Applies to: Pro, Enterprise, and Audit
Supported target
Use NVMe Format NVM – Secure Erase for a compatible directly attached NVMe storage device. The active controller and driver must permit NVMe protocol commands from the Privileged Execution Environment.
Operation
DriveErase requests the NVMe Format NVM operation using the secure-erase setting for user-data erasure. The device performs the operation internally and reports completion or failure through the NVMe protocol.
The operation can take a significant period. Do not interrupt power or reset the device while the command is active.
Namespace and subsystem scope
NVMe devices can expose one or more namespaces and can have controller or subsystem characteristics that affect sanitization scope. A successful command result must be interpreted together with the device configuration and the report’s compliance statement.
DriveErase can withhold a broader subsystem-level Purge claim when it cannot establish that all relevant namespaces, caches, or subsystem-managed areas were covered.
Common failure conditions
- Format NVM is not supported or is disabled by the device;
- The controller driver blocks protocol passthrough;
- The NVMe device is presented through USB, RAID, or another translated path;
- The device is in an incompatible state;
- The command times out or returns an error;
- The target identity changes between job preparation and execution.
Recommended workflow
Use direct motherboard or supported controller attachment where possible. Confirm the device identity and namespace configuration, retain the firmware result, and select a post-erasure assessment appropriate to the planned reuse.
Where the device cannot complete the firmware operation, use Firmware + Fallback only when logical overwrite provides an acceptable alternative. Otherwise, follow the approved destruction procedure.
