The three ways to encrypt a USB drive
You can encrypt a USB flash drive using built-in tools on Windows or Mac, third-party software, or hardware-encrypted drives that lock at the device level. The easiest route depends on what operating system you use and whether you want to encrypt the whole drive or just a folder inside it.
Windows 11 and 10 include BitLocker To Go, which encrypts the entire drive and requires a password to access it on any computer. Mac users have Disk Utility, which creates an encrypted container on the drive. If you want something that works the same way on Windows and Mac, or if you use Linux, VeraCrypt is free and open-source. Some USB drives come with built-in encryption hardware that does not rely on software at all.
Each method has a trade-off: built-in tools are simpler but may lock you out if you forget the password, third-party software is more portable across devices, and hardware encryption is fastest but costs more upfront.
Key Takeaways
- Windows BitLocker To Go and Mac Disk Utility are free and built in, but they encrypt the entire drive and require you to remember your password.
- VeraCrypt is free, works on Windows, Mac, and Linux, and lets you create an encrypted folder inside an unencrypted drive so you can share the drive with others.
- Hardware-encrypted USB drives do the encryption on the device itself and do not depend on your computer's software, but they cost more than standard drives.
- Once you encrypt a drive, you must enter the password every time you plug it in, and forgetting the password usually means the data is permanently inaccessible.
Using BitLocker To Go on Windows
BitLocker To Go is the simplest option if you use Windows 11 or Windows 10 Pro, Enterprise, or Education editions. It encrypts the entire USB drive so that anyone who plugs it in must enter a password before they can see any files. The drive will work on any Windows computer, but on a Mac or Linux machine it will appear locked and unreadable.
To encrypt a drive with BitLocker, plug in the USB, right-click it in File Explorer, and select Turn on BitLocker. Windows will ask you to create a password and choose whether to save a recovery key (you should save it, in case you forget the password). The encryption happens in the background and can take a few minutes on a large drive. After that, every time you plug the drive into a Windows computer, you will be prompted for the password before you can open any files.
The main limitation is that BitLocker is not available on Windows 10 or 11 Home edition. If you have Home, you will need to use VeraCrypt or a third-party tool instead.
Using Disk Utility on Mac
Mac users can encrypt a USB drive using Disk Utility, which comes built in to macOS. Unlike BitLocker, Disk Utility creates an encrypted container — a single file that acts like a locked folder — rather than encrypting the whole drive. This means you can have both encrypted and unencrypted files on the same USB.
To create an encrypted container, open Disk Utility (in Applications > Utilities), go to File > New Image > Blank Image, and choose a size and location on your USB drive. Select APFS Encrypted as the format, create a password, and click Save. Disk Utility will create a file on your USB that you can double-click to mount (unlock) whenever you need it. On a Mac, this works seamlessly. On Windows or Linux, the file will appear as a regular file and you will not be able to open it without additional software.
If you want the entire drive encrypted instead of just a container, you can right-click the USB in Disk Utility and select Encrypt, but this works only on Mac and makes the drive unreadable on Windows.
Using VeraCrypt for Windows, Mac, and Linux
VeraCrypt is free, open-source software that works the same way on Windows, Mac, and Linux. It creates an encrypted container on your USB drive, so you can keep some files unencrypted and others locked behind a password. This is useful if you want to share the drive with someone who does not need access to the encrypted files.
Download VeraCrypt from the official website (veracrypt.fr), install it, and plug in your USB drive. Open VeraCrypt, click Create Volume, and choose Create an encrypted file container. Select the USB drive as the location, choose a size for the container (for example, 2 GB), and set a password. VeraCrypt will create a file on your USB. To use it, open VeraCrypt, click Select File, choose the container file, enter your password, and click Mount. The encrypted folder will appear on your desktop or in File Explorer.
VeraCrypt is slower than BitLocker or Disk Utility because it encrypts and decrypts files on the fly, but the difference is usually not noticeable unless you are working with very large files. The main advantage is that it works the same way on any operating system, so you can use the same encrypted container on Windows at work and Mac at home.
Hardware-encrypted USB drives
Some USB drives come with built-in encryption hardware that does not depend on your computer's software. These drives have a keypad or fingerprint reader on the device itself, and you enter the password directly on the drive before plugging it in. Once unlocked, the drive appears as a normal USB to your computer.
Hardware encryption is faster than software encryption because the drive handles all the encryption work internally. It also works the same way on any computer — Windows, Mac, or Linux — without needing to install software. The trade-off is cost: hardware-encrypted drives typically cost two to three times more than standard USB drives of the same size.
Popular hardware-encrypted drives include the iStorage datAshur and Kingston DataTraveler Vault. Before buying one, check that it supports the operating systems you use and that the keypad or biometric reader works reliably with your hands or fingers.
What happens if you forget your password
If you forget the password to an encrypted drive, the data is almost always permanently inaccessible. BitLocker, Disk Utility, and VeraCrypt all use encryption strong enough that there is no back door — even the software makers cannot unlock the drive for you. This is by design: strong encryption means nobody can read your files without the password, including you if you forget it.
The only exception is if you saved a recovery key when you first encrypted the drive. BitLocker asks you to save a recovery key, and you should store it somewhere safe (a password manager, a printed copy in a drawer, or an email to yourself). If you have the recovery key, you can use it to unlock the drive instead of the password. VeraCrypt and Disk Utility do not offer recovery keys, so forgetting the password means the data is gone.
Before you encrypt a drive, write down your password in a place you will remember, or store it in a password manager like Bitwarden or 1Password.
Choosing between methods
If you use only Windows and want the simplest option, BitLocker To Go is built in and requires no extra software. If you use Mac, Disk Utility is the easiest choice. If you switch between Windows and Mac, or use Linux, VeraCrypt is the most portable option and costs nothing.
If you need to share the drive with someone who does not need access to all your files, use VeraCrypt or Disk Utility to create an encrypted container instead of encrypting the whole drive. If you work with very sensitive data and want the fastest encryption, a hardware-encrypted drive is worth the extra cost.
The most important step is to choose a strong password — at least 12 characters, mixing uppercase, lowercase, numbers, and symbols — and write it down somewhere safe. A forgotten password is permanent.
Frequently Asked Questions
Can I encrypt a USB drive that already has files on it?
Yes, but the method depends on your software. BitLocker and Disk Utility encrypt the entire drive in place, so all existing files become encrypted. VeraCrypt creates a new container, so you must move files into the container manually. If you want to encrypt an existing drive with BitLocker or Disk Utility, back up the files first in case something goes wrong.
Will an encrypted USB drive work on any computer?
BitLocker-encrypted drives work on any Windows computer but appear locked on Mac or Linux. Disk Utility containers work on Mac but not Windows or Linux without additional software. VeraCrypt containers and hardware-encrypted drives work on any operating system as long as you have the password or the drive is unlocked.
How long does it take to encrypt a USB drive?
BitLocker and Disk Utility usually take a few minutes for a drive under 64 GB. VeraCrypt is slower because it encrypts files as you add them, so the initial setup is fast but encryption happens in the background. Hardware-encrypted drives have no setup time — you just set a password on the device itself.
Can I use an encrypted USB drive on my phone?
Most phones do not support USB drives at all, and encrypted drives are even less likely to work. If your phone has a USB-C port, you may be able to plug in a USB drive with an adapter, but the phone will not recognize an encrypted container or BitLocker drive. Hardware-encrypted drives might work if your phone supports USB storage, but you should test it before relying on it.
Is encryption slower than using an unencrypted drive?
BitLocker and Disk Utility have almost no speed penalty because they encrypt at the hardware level. VeraCrypt is noticeably slower on older computers, but on modern machines the difference is usually under 10 percent. Hardware-encrypted drives are as fast as unencrypted drives because the encryption happens on the device.