Skip to content

Resources

NIST 800-88, explained properly

Most summaries of this standard are years out of date. Revision 2 landed in September 2025 and changed what the document is actually for — so it is worth understanding as it stands now, not as it stood in 2014.

Start here

It is a framework for a programme, not a recipe for a wipe

NIST Special Publication 800-88, Guidelines for Media Sanitization, is the reference most auditors and enterprise procurement teams mean when they ask whether your disposal process meets a standard. Revision 1 was published in 2014. Revision 2 was published in September 2025 and supersedes it.

The most useful thing to understand about Revision 2 is what it deliberately stopped doing. Where Revision 1 described sanitization techniques in detail, Revision 2 shifts its focus to establishing an organizational sanitization programme and defers the technique specifics to current standards — IEEE 2883 in particular. The reasoning is straightforward: storage technology evolves faster than a NIST revision cycle, so hard-coding techniques into the framework guarantees the framework goes stale.

It also does something that matters for anyone selecting a disposal vendor. It assigns responsibility for sanitization decisions to roles inside the owning organization — the CIO, the information system owner, the information owner. The obligation is yours. What a provider supplies is execution and evidence.

The three methods

Clear, Purge, Destroy

Retained in Revision 2, and still the vocabulary your auditor will use. The difference between them is the level of attack each is designed to withstand — and whether the device survives.

Clear

Logical techniques applied through the device's standard read-write interface to sanitize data in all user-addressable storage locations.

Protects against non-invasive recovery — someone with the device and ordinary tools.

Device remains usable

Purge

Physical or logical techniques that make recovery of the target data infeasible using state-of-the-art laboratory techniques. Cryptographic erase is a logical purge technique.

Protects against laboratory-grade recovery attempts.

Device remains usable

Destroy

Renders recovery infeasible using state-of-the-art laboratory techniques and also renders the storage media itself unusable.

Highest assurance.

Device is consumed

Cryptographic erase deserves specific mention: Revision 2 elevates it as a logical purge technique, and in virtualised or cloud storage — where the physical medium is abstracted beyond your reach — it may be the only viable purge option available to you.

The distinction most people miss

Verification is not validation

Revision 2 separates these two words on purpose, and the separation is genuinely useful when you are assessing a provider.

Verification determines the outcome of the technique that was applied — did this operation complete as intended on this device. Validation is the further judgement that the target data was effectively sanitized, and the decision to approve or reject the result on that basis.

The gap between them is where failures hide. A technique can execute perfectly and still be the wrong technique for that medium — an interface-level overwrite on flash storage being the obvious case. A process that verifies but never validates will report success in exactly that scenario.

FAQ

Common questions about NIST 800-88

Is NIST 800-88 mandatory?
It is a guideline, not a law. It carries binding force for US federal agencies and their contractors through FISMA, and it is written for that audience — the document assigns responsibilities to roles like the CIO, the information system owner and the information owner. For private-sector organizations it is not legally mandatory, but it has become the reference standard that auditors, insurers and enterprise procurement teams expect you to work to. In practice, saying you sanitize to NIST 800-88 is how you demonstrate a defensible standard of care.
Which method should we use?
It depends on the sensitivity of the data and whether you want the device back. Clear is appropriate where the risk of a laboratory-grade attack is low and the device is being reused internally. Purge is the usual answer for equipment leaving your control with sensitive data on it. Destroy is for the highest-sensitivity cases and for media that has failed sanitization. The decision is yours to make — the standard is explicit that sanitization decisions sit with the organization that owns the information, not with its service provider.
Does it apply to SSDs?
Yes, but the technique matters more than it does for magnetic media. Flash storage manages its own physical layout through wear levelling and over-provisioning, so an overwrite issued through the standard interface does not necessarily reach every physical cell holding your data. That is why cryptographic erase and device-native sanitize commands matter for flash, and why choosing a method by media type rather than by habit is the whole point of the standard.
What changed in Revision 2?
Revision 2 was published in September 2025, superseding Revision 1 from 2014, and the change is more significant than a version bump. Clear, Purge and Destroy are retained, but the focus shifts from prescribing techniques to establishing a media sanitization programme — and for the techniques themselves it now points to current standards, IEEE 2883 in particular, on the reasoning that storage technology changes faster than a NIST revision cycle. It also elevates cryptographic erase, formally introduces sanitization validation as distinct from verification, and adds the concept of logical sanitization for modern virtualised and cloud environments.
What is the difference between verification and validation?
Revision 2 separates them deliberately. Verification determines the outcome of the sanitization technique that was applied — did the operation complete as intended on this device. Validation is the further step of deciding whether the target data was effectively sanitized, and approving or rejecting the result on that basis. The distinction matters because a technique can execute successfully and still be the wrong technique for that medium. A provider who only verifies is answering a narrower question than the standard asks.
How does NIST 800-88 relate to IEEE 2883?
They are complementary rather than competing, and Revision 2 makes the relationship explicit by recommending that sanitization be performed in a manner that complies with IEEE 2883 and that practitioners consult the latest version of such standards. Read NIST as the programme-level framework — who is responsible, how decisions are made, what evidence is produced — and IEEE 2883 as the technical specification for how a given medium is actually sanitized.
Is deleting or reformatting the same as sanitizing?
No, and this is the most common and most consequential misunderstanding. Deleting a file removes the pointer to the data, not the data. Reformatting rewrites the filesystem structures, not the contents. Both leave the underlying data recoverable with ordinary tools. Sanitization is a deliberate operation with a defined method, a verified outcome and a record — none of which a delete or a format produces.
What about data in cloud or virtualised storage?
This is where Revision 2 added genuinely new guidance, and the practical implication is sharp: where storage is logical or virtual and the underlying physical media is abstracted away from you, cryptographic erase may be the only viable purge technique available — because you have no direct access to the physical medium to sanitize or destroy it. That has real consequences for how encryption keys are managed in cloud environments, and it is worth understanding before a migration rather than after.

Primary sources

This guide is provided for general information and is not legal or compliance advice. Sanitization decisions rest with the organization that owns the information.

Need this applied to real equipment?

We sanitize to NIST 800-88, select the method by media type, and issue a certificate for every device.