Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · Suspecting It Is the Time to Act

NVMe Failing Its SMART Check: the Backup That Started Too Late

His enquiry is unusually well observed and contains one thing almost nobody brings. A 2TB NVMe SSD: "Suffered catastrophic failure. I was taking a backup image overnight after I suspected it was going, but it was too late. A good sign is that in the UEFI boot it knows the drive is still there, but it fails the SMART check, whatever that means. Also worth noting that the drive is encrypted, and I have the recovery key available if needed." Three things to unpack, and the last is the one that transforms the case. He acted on a suspicion — one night late. His firmware observation is genuinely informative. And he has brought his recovery key, unprompted, which is the single most useful thing an owner of an encrypted drive can do.

Media2TB NVMe solid-state drive — enumerated by system firmware but failing its self-assessment; full-disk encryption enabled with the recovery key held by the owner
Reported situationDeterioration suspected and an overnight backup image begun · failure completed before the image finished · drive still detected by firmware · self-check reported as failed · recovery key available
Fault classSSD self-reporting failure while still identifying — controller or NAND degradation; decryption available against a lawfully-held key
Equipment usedVendor technological and safe-mode access (PC-3000 portfolio, SSD support) · controller state and firmware area assessment · imaging on restored access · decryption strictly against the owner's own recovery key (Passware Kit Forensic) · contents verified by opening

The decode: the suspicion, the self-check, and the key

What "I suspected it was going" should have triggered: said as a lesson rather than a reproach, because he did the right thing one step too slowly. When a drive starts behaving oddly, the instinct is to make a complete image — thorough, orderly, and started overnight because it takes hours. But a drive that is failing may not have hours. The better first move is to copy the irreplaceable material first, in priority order, small and fast, and only then attempt a full image with whatever time remains. Photographs, documents and current projects before system files and applications. A full image is the ideal; a prioritised copy is what survives a drive that gives out at three in the morning.

What the firmware and the self-check are telling him together: and he is right that the first is a good sign. Being seen by the UEFI means the drive still powers, identifies itself and completes the basic exchange — which rules out the dead-controller category that makes SSDs unreachable. Failing the SMART check means the drive's own self-assessment has crossed a threshold it considers terminal: reallocated blocks exhausted, error rates beyond tolerance, or the controller flagging its own state. So the drive is alive enough to talk and honest enough to say it is finished. That combination is workable — access exists, and the job is to spend it well.

Why the key changes everything: the part worth emphasising for every reader. An encrypted drive without a lawful key is unreadable no matter how perfectly it is imaged — the archive is full of cases that end there. He has the recovery key in hand, which means the encryption is simply a step rather than a wall, and the entire question becomes technical again. Anyone with an encrypted drive should find their key before contacting anybody, because it determines whether the work is worth commissioning at all.

What the route looks like: the honest NVMe picture. The realistic road runs through the controller — vendor technological and safe modes, firmware area assessment, and imaging while access holds — rather than around it, because on modern SSDs the address mapping and often the encryption live inside the controller and reading the memory packages directly returns little of use. Where access holds, everything is imaged immediately and prioritised, because a drive failing its own self-check is a diminishing resource.

On the bench

Access was attempted through the PC-3000 portfolio's SSD support: the controller addressed in its vendor modes, its state and firmware area assessed, and the drive's own self-reported statistics read directly to establish how much margin remained. Imaging ran immediately on restored access and prioritised rather than sequentially, because a drive reporting itself as failed should be spent on the material that matters first — the same principle his overnight image had lacked. Decryption then ran against his own recovery key through Passware Kit Forensic, and the volume was rebuilt from the image with his files verified by opening before delivery on fresh media.

The outcome

The drive accessed at controller level, imaged in priority order and decrypted with the owner's own key, with the contents verified and delivered. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who suspects a drive is going: copy the irreplaceable material first in priority order, and attempt a full image afterwards — a complete backup is the ideal and a prioritised copy is what survives a drive that fails overnight; being seen by firmware while failing its self-check means the drive still talks and knows it is finished, which is workable; and find your recovery key before you contact anyone, because on an encrypted drive it determines whether any of the rest is worth doing.

Drive you suspect is failing

Copy the irreplaceable things first, right now, before starting anything thorough. The instinct is to run a complete image overnight, and it's a good instinct — but a failing drive may not last the night, and an image that gets three-quarters through gives you whatever happened to be at the start. Work in priority order instead: photographs, documents and current projects before applications and system files, smallest and most valuable first, then attempt a full image with the time that remains. Two other things. If your firmware still sees the drive but a health check reports failure, that's a workable position — the drive is alive enough to talk and honest enough to warn you — so act on it rather than continuing to use the machine. And if the drive is encrypted, find your recovery key before contacting anyone; without it, even a perfect image is unreadable.

Drive warning you it is about to go?
Copy what matters first — then call Glasgow Data Recovery on 0141 404 0294; controller addressed in vendor modes, imaged in priority order, decrypted only with your own key.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294