NIST Special Publication 800-88 is the U.S. standard for media sanitization. It defines three levels (clear, purge, destroy) matched to media type and data sensitivity, and it is the backbone of every defensible data destruction program.
The three levels
Clear overwrites data using standard read/write commands: appropriate for lower-sensitivity data staying inside an organization. Purge uses stronger techniques (cryptographic erase, firmware-level sanitize commands, degaussing for magnetic media) that defeat laboratory recovery. Destroy physically ends the media: shredding, disintegrating, or pulverizing. The right level depends on the media type and where the device is headed next: a drive being resold needs verified purge; a drive under a destroy-only policy gets shredded.
The part people miss: verification and documentation
The method is only half the standard. NIST 800-88 also expects verification that the sanitization worked and documentation of what was done to which device. In practice that means a certificate of destruction tied to each serial number and a chain-of-custody record showing the device's path from your dock to final disposition. Without the paper trail, even a perfect wipe is indefensible in an audit.
What to demand from any vendor
- Sanitization aligned to NIST 800-88, with the level matched to your policy
- A certificate of destruction per device, tied to the serial number
- A complete, auditable chain of custody
- Clarity on where the work physically happens
Frequently asked questions
Is NIST 800-88 a certification?
No. It's a standard (a NIST Special Publication) that defines sanitization methods and documentation. Vendors align their processes to it; the proof is in per-device certificates and chain-of-custody records.
Which level do I need?
It depends on media type, data sensitivity, and whether the device will be reused. Resold devices need verified purge; destroy-only policies call for physical destruction. We align the method to your policy per device.
