The PC-Doctor Blog

R2v3, ADISA, and NAID AAA: What Each Certification Requires of Your Erasure Process

R2v3, ADISA, and NAID AAA: What Each Certification Requires of Your Erasure Process

Last technical review: September 29, 2026 by PC-Doctor Engineering

R2v3, ADISA, and NAID AAA all require documented data sanitization, and they all ask for different things. R2v3 sets a recoverability threshold and requires independent verification sampling.[1] ADISA audits the technical efficacy of the erase, on site, with forensic tools.[2][3] NAID AAA audits the people, the access controls, and the chain of custody around the erase, and leaves the technique to the operator’s policy.[4]

Most operations learn those differences during an audit. The better time is before one.

Read more

What a Certificate of Erasure Must Contain to Survive an Audit

What a Certificate of Erasure Must Contain to Survive an Audit

Last technical review: September 29, 2026 by PC-Doctor Engineering

Most drive erase certificates are generated automatically, filed automatically, and never read by anyone until the day they matter.

That day is an audit, a customer dispute, or a data incident. And on that day the certificate is either evidence or it is a PDF with a green checkmark on it.

The difference is what's on the page.

Read more

Clear, Purge, Destroy: How NIST 800-88 and IEEE 2883 Define Sanitization

Clear, Purge, Destroy: How NIST 800-88 and IEEE 2883 Define Sanitization

Last technical review: September 16, 2026 by PC-Doctor Engineering

Clear, Purge, and Destroy are the three sanitization levels defined in NIST SP 800-88. Clear removes data from every user-addressable location and defeats simple recovery. Purge makes recovery infeasible even with laboratory techniques. Destroy does the same and leaves the media unusable afterward. Since Revision 2 of the NIST guideline, published in September 2025, NIST defines the levels and IEEE 2883-2022 defines the techniques that reach them.[1][5]

That last sentence is where most explanations of these standards go wrong, because it was not true until recently. For eleven years the two documents overlapped, and it was reasonable to ask which one applied. It is no longer the right question. The two standards now occupy different layers, and a sanitization program needs both.

Read more

Why a Software Overwrite Doesn’t Sanitize a Modern Drive

Why a Software Overwrite Doesn’t Sanitize a Modern Drive

Last technical review: September 14, 2026 by PC-Doctor Engineering

A software overwrite writes to logical addresses. On a modern drive, the logical address the host writes to is not necessarily the physical location where the earlier data lives. Wear-leveling remaps writes on solid-state drives, retired sectors on any drive fall out of the address space, and ATA features such as HPA and DCO hide entire ranges from the host. Sanitization therefore has to be performed by the drive’s own firmware, which knows where every block is, rather than by a host that can only see the addresses it has been shown.

That is the whole argument. The rest of this article is about why it holds, where the exceptions are, and what a tool has to do about it.

Read more

Recovered Isn't Ready: When a Used Part Earns Its Way Back In

Recovered Isn't Ready: When a Used Part Earns Its Way Back In

A follow-up to "Premium Prices Demand Premium Refurbished PCs"

Last technical review: July 16, 2026 by PC-Doctor Engineering

IBM just put a public number on something refurbishers have been feeling for months.

In the last weeks of June, IBM's clients yanked their capex toward servers, storage, and memory... buying early to lock in supply before prices climbed again. It hit IBM's own results hard enough that the CEO wrote a letter about it.1

Read more