In many compliance-heavy fields, there are specific requirements around data destruction, sometimes involving physically destroying the storage medium up to some given standard.
I’d assume this device targets that market.
If they are strict enough to not allow for cryptographic erasure (or the data is above a specific sensitivity), this device would likely not be in compliance either -- physical destruction generally requires shredding/grinding to a specific particulate size, or incineration, and this device does not appear to do either.
I'm also not saying that all compliance standards related to data security require physical destruction; just that these absolutely exist, mostly in defense and similar areas.
But, I mainly made my comment in reply to this part of your comment:
>I’d assume this device targets that market.
Because I don't think there is any market where this SSD punching device would be compliant and cryptographic erasure wouldn't be compliant. At least, in my career, I have not seen any environment or standard where this would be considered compliant but cryptographic erasure wouldn't be.
I didn't explicitly say this in my original comment since it seemed implicit given the context.
I am very explicitly saying cryptographic erasure is not required if you are following physical destruction standards (in ISO 27001 and NIST 800-88, at least).
Of course, this clarification only matters if your threat model involves dealing with top-secret data and/or nation-state enemies.
I'm not sure if I wasn't clear or if you didn't read my comment correctly.
Encrypting is not enough to prevent data recovery if data was written to disk prior to encrypting it.
In other words, if you want to be 100% sure about your data being safe, you must encrypt first (when the drive is brand new), or you must physically destroy the drive.
But if your threat model is that relaxed, you can just encrypt the whole drive, toss the key, and then format the device. This would likely be quicker than doing 10x write passes.
As a note, write passes are really only good for HDDs due to wear-leveling algorithms in every SSD.
The boot password might be needed to be configured but it's unlocks your SSD. It's enough for the SSD to forget the AES key