You can wipe a laptop yourself in about twenty minutes. What you cannot easily produce yourself is evidence that somebody else will accept, and that distinction is the entire basis for paying for this.

TL;DR

  • Wiping is a technical operation most teams can perform. Evidencing it to a third party is a different product.
  • If nobody will ever ask you to prove it, wipe in-house, record the date and method, and spend nothing.
  • The device you cannot wipe yourself is the one that will not power on, and every batch contains a few.
  • Degaussing does nothing to a solid-state drive. This error recurs and it is serious.
  • Wipe on arrival into storage, not at disposal, so the obligation closes while the device is in your custody.
  • Record the wipe against the asset with a date, method and person, or you have performed a destruction you cannot demonstrate.

What you are actually buying

Three things, and only the first is technical.

The erasure itself, which for a working modern laptop is straightforward and which your own team can do reliably. The evidence, meaning a tamper-resistant report tying a specific serial to a specific method on a specific date, issued by somebody other than you. And the handling of exceptions, meaning drives that have failed and cannot be erased by any software method.

Companies that buy a service and only needed the first are overpaying. Companies that wipe in-house and needed the second have a gap they will discover at an awkward moment.

Doing it yourself

For a working device that was encrypted from deployment, erasure is quick and dependable: destroying the encryption key renders the contents unreadable in seconds regardless of drive size, and the machine can then be reset for reissue.

The prerequisite is encryption at deployment rather than at disposal. A device encrypted from day one is trivial to clear at the end. One that was never encrypted needs a full overwrite, which is slow on a large drive and unreliable on solid-state media because wear levelling can leave blocks the overwrite never reaches.

So the most useful thing you can do about end-of-life data is enforce encryption at the start of life, which costs nothing and converts a slow, uncertain job into a fast, certain one.

The four methods

Cryptographic eraseDestroys the encryption keyBest option for modern encrypted drives. Seconds, regardless of capacity
OverwriteWrites patterns across the driveFine for conventional hard drives. Slow, and incomplete on solid-state
DegaussingMagnetic field destroys the mediumMagnetic media only. Does nothing whatever to an SSD
Physical destructionShredding or disintegrationRequired for failed drives. Ends any resale value

Every batch contains at least one drive that will not power on, and no software method can touch it. That device needs physical destruction, which is the single most common reason a company that wipes in-house still needs an external supplier occasionally.

A worked example

A company recovered devices from leavers, stacked them in a storeroom, and wiped each one at the point it was either reissued or sent for disposal. That felt efficient, since the work happened once and only when needed.

A security review asked how many devices in the company’s possession held company data. The honest answer was that every machine in the storeroom did, because none had been cleared on arrival. Forty-one devices, sitting in a cupboard for up to fourteen months, each carrying an open obligation nobody had recorded.

Moving the wipe to the point of arrival fixed it permanently. The work is identical, it happens at a different moment, and the storeroom stopped being a liability.

When to pay somebody

What to do:

  • Wipe in-house where you only need the data gone and nobody external will ask for proof.
  • Buy certified erasure software where you need your own tamper-resistant reports but keep the hardware.
  • Use a certified disposal vendor where hardware is leaving you and evidence matters.
  • Send failed drives for physical destruction regardless of which route you use for the rest.
  • Enforce encryption at deployment, which makes every later decision cheaper.
  • Record every wipe against the asset with a date, a method and the person who did it.

The last item is the one most often skipped by teams doing this well technically. An undocumented destruction is close to a destruction that did not happen, from the point of view of anybody assessing you afterwards.

The suppliers

Blancco is the best-known certified erasure option, producing its own reports at the point of erasure rather than afterwards, which suits companies retaining or reselling hardware themselves. It publishes no price and is quote-based, confirmed on its own site 9 October 2026.

Certified disposition specialists wipe as part of a wider service and issue the certificate. They are built around pallets at a facility and generally will not collect single devices from homes, which is the constraint for distributed fleets.

Disclosure: RemoAsset is owned by the same people who publish PeopleOpsHQ. It recovers devices from distributed staff and wipes them on arrival, which addresses the storeroom problem in the example above. It is not a certified IT asset disposition vendor and does not issue disposition certification, it publishes no price and requires a demo, and it is weaker for hardware it did not supply. For certification it sits alongside a specialist, and those are compared in our IT asset disposition comparison.

Final thoughts

Most companies can wipe their own devices and most companies should, provided they record it. The question that decides whether to pay somebody is not whether you can perform the erasure but whether anybody will later require independent evidence of it.

Enforce encryption at deployment, wipe on arrival into storage rather than at disposal, record the date and method against the asset, and send the failed drives to somebody with a shredder. That covers the large majority of fleets at close to no cost, and it leaves a much smaller question about certification to answer separately.

Frequently asked questions

Can we wipe laptops ourselves instead of paying a service?

For working devices that were encrypted at deployment, yes, and it takes minutes rather than hours because destroying the encryption key renders the contents unreadable regardless of drive size. What you cannot easily produce in-house is independent evidence that a third party will accept, so the decision rests on whether anybody will ask you to prove it rather than on whether you can do it. You also cannot wipe a drive that will not power on, and every batch contains a few.

When should devices be wiped?

On arrival into your custody rather than at the point of disposal or reissue. Wiping on arrival closes the data obligation at the moment the device enters your possession, which means a storeroom full of returned machines carries no exposure, and it removes time pressure from the disposal decision. Teams that wipe at the point of disposal frequently discover that every device in their cupboard has been holding company data for a year, which is an uncomfortable answer to a security review.

Does degaussing work on solid-state drives?

No, and this is a recurring and serious error. Degaussing applies a magnetic field powerful enough to destroy data on magnetic media, and solid-state drives store nothing magnetically, so a degaussed SSD is entirely intact with all its data present. For solid-state media the correct approaches are cryptographic erase where the drive was encrypted, or physical destruction where it was not or where the drive has failed and cannot be addressed by software.

What is the single most useful thing we can do?

Enforce full disk encryption at deployment rather than thinking about data destruction at end of life. A device encrypted from its first day can be cleared in seconds by destroying the key, while one that was never encrypted needs a full overwrite that is slow on large drives and unreliable on solid-state media because wear levelling can leave blocks untouched. The decision made at the start of a device’s life determines how easy and how certain the end of it will be.

What do we do with drives that have failed?

Physical destruction, because no software method can address a drive that will not power on, and this is the most common reason a company wiping in-house still needs an external supplier occasionally. Collect them separately rather than mixing them into a general disposal batch, since they need a different treatment and should appear differently on any certificate. Keep a record of each one by serial, because a failed drive you cannot evidence the destruction of is exactly the gap an audit will find.

How should we record a wipe?

Against the asset record, with three things: the date, the method used, and the person or system that performed it. A wipe recorded only in somebody’s memory or in a chat message is a destruction you cannot demonstrate, which from the perspective of anybody assessing you afterwards is close to one that did not happen. Adding a simple state field to the register, showing whether each device’s data obligation is open or closed, turns this from a set of notes into a report you can produce on request.