Resources
NIST 800-88, explained properly
Most summaries of this standard are years out of date. Revision 2 landed in September 2025 and changed what the document is actually for — so it is worth understanding as it stands now, not as it stood in 2014.
Start here
It is a framework for a programme, not a recipe for a wipe
NIST Special Publication 800-88, Guidelines for Media Sanitization, is the reference most auditors and enterprise procurement teams mean when they ask whether your disposal process meets a standard. Revision 1 was published in 2014. Revision 2 was published in September 2025 and supersedes it.
The most useful thing to understand about Revision 2 is what it deliberately stopped doing. Where Revision 1 described sanitization techniques in detail, Revision 2 shifts its focus to establishing an organizational sanitization programme and defers the technique specifics to current standards — IEEE 2883 in particular. The reasoning is straightforward: storage technology evolves faster than a NIST revision cycle, so hard-coding techniques into the framework guarantees the framework goes stale.
It also does something that matters for anyone selecting a disposal vendor. It assigns responsibility for sanitization decisions to roles inside the owning organization — the CIO, the information system owner, the information owner. The obligation is yours. What a provider supplies is execution and evidence.
The three methods
Clear, Purge, Destroy
Retained in Revision 2, and still the vocabulary your auditor will use. The difference between them is the level of attack each is designed to withstand — and whether the device survives.
Clear
Logical techniques applied through the device's standard read-write interface to sanitize data in all user-addressable storage locations.
Protects against non-invasive recovery — someone with the device and ordinary tools.
Device remains usable
Purge
Physical or logical techniques that make recovery of the target data infeasible using state-of-the-art laboratory techniques. Cryptographic erase is a logical purge technique.
Protects against laboratory-grade recovery attempts.
Device remains usable
Destroy
Renders recovery infeasible using state-of-the-art laboratory techniques and also renders the storage media itself unusable.
Highest assurance.
Device is consumed
Cryptographic erase deserves specific mention: Revision 2 elevates it as a logical purge technique, and in virtualised or cloud storage — where the physical medium is abstracted beyond your reach — it may be the only viable purge option available to you.
The distinction most people miss
Verification is not validation
Revision 2 separates these two words on purpose, and the separation is genuinely useful when you are assessing a provider.
Verification determines the outcome of the technique that was applied — did this operation complete as intended on this device. Validation is the further judgement that the target data was effectively sanitized, and the decision to approve or reject the result on that basis.
The gap between them is where failures hide. A technique can execute perfectly and still be the wrong technique for that medium — an interface-level overwrite on flash storage being the obvious case. A process that verifies but never validates will report success in exactly that scenario.
FAQ
Common questions about NIST 800-88
Is NIST 800-88 mandatory?
Which method should we use?
Does it apply to SSDs?
What changed in Revision 2?
What is the difference between verification and validation?
How does NIST 800-88 relate to IEEE 2883?
Is deleting or reformatting the same as sanitizing?
What about data in cloud or virtualised storage?
Primary sources
- NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (September 2025)
- NIST SP 800-88 Rev. 1 (December 2014) — superseded
- IEEE 2883-2022, IEEE Standard for Sanitizing Storage
This guide is provided for general information and is not legal or compliance advice. Sanitization decisions rest with the organization that owns the information.
Need this applied to real equipment?
We sanitize to NIST 800-88, select the method by media type, and issue a certificate for every device.