What changed with NIST SP 800-88 Rev. 2?
NIST published Special Publication 800-88 Revision 2, Guidelines for Media Sanitization, in September 2025. It superseded Revision 1 from 2014. The new revision shifts the emphasis away from being primarily a hands-on catalogue of device sanitisation techniques and toward establishing an enterprise or agency media-sanitisation programme.
For IT asset disposition, that distinction matters. A supplier should not simply claim that a drive has been “NIST wiped.” The organisation needs a defined sanitisation policy, an appropriate method for the information and media, an approved technique or standard, verification that the operation completed, validation that the result is acceptable, and evidence linking the result to the asset.
What does media sanitisation mean?
NIST describes media sanitisation as rendering access to target data on media infeasible for a given level of effort. The required level of effort depends on the sensitivity of the information and the sanitisation method selected.
Revision 2 recognises three sanitisation methods: Clear, Purge and Destroy. These are not three brands of wiping software and they are not interchangeable labels for deletion.
Clear: protection against simple, non-invasive recovery
Clear applies logical techniques to sanitise data in user-addressable storage locations so that the original data is protected against simple, non-invasive recovery using the normal interface available to the user.
The important limitation is the scope: Clear is aimed at the locations and interfaces addressed by the applicable technique. Organisations should not assume that ordinary file deletion, quick formatting or removing a partition automatically satisfies an approved Clear process.
When might Clear be appropriate?
Clear may be suitable where the organisation's sanitisation policy, information sensitivity, media characteristics and intended reuse make that level of assurance acceptable. Typical decisions might involve controlled internal reuse or another disposition route where the risk assessment supports Clear.
The decision should come from the organisation's policy and approved sanitisation standard rather than from convenience or the resale value of the equipment.
Purge: stronger protection while potentially preserving reuse
Purge applies physical or logical techniques intended to make target-data recovery infeasible using state-of-the-art laboratory techniques. For information storage media, Purge can preserve the media in a potentially reusable state.
NIST Rev. 2 states that, when possible, Purge should be used instead of Clear. This makes Purge especially important in ITAD projects where an organisation wants stronger sanitisation assurance without automatically destroying reusable storage.
Purge is not one universal command
The appropriate Purge technique depends on the media. NIST points organisations toward current relevant standards, including IEEE 2883, NSA specifications or an organisationally approved standard.
Examples discussed by NIST for logical Purge can include overwrite, block erase and cryptographic erase when performed using appropriate dedicated, standardised device sanitisation commands. The exact technique must be suitable for the storage technology.
Destroy: sanitisation that prevents subsequent media use
Destroy renders target-data recovery infeasible using state-of-the-art laboratory techniques and leaves the media unable to be used subsequently to store data.
Destruction can be appropriate for failed media, equipment that cannot be sanitised to the required assurance, media subject to a destruction-only policy, or information for which the risk decision rules out reuse.
Clear, Purge and Destroy compared
The practical difference is not simply “weak, medium and strong.” Clear and Purge can preserve media for reuse, while Destroy deliberately prevents subsequent use. Purge addresses a stronger recovery threat than Clear.
The correct method depends on information sensitivity, media type, intended disposition, available approved techniques, organisational policy, contractual requirements and the organisation's risk decision.
NIST Rev. 2 does not prescribe one method for every business
NIST SP 800-88 Rev. 2 is a framework for establishing an effective sanitisation programme. It does not mean every organisation should destroy every drive, nor does it mean every reusable drive should receive the same logical sanitisation technique.
The organisation should define its sanitisation requirements before assets reach the disposal stage. This prevents operators or suppliers from making inconsistent decisions asset by asset.
HDDs: understand the approved technique
Magnetic hard drives may support different sanitisation approaches depending on the device, interface and approved standard. A normal operating-system file deletion is not equivalent to media sanitisation.
If the drive is healthy and reuse is permitted, an approved Clear or Purge technique may preserve value. Failed drives or drives that cannot complete the required process should enter an exception route.
SSDs and NVMe: flash changes the problem
Flash-based SSD and NVMe devices use controllers, remapping, wear levelling and over-provisioned storage. These characteristics mean assumptions derived from traditional magnetic disks should not automatically be applied to flash.
Use supported device sanitisation capabilities and the applicable approved standard. A generic claim such as “we overwrite every SSD several times” is not, by itself, evidence that the appropriate sanitisation outcome has been achieved.
Why degaussing is not a universal answer
Degaussing applies to susceptible magnetic media; it is not a general-purpose sanitisation technique for semiconductor flash. Applying a magnetic-media technique to an SSD does not address how that SSD stores data.
Media identification therefore needs to occur before the sanitisation method is selected.
Cryptographic erase
Cryptographic erase is an important Purge technique for appropriately implemented encrypted media. It sanitises the relevant cryptographic keys so that the encrypted target data cannot feasibly be recovered through decryption.
Revision 2 expands guidance on cryptographic erase, including key sanitisation and circumstances involving externally managed keys. The organisation must understand where usable keys exist; eliminating one local key is not sufficient if another key remains capable of decrypting the data.
Encryption enabled does not automatically mean sanitised
Full-disk encryption is valuable, but an encrypted device should not simply be declared sanitised because encryption was turned on. The sanitisation decision must account for the cryptographic implementation, key lifecycle and the approved cryptographic-erase process.
ITAD evidence should record the actual sanitisation operation and its result rather than relying solely on an inventory field saying “encrypted.”
Technique selection and vendor trust
One of the significant changes in Revision 2 is greater attention to establishing trust in vendor implementations of sanitisation techniques. Organisations need confidence that the device or tool behaves as expected.
That can involve understanding vendor documentation, supported commands, standards conformance, tool approval, firmware behaviour and known limitations. A sanitisation programme should not rely on an unexplained proprietary “secure wipe” button.
Verification: did the operation complete?
Sanitisation verification determines the outcome of the technique used. For tool-driven Clear and logical Purge operations, this can include checking completion status, errors, anomalies and media health. For physical techniques, it can include confirming that the equipment completed its operation correctly.
Verification is therefore different from merely starting a sanitisation job. A job that terminates with an error should not be recorded as a successful result.
Validation: is the result acceptable?
Sanitisation validation considers whether the target data was effectively sanitised and whether the result should be accepted or rejected. Verification results, errors, anomalies, technique suitability and confidentiality risk inform that decision.
If the result is rejected, the organisation may repeat sanitisation with a different technique or escalate to a more secure method. In an ITAD workflow, this is where failed processing should become a controlled exception rather than quietly disappearing from the report.
Why verification and validation matter for ITAD evidence
A certificate saying “NIST compliant” is weak evidence if it does not explain which assets were processed, what method or approved technique was used, whether processing completed successfully and how exceptions were handled.
Serial-level processing records make it possible to reconcile sanitisation outcomes to the original asset inventory and demonstrate that failed devices followed the required alternative route.
Failed drives
A failed or inaccessible drive is not automatically sanitised. If the approved Clear or Purge technique cannot be completed or validated, the device should remain controlled and follow the organisation's exception policy.
Depending on the risk decision, this may mean retrying with another approved technique or escalating to physical destruction.
Partial failures and inaccessible storage
Modern devices can contain regions that are no longer accessible through normal interfaces because of errors, remapping or performance conditions. Revision 2 explicitly recognises that a device can appear functional while part of its storage is inaccessible.
Validation should consider whether such conditions undermine confidence in the sanitisation result.
Embedded and non-obvious storage
The sanitisation programme should cover information storage media wherever it exists, not only removable HDDs. Servers, network appliances, printers, storage arrays and specialist equipment can contain embedded flash, cache, management modules or removable storage.
Asset discovery should therefore precede sanitisation selection.
Internal reuse versus external reuse
An organisation may set different sanitisation requirements for internal redeployment and external release. The difference should be defined in policy rather than decided informally by the disposal operator.
External reuse can provide residual value and environmental benefits, but only after the required sanitisation outcome has been achieved and accepted.
When destruction can be the appropriate decision
Destroy can be appropriate when media is damaged, sanitisation support is uncertain, the required assurance cannot be validated, policy requires destruction, or the organisation's risk assessment rules out reuse.
Destroying every device is not automatically the best ITAD strategy. Where approved sanitisation allows secure reuse, unnecessary destruction can eliminate residual value and shorten the useful life of equipment.
NIST and NCSC for UK organisations
NIST SP 800-88 Rev. 2 is a US publication but is widely useful as a technical media-sanitisation reference. UK organisations should also consider applicable UK requirements, contractual obligations, organisational security policy and NCSC guidance.
For UK government information, classification-specific requirements matter. NCSC's public storage-media guidance is designed around protections proportionate for OFFICIAL data and directs organisations handling HMG SECRET or above to separate guidance.
What should an ITAD sanitisation policy define?
A practical policy should identify information categories, media classes, approved sanitisation methods, approved standards or techniques, internal and external reuse rules, validation requirements, failed-media handling, destruction requirements, responsible roles, evidence requirements and exception approval.
The policy should be understandable enough that two competent operators facing the same asset and risk context reach the same disposition decision.
What should an ITAD provider record?
Useful processing evidence can include asset serial number, asset tag where applicable, media identifier, sanitisation method, technique or standard reference, tool/device result, completion status, processing reference, validation outcome, exception status and final disposition.
The exact evidence set should match the customer's assurance requirements. Avoid collecting unnecessary sensitive information simply to make reports look more detailed.
Do multiple overwrite passes equal NIST compliance?
Do not reduce NIST SP 800-88 Rev. 2 to a fixed number of overwrite passes. Revision 2 intentionally moves away from being a detailed catalogue of sanitisation techniques and directs organisations toward current relevant standards and approved techniques.
The appropriate technique depends on the media and required sanitisation outcome. “Three-pass,” “seven-pass” or similar marketing statements are not substitutes for selecting and validating an appropriate process.
Does factory reset count as Clear?
A reset operation may form part of a Clear technique where it actually sanitises user-addressable storage as required and is appropriate for the device. The label “factory reset” alone does not establish the outcome.
The organisation should understand what the function does on that specific product and whether it is an approved technique for the sanitisation requirement.
Can a sanitised drive be resold?
Potentially, yes, where organisational policy permits external reuse and the required sanitisation has been successfully completed and validated. Asset release should occur only after processing records and exceptions have been reconciled.
This is where secure ITAD and asset recovery can work together: data protection is the gate, and residual value is considered only after that gate has been passed.
Can destruction replace poor inventory control?
No. Destruction does not solve an accountability problem if the organisation cannot prove which media was actually destroyed. Serial-level reconciliation and chain of custody remain important.
A secure process needs both an appropriate sanitisation outcome and evidence that the intended assets reached that outcome.
A practical Clear/Purge/Destroy decision workflow
First identify the asset and all storage media. Determine the sensitivity of the target information and intended disposition. Consult organisational policy and the applicable approved sanitisation standard. Select Clear, Purge or Destroy. Perform the approved technique. Verify completion. Validate the result. Quarantine and resolve exceptions. Reconcile the asset to the source inventory. Only then release the asset for reuse, resale, recycling or final destruction.
Questions to ask an ITAD provider about NIST SP 800-88 Rev. 2
Ask which revision of SP 800-88 they use; how they distinguish Clear, Purge and Destroy; which approved standards and device techniques they rely on; how SSD/NVMe media is handled; how cryptographic erase is validated; what happens when a drive fails; how sanitisation verification and validation are recorded; whether reports are serial-linked; and how exceptions are reconciled before project closure.
Common NIST sanitisation mistakes
Common mistakes include referring to obsolete Revision 1 as current guidance; treating file deletion as sanitisation; using a fixed overwrite-pass count as proof of compliance; applying HDD assumptions to SSD/NVMe; treating encryption alone as cryptographic erase; ignoring failed media; recording a started job as a completed job; skipping validation; and issuing generic certificates that cannot be reconciled to individual assets.
How Compritech applies the framework
Compritech's engineer-led ITAD approach separates the sanitisation requirement from the commercial disposition decision. Assets can be identified, classified by intended disposition, processed using the approved method, validated, reconciled and then routed to reuse, asset recovery, recycling or destruction.
For infrastructure projects, the same process can be integrated with server/storage decommissioning, Cisco and Juniper retirement, onsite engineering, chain of custody and serial-level asset reconciliation.
Final takeaway
The most useful question is not simply “Should we wipe or shred this drive?” It is: what information is on the media, what recovery threat must the organisation protect against, what disposition is intended, which approved technique achieves the required outcome, and can the result be validated and evidenced?
NIST SP 800-88 Rev. 2 provides the programme framework. Clear, Purge and Destroy are the sanitisation methods within that framework; the organisation's risk, policy, media technology and intended reuse determine which method belongs in the workflow.
Related Compritech guides
- Secure Data Erasure vs Physical Destruction
- HDD, SSD and NVMe Destruction: Which Method Should You Use?
- Why an Auditable Chain of Custody Matters in IT Disposal
- How to Securely Decommission Servers and Storage Systems
Primary guidance
- NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
- NIST — Revision 2 publication announcement
- NIST CSRC — Clear
- NIST CSRC — Purge
- NIST CSRC — Destroy
- NCSC — Secure sanitisation and disposal of storage media
Need an auditable media-sanitisation process?
Compritech provides engineer-led ITAD, onsite data sanitisation and destruction, serial-level asset reconciliation, infrastructure decommissioning and evidence-led project closure across the UK.
Discuss your projectControlled data destruction servicesOnsite data destruction