Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

NIST 800-88 Media Sanitization Guide for Businesses (2026)

Technician removing an SSD for NIST 800-88 media sanitization at a secure workbench

NIST 800-88 is the federal guideline most businesses point to when they say a drive was “wiped properly.” It explains how to make data on a retired laptop, server, phone, copier or cloud volume unrecoverable before the device leaves your control. The current version, NIST SP 800-88 Revision 2, was published in September 2025, so certificates and IT policies written before then cite the 2014 version it replaced.

This guide explains what changed, how to choose between clear, purge and destroy, why SSDs need different handling than hard drives, what a certificate of sanitization should show, and why you must check for a legal hold before anything is destroyed. If you want the work done and documented for you, Honeybadger provides secure data destruction and NIST media sanitization services with a certificate for every drive.

This is general information, not legal advice; confirm your specific retention and disposal duties with counsel or your assessor.

Key takeaways

  • NIST SP 800-88 Rev. 2 (September 2025) replaced Rev. 1, which NIST withdrew on September 26, 2025.
  • Clear protects against simple recovery, purge against state-of-the-art lab recovery, and destroy leaves the media unusable. NIST says to use purge instead of clear when possible.
  • Multi-pass overwriting is unnecessary, and on SSDs it gives very little protection. Degaussing does not work on SSDs.
  • A certificate of sanitization should list each drive’s make, model and serial number, the method, technique, tool and version, and who verified it.
  • Before you wipe or shred anything, confirm in writing that no legal hold, preservation letter or investigation covers the device.

Where this guidance comes from. This article is based on NIST SP 800-88 Rev. 2 (September 2025) and the NIST FAQ for that publication (July 2026), the FTC Disposal Rule (16 CFR Part 682), the FTC Safeguards Rule disposal requirement (16 CFR 314.4), the HHS guidance on HIPAA disposal, Arizona’s records disposal statute (A.R.S. 44-7601), and Federal Rule of Civil Procedure 37(e). It also reflects what our veteran-led forensics team finds on drives that were supposedly erased.

What changed in NIST 800-88 Revision 2

NIST published Revision 2 of SP 800-88, Guidelines for Media Sanitization, in September 2025. It superseded Revision 1 from December 2014, and NIST withdrew Rev. 1 on September 26, 2025. If your policy, vendor contract or certificate template says “NIST SP 800-88 Rev. 1,” it is time to update the reference.

According to NIST’s July 2026 FAQ, Rev. 1 leaned on media-specific technique tables, while Rev. 2 asks organizations to run a sanitization program, with:

  • A written storage sanitization policy that maps your data classification (low, moderate, high) to acceptable methods.
  • Sanitization assurance, split into verification (did the tool finish without errors?) and validation (is the result good enough for this data?).
  • A new term, information storage media (ISM), that covers physical drives as well as cloud, container and object storage.
  • A decision flow based on data sensitivity and whether the media will be reused inside or outside the organization.

For device-specific techniques, Rev. 2 points to the IEEE 2883 standard instead of its own tables. The one technique NIST still covers in depth is cryptographic erase, because self-encrypting SSDs rely on it.

Clear vs purge vs destroy under NIST 800-88

NIST 800-88 defines three sanitization methods. The right one depends on data sensitivity, media type and whether the device will be reused.

MethodProtects againstDevice reusable?Typical techniquesGood fit
ClearSimple, non-invasive recovery through the normal interfaceYesSingle-pass overwrite of user-addressable space; factory reset where rewriting is not supportedLow-sensitivity data staying in house
PurgeRecovery even with state-of-the-art laboratory techniquesUsuallyDedicated sanitize commands, block erase, cryptographic erase; degaussing for some magnetic mediaDevices sold, donated, returned from lease or redeployed
DestroyRecovery with state-of-the-art laboratory techniques; media can never store data againNoDisintegrate, incinerate, melt; shred or pulverize only for the lowest-sensitivity dataFailed drives and the most sensitive data

Clear uses the device’s normal read and write commands, usually a single overwrite pass, or a manufacturer reset on equipment that cannot be rewritten. It stops ordinary undelete tools, not a laboratory. The old habit of overwriting in many passes, sometimes up to 39 and often citing a DoD standard that DoD dropped in 2006, is unnecessary according to NIST, and it wears out flash media.

Purge makes recovery infeasible even for a lab while usually leaving the device usable, through sanitize commands, block erase or cryptographic erase. NIST states that purge should be used instead of clear whenever possible.

Destroy means the media can never store data again. NIST warns that bending, cutting or drilling a hole may leave readable areas, and that shredding and pulverizing should be avoided for anything but the lowest-sensitivity data because modern storage is so dense. The July 2026 FAQ points to incineration, smelting or melting for medium- and high-sensitivity SSDs.

Why SSDs need different handling than hard drives

Flash storage, including SSDs, phones and USB drives, uses spare cells and wear leveling to spread writes across the chip. NIST says this makes it infeasible to sanitize all previous data by overwriting through the normal interface.

Degaussing should not be used on SSDs at all; NIST notes a degausser can report success on an SSD while sanitizing nothing. Use the drive’s sanitize commands or cryptographic erase instead. For the recovery side of the same problem, see our guide to SSD forensics and data recovery.

When is cryptographic erase enough?

Cryptographic erase (CE) destroys the keys that encrypt the data. It is fast and counts as purge only when NIST’s conditions are met:

  • No sensitive data was stored on the media in plaintext before encryption was turned on.
  • The encryption has a security strength of at least 128 bits, such as AES, and federal agencies must use FIPS 140 validated modules.
  • The keys themselves are sanitized, and no backed-up or escrowed copy is left unaccounted for.
  • For data that must stay secret for decades, future weaknesses in the algorithm could make CE unacceptable.

For cloud storage, CE is often the only viable purge method, so check how your provider manages keys.

Retiring laptops, servers or a whole office? Send us the device count, the types of media and whether any drives have failed, and we will quote sanitization and certificates per drive. Request data destruction online, or book a consultation online if you want to talk through a policy first.

How to choose a sanitization method: the decision factors

NIST 800-88 asks you to make the choice based on risk, not habit. The decision usually comes down to four questions:

  • How sensitive is the data? Classify it as low, moderate or high confidentiality.
  • Will the device be reused? NIST notes that if media will not be reused, destroying it can be the simplest and most cost-effective option.
  • Will it leave your control? Lease returns, donations, resale, recycling and warranty swaps all move media outside your control.
  • What type of media is it? Hard drives, SSDs, phones, copiers and cloud volumes each need a matched technique.

For example, a hypothetical dental office donating old laptops would purge and certify each drive, while a failed server drive would go to physical destruction.

What a certificate of sanitization should show

NIST says a certificate of sanitization should be completed for each piece of media, on paper or electronically. It should record at least:

  • Manufacturer, model and serial number, plus any property or asset tag number.
  • Media type and media source, such as the user or computer it came from.
  • The sanitization method (clear, purge or destroy) and technique (for example overwrite, block erase or cryptographic erase).
  • The tool used, including its version, and the verification method.
  • The name, title, date, location, contact information and signature of the person who verified and validated the work.

A certificate is only as good as your asset records. NIST recommends tracking media from the day it arrives to its final destination; otherwise certificates prove some drives were sanitized, not all of them.

Check for a legal hold before any destruction

This is the step most disposal checklists skip. Federal Rule of Civil Procedure 37(e) applies when electronically stored information that should have been preserved for litigation is lost because a party did not take reasonable steps, and it cannot be restored or replaced. A court can order measures to cure the prejudice. If it finds intent to deprive the other side of the information, it can presume the lost data was unfavorable, instruct the jury to do the same, or dismiss the case or enter a default judgment.

The 2015 committee note says the duty to preserve generally starts when litigation is reasonably foreseeable, which can be well before a lawsuit is filed. A demand letter, a regulator’s inquiry or an internal investigation can all trigger it. NIST 800-88 makes a related point: consult your privacy and records retention owners before sanitizing.

A practical hold check before every disposal job looks like this:

  1. List the devices by serial number and assigned user.
  2. Ask legal whether any hold, preservation letter, subpoena or investigation covers those users or systems.
  3. Get written confirmation from an authorized person for each batch.
  4. If a device is covered, set it aside or have a forensic image made under chain of custody before any wipe.
  5. Keep the confirmation with the certificates.

Departing employees are the classic trap, because reimaging a laptop can erase the best evidence of data theft. Our guides to forensic data recovery after wiping and forensic data preservation and legal holds explain what can and cannot be recovered.

Which laws require secure disposal of business data?

No single law makes every business follow NIST 800-88, but several rules require reasonable disposal. As of October 2026:

  • FTC Disposal Rule, 16 CFR Part 682. In effect since June 1, 2005, it covers anyone holding consumer report information for a business purpose, such as employers and landlords who run background checks. Disposal includes selling, donating or transferring computer equipment that stores it, and electronic media must be erased or destroyed so the data cannot practicably be read or reconstructed.
  • FTC Safeguards Rule, 16 CFR 314.4(c)(6). Covered financial institutions must securely dispose of customer information within two years of its last use unless it is still needed or legally required. See our FTC Safeguards Rule compliance checklist.
  • HIPAA Security Rule, 45 CFR 164.310(d)(2). Covered entities and business associates need policies for disposing of electronic PHI and its media and for removing it before reuse. HHS refers readers to NIST SP 800-88.
  • Arizona, A.R.S. 44-7601. It bars discarding records pairing a name with a full Social Security, card, account or driver license number unless redacted or destroyed, but it applies only to paper records and exempts GLBA, HIPAA and FCRA entities.

Disposal failures can also become breaches. NIST notes that in some jurisdictions simply losing control of sensitive information is enough to count as a breach, so a resold drive holding names and account numbers can trigger notice duties under your state’s breach law. Health practices should also review our guide to physical security for PHI under HIPAA.

NIST 800-88 media sanitization checklist for businesses

Use this sequence for each disposal batch, whether you do the work in house or hire a vendor:

  1. Write or update a sanitization policy that maps your data classes to clear, purge or destroy and cites Rev. 2.
  2. Inventory every device and loose drive by serial number, including copiers, printers, phones, firewalls, USB drives and backup media.
  3. Run the legal hold check and get written sign-off.
  4. Classify the data on each device and decide whether it will be reused, and where.
  5. Pick the technique for each media type; use sanitize commands or cryptographic erase for flash, and destruction for failed drives.
  6. Sanitize, then verify the tool completed without errors.
  7. Validate the result against the sensitivity of the data.
  8. Issue a certificate per drive and reconcile it to the asset list.
  9. Rebuild, return, donate or recycle the device, and keep the records.

How to choose a NIST 800-88 data destruction provider

The FTC Disposal Rule expects due diligence on disposal vendors, such as reviewing audits, references, certifications and security policies. Ask any provider:

  • Do your certificates cite SP 800-88 Rev. 2 and list every field NIST recommends, per drive?
  • How do you handle SSDs, phones and self-encrypting drives?
  • What happens to failed drives, and is destruction certificated separately?
  • How is chain of custody kept from pickup or shipping through final disposition?
  • Do you require a written legal hold check before you start?

How Honeybadger handles NIST 800-88 data destruction

Honeybadger Solutions is a veteran-owned firm in Casa Grande, Arizona, and an Arizona DPS-licensed private investigation agency (License No. 1759795). Our sanitization work sits beside our forensics practice, so we know how much a careless wipe leaves behind.

  • Per-drive sanitization with verification, matched to the media type, and a certificate for each drive with the fields NIST lists.
  • A written hold check before any work, and a forensic image under chain of custody if a device turns out to be covered.
  • Physical destruction with chain of custody for failed or high-sensitivity drives, quoted separately.
  • Asset tracking and secure rebuilds through our managed IT services.

We sanitize only devices you own or may dispose of, and we will not destroy data under a legal hold. Send your device list and hold confirmation through the request form, or book a consultation if you need a policy written first.

Why the online intake is faster than a phone call. The request takes about two minutes. Picking the service routes it straight to the specialist team that handles that type of case, so there is no phone tag and no waiting for a call-back to explain it all again. For anything happening right now, use the urgent intake form.

Frequently asked questions

Is NIST 800-88 Rev. 1 still valid?

No. NIST withdrew SP 800-88 Rev. 1 on September 26, 2025, when it published Rev. 2. Policies, contracts and certificate templates should now cite Rev. 2.

Is a factory reset enough to meet NIST 800-88?

At best it meets the clear method, and only if the device interface cannot retrieve the original data. NIST prefers purge whenever possible, such as a sanitize command or cryptographic erase.

Does NIST still recommend multi-pass overwrites like the DoD 7-pass method?

No. NIST’s July 2026 FAQ says multi-pass overwriting is unnecessary. A single pass is typical for clear, and on SSDs overwriting gives very little protection.

Can you degauss an SSD?

No. Degaussing relies on magnetism and should not be used on flash storage. NIST gives the example of an SSD degaussing job that completes successfully while sanitizing nothing.

What should a certificate of sanitization include?

The make, model and serial number, media type, method and technique, tool and version, verification method, and who verified the work, when and where, with a signature.

Do we need to check for a legal hold before destroying old drives?

Yes. If data that should have been preserved for litigation is lost, FRCP 37(e) lets courts order curative measures, and with intent to deprive, adverse inferences or dismissal. Get written confirmation that no hold covers each device first.

Sources and further reading

Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.