Hard Drives

SED and FIPS 140-2 Drives Explained: Do You Need One?

Sarah Jane Sep 12, 2026 5 min read

Self-encrypting drives are listed with the letters SED and sometimes FIPS 140-2, and most buyers are not sure whether they need them or what changes if they buy one by accident. This covers both.

What is a self-encrypting drive (SED)?

A drive that encrypts everything written to it, in hardware, all the time.

The encryption is always on. What changes is whether it is locked. An SED that has not been set up behaves exactly like a normal drive β€” data goes in, data comes out, nothing appears encrypted from the outside. Once an authentication key is set, the drive refuses to release data without it.

Two things follow from that.

Buying an SED by accident does no harm. Unconfigured, it is just a drive.

Buying an SED on purpose requires something to manage the key. Usually a RAID controller or host software that supports drive encryption. Without that, the encryption is present but not protecting anything.

What does FIPS 140-2 mean on a hard drive?

A validation standard for cryptographic modules, used by US federal government and by organisations that follow its requirements.

A FIPS 140-2 validated SED has had its encryption implementation tested and certified against that standard. The drive does the same thing as a non-validated SED; the difference is the paperwork, and for some buyers the paperwork is the requirement.

Where it matters: government, defence, healthcare, finance and any contract that specifies it. Where it does not: everywhere else. A FIPS drive is not faster or more reliable, and it typically costs more.

Our procurement guide covers where these requirements come from.

Do I need an SED?

Three situations where the answer is yes.

Compliance requires encryption at rest and you want it done in hardware rather than in software.

Drives leave your control β€” returns, RMA, disposal, relocation. A locked SED that goes missing is a drive with nothing readable on it.

Fast secure erase matters. Cryptographic erase deletes the key rather than overwriting the drive, which takes seconds rather than hours. Our sanitisation guide covers this against other methods.

And one situation where it is not worth paying for: you have no controller or software to manage the keys. The feature will sit unused.

Does my RAID controller support SED?

The question that decides whether the feature does anything.

Many enterprise controllers support SED management, but frequently as a licensed feature rather than a default one. The controller must be able to set and hold the authentication key, unlock the drives at boot, and manage key rotation.

Two things to check. Whether the controller supports it at all β€” our controller guide covers identification. And whether a licence is required, which is a separate purchase on some platforms.

Behind a plain HBA with software-managed storage, SED support depends on the operating system or storage software instead.

What happens if I lose the SED key?

The data is gone. That is the point.

A locked SED without its key is unrecoverable by design, and no vendor can help. Two consequences.

Key management is an operational responsibility, not a set-and-forget. Where the key lives, who can access it and what happens when the controller fails all need answering before you enable encryption.

A controller failure can lock you out if the key was held only on the controller. Some platforms support external key management for exactly this reason. Our DR guide covers planning for the failure of the thing holding your keys.

Can I use an SED as a normal drive?

Yes, and many are used this way without anyone knowing.

Unconfigured, an SED is indistinguishable from a standard drive in use. Capacity, speed, interface and compatibility are unchanged. The only practical difference is that a locked SED from a different system will refuse to release data, so a second-hand SED should be cryptographically erased or confirmed unlocked before purchase.

When buying, confirm one further thing: compatibility with your controller does not change because a drive is an SED. Carrier generation, firmware coding and sector format all still apply β€” our sector format guide covers one of those.

Frequently asked questions

What does SED mean on a hard drive?

Self-encrypting drive. It encrypts everything in hardware, always. Unconfigured it behaves like a normal drive; once an authentication key is set, it refuses to release data without it.

Is a FIPS 140-2 drive better than a regular SED?

Not functionally. FIPS 140-2 validation means the encryption implementation has been certified against a US federal standard. It matters where a contract or regulation specifies it, and nowhere else. It is not faster or more reliable.

Can I use an SED without enabling encryption?

Yes. Unconfigured, an SED is indistinguishable from a standard drive. Buying one by accident does no harm. Buying one on purpose requires a controller or software to manage the key.

Does my RAID controller need a licence for SED?

On some platforms, yes. SED management is frequently a licensed feature rather than a default one. Check whether your controller supports it and whether a licence is a separate purchase.

What if I lose the encryption key?

The data is unrecoverable by design, and no vendor can help. Key management is an operational responsibility, and a controller failure can lock you out if the key was held only there. Some platforms support external key management for this reason.

Should I buy a second-hand SED?

Only if it is confirmed unlocked or cryptographically erased. A locked SED from a different system will refuse to release data and cannot be unlocked without its key.

If a contract specifies FIPS 140-2, tell us and we will confirm the exact drive validation before you order. If it does not, we will tell you honestly whether the SED premium is worth paying.

Sarah Jane

Sarah Jane

Senior IT Hardware Specialist · TechSellerUSA
Sarah helps businesses and IT teams source the right enterprise hardware at wholesale prices. View profile →