Nothing else in a computer stops this cleanly. There is no noise to catch and no gradual decline — the entire warning is a machine that worked on Friday putting up an error on Monday where the drive used to be. M.2 sticks and add-in cards come in from spare-room builds, from households, and from the offices and workshops around Coventry and Rugby, and behind almost all of them is a controller that has stopped speaking rather than memory that has been used up.
Looking at an NVMe blade costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: £300 + VAT for one hard disk or SSD, an NVMe blade counting as a single drive.
Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.
Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.
The machine went to sleep with the module present and woke up without it, or an update restarted the computer and the boot device was no longer there. On a module this is nearly always the controller failing to resume rather than the flash losing anything. Leave the machine off from that point, because every further boot attempt is another chance for the firmware to write something over the top of a state it might otherwise recover from.
The slot is empty as far as the computer is concerned. Before drawing conclusions, move the module to another slot or another machine, since M.2 sockets and their retaining screws do fail. If it stays invisible everywhere, that is a controller that has stopped enumerating on the bus, and the packages behind it are usually untouched.
The module answers, gives its name, and reports a size of zero or something absurd. Several controller families do exactly this when they cannot validate their internal tables, as a deliberate protective state. It is not the flash reporting an empty condition; it is the controller declining to guess. The route back is the production diagnostic path.
Fine from cold, gone twenty minutes later, and back again after the machine has cooled. M.2 modules run hot, particularly the faster generations under a shield in a thin laptop, and a controller drifting out of tolerance behaves precisely like this. It is imaged here with active cooling in short passes, which recovers a great deal more than one long attempt that dies at the same point every time.
An update that lost power or was cancelled leaves an incomplete image and a controller with nothing valid to start from. The module is generally invisible or reports zero. Most of these come back through the manufacturer's programming path, so keep the module rather than replacing it and throwing the original away.
The computer starts, the fans run, and it hunts through its boot list and finds nothing. If the module is still listed in the firmware setup then the problem is the boot structures rather than the hardware, and that is one of the more hopeful lines on this page. If it is not listed at all, treat it as a hardware fault and stop restarting.
This has to be said clearly. On a module with power going into it, deleted blocks are handed to the controller as unwanted and cleared in the background within minutes, whether or not anybody is using the machine. The single most useful thing anybody can do after an accidental deletion is shut the computer down properly, immediately, and leave it off. Every minute it stays on is spent erasing.
A module spending its time on error correction and retries drags an entire machine down with it, because it is generally the boot device. Folders take seconds to list, saves hang, and the system feels broken rather than slow. It is still readable in that state, which makes the copy you take today worth vastly more than the diagnosis you postpone.
Some ultrabooks, most recent Macs, Surface models and several consoles carry their flash as packages soldered directly to the logic board with no module to remove. That is a firm no here, and it is refused at the enquiry stage rather than after you have paid for postage. If the machine still starts, copy everything off it today, because there is no second route into that storage.
Off, on, off, on, and on the fourth attempt it appears. A module behaving that way is failing to complete its start-up sequence reliably, and each cycle is a coin toss. Do not settle for the machine working sometimes. Copy off what matters during the next successful boot, then stop, because these do not stabilise and the run that fails is always the important one.
M.2 is a shape, not a promise. Some sockets carry only SATA, some carry only PCIe, and some carry both, and the notches in the module's edge connector say which ones it can occupy. A module in a slot that cannot speak its language is invisible in exactly the same way as a dead one. Worth ruling out at home in two minutes before anything is posted.
It appears, but at a fraction of its rated speed, or drops to one lane and stays there. Damaged pads on the module edge, a contaminated socket or a cracked track will all do it. Nothing is lost at that point, and it usually means a module that can still be read carefully on the bench with the connection made properly.
An external caddy with an M.2 module inside is two devices, and either can be the fault. Take the module out and test it directly if you can do so without forcing anything, because a great many of these turn out to be the bridge in the caddy rather than the module. Send both if you cannot tell, and say in the note which one you suspect.
The most common serious fault on this page. With the controller gone, the map linking logical addresses to physical pages goes too, so the packages are read directly and the mapping is rebuilt from the patterns that come off them. The work involved is real and the results are frequently complete, and it is chip-level work at 50% up front and outside the guarantee.
Data is interleaved across the packages for speed, so losing one does not lose a quarter of the files in a neat block; it damages a portion of nearly everything. Where the controller maintained a parity scheme across the packages, the missing share can often be rebuilt. Whether yours did is one of the questions the diagnostic answers.
The far end of an M.2 module is held by a single small screw, and the board is thin. Levering it out at an angle, or over-tightening the screw, cracks the substrate and severs tracks too fine to see. Repaired at magnification it will usually come back up for long enough to image, and the packages themselves are rarely affected by that kind of break.
A dead short or an out-of-tolerance supply rail. The scorching is confined to the electronics and the flash packages either side of it are generally fine. If there is a burnt smell, do not put the module back in a machine to check: the second attempt is what takes the packages out along with the controller.
Encryption at rest is standard on modern modules and invisible while everything works. Read the packages directly on a module whose controller has died and the result is ciphertext. Recovering the key from the controller is sometimes possible and sometimes not, and which applies to yours is settled during the free diagnostic rather than assumed in advance.
These commands clear the flash electrically and regenerate the encryption key. When one has finished, the data is gone in the strongest sense of the word: there is no shadow copy, no laboratory technique and no service anywhere that reverses it. If a command was interrupted early, some regions may not have been reached, which is worth checking and worth describing honestly as a slim chance.
The module appears in Disk Management as unknown and not initialised, with a dialogue waiting for an answer. Decline it. Initialising writes a fresh partition scheme over the existing one, and the existing one is very often merely unreadable rather than absent. This is one of the few moments on this page where a single click genuinely decides the outcome.
The partition is declared and its contents cannot be identified. On a module that usually means an unclean shutdown caught the mapping tables or the file system header mid-update. Worked from an image it is often a complete recovery. Worked from the original with a repair utility it frequently is not.
The counterfeit trade reached M.2 some time ago. A module reporting four terabytes for the price of a takeaway is a small module told to lie, and it works until the writing wraps around and destroys what was recorded first. If yours arrived from a marketplace listing well under the going rate, mention it, because it changes what the bench looks for first.
Small modules fitted alongside a larger disk to accelerate it hold no complete copy of anything, but the volume above them will not assemble without them. If a caching module has failed, the disk it was accelerating is the thing that needs recovering, and both should travel together with a note explaining the arrangement.
Files failing their integrity checks, games refusing to launch, a machine that has to be reinstalled every few weeks. That pattern points at marginal cells or a controller quietly retiring blocks. Machines built in spare rooms around Coventry and Rugby are strongly represented here, usually with everything on one module and no second copy anywhere.
A pair configured for speed rather than safety. A stripe has no redundancy, so the loss of one member takes the whole volume with it, and both modules are needed before anything can be assembled. Sets of this kind are the array band from 500 pounds + VAT, and there is a page on this site that explains exactly why one lost member ends a striped volume.
Expansion modules from consoles use the standard shapes and can be worked in the ordinary way. The saved data on them is frequently tied to an account rather than to the hardware, so it is worth establishing what you are actually trying to recover before paying for anything: sometimes the answer is available online for nothing.
Modules can be fussy about the slot they sit in, particularly older mainboards with firmware that predates the module's generation. Before concluding a module is dead, try it in a machine known to support it. A module that reads in one computer and not in another is a compatibility problem, not a failure, and nothing needs recovering.
Flash holds charge, and charge leaks. A module put away as a backup and left for several years, especially one that had already been well used, can come back with regions that no longer read reliably. Adjusting read thresholds at a low level recovers a good deal of it. The wider point stands: flash is not archival storage and never has been.
NVMe modules can be reformatted to present a different block size, and doing so makes the existing structures unreadable even though nothing has been erased. It happens accidentally during migrations and deliberately in servers. It is recoverable, provided nothing has been written since, and it is exactly the sort of history worth writing on the booking form.
Spilt drink, a failed mainboard, a machine dropped down a stairwell. If the module unclips, that is all that needs to travel: an M.2 stick in a padded envelope, not a laptop in a box. It is imaged on the bench and the files come back on fresh media, and the state of the computer it came out of is irrelevant to the job.
There is no motor in an NVMe drive and nothing that can be heard, which removes every early warning a spinning disk gives. On the board there is a controller, a firmware layer of some size, and stacked memory. The controller's main job is bookkeeping. It maintains a live index of which physical block currently holds which piece of your data, because flash cannot be overwritten in place and everything therefore moves around constantly. Damage the controller or corrupt that index and the module stops answering the bus, while the contents sit precisely where they were left. Two routes lead back. Most controller families still honour the diagnostic mode their manufacturer uses at the end of the production line, and that is attempted first because it leaves the module in one piece and takes hours rather than days. Where nothing answers, the memory packages are removed from the board and read individually, and the interleave, the page ordering and the error correction the controller had been applying all have to be worked out afterwards before anything looks like a file. That second route is chip-level work: half the fee up front, outside no fix, no fee, and named as such before you agree to anything. What helps neither route is another evening of restarts.
The test is mechanical. If it unclips and fits in a padded envelope it is worked on here — 2280 down to 2230, add-in cards for a full-length PCIe slot, modules living in external caddies, console expansion drives, Gen3 through Gen5, any badge. If the flash is soldered to a mainboard it is not, and no amount of asking changes that. Heat earns its own mention, because it accounts for more failures on this page than wear does. A module running hard with nothing over it throttles first and drops off the bus second, and one that has been round that loop a few dozen times usually arrives with its index in poor condition. Small form-factor builds and thin laptops supply a steady trickle of exactly that every summer. The last point is the urgent one: TRIM operates on NVMe whenever the machine has power, so anything deleted is being genuinely erased in the background while you read this. Shut the computer down fully, not to sleep, and leave it off until the module is out and in the post. A module is £300 + VAT, the same as a hard drive.
Something that fits in an envelope still gets the treatment a full-size drive would get, which starts with read-only handling from the first moment of contact. What follows spans the whole range, from a module that only wants persuading back onto the bus to one whose packages have to be taken off the board and read one at a time.
Phison, Silicon Motion, Marvell, Samsung and Realtek controllers all have a path the manufacturer uses on the production line, and getting a stalled module back onto that path is both the first thing tried and the safest, because it works with the module's own mapping rather than reconstructing one from outside.
2280, 2260, 2242 and 2230 sticks, add-in cards, Apple blade connectors and the USB bridges used in external caddies. A module that refuses to talk to your mainboard very often talks perfectly well to a bench adaptor, and establishing that costs nothing and takes minutes.
Modules that vanish when warm are imaged with forced cooling and in short runs rather than in one continuous pass. It is unglamorous and it is regularly the difference between a complete image and one that stops at the same address every time.
Where the controller cannot be revived, the packages come off under controlled heat and are read one by one, after which the page order, the interleave, the XOR scheme and the error correction all have to be reproduced before any of it becomes a file. This is the slow half of the job and the part that decides whether it works.
Cracked substrates, lifted pads and burnt rails repaired under a microscope, enough to bring a module back up for the length of one imaging pass. Nothing here is repaired for further service; it is repaired to be read once and then retired.
Every adaptor and every port has write blocking in front of it. On flash that matters more than on a spinning disk, because an operating system that mounts a module for writing can begin clearing blocks within seconds, and seconds are all it takes.
Modules fitted on the production line, the Samsung PM981 and the Kioxia BG4 among them, arrive in greater numbers than anything sold in a box, because they are what the laptop makers chose. If it unclips, it is worked on: 2280 down to 2230, Gen3 through Gen5, whether it came out of a notebook, a tower, a USB caddy or a console. The single thing turned away every time is flash soldered to a logic board, and that answer is given at the enquiry rather than after you have paid to post it. A module costs 300 pounds + VAT, the same as a SATA drive or a spinning disk. Looking at it is free and finishes on the second working day after it arrives. Take the packages off the board and it becomes chip-level work, which wants half in advance and appears among the published exclusions. One instruction is worth saying twice: after an accidental deletion, shut the machine down properly and leave it off, because the erasing only happens while current is flowing.
Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.
Looking at it costs nothing, one written figure follows, and the band governing this page is £300 + VAT for one hard disk or SSD, an NVMe blade counting as a single drive.