Erasing a PC before you sell it: what Windows' "Clean data" claims, and why overwriting an SSD is the wrong tool
Before hardware goes to a stranger, the useful question is not whether the data is gone but how far each method's own maker is willing to go in describing it. Microsoft says its Clean data option "makes it harder for other people to recover files you've removed" - and, on the same page, that "the data erasure functionality is targeted at consumers and does not meet government and industry data erasure standards". NIST published revision 2 of SP 800-88 in September 2025; revision 1 (December 2014) was withdrawn on 26 September 2025. Revision 2 says that for media such as SSDs with overprovisioning, multi-pass overwriting "should be avoided as very little confidentiality protection is achieved". This guide separates clear, purge and destroy, explains why cryptographic erase is described as fast and high-assurance and what conditions that depends on, and gives the practical Windows route including the BitLocker prerequisite and the 15-minute black screen.
Published · Updated · FaultNote editorial policy
Who this guide is for and what to prepare
- Anyone about to sell, trade in, give away or recycle a PC and deciding how to erase it
- Anyone unsure what "Clean data" adds to "Remove everything"
- Anyone wondering whether to run multi-pass overwrite software on an SSD
- Anyone disposing of a bare SSD or HDD that has been removed from a machine
What you need
- Move the data you want to keep somewhere else first (this site's backup and migration guides cover that step)
- Check whether the drive is encrypted and, if it is, have the BitLocker recovery key in hand
- Establish which case you are in: a working PC, a bare drive, or a machine that will not start - the available methods differ
- Think about who receives it and what kind of information would actually matter if it leaked
1. What deleting and formatting do not do
NIST splits sanitization into three methods - clear, purge and destroy - and defines clear as "A method of sanitization that applies logical techniques to sanitize data in all user-addressable storage locations". Emptying the recycle bin or running a quick format does not overwrite all user-addressable locations in that sense.
On overwriting, which is the classic clear technique, NIST is positive: "Overwriting typically hinders the recovery of data even if state-of-the-art laboratory techniques are applied to attempt to retrieve the data."
But it also states where overwriting cannot be used at all: "Overwriting cannot be used on a non-rewriteable ISM or one that is damaged to the point of being inoperable and, therefore, cannot address all areas of the ISM where sensitive data may be retained." If the PC will not start or the drive is not detected, the options narrow at this point.
2. The advice to overwrite an SSD several times is not what the current standard says
This is the correction most worth making. NIST describes the history first - hard drives were often erased with multiple overwrite passes under schemes such as DoD 5220.22-M, and "The number of passes ranged from a single pass to as high as 39. The binary pattern could change for each pass, and there could be verification after some or all of the overwrite passes."
And then the current position: "For certain ISM (e.g., SSDs with overprovisioning), such practices should be avoided as very little confidentiality protection is achieved. If additional assurances are needed, a more secure sanitization method in the form of purge ... or destroy ... should be used."
The reasoning is given too: "flash memory-based storage devices that contain spare cells and perform wear levelling make it infeasible for a user to sanitize all previous data using this approach because the device cannot support directly addressing all areas in which sensitive data has been stored using the native read and write interface."
NIST even names the situation a reader may be in: "Users who have become accustomed to relying on overwrite techniques on magnetic ISM and who have continued to apply these techniques as ISM types evolved (e.g., to flash memory-based devices) can be exposing their data to increased risk of unintentional disclosure."
There is a practical cost as well: an unnecessary full-drive write consumes SSD write endurance. This site's guide to TBW and warranty covers what that means over a drive's life.
Scroll horizontally to see the full table →
| Method | What the source says it achieves | Source |
|---|---|---|
| Delete or format (recycle bin, quick format) | Not addressed as sanitization; NIST's clear method requires logical techniques across all user-addressable storage locations | NIST SP 800-88r2 |
| Overwriting an HDD (one or more passes) | A clear technique: "typically hinders the recovery of data even if state-of-the-art laboratory techniques are applied" | NIST SP 800-88r2 |
| Multi-pass overwriting on an SSD or flash | "Should be avoided as very little confidentiality protection is achieved"; wear levelling and spare cells prevent addressing all areas | NIST SP 800-88r2 |
| Windows "Remove everything" with "Clean data" | "Makes it harder for other people to recover files you've removed" - but "does not meet government and industry data erasure standards" | Microsoft: Reset your PC |
| Cryptographic erase (destroying the keys) | A purge technique: "sanitization can be performed with high assurance much faster than with other sanitization techniques", subject to the document's constraints | NIST SP 800-88r2 |
| Physical destruction | The destroy method | NIST SP 800-88r2 |
3. Why cryptographic erase is called fast and high-assurance - and what it depends on
NIST singles it out among purge techniques: "Of the logical purge sanitization techniques, cryptographic erase is noteworthy in its ability to rapidly sanitize target data." The mechanism is "the sanitization of keys used to encrypt data or to prevent access to the keys that encrypt data".
Its advantage is stated directly: "Thus, with CE, sanitization can be performed with high assurance much faster than with other sanitization techniques. The encryption itself acts to sanitize the data, subject to the constraints identified in the guidelines in this document."
Those constraints are the part that matters here. NIST writes that "the effective use of cryptographic erase depends on the pedigree of cryptographic capabilities and meeting certain pre-conditions", devotes a section to the strength of the cryptography, and requires federal agencies to use encryption modules "validated to the current FIPS-140 standard" in order "to have assurance that the conditions stated above have been verified for the self-encrypting drive (SED)".
A consumer cannot verify those conditions on an arbitrary drive. So "it was encrypted, therefore it is erased" is not an automatic conclusion - that judgement is this guide's, not NIST's. The realistic position for a machine being sold is: it was encrypted throughout, and it was reset with Clean data. Neither Microsoft nor NIST says that combination meets any standard.
4. Handing over a working PC: the Windows route
Microsoft describes the option it calls Remove everything: "this option reinstalls Windows and removes all your personal files, apps, and settings. It's ideal for a fresh start or when you are giving away or selling your PC." And within it, "Clean data: when enabled, it removes files and cleans the drive. If you're planning to donate, recycle, or sell your PC, use this option. This might take some time, but it makes it harder for other people to recover files you've removed."
The same page scopes the claim: "The data erasure functionality is targeted at consumers and does not meet government and industry data erasure standards." This guide makes no larger claim than that either.
One prerequisite comes first. Microsoft: "If your device is encrypted, make sure you have your BitLocker recovery key." This site has a troubleshooting record on locating that key.
And one warning belongs in the steps rather than the footnotes: "During the resetting process, it's possible that your screen might go black for a long period of time (occasionally upwards of 15 minutes) and that your device might attempt to restart itself. Manually attempting to restart the device yourself during this process could cause the reset to fail." That is exactly the moment people pull the plug.
The reinstall source is a choice between Cloud download and Local reinstall. Either leaves the recipient with a working, freshly installed Windows.
Scroll horizontally to see the full table →
| Step | What to do | What to confirm |
|---|---|---|
| 1 | Move the data you are keeping somewhere else | That the files actually open from the new location |
| 2 | Check for encryption and retrieve the BitLocker recovery key | Whether the key lives in a Microsoft account, on paper, or in a file |
| 3 | Settings > System > Recovery > Reset this PC | Choose "Remove everything" |
| 4 | Turn on "Clean data" | Without it, the drive is not cleaned - only the files are removed |
| 5 | Choose Cloud download or Local reinstall and start | Keep the machine on mains power and start when you have time |
| 6 | Do not restart manually while the screen is black | Microsoft warns this can last upwards of 15 minutes |
5. If you are disposing of a bare drive, or the machine will not start
A drive already removed from the PC cannot be handled with the Windows reset. What remains is the drive maker's own sanitize utility, or physical destruction.
Vendor tools and low-level commands were deliberately not researched for this version of the guide, and nothing unverified is printed as a procedure here. Nor will this guide paste a command that destroys whatever disk number you typed by mistake. If you go that route, follow the instructions published by the maker of that specific drive.
If the machine will not start or the drive is not detected, neither overwriting nor a reset is possible - in NIST's terms, overwriting "cannot be used on ... one that is damaged to the point of being inoperable". What is left is destroy: physical destruction, or a service that performs it.
Smashing a drive yourself is not recommended: it is a real injury risk, and it is not necessary when disposal services exist. For Japan specifically, this site's guide to disposing of an old PC covers who accepts the hardware.
One piece of plain advice, labelled as advice rather than a sourced claim: if the data on a drive would genuinely hurt you if it leaked, keep the drive and sell the machine without it.
6. The standard everyone cites has changed
Most guides on this topic cite NIST SP 800-88 Rev. 1 (December 2014). That revision was withdrawn on 26 September 2025. The PDF NIST now serves at the Rev. 1 address opens with a withdrawal notice: "NIST SP 800-88r1 is withdrawn and superseded in its entirety by NIST SP 800-88r2."
The current document is NIST SP 800-88r2, "Guidelines for Media Sanitization", dated September 2025. Every quotation in this guide comes from r2.
Revision 2 limits its own scope as well: "Except for cryptographic erase ..., technology-specific sanitization techniques are" outside it, and it points readers at the latest version of standards such as IEEE 2883 for media-specific techniques. In other words, whether a particular sanitize command is appropriate for a particular SSD is not settled by this document.
Limitations and requirements
- No consumer method is described here as making data unrecoverable. Microsoft states that its own feature "does not meet government and industry data erasure standards", and NIST's statements are all conditional.
- Multi-pass overwrite software is not recommended for SSDs: NIST says such practices "should be avoided as very little confidentiality protection is achieved" on media with overprovisioning, and an unnecessary full-drive write also consumes endurance.
- Low-level sanitize commands - the kind that destroy whichever disk you pointed them at - are not printed here as steps. If you use one, follow the drive maker's own instructions.
- Do not smash a drive by hand. The injury risk is real and disposal services exist.
- Retrieve the BitLocker recovery key before resetting an encrypted device; without it the process can stop part-way.
Frequently asked questions
Is "Remove everything" with "Clean data" enough?
Microsoft's claim is that it "makes it harder for other people to recover files you've removed", and the same page states that "the data erasure functionality is targeted at consumers and does not meet government and industry data erasure standards". So it is the feature built for selling and donating, but it is not presented as meeting any standard. If the machine held data whose exposure would be serious, removing the drive and keeping it is a reasonable alternative.
Should I run multi-pass overwrite software on an SSD to be safe?
NIST SP 800-88r2 says the opposite: "For certain ISM (e.g., SSDs with overprovisioning), such practices should be avoided as very little confidentiality protection is achieved." The reason is that spare cells and wear levelling make it infeasible for a user to address every area through the normal read/write interface. Where more assurance is needed, NIST directs readers to purge or destroy instead.
The drive was encrypted. Is that enough on its own?
Not automatically. NIST treats destroying the keys - cryptographic erase - as a purge technique and says sanitization can then be "performed with high assurance much faster than with other sanitization techniques". But it also says "the effective use of cryptographic erase depends on the pedigree of cryptographic capabilities and meeting certain pre-conditions", including the strength of the algorithm and its key management. A consumer cannot verify those conditions on a given drive. For a machine you are handing over, the practical answer is: it was encrypted throughout, and you also ran the reset with Clean data.
The screen has been black for ages during the reset. Has it failed?
Probably not - and this is the documented behaviour. Microsoft writes: "During the resetting process, it's possible that your screen might go black for a long period of time (occasionally upwards of 15 minutes) and that your device might attempt to restart itself. Manually attempting to restart the device yourself during this process could cause the reset to fail." Leave it on mains power and wait.
Can I trust a tool that advertises "NIST 800-88 compliant" erasure?
Check which revision it means. NIST SP 800-88 Rev. 1 (December 2014) was withdrawn on 26 September 2025 and superseded in its entirety by NIST SP 800-88r2 (September 2025). Revision 2 also places technology-specific techniques, apart from cryptographic erase, outside its own scope and points to standards such as IEEE 2883 for media-specific methods. The phrase "800-88 compliant" on its own does not say which technique was applied to which kind of media.
Sources and verification date
Sources checked: . These sources support the specifications, procedures or prices discussed here. Check each source for applicable conditions and current information.
- NIST SP 800-88r2: Guidelines for Media Sanitization (September 2025; clear/purge/destroy, overwriting and flash media, cryptographic erase. PDF retrieved 2026-09-20) ↗
- NIST: withdrawal notice for SP 800-88r1 (December 2014), withdrawn 26 September 2025 and superseded in its entirety by r2. PDF retrieved 2026-09-20 ↗
- Microsoft: Reset your PC (Remove everything, Clean data, the standards note, the BitLocker prerequisite and the 15-minute black screen. Observed 2026-09-20) ↗
Related practical guides
- Disposing of an old PC in Japan: the PC Recycle Mark, maker take-back, the small appliance route, and self-built machines
- PCIe 4.0 or 5.0 SSD for gaming? Check load times, capacity and slot sharing
- CMR vs. SMR Hard Drives: Tell Them Apart by Model Number for NAS, RAID and Backup
- SSD Endurance (TBW) and Warranty: Compare Write Limits of Popular NVMe SSDs by Capacity and Check Wear in Windows
- TLC vs QLC and DRAM vs DRAM-less (HMB): reading post-SLC-cache write speed off the datasheet
- M.2 SSD heatsinks: clearance, warranty terms and the PS5 requirement decide bundled or bare