NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
Every retention schedule ends in an action: at some point data has to actually go, and something has to show that it went. When the storage it lived on leaves your control — returned leases, recycled laptops, decommissioned servers, a cloud contract ending — the phrase doing the work in the policy is usually “securely erased”, and the reference we most often see behind that phrase is NIST SP 800-88. In September 2025 NIST revised it for the first time since 2014 and withdrew the 2014 edition the same day — so paperwork written before then that names SP 800-88 now points at a withdrawn document. This page covers what the new edition says, and what may be worth re-reading in your own.
- Published by
- The National Institute of Standards and Technology (NIST), an agency of the US Department of Commerce. Authors: Ramaswamy Chandramouli (NIST) and Eric Hibbard (Samsung Semiconductor). We have no relationship with NIST and inclusion here is not an endorsement in either direction.
- Type
- NIST Special Publication — final, published 26 September 2025 (initial public draft 21 July 2025). Supersedes SP 800-88 Rev. 1 of 17 December 2014, which NIST marked withdrawn on the same day; Rev. 1 had itself replaced the 2006 original. A 13-question FAQ, dated 16 July 2026, followed, and it is the quickest way we have found into what changed.
- Jurisdiction
- A US federal instrument, written against FISMA and OMB Circular A-130 — but the method (match the sanitization method to the sensitivity of the data and to where the media goes next) is jurisdiction-neutral, and nothing in it depends on US law. It is not binding in the UK, and UK GDPR names no sanitization standard; what UK law requires is the outcome — personal data kept no longer than necessary (Art. 5(1)(e)), protected against unauthorised processing, accidental loss and destruction (Art. 5(1)(f), Art. 32(1)), and deleted or returned by a processor at the end of the service (Art. 28(3)(g)). The ICO’s data protection audit framework carries a dedicated disposal and deletion toolkit under records management (currently marked as under review following the Data (Use and Access) Act 2025), and elsewhere the ICO’s long-standing position on deletion is that where full deletion is not technically possible, data must at least be put beyond use. Worth noting as you read the two together: the ICO toolkit still names degaussing and hardware shredding among the ways to meet its expectations, while Rev. 2 would put both in a narrower place — something to know before a disposal procedure is written against either alone.
- Primary audience
- Whoever owns the retention schedule, the asset-disposal procedure, the decommissioning plan or the processor exit clause — DPOs and privacy teams working alongside security, IT asset management and procurement.
- Topic tags
- media sanitization · secure erase · cryptographic erase · storage limitation · asset disposal · retention · processor exit
- Availability
- Free PDF from csrc.nist.gov (DOI 10.6028/NIST.SP.800-88r2), with the FAQ alongside. No registration.
Why it matters
Rev. 1 was, at its heart, a set of lookup tables: find your media type, apply the listed technique. NIST’s own FAQ describes the shift in Rev. 2 plainly: the focus moves from hands-on techniques to running a media sanitization programme — the three methods (clear, purge and destroy) treated in depth, a decision flow driven by the sensitivity of the data and by whether the media is reused inside the organisation, leaves it, or is disposed of, and a deliberately wider term, information storage media (ISM), adopted so that virtual and logical storage — cloud, containers, object storage — sits in scope alongside drives and tape. For technique-level detail per media type, Rev. 2 now points outward to evolving industry standards, IEEE 2883 in particular, rather than carrying its own tables.
Four positions in the new edition are worth reading against your own procedures, because each may contradict something written down years ago and still faithfully followed. All four are stated in NIST’s FAQ:
- Multi-pass overwriting is unnecessary. For modern storage, the old multi-pass patterns “achieve very little confidentiality protection” and can significantly shorten the life of flash media. Under the clear method, an overwrite of user-addressable space, typically in a single pass — or a manufacturer factory reset where rewriting is not supported — is the position.
- Degaussing is no longer a destroy method. Rev. 2 treats it as a physical purge technique for legacy magnetic media only: it can render a drive inoperable yet still fail to sanitize the data where flash or hybrid components are present, or where the degausser’s field strength is mismatched to the media’s coercivity. It remains available as a purge technique for purely magnetic media — the narrowing is about what counts as destruction.
- Shredding and pulverising are for the lowest security categories only. Counterintuitive enough that the FAQ takes it as a question: Sec. 3.1.3 says these techniques “should be avoided for anything but the lowest security categories of data”, because modern data density means fragments can retain recoverable data. For higher categories the direction is high-powered degaussers from the NSA’s Evaluated Products List for magnetic media, and incineration or melting for the rest. The industry standards the FAQ cites are close but not identical on this: IEEE 2883 deprecates shredding and pulverising as destruction methods for all modern HDDs and SSDs, while ISO/IEC 27040:2024 still lists both and recommends melting specifically where high-sensitivity media leaves organisational control.
- Cryptographic erase carries preconditions. No sensitive data ever stored in plaintext before the encryption keys were established, security strength of at least 128 bits, random-number entropy matching or exceeding the key length, and permanent zeroization of the target keys. FIPS 140-validated modules are a US federal requirement; the read-across for everyone else is that cryptographic erase is only as good as the key management underneath it.
The part that earns the entry for a UK reader is the virtual-media section. Where you never touch the physical media, the FAQ is candid that cryptographic erase is often the only viable purge method, and that organisations must review their cloud service agreements to ensure keys are securely managed and zeroization can be traceably validated. That is a contract question, not a data-centre question, and it lands squarely on Art. 28(3)(g): the deletion a processor owes at exit is, in practice, a key-destruction event, and the evidence worth asking for is the validation record. Rev. 2’s sanitization assurance split gives that record its shape — verification (the operational check that the technique completed without error) and validation (a decision, by someone with authority, that the outcome is acceptable against the sensitivity of the data, with the residual risk formally accepted). A certificate of sanitization that shows both is an artefact a retention schedule, a DPIA or an Art. 30 record can point to with confidence.
Done well, the same record serves everyone it touches. It closes the storage-limitation loop the policy promised, answers an auditor or a due-diligence questionnaire in a sentence, lets hardware be reused, remarketed or returned off-lease without a second thought, and delivers the people whose data it was the outcome the retention notice described. Disposal is one of the few controls where the organisation’s interest and the data subject’s interest point exactly the same way.
The practical check is small. Read the disposal clause in your DPAs and exit schedules, the disposal column of the retention schedule, and the certificates your disposal vendor issues. Where they name SP 800-88 Rev. 1 or a legacy multi-pass pattern, nothing suddenly broke on 26 September 2025 — but a disposal record that cites a withdrawn standard invites a question that costs very little to close: repoint the citation, and while the document is open, check that the named method still matches the media you actually hold.
Is there a European equivalent?
Not that we are aware of at EU-institution level — neither the EDPB nor ENISA publishes a sanitization standard. The route a European organisation usually takes is the international standards NIST’s own FAQ points to: ISO/IEC 27040:2024, which structures storage sanitization around the same clear, purge and destruct categories, and IEEE 2883 for device-level techniques. The nearest regulator-authored treatment we have found sits in the CNIL security guide from issue #6: factsheet 15, Supervising the maintenance and end-of-life of hardware and software, requires data to be securely deleted before equipment is disposed of, sent for repair or returned at the end of a rental contract, warns against reusing, reselling or discarding media without secure deletion — and notes that France’s ANSSI certifies dedicated data-deletion software.
Germany comes closest to a national equivalent, with two instruments at different layers. DIN 66399 is the destruction standard — the protection classes and P/F/O/T/H/E security levels that European disposal vendors print on destruction certificates; its terms were internationalised as ISO/IEC 21964:2018. It covers physical destruction only — no logical erase, no cryptographic erase — so it complements SP 800-88 rather than replacing it: a certificate quoting an H-5 particle size answers how small the pieces were, not Rev. 2’s validation question. BSI IT-Grundschutz module CON.6, Löschen und Vernichten (Edition 2023) is the programme layer — procedural and organisational requirements for deletion and destruction across analogue and digital media, and the closest German analogue to Rev. 2’s programme focus.
SP 800-88 Rev. 2 is listed in our Standards & Frameworks directory. Read alongside the CNIL Practice Guide — Security of Personal Data from issue #6, which covers the wider Art. 32 baseline this sits inside — disposal is one control among its twenty-five factsheets, and this is the document to open when that one control has to carry weight.
