
September 30, 2026 · 7 min
NIST SP 800-88: what the guideline defines, and what a certificate that cites it does not
Fifty searches a month at $21.08, plus ninety for data destruction standards that nobody bids on. Both readers want the same thing: to know what the reference on the certificate actually commits the vendor to.
NIST SP 800-88 is the document most often named on data destruction certificates in the United States. It is a guideline for media sanitization published by a federal standards body, and what follows is how we read it and how we think a buyer should read a certificate that cites it. It is not a substitute for the document, which is public, and it is not legal advice. Where your obligations depend on it, the text and your counsel decide, not this page.
What the document is, and what it is not
It is a set of guidelines: a vocabulary for sanitization outcomes, a way of thinking about which outcome a given piece of media and a given data sensitivity call for, and guidance on verifying and documenting the result. It is not a certification scheme. As far as we are aware, no body audits vendors against it and issues them a badge, and a vendor who says they are certified to it should be asked what they mean. It is also not a law. Regulations and contracts may point to it as a reference for acceptable practice, and whether yours do is a question for the text of those regulations and contracts.
Clear, purge, destroy: categories, not brands
The guideline groups sanitization outcomes into categories. In outline, and as we understand it: clear describes methods that protect against simple, non-invasive recovery, typically by overwriting through standard commands; purge describes methods that protect against recovery using laboratory techniques, which may include cryptographic erase, dedicated sanitize commands or degaussing depending on the media; destroy describes methods that render the media unusable and the data infeasible to recover, such as shredding or disintegration. The categories describe the level of assurance achieved, not a product. Two vendors can both perform a purge with different tools, and one tool can achieve different categories on different media.
Media type decides which categories are available
This is the part of the guideline that does the most work in practice. The same method does not produce the same category on every device: a technique that purges one kind of media may only clear another and may do nothing meaningful to a third. The guideline addresses this media by media, which is why a competent vendor identifies the media type of each device before choosing a method, and why the choice discussed in destruction or verified erasure has to be made per device rather than per job.
Verification and the record
The guideline treats verification and documentation as part of sanitization, not as an afterthought. Read it for what it says about confirming the result and about what a record should contain. In our practice that translates into a verified result per device where erasure is used, a witnessed or recorded destruction where it is not, and a line per serial number stating the method, the category claimed, the date and the operator.
How to read a certificate that cites it
A certificate that says the work was performed in accordance with NIST SP 800-88 is making a claim per device, whether or not it is laid out that way. So the questions are per device: which category is claimed for this serial number, by which method, on which media type, and how was the result verified. If the certificate cannot answer those for a given device, the citation is decoration. The general anatomy of a defensible certificate is in the certificate article.
What the citation does not certify
It does not certify the vendor, because nothing in the guideline does. It does not certify that the method was applied correctly on the day; that rests on the vendor’s process and on your custody chain. It does not certify that every device reached the bench, which is a chain of custody question the guideline is not about. And it does not establish that your regulatory obligations are met, because whether a given category satisfies a given obligation depends on the obligation, and that is a reading of your regulation, with counsel, not a reading of the guideline.
Other standards you will see named
Certificates and proposals also cite military and departmental overwriting standards, industry certifications for facilities, and internal procedures with impressive names. Treat each the same way: find out what the document actually is, whether it is a method, a guideline, or a third-party audit, and what it says about the specific device in front of you. A standard cited without a category and a method is a word on a page.
Ask for the document, then ask the vendor
Read the guideline, then ask any vendor, including us, which category they will claim for each media type on your register and how they verify it. We answer that per device, and the record we produce is described on the secure data destruction page.
Ask us which category we claim, per media type
We answer per device: method, category, verification. Send the media types on your register and we put it in writing.
Data Center Exit is an independent reference on buying a data hall decommission. It decommissions nothing, destroys no media and holds no certifications of its own. It explains what a defensible chain of custody has to contain, which certificates are verifiable and how, and what to specify before a vendor quotes.