A retired drive isn't automatically safe just because it's been "wiped". NIST SP 800-88 defines three distinct sanitisation tiers — Clear, Purge, and Destroy — and the standard is explicit that organisations should use Purge instead of Clear wherever possible, because it defends against state-of-the-art laboratory recovery rather than just casual undeletion. For UK buyers deciding whether retired laptops, server drives or SSDs can be reused, resold, or must go to certified disposal, the choice of tier — and whether it actually fits the media type — is the detail that separates genuine data safety from a wipe certificate that doesn't hold up.
View the data behind this chart
| Protects Against | Media Reusable… | Typical Fit | |
|---|---|---|---|
| Clear | Simple non-invasive… | Yes | Modern HDDs, low-risk… |
| Purge | State-of-the-art lab… | Yes | SSDs, media leaving… |
| Destroy | State-of-the-art lab… | No | Hard copy, most system… |
Why the Clear/Purge/Destroy Decision Matters for UK IT Teams in 2026
Every laptop refresh, server decommission, or storage-array retirement produces media that still holds business data long after the hardware itself has stopped being useful. NIST SP 800-88 is the reference framework most disposal partners and IT buyers work to when deciding what happens next — not because it's a UK-specific rule, but because it is the practical benchmark for evidence of sanitisation that stands up to scrutiny.
The real risk sits in the gap between the three tiers. A drive can genuinely be "sanitised" in the loose sense of the word without meeting the assurance level a buyer actually needs — and that gap is widest for flash storage. Getting this wrong doesn't just create a security exposure; it also affects whether retired assets can legitimately be reused or resold, or whether they have to be scrapped outright.

NIST SP 800-88's Three-Tier Hierarchy, Precisely Defined
NIST SP 800-88 sets out three sanitisation categories, each with a different protection scope and a different outcome for the media itself.
Clear uses logical techniques — typically the same read/write interface available to the user — to sanitise all user-addressable storage locations. It protects against simple, non-invasive recovery techniques: the kind of casual undelete or file-recovery attempt anyone could run.
Purge goes further, applying physical or logical techniques that render the target data infeasible to recover even using state-of-the-art laboratory techniques. NIST's own guidance says Purge should be used instead of Clear wherever possible, precisely because it closes the gap that simple overwriting leaves open.
Destroy sits above both: it renders recovery infeasible against laboratory-grade techniques and leaves the media physically unable to store data afterward. NIST states Destroy is appropriate for all hard copy and most information system media, with the exception of logical or virtual storage. Crucially, a device can be reused after Clear or Purge — but Destroy ends the medium's storage life entirely.
- •Clear — logical wipe via standard interface; defeats simple, non-invasive recovery; media reusable
- •Purge — physical or logical technique; defeats state-of-the-art laboratory recovery; media reusable
- •Destroy — media rendered unable to store data afterward; no reuse; appropriate for hard copy and most system media
The HDD/SSD Split: Why Flash Storage Breaks the Old Playbook
Vendor guidance summarising NIST 800-88 describes a single overwrite pass as sufficient for Clear-level sanitisation on modern hard disk drives — magnetic media generally responds predictably to overwrite-based logical techniques.
That logic does not transfer cleanly to solid-state drives. Because flash storage uses wear-levelling and over-provisioning, a straightforward overwrite command doesn't reliably touch every physical cell that once held data, which is exactly why simple overwrite is described as not always sufficient on modern SSDs. This is the specific reason Purge exists as a distinct tier rather than a stricter version of Clear.
For SSDs, purge-grade sanitisation typically relies on a verified cryptographic erase or a firmware/controller sanitize command rather than repeated overwriting. This is the single detail that decides whether a retired SSD is genuinely safe to resell or redeploy, or merely appears wiped.
Choosing the Right Method: Matching Media, Risk and End-of-Life Path
NIST-aligned guidance ties the sanitisation decision directly to what happens to the asset next — reuse, resale, or disposal — rather than treating "wipe" as a single generic action.
As a working rule: devices staying inside organisational control for low-risk internal redeployment may be adequately covered by Clear, depending on the media and data sensitivity. Devices leaving organisational control — through resale, donation, or third-party disposal — should default to Purge as the recommended minimum where the media won't be physically destroyed. Where there is no viable reuse path, or the media type can't support a trustworthy purge (some hard-copy and legacy system media), Destroy is the appropriate route, accepting that it removes any resale value.
This is where storage end-of-life considerations and server end-of-life planning intersect with security: the method chosen should be decided at the point an asset is retired, not left to whoever happens to be handling the box.
Verification, Evidence and Chain of Custody
A sanitisation tier is only as trustworthy as the evidence behind it. Because a device can be "cleared" without meeting the laboratory-grade bar that Purge requires, buyers should insist on documentation that names the specific method used and confirms it matches the media type — not a generic "data wiped" statement.
Remember that Purge's protection scope — resistance to state-of-the-art laboratory recovery — is a fundamentally different bar from resistance to ordinary consumer file-recovery or undelete tools. Evidence of destruction should reflect which of these two bars was actually cleared, since conflating them is the most common way an organisation ends up with a false sense of security about a retired fleet.
In practice, this evidence takes the form of documented sanitisation controls and certificates from disposal partners, confirming which tier and method were applied — and to which asset — before it is reused, resold, or scrapped. This matters most for laptops, endpoints, and server SSDs leaving organisational control, where a certificate stating "wiped" is not the same as one confirming a verified cryptographic erase or sanitize command was run and matched to the media type.
In-House Wiping vs Outsourced Destruction: The Practical Trade-offs
Running sanitisation in-house means having the right tool for the right media: overwrite-capable tools for HDD Clear, and crypto-erase or firmware sanitize tooling for SSD Purge — plus the process discipline to record exactly which method was applied to which serial number.
For mixed fleets, especially during large refresh cycles or data centre decommissioning services, outsourcing to a specialist removes the judgment call of matching method to media type from busy internal teams, and centralises the evidence trail in one place.
Whichever route is chosen, the decision belongs at the point of retirement — tied explicitly to whether the asset is destined for reuse, resale, or disposal — and should follow the same logic as broader how to dispose of old IT equipment planning, not be treated as an afterthought once the hardware is already off the rack.
Environmental Trade-offs: Reuse, Resale and E-Waste
Destroy ends the medium's storage life outright — the device can no longer store data, which also means it can no longer be resold or redeployed. Clear and Purge, by contrast, both preserve the option to reuse the hardware.
This is precisely why NIST recommends defaulting to Purge over Clear wherever feasible: it gets close to Destroy-level assurance against laboratory recovery without permanently ending the asset's useful life, giving organisations the best available balance between data risk and unnecessary e-waste.
Destroy still has a legitimate place — NIST treats it as appropriate for all hard copy and most information system media where no credible reuse path exists — but it should be a deliberate choice for media that genuinely can't be trusted at a lower tier, not a default reached for convenience.
Sources
Every figure in this article traces to the sources below.
- •NIST SP 800-88r1 — Clear, Purge, Destroy definitions and protection scope
- •NIST SP 800-88r1 (publication record) — Purge-over-Clear recommendation and Destroy scope
- •IT Asset Management — reuse implications of Clear/Purge vs Destroy; SSD overwrite limitations
- •DriveWipe — single overwrite pass sufficiency for modern HDD Clear
- •SKTES — sanitisation choice tied to reuse, resale, or disposal path
- •InventiveHQ — Purge as recommended minimum when media leaves organisational control
View the data behind this chart
| Layer | Detail |
|---|---|
| Clear | Defeats simple, non-invasive recovery attempts |
| Purge | Defeats state-of-the-art laboratory recovery |
| Destroy | Media unable to store data; no reuse possible |
