Skip to main content
Category: NIST Standards & Publications

NIST SP 800-88

Also known as: SP 800-88, NIST 800-88, Guidelines for Media Sanitization
Simply put

NIST SP 800-88 is a publication from the National Institute of Standards and Technology that helps organizations securely remove data from storage devices so it cannot be recovered. It describes methods for wiping or destroying media, generally organized into categories such as Clear, Purge, and Destroy. Organizations use it to set up a media sanitization program with techniques appropriate to the sensitivity of the data and the type of media.

Formal definition

NIST SP 800-88, titled 'Guidelines for Media Sanitization,' is issued and maintained by NIST to assist organizations and system owners in establishing a media sanitization program using techniques suited to the media type and the required level of assurance. It defines sanitization as a process that renders access to target data on the media infeasible for a given level of effort, and in most implementations it organizes methods into categories commonly identified as Clear, Purge, and Destroy. Practitioners should note the publication has been revised over time: Revision 1 (2014) was withdrawn on September 26, 2025, having been superseded by Revision 2 (2025); readers should confirm which revision applies to their environment against the current authoritative NIST text. The guidance itself is non-binding except where incorporated by reference into an organization's policies, contracts, or applicable authorities, and this entry does not address specific contractual, control-baseline, or agency-tailored implementation requirements.

Why it matters

Data that is not properly removed from storage media before disposal, reuse, or return to a vendor can be recovered by someone with the right tools and motivation, exposing Controlled Unclassified Information (CUI), personally identifiable information, or other sensitive data long after a system leaves active service. NIST SP 800-88 matters because it gives organizations a structured, media-aware way to reason about how thoroughly data must be removed based on the sensitivity of the information and the type of storage device, rather than relying on ad hoc wiping practices that may leave data recoverable.

The guidance is frequently referenced when organizations retire laptops, servers, mobile devices, and removable media, and its Clear, Purge, and Destroy categories provide a common vocabulary that compliance officers, ISSMs, and auditors can use to specify and verify sanitization outcomes. Because a single lost or improperly decommissioned device can undermine an otherwise well-run security program, aligning media disposal to a recognized reference such as SP 800-88 helps demonstrate due care.

It is important to keep the publication's role in perspective. SP 800-88 is guidance, not a binding mandate in itself, and it becomes obligatory only where an organization's policies, contracts, or applicable authorities incorporate it by reference. Readers should also confirm which revision governs their environment: Revision 1 (2014) was withdrawn on September 26, 2025, having been superseded by Revision 2 (2025), so citing the correct current text matters for compliance and audit purposes.

Who it's relevant to

Information System Security Managers (ISSMs) and system owners
ISSMs and system owners use SP 800-88 to establish and document a media sanitization program, selecting Clear, Purge, or Destroy methods appropriate to the media type and required assurance level. They are responsible for confirming which revision applies to their environment and for tying sanitization procedures to the sensitivity of the data being handled.
Compliance officers and auditors
Compliance and audit staff reference SP 800-88 as a recognized benchmark when reviewing how an organization removes data from retired or reused media. They should verify whether the guidance is actually incorporated by reference into the organization's policies, contracts, or applicable authorities, since the publication is otherwise non-binding, and confirm that the cited revision is current.
IT asset disposition and property disposal personnel
Staff responsible for decommissioning, reusing, or disposing of laptops, servers, mobile devices, and removable media rely on the Clear, Purge, and Destroy categories to choose an appropriate technique before media leaves organizational control. They should coordinate with security stakeholders to match the sanitization method to data sensitivity rather than defaulting to a single approach.
Government contractors handling sensitive information
Contractors that store CUI or other sensitive data may encounter SP 800-88 where it is invoked through their policies or contractual requirements. Because this entry does not address specific contractual or agency-tailored obligations, contractors should confirm exactly which sanitization expectations apply to them against the governing contract and current authoritative sources.

Inside SP 800-88

Media Sanitization Guidelines
NIST SP 800-88 (Guidelines for Media Sanitization), issued by NIST, provides guidance on sanitizing information system media to prevent unauthorized recovery of data prior to disposal, reuse, or release from organizational control.
Clear
A sanitization method that applies logical techniques to protect against simple, non-invasive data recovery techniques, typically using standard read/write commands. Practitioners should verify the current revision's specific technique descriptions against the authoritative text.
Purge
A sanitization method that applies physical or logical techniques rendering target data recovery infeasible using state-of-the-art laboratory techniques. The applicability of specific purge techniques varies by media type.
Destroy
A sanitization method that renders target data recovery infeasible and typically results in the media being unable to be reused for storage. Examples generally include disintegration, incineration, or shredding, subject to the media type addressed in the guidance.
Media Type Considerations
The guidance generally addresses sanitization approaches that differ by media type, since techniques appropriate for one storage technology may not be effective for another. Readers should confirm applicable techniques for their specific media against the current publication.
Verification and Documentation
The guidance generally emphasizes verifying that sanitization was effective and documenting the process, often including a record or certificate of sanitization to support accountability.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-88.

Does NIST SP 800-88 require physical destruction of all media?
No. NIST SP 800-88 defines multiple sanitization categories, generally Clear, Purge, and Destroy, and does not mandate physical destruction in all cases. The appropriate method depends on factors such as the media type, the confidentiality of the data, and whether the media will be reused, leave organizational control, or be disposed of. Physical destruction is one option, but Clear or Purge may be sufficient in many scenarios. Organizations should select the method based on their own risk decisions and the guidance as written in the applicable revision, and verify requirements against the current authoritative text.
Is completing sanitization under NIST SP 800-88 the same as satisfying my compliance obligations?
Not by itself. NIST SP 800-88 provides guidance on media sanitization, but performing sanitization is distinct from demonstrating compliance. Most implementations also require verification that sanitization was effective and documentation of the process, and the guidance is generally referenced by other control frameworks rather than serving as a standalone compliance mandate. Sanitizing media does not automatically satisfy broader program requirements such as records retention, control implementation evidence, or agency-specific policies, which readers should confirm against their governing framework.
How do I decide between Clear, Purge, and Destroy for a given piece of media?
The selection generally depends on the media type, the confidentiality level of the information, and the intended disposition of the media, for example, whether it will be reused internally, released outside organizational control, or discarded. NIST SP 800-88 provides decision guidance and media-specific considerations to support this determination. Organizations typically make this a risk-based decision aligned with their data classification and disposition policies. Confirm the specific technique for your media type against the current authoritative text, as recommended methods can vary by media technology.
What documentation should accompany a sanitization action?
NIST SP 800-88 generally addresses the value of recording sanitization activities, and many implementations produce a record capturing details such as the media identity, the method applied, verification performed, and the personnel involved. The specific documentation format and retention expectations are usually driven by the organization's governing framework and agency policy rather than dictated by the guidance alone. Readers should align documentation practices with their applicable control baseline and verify content requirements against current authoritative and organizational sources.
How does verification fit into the sanitization process?
Verification is generally treated as a step to confirm that the selected sanitization method achieved its intended result before media is reused or released. NIST SP 800-88 addresses verification as part of the overall process rather than treating sanitization and verification as the same action. The specific verification approach can depend on the media type and the sanitization method used. Organizations should determine appropriate verification steps based on their risk decisions and the applicable revision of the guidance.
Does NIST SP 800-88 apply differently to media leaving organizational control versus being reused internally?
The intended disposition of the media is generally a key factor in selecting a sanitization approach under NIST SP 800-88. Media that will leave organizational control or be released externally typically warrants a different consideration than media that remains under organizational control and is reused internally. The guidance frames these disposition scenarios to help inform method selection, but the precise decision remains organization-specific and risk-based. Readers should confirm the applicable considerations against the current authoritative text and their own policies.

Common misconceptions

NIST SP 800-88 is a binding legal or contractual requirement on its own.
NIST SP 800-88 is guidance issued by NIST. Its binding force generally derives from being referenced by other authorities, contracts, or agency policy rather than from the publication itself. Readers should confirm whether and how it is incorporated into their specific obligations.
Deleting files or reformatting a drive satisfies the guidance.
Routine deletion or reformatting generally corresponds to weaker protection than the Clear, Purge, or Destroy methods described, and does not necessarily prevent data recovery. The appropriate method depends on the media type and the confidentiality of the data involved.
One sanitization method is universally sufficient for all media and all data.
The appropriate method generally depends on media type and the sensitivity of the information. A method effective for one storage technology may not be effective for another, and the selection should be driven by risk and applicable policy rather than a single default.

Best practices

Select the sanitization method (Clear, Purge, or Destroy) based on the media type and the confidentiality level of the data, rather than applying a single default approach.
Verify that sanitization was effective before releasing media from organizational control, and retain documentation such as a certificate of sanitization.
Confirm the applicable techniques for your specific storage technology against the current revision of NIST SP 800-88, since techniques effective for one media type may not apply to another.
Check how NIST SP 800-88 is incorporated into your governing authorities, contracts, or agency policy to determine what is actually required in your environment.
Establish and follow a documented media sanitization process covering disposal, reuse, and release scenarios.
Treat sanitization decisions as risk-based, giving stronger consideration to Purge or Destroy for higher-sensitivity data such as media that may contain CUI or other protected information.