different era, although it is still currently used in data wiping practices today. However, the National Institute of Standards and Technology (NIST), the current authoritative standard for media sanitisation, does not recommend multi-pass overwrite for SSDs or NVMe devices. Instead it classifies acceptable sanitisation methods as: Clear, Purge, or Destroy.

The Different Classes of Risk between Self-Encrypting Drives and Cloud-Attached Storage

Let’s get technical on the compounded challenges of encrypted storage environments.

Self-Encrypting Drives

Enterprise SSDs are commonly Self-Encrypting Drives (SEDs) that encrypt all data at rest using an internal Advanced Encryption Standard (AES) key. 

Think of an enterprise SSD as a high-security hotel.

Inside this hotel, every single piece of data is locked inside a room. When a company wants to throw away the drive, instead of spending hours clearing out every single room, they use a shortcut called Cryptographic Erase. This means they just destroy the master key to the hotel. Since nobody can get into the rooms anymore, the company assumes the data is safe.

The standard decommissioning assumption is that Cryptographic Erase, which is essentially destroying the encryption key, would render the data unrecoverable. This is perfect in theory but in real life, organisations usually mess up the execution and that’s a serious data security problem.

Cryptographic Erase depends entirely on the integrity and auditability of the key lifecycle.

Here are 3 reasons why this is a high-risk issue for a company’s data security:

  1. There are key management failures because spare keys are often still floating around. The master key on the drive may be erased, but the spare copy that is back up in their cloud or digital filing cabinet means the data isn’t actually gone. Anyone who still has or finds that spare key can unlock the “hotel”.
  2. Companies often lack auditing or have poor paperwork in place. If a company doesn’t keep a strict, legally binding report or certificate that proves exactly when and how the key was destroyed, they can’t actually prove to regulators that that the data is safe.
  3. Firmware flaws that built fake locks. Sometimes, a drive will tell the computer that everything is locked, but behind the scenes, the master key is actually stored insecurely on the drive itself and the password to unlock the drive is just defaulted to “blank”.

Cloud-attached and Virtualised Data Storage

Imagine you rent a single room in a massive apartment building (that’s the Cloud).

You don’t own the building, you don’t manage the maintenance staff, and you share the pipes, walls, and foundation with thousands of other renters. If you want to move out and make sure nobody can ever find your personal paperwork, you can’t just burn the apartment down. It isn’t yours, and other people live there. That’s the distinct data privacy and security challenge in a cloud or virtual storage.

Standard overwrite approaches are meaningless here because you cannot meaningfully overwrite storage you do not physically manage. Secure data destruction in this context requires documented evidence of physical media disposal from the cloud provider, combined with cryptographic erasure of all accessible data before decommissioning.

However, expecting a cloud provider to hand you a physical destruction receipt for your specific instance’s hardware is unrealistic. Cryptographic erasure under your own key management is your primary and most reliable boundary of defense. 

What Secure Data Destruction actually Requires at Scale

Purging Data-Bearing Devices

For enterprise NVMe and SSD arrays, the minimum standard for sensitive or regulated data is Purge. That means a secure erasure and sanitisation command is issued through the drive’s native firmware to trigger a block-erase cycle across the entire NAND array, including the over-provisioned space.

Physical Destruction

For data classified at higher sensitivity levels or where the hardware will leave your direct control, secure data removal through physical destruction is the appropriate endpoint. That means degaussing, shredding to a verified particle size or disintegration in a controlled, certified process. 

The particle size matters because industry standards referenced by NIST and adopted under e-Stewards and R2v3 certification typically require shredding to 2mm for high-security media destruction. 

Chain of Custody

Without independent verification, none of the above are defensible compliance positions. What makes secure data destruction more than a checkbox is in its chain of custody documentation. Your individual IT assets should undergo documentation and be audited with accountability from the moment it leaves your server room to confirmed destruction.

The Governance Gap of Traditional Processes

Most decommissioning failures are procedural.

  • The drive left your premises on a transfer without a proper hand off log.
  • A batch was staged for collection but assets were not individually logged before leaving the building.
  • A retired server was sold through a secondary channel without confirming whether the drives had been sanitised.

This risk category is a common occurrence in traditional, in-house decommissioning processes because of a breakdown in one or more of these technical steps. 

Certified IT Asset Disposition Partners

To circumnavigate the risks, a credible ITAD partner can integrate your decommissioning workflow from end-to-end and rack-to-rack. Starting at the point of collection, maintaining chain of custody documentation through verified secure data destruction and/or certified data wiping, until finally delivering reports that closes the audit loop.

For drives that fail sanitisation verification due to damages, errors, or when the over-provisioned space cannot be confirmed “cleared”, the default response must be an immediate escalation to physical destruction.

Each asset should also include certificates of destruction that maps directly to your asset register. That way, when your compliance team is answering an auditor about data privacy or data security controls, a serial-number-level certificate of destruction would clearly link the execution to a verifiable chain of custody.

That is the difference between a decommissioning process and a secure data destruction programme.

For organisations subject to data privacy frameworks, i.e. GDPR, financial sector regulations, healthcare data requirements, the burden of proof is on the data controller. That accountability falls on the organisation. Certification to standards such as R2v3 provides independent evidence that a partner’s data destruction processes have been externally audited and verified, including their downstream handling of materials.

Navigating the Complexities of IT Asset Decommissioning

As enterprise storage environments grow more complex, the gap between traditional decommissioning assumptions and actual data security risk widens. The catastrophic consequences of that gap are regulatory and reputational, especially  in sectors handling sensitive data.

SPW Circular Services is an R2v3-certified ITAD provider operating across APAC, ANZ, and MENA. We have recently been awarded the EcoVadis Platinum sustainability rating (top 1% globally). Our data destruction processes are aligned to NIST SP 800-88 and backed by asset-level certificates of destruction and full chain of custody documentation.

We’re happy to discuss your decommissioning requirements, click here to schedule a call with us today.

We Have Your Back

Our secure IT asset disposal services provides the dependable solution you need for your e-waste and end-of-life asset needs. Our team applies safe and sustainable steps that are regulatory-compliant at every stage of the process.

From the point of collection, auditing, shredding and/or wiping to remarketing and/or donating your IT assets, you can be sure with our end-to-end services that we take your security seriously.

We have coverage against the loss of or damage to your goods during transportation. This includes marine cargo shipment from the ports to the warehouses

Our professional team of asset removers ensure your devices are packed safely into our vehicles which are also equipped with GPS-tracking systems. We have armed our warehouses with fingerprint-only access complete with security alarms and 24/7 CCTVs in place

Our reach spans across the globe through our networks of partners and vendors. Wherever your business is based, you can leverage our worldwide network and we would be happy to assist you throughout your ITAD journey