Certified Data Erasure

UK DWP SS-036 v1.2

SS-036 Secure Sanitisation Software

Aligned with the UK DWP "Secure Sanitisation and Destruction" standard: Clear · Purge · Destroy classification and every certificate field Appendix C requires — method, tool version, verification — recorded automatically.

✓ Clear · Purge · Destroy ✓ NIST 800-88 based ✓ Appendix C certificate fields ✓ Cryptographic Erase ✓ SHA-256 integrity

The Problem

Three places organisations fail an SS-036 audit

SS-036 is mandatory for organisations and suppliers handling DWP data, yet failures cluster around records and verification rather than the wipe itself. The three gaps below are the findings that come back most often in audits and supplier approvals.

Missing Certificate Fields

SS-036 Appendix C mandates the sanitisation type, method used, tool version, verification method, and operator signature on the certificate. A "we wiped it" statement or a PDF with missing fields is rejected in audit.

Wrong Level on SSDs

SS-036 requires a minimum of "Purge" for SSD and flash memory and does not approve their external re-use. A single-pass software wipe only reaches "Clear" on an SSD — the standard is not met.

Broken Chain of Custody

The standard requires devices held in a controlled environment until sanitisation, a recorded chain of custody, and Risk Owner sign-off. Without timestamps, operator identity, and immutable records, that chain cannot be evidenced.

SS-036 Levels

Clear, Purge, Destroy — the NIST framework SS-036 adopts

SS-036 adopts NIST SP 800-88 Rev. 1's three-level sanitisation framework directly. The correct level is chosen by risk assessment based on device type and data classification.

CLEAR
Against Logical Recovery
Software/hardware overwrite — only for media staying within the Authority

All addressable storage is overwritten with non-sensitive data. Under SS-036, Clear is suitable only for media remaining within the Authority; it is not sufficient for devices leaving the organisation.

PURGE
Against Laboratory Recovery
Cryptographic erase or degauss — minimum for SSD/flash

Encryption applied before deletion (cryptographic erasure) or lab techniques such as degaussing render recovery infeasible. SS-036 mandates a minimum of Purge for SSD and flash memory. PIWIPE achieves this via NVMe Sanitize or Cryptographic Erase (CE).

DESTROY
Physical Destruction
≤6mm particles; optical media must be destroyed

Media is reduced to particles of 6mm or less, with particle size verified after destruction. Optical media cannot be sanitised and must always be destroyed. PIWIPE does not perform physical destruction in software; it sanitises and certifies data before Destroy to establish the evidentiary chain.

Method by Media Type

SS-036 media-specific requirements

SS-036 sets a different minimum method per device type. Rows PIWIPE covers in software (✓); rows requiring process/hardware (◐).

  • Hard Disk Drives (ATA/SCSI) — Apply NIST 800-88; risk assessment sets the Clear/Purge/Destroy level.
  • SSD / Flash Memory — Minimum "Purge"; not approved for external re-use. PIWIPE: NVMe Sanitize / CE.
  • USB / Memory Cards — At least two-pass overwrite (pattern and complement).
  • Mobile Devices — Full manufacturer reset + complete sanitisation; via MDM where possible. PIWIPE: on-device CE.
  • Optical Media (CD/DVD/BD) — Cannot be sanitised; must be destroyed (~0.5mm edge).
  • Cloud Storage — Cryptographic erasure or approved method; comply with SS-023.
  • Magnetic Tape / DRAM / EEPROM — Re-record or destroy tape; DRAM power-starve ≥24h; EEPROM must be destroyed.

Appendix C

SS-036 certificate fields — PIWIPE fills them automatically

SS-036 Appendix C lists the exact fields a valid sanitisation certificate must contain. PIWIPE generates these automatically for every wipe and adds an "Aligned with DWP SS-036" statement to the certificate.

Device Identity

Manufacturer, model, serial number, and capacity — verified via S.M.A.R.T. read.

Sanitisation Type

Clear / Purge / Destroy classification; the "Sanitisation Method (SS-036)" line on the certificate.

Method Used

Overwrite, block erase, NVMe Sanitize, or cryptographic erasure — whichever ran.

Tool + Version

"Sanitisation Tool: PIWIPE vX.Y.Z" — Appendix C explicitly requires the tool version.

Verification Method

Random-sample or full-sector verification result recorded on the certificate.

Operator + Time + Hash

Personnel identity, date/time, machine name, and SHA-256 integrity hash.

Compliance Checklist

SS-036 implementation checklist

A checklist based on SS-036 §11.1–§11.6. Items PIWIPE fulfils directly in software (✓); items requiring organisational process/supplier (◐).

  • Method by Device Type — PIWIPE auto-selects the SS-036/NIST minimum level per media type.
  • SSD Minimum Purge — Purge level guaranteed via NVMe Sanitize / CE.
  • Certificate (Appendix C) — All mandatory fields + tool version + verification, automatic.
  • Verification + Integrity — Verification result and SHA-256 hash on every certificate.
  • Record Retention + Export — Cloud console keeps indefinitely; CSV export and write to your own FTP/SFTP.
  • Chain of Custody + Sign-off — PIWIPE provides timestamp/operator records; Risk Owner sign-off is organisational.
  • Approved ITAD Supplier — Off-site destruction requires an NCSC CAS-S accredited supplier.
  • Personnel Vetting — Operators must be vetted per the Authority Security Vetting Policy.

Frequently Asked

SS-036 & Secure Sanitisation

What is SS-036?
SS-036 is the "Secure Sanitisation and Destruction" security standard published by the UK Department for Work and Pensions (DWP) Chief Security Office (v1.2, 26 June 2025). It defines the sanitisation methods, certificate, and record requirements that any organisation or supplier handling DWP data must apply when disposing of devices and media. It adopts the NIST 800-88 Clear/Purge/Destroy framework.
Which fields does SS-036 require on a certificate?
SS-036 Appendix C requires every sanitisation certificate to record: hardware manufacturer, model, serial number; sanitisation type (Clear/Purge/Destroy); method used (overwrite, block erase, cryptographic erasure, degauss, etc.); tool employed (including version); verification method; personnel name, role, date/time, location, signature, and contact information. PIWIPE certificates populate these fields automatically — including the "Sanitisation Method (SS-036)" and "Sanitisation Tool (PIWIPE vX.Y.Z)" lines.
What level does SS-036 require for SSDs?
SS-036 mandates a minimum NIST 800-88 "Purge" level for SSDs and flash memory, and states this media is "not approved for re-use external to the Authority." PIWIPE achieves Purge on SSD/NVMe via cryptographic erase (CE) or NVMe Sanitize and records the result on the certificate.
Is PIWIPE SS-036 compliant?
SS-036 compliance is organisational: it covers CAS-S accredited ITAD suppliers, personnel vetting, and chain-of-custody processes as well as approved sanitisation methods. PIWIPE covers the software portion of the standard — providing SS-036-aligned Clear/Purge classification and the Appendix C certificate fields. In other words, PIWIPE helps your organisation meet SS-036 requirements; the certificate itself carries the "Aligned with DWP SS-036" statement.
How does SS-036 relate to NIST 800-88?
SS-036 adopts NIST SP 800-88 Rev. 1 as its primary external reference standard and uses the Clear/Purge/Destroy three-level framework directly. It adds UK-specific requirements such as the NCSC CAS-S scheme, ISO/IEC 27001, and the HMG Security Classification Policy. PIWIPE already implements NIST 800-88, so aligning with SS-036 requires no extra work on the method side. NIST 800-88 page →
What does SS-036 require for USB and memory cards?
SS-036 requires at least a two-pass overwrite (pattern and complement) for USB drives and memory cards. Optical media (CD/DVD/BD) cannot be sanitised and must be destroyed. PIWIPE records the pass count and verification for overwrite-based media on the certificate.
What is the particle-size requirement for physical destruction?
At the Destroy level, SS-036 requires media to be reduced to particles of 6mm or less, with particle size verified after destruction (~0.5mm edge for optical media). PIWIPE does not perform physical destruction in software; however, it sanitises and certifies the data before Destroy to establish the evidentiary chain-of-custody foundation.
What does SS-036 say about records and chain of custody?
SS-036 requires devices to be held in an "approved, controlled environment" until sanitisation is complete, a "robust chain of custody and approvals" to be recorded, formal sign-off by the Authority Risk Owner, and the asset inventory/CMDB to be updated. The PIWIPE cloud console stores every certificate with timestamp, operator identity, and SHA-256 hash; records export to CSV and can be written to your own FTP/SFTP server.

Scope

Where PIWIPE ends and organisational process begins

PIWIPE is a sanitisation software aligned with SS-036; it fulfils the standard's method and certificate/record requirements. Full SS-036 compliance additionally requires organisational controls such as selecting a CAS-S accredited ITAD supplier, personnel vetting, physical security, and Risk Owner sign-off. That is why the certificates carry an honest "Aligned with DWP SS-036" statement rather than "compliant" — it shows an auditor clearly that the method and record meet the standard while the process responsibility remains with the organisation.

PIWIPE
Vendor-Lock-Free Certificate Custody
Your own FTP/SFTP + SHA-256 integrity

PIWIPE can write each certificate to the FTP/SFTP server you designate; even if the cloud console were down, your archive belongs to you — portable and immutable. A SHA-256 hash embeds independent integrity verification in every file. Blancco/BitRaser comparison →

Start SS-036-aligned sanitisation with PIWIPE.

Request a Demo Contact Sales