In simple terms a write blocker sits between the original drive or device and your forensic workstation and stops any write commands from getting through, while letting you read every bit. Along with checksums, write blockers help maintaining chain of custody, ensuring that the imaging step is repeatable and verifiable. Hardware write blockers are physical devices you plug the source media into, software write blockers are installed on the acquisition system, and the former type is more robust than the latter. The point, however, is not speed or convenience, it is to make a forensic copy without changing the original, so the evidence you work from is the same as the evidence you seized. And here comes the question: which laws or standards mandate using a write blocker?
How do you test a write blocker? If you have time to spare, read Minimum Requirements for Testing Tools Used in Digital and Multimedia Forensics and A Strategy for Testing Hardware Write Block Devices, and/or check out the specs at Software Write Block | NIST. If not, just use the tool: CRU NIST Federated Write Block Validation Utility v2.1.1.0
There is no general law, in most countries at least, that says you must use a write blocker to image a drive. Courts do not cite a statute that mandates a hardware write blocker by name. What you do have is a strong expectation of integrity, and that expectation is enforced through professional standards, laboratory accreditation and admissibility.
Best practice in forensic disk imaging is to treat the original as read-only from the moment you touch it. That means using a validated write blocker when you can, imaging to a forensic container with hashing, documenting the process and never doing analysis on the original. During examination the same logic applies: work from a verified copy, and if you must mount the original for any reason, protect it with a write blocker so accidental writes cannot happen.
That, however, is not law; in most countries it is merely consensus. The difference matters in the lab. If you are accredited to ISO/IEC 17025, you are mandated to have documented procedures, competence and validation for your processes. You must be able to prove your imaging workflow preserves integrity and is repeatable. If you are not accredited, the SWGDE and NIST guidance is what judges, opposing experts and accreditation bodies will hold you against – without being legally binding. In practice the line between mandate and recommendation disappears: you do not need a law to force a write blocker, you need a defensible case file.
The guidance you will likely see referenced comes from a small, interconnected set of sources. NIST SP 800-86 (2006) Guide to Integrating Forensic Techniques into Incident Response, is the broader of the two, and NIST SP 800-101 Rev. 1 (2014) Guidelines on Mobile Device Forensics are the most cited technical overviews. They are explicitly guidance, not legal advice, and they describe write protection as the accepted way to prevent writes to the original during acquisition. The SP 800-101 mobile guide specifically talks about blocking or eliminating write requests to the device.
Those NIST documents sit alongside SWGDE best practices. The SWGDE Best Practices for Computer Forensic Acquisitions (SWGDE 17-F-002) recommends hardware or software write blockers should be used when possible to prevent writing to the original evidence, and the Best Practices for Computer Forensic Examinations (SWGDE 18-F-001) says digital evidence should be protected with a software or hardware write blocker during examination and analysis should be done on a copy. The SWGDE documents are recommendations, and they are now being transitioned into formal standards by the Organization of Scientific Area Committees for Forensic Science, OSAC.
The international process framework that ties this together is ISO/IEC 27037 (2012), Guidelines for identification, collection, acquisition and preservation of digital evidence. Without mentioning write blockers specifically, it requires the same four steps carried out with integrity and chain of custody maintained. In practice that principle is met by using validated write blocking during acquisition and preservation.
ISO/IEC 17025 is the competence standard for testing and calibration laboratories. No word about write blockers in particular, but it requires you to validate equipment and procedures, document them, and demonstrate technical competence. A lab accredited under 17025 will have a validated imaging procedure that includes a validated write blocker, because that is how it demonstrates compliance with 27037 principles.
NIST’s Computer Forensics Tool Testing Program (CFTT) for hardware and software write block, run jointly with the Department of Homeland Security’s Cyber Forensics program, supports this whole chain. Again, the CFTT tests are not legally binding, but using a tool that has been through CFTT validation is how most labs show their procedure meets the expectations set by NIST, SWGDE and ISO.
So in your day-to-day work you are not following a law about write blockers. You are following NIST guidance that informs SWGDE best practices, which feed into OSAC standards, all interpreted through ISO 27037 for evidence handling and ISO 17025 for laboratory competence. The standards reference each other and ultimately point to the same outcome: protect the original, work from a verifiable copy, document what you did.
There is no universal law that forces a forensic practitioner to use a write blocker. There is no statute that says you must use Faraday bags for mobile devices either, yet everybody does it because it is best practice and you will regret it if you do not. Write blocker use is the same: it is mandated by professional expectations, accreditation requirements and the need to keep evidence defensible. Follow the guidance, validate your tools, and document your process, and the lack of a law will never be a problem in court.