What you need to know
NIST SP 800-88 Rev. 2 emphasizes a governed media-sanitization program, appropriate clear, purge, or destroy methods, and separate verification and validation.
Potentially affected
Camera SD cards, recorder HDDs and SSDs, appliance flash, removable export media, virtual or cloud storage, and other information storage media leaving use or control.
DSE recommendation
Classify the stored information, select an approved method using current technical guidance, verify execution, validate residual risk, and retain disposition evidence.
Rev. 2 is a program, not a wipe-command table
Source fact: NIST SP 800-88 Rev. 2 defines media sanitization as making access to target data infeasible for a given level of effort. The revision shifts emphasis from media-specific command tables toward an enterprise program that protects sensitive information during reuse or disposal.
NIST organizes the program around three methods: clear, purge, and destroy. Its July 2026 FAQ says policy should connect information classification to acceptable methods and define documentation, evidence, roles, training, tool configuration, maintenance, verification, and validation. Rev. 2 does not recommend a specific command for each product; it points organizations toward current standards and approved policy.
The FAQ also rejects a common shortcut: a seven-pass overwrite is not required. NIST says legacy multi-pass practices provide little additional confidentiality for modern storage and can shorten flash-media life. Sanitizing the entire information-storage-media device is preferred because selected data can spill into overprovisioned areas, remapped bad blocks, or other locations outside a logical boundary.
Verification and validation are different
Verification checks whether the sanitization technique completed without technical errors or anomalies. Validation is the organizational decision that reviews that evidence against data sensitivity and accepts any residual confidentiality risk. Both are needed for sanitization assurance.
Cryptographic erase is not automatically valid because a product used encryption. NIST lists prerequisites including adequate cryptographic strength, no prior sensitive plaintext outside the protected boundary, and permanent zeroization of the relevant keys. Cloud or virtual storage introduces additional service and key-management dependencies.
DSE disposition checklist
DSE recommendation: This is DSE operational synthesis. Confirm preservation obligations and approved techniques before changing media.
- Inventory every storage location, including removable, embedded, replica, archive, cloud, and exported copies.
- Confirm that retention requirements, investigations, legal holds, and evidence-preservation needs permit disposition.
- Classify the information and determine whether media stays inside organizational control or leaves it.
- Select clear, purge, or destroy through approved policy, current industry guidance, and device-manufacturer capabilities.
- Prefer whole-media sanitization; document and approve any selective approach and its encrypted boundary.
- Verify that the technique completed successfully and retain logs or tool output.
- Have an authorized role validate effectiveness and accept residual risk.
- Record media identity, method, date, operator, verifier, validator, destination, exceptions, and certificate of sanitization.
Official references
- NIST SP 800-88 Rev. 2: Guidelines for Media Sanitization — the September 26, 2025 final publication.
- Frequently Asked Questions for NIST SP 800-88r2 — the July 16, 2026 program, method, overwrite, assurance, and cryptographic-erase clarifications.
Review the official source
NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization · Published September 26, 2025
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE