If you’ve started researching secure data erasure, you’ve probably come across two names more than any others: DoD 5220.22-M and Peter Gutmann. They represent very different points on the spectrum of erasure thoroughness — and for most businesses, one of them is overkill. Here’s what each standard actually does and how to choose.
US DoD 5220.22-M: The Government Default
The US Department of Defense 5220.22-M standard has three overwrite passes:
- Writes zeros (0x00) across every sector
- Writes ones (0xFF) across every sector
- Writes random characters across every sector
After the three passes, a final verification read confirms the last pass of random data is present and no original data pattern can be detected. The total process renders the drive’s original content unrecoverable using any known forensic method available today.
This is Kinsoft’s default standard for all e-waste erasure work, and it satisfies the requirements of most Australian industry regulations, professional standards bodies, and cyber insurance policies.
Peter Gutmann: 35 Passes of Maximum Paranoia
The Gutmann method, published by cryptographer Peter Gutmann in 1996, performs 35 overwrite passes using a carefully designed sequence of patterns. The original rationale was that different magnetic encoding schemes used by different hard drive manufacturers might require different overwrite patterns to fully destroy data. The 35-pass sequence covers all of them.
In practice, the Gutmann method is largely considered excessive for modern drives. Drive encoding has standardised significantly since 1996, and Gutmann himself has noted in updated publications that for modern drives, a few passes of random data are sufficient. The 35-pass method also takes substantially longer — on a large drive, hours rather than minutes.
Which Should Your Business Use?
For the vast majority of Australian businesses, DoD 5220.22-M is the right choice. It exceeds what’s required by the Privacy Act, satisfies most industry regulators, and is completed in a reasonable timeframe.
Peter Gutmann may be appropriate if:
- Your organisation is subject to defence or intelligence security requirements
- Your contract or policy specifically mandates it
- You’re dealing with drives that held classified government information
For SSDs, neither standard applies in the traditional sense — SSD wear levelling means overwrite tools don’t reliably cover all memory cells. For SSDs, Secure Erase (ANSI ATA), which resets all cells via the drive’s own firmware, is the appropriate method.
Other Standards Worth Knowing
Beyond DoD and Gutmann, several other standards are commonly requested:
- NIST 800-88 — the current US government recommendation; supports single-pass and three-pass variants, and explicitly addresses SSDs
- Australian ISM-6.2.93 — the Australian Signals Directorate standard; single random pass with verification
- British HMG IS5 Enhanced — equivalent to DoD 5220.22-M; used for UK government data
- Bruce Schneier — seven passes designed by security researcher Bruce Schneier; a middle ground between DoD and Gutmann
Kinsoft supports all of the above and 17 other international standards. We default to DoD 5220.22-M but can apply any standard on request. See our full e-waste service and supported standards.