Skip to main content
Data Center Exit

NIST 800-88: what Revision 2 changed, and what it asks of you

Revision 2 reached final status on 26 September 2025. A great deal of what is written about media sanitization, including pages ranking on this subject today, still describes Revision 1. What moved is not cosmetic.

What the document is, and what it is not

NIST SP 800-88 Revision 2, Guidelines for Media Sanitization is the United States reference for removing data from storage media so that it cannot be recovered. It is published by NIST, it is free, and anybody selling you sanitization has read it or should have.

It is guidance, not law. It becomes an obligation for one organization through something else: a contract, a sector regulator, a certification scheme, an insurer, or an internal policy that adopts it. Which of those reaches you is a question about your organization and not about the document, and a vendor telling you that NIST requires something of you is describing a route they have not named.

The four things Revision 2 moved

Summarised from the publication notice. The document itself is the authority, and it is worth an hour of anybody’s time who signs off on a decommission.

1. From techniques to a program

Revision 1.
Revision 1 read as a catalog: here are the media, here are the methods.
Revision 2.
Revision 2 shifts the focus toward establishing an agency or enterprise media sanitization program. The unit of analysis stops being the drive and becomes the organization's rule for drives.

What that means for you. If a vendor proposes a method before asking who classified your data, they are answering the Revision 1 question. The current one starts earlier.

2. From described procedures to current standards

Revision 1.
Revision 1 described the procedures inside the document itself.
Revision 2.
Revision 2 replaces those descriptions with recommendations to comply with the latest relevant standards, which is a maintenance decision: storage media change faster than a reference document can be revised.

What that means for you. Work sold as being “to NIST 800-88” now has to name the execution standard it actually follows. Without that, the reference has become a label.

3. Validation becomes part of the text

Revision 1.
Revision 1 concerned itself principally with performing sanitization.
Revision 2.
Revision 2 introduces sanitization validation: confirming that the operation achieved its purpose, judged against the confidentiality and sensitivity of the data involved.

What that means for you. This is the difference between a vendor asserting that drives were wiped and demonstrating it. On a lot of several thousand, it is the only part an auditor examines.

4. Logical sanitization and cloud enter scope

Revision 1.
Revision 1 was written for media you could hold.
Revision 2.
Revision 2 addresses modern storage environments, including logical sanitization where there is no physical device to destroy.

What that means for you. A data hall exit that leaves data in an associated cloud tenancy is not complete, and the exit plan has to account for it in writing.

The through-line

Both of the substantive changes push in the same direction: away from what was done to a device, and toward what the organization can show. A program rather than a technique. Validation rather than assertion. That is also, not by coincidence, what somebody auditing your exit will ask for, and it is why what your certificate of destruction contains matters more than which machine processed the drives.

Five things that catch out serious people

None of these is an opinion, and every one of them has produced a lot of media that somebody believed was handled.

Degaussing does nothing to an SSD

A degausser works by collapsing a magnetic field, which is exactly how a spinning hard drive stores data and exactly not how flash memory does. Passing an SSD through a degausser produces a device that looks processed and is not. The same applies to any solid state medium: NVMe drives, memory cards, USB sticks.

Ask this. A mixed lot of HDDs and SSDs processed by a single degaussing step has been half processed. Ask which devices were which, and what was done to the SSDs instead.

A quick format is not sanitization under any reading

Formatting rewrites a table of contents. The data stays on the platters or in the cells until something overwrites it, and recovery tools are sold openly to anybody.

Ask this. If a supplier's process description contains the word format and nothing stronger, the process is not what you think you bought.

Encryption is a strong answer only if the key is truly destroyed

Cryptographic erasure works by destroying the key rather than the data, and it is fast and legitimate. It rests entirely on the key being unrecoverable, and on the drive having genuinely encrypted everything from first use rather than from the day somebody turned it on.

Ask this. Ask when encryption was enabled on each device, and how the key destruction is evidenced. Those two answers are the whole of the method.

A drive that will not power on has not been sanitized

It has been set aside. The data on a dead drive is often perfectly recoverable by somebody with a clean room, and a dead drive is exactly the one that ends up in a corner rather than in the process.

Ask this. A lot of 340 drives with 6 dead ones needs a written rule for the 6, decided before the lot leaves your building.

Shredding is a size question, not a yes-or-no question

Physical destruction reduces media to particles, and how small those particles have to be depends on the density of what was stored. A shred size that was adequate for a drive of one era is not automatically adequate for a denser one.

Ask this. Ask for the particle size in the specification, not simply that shredding took place.

The decision the standard will not make for you

Which category applies to which media follows from how sensitive the data is and where the device is going afterwards. That classification belongs to the organization that owns the data, and it is the one part of this no vendor can supply, because they do not know what is on the drives.

A supplier who proposes a method before asking about classification is offering a product. One who asks first is doing the work. The difference shows up in the first conversation and costs nothing to test.

What has to appear on the document at the end is on certificate of destruction, what each stage of destruction involves is on secure data destruction, and what happens to hardware that is erased rather than destroyed is on IT asset disposition. How to check the vendor applying any of it is on the ITAD page.