Understanding NIST 800-88: Clear, Purge, and Destroy Explained

15/02/2022

NIST 800-88 is a globally recognized standard for media sanitization that provides guidance on securely removing data from storage devices so it cannot be recovered. The standard defines three sanitization outcomes: Clear, Purge, and Destroy, helping organizations protect sensitive information when IT assets are reused, resold, redeployed, or disposed of.
With data breaches averaging US$4.4million in 2025, according to IBM’s Cost of a Data Breach Report, organizations continue to face escalating risks as storage technologies evolve and attack surfaces expand. This makes it more critical than ever to implement a watertight strategy for the safe handling and sanitization of your business’s data.

NIST SP 800-88 Revision 2 (r2), the latest update to the U.S. government’s media sanitization guidelines, introduces a modern, program-focused framework to ensure sensitive information is removed safely and consistently from information storage media (ISM) before reuse, resale, redeployment, or disposal. The updated standard, focused on enterprise program governance rather than standalone wipe actions, helps organizations meet legal, regulatory, and cybersecurity obligations while reducing the risk of residual data exposure.

It’s also business-critical to ensure that your assets are handled by a third party that adheres to a strict set of standards and has a process that ensures confidential information doesn’t reach unintended or inappropriate parties. Additional challenges to consider regarding data protection include country-specific requirements, economic viability, and your own legal requirements. NIST 800-88 is one of several sets of guidelines for the sanitization of data-bearing technology assets.

SK Tes supports organizations worldwide by delivering secure, standards-aligned data sanitization, wherever assets are located. SK Tes has been recognized by Gartner as the largest global ITAD vendor in the world, allowing us to deliver this service at unmatched levels of consistency. Contact us to discuss your requirements today.

Contents 

What is media sanitization?

Media sanitization is defined by NIST as:

“a process that renders access to target data on information storage media (ISM) infeasible for a given level of effort.”NIST SP 800-88 R2.

Under NIST SP 800-88 Revision 2 the focus shifts away from device-specific wipe techniques and toward a broader, program-driven, risk-based approach that ensures data confidentiality across all stages of the sanitization process. The new standard replaces all specific instructions with: ‘Refer to IEEE 2883 for technique selection.” Click here to find out more about the IEEE 2883-2022 data destruction standard.

Organizations generate vast amounts of data, including personal and sensitive data, standard business data (phone lists, marketing information, supplier data, etc.), confidential business data (business reports, financial and accounting documents, balance sheets, and annual financial statements), top secret business data (research and development of business enterprises), and banking information. This data may reside across a wide range of ISM types: HDDS, SSDs, flash media, mobile devices, servers, memory components, networking equipment, and even cloud or virtualized environments.  

Therefore, data sanitization decisions must consider:

  • What will the media be used for in the future? For example, a shredded device is permanently unusable, whereas Clear or Purge may allow reuse.

  • How confidential is the data? Higher sensitivity typically requires Purge or Destroy.

  • What storage medium is being sanitized? Device behaviour varies widely, particularly between magnetic and flash-based media.

NIST r2 reinforces that the security concern lies in the formation stored on the information storage media – not the device itself:

 

The information security concern surrounding media sanitization arises from the information stored on the ISM. Improper handling or disposal can lead to unauthorized disclosure. – NIST SP 800-88r2

 

What is NIST? 

The National Institute of Standards and Technology (NIST) is a physical science laboratory and a nonregulatory agency of the United States Department of Commerce. Founded in 1901, it has a long history of developing measurements, metrics, and standards that can be applied to the science and technology industries. This makes NIST the ideal institution for offering guidance on how organizations and their employees can properly handle confidential data stored on electronic devices. 

What is NIST 800-88?

NIST 800-88, (Guidelines for Media Sanitization), is a framework that helps organizations securely remove data from information storage media. Its goal is to ensure information cannot be recovered after a device is reused, redeployed, sold, recycled, or destroyed.

Originally developed for U.S. government agencies, NIST 800-88 is now widely adopted by enterprises worldwide as a best-practice standard for secure data sanitization. The framework applies to hard drives, SSDs, mobile devices, servers, storage arrays, and other information storage media.   

Department of Defense (DoD) 5220.22

Prior to the publication of the NIST 800-88 guidelines, organizations typically used the U.S. Department of Defense (DoD) 5220m standard. This standard was originally created for the military and was later adopted by the public sector. Although it was considered a benchmark for many years and is still occasionally used worldwide, this standard has now been succeeded by NIST 800-88, as it was not designed to erase data from chip-based storage media like solid-state drives (SSDs), which are now so common. 

What do Clear, Purge, and Destroy mean? 

NIST 800-88 defines three levels of media sanitization.

NIST Clear

NIST Clear removes data from user-accessible locations using logical techniques such as overwriting.

Best for:
  • Internal device reuse
  • Lower-risk data environments
  • Operational redeployment
Advantages:
  • Preserves asset value
  • Supports reuse and sustainability
  • Fast and cost-effective
Limitations:
  • May not address all inaccessible storage areas

NIST Purge

NIST Purge uses advanced sanitization methods, such as cryptographic erase or block erase, (per the guidance in the IEEE 2883 Standard) to prevent sophisticated data recovery attempts.

Best for:
  • Sensitive business information
  • End-user devices
  • Asset resale programs
Advantages:
  • Higher level of protection than Clear
  • Supports asset reuse
  • Recommended by NIST whenever feasible

NIST Destroy 

NIST Destroy physically renders media unusable and makes data recovery infeasible.
 
Best for:
  • Highly confidential information
  • Damaged devices
  • Assets that cannot be securely sanitized by other methods
Advantages:
  • Highest level of assurance
  • Eliminates recovery risk
Limitations:
  • Device cannot be reused
  • Reduces residual asset value

*Important r2 update:

    • Degaussing is no longer recognized in NIST 800-88 r2 guidance

    • Shredding and pulverizing may not provide sufficient sanitization for modern information storage media such as SSDs unless particle size standards defined in IEEE 2883 are met.

NIST Clear vs. Purge vs. Destroy Comparison Table
Method Protection Level Reuse Possible Typical Use Case
Clear Basic Yes Internal redeployment
Purge High Yes Resale or reuse of sensitive devices
Destroy Maximum No Highly confidential or damaged media

Download our guide below for more information and the recommended media sanitization process below. 

Download NIST 800-88 Guide

NIST Clear, Purge & Destroy compared and explained.

What is NIST 800 88 Clear Purge Destroy

 

 SK Tes provides hard drive destruction services in line with NIST 800-88.

 

NIST 800-88 revision

The NIST 800-88 guidelines were originally published in 2006. The December 2014 update became NIST Special Publication 800-88 Revision 1 (NIST SP 800-88 Rev. 1) – long considered the industry gold standard.

In September 2025, NIST released Revision 2 (r2), modernizing the guidance for today’s distributed, virtual, encrypted, and cloud-enabled environments.

Why were the guidelines updated?

The Revision 2 update was driven by several factors:

  • The widespread use of SSDs and non-magnetic ISM

  • Increased adoption of encryption and cryptographic erase capabilities

  • Growth of cloud and virtual storage environments

  • Need for alignment with frameworks such as NIST SP 800-53 and ISO/IEC 27040

  • A shift from device-specific instructions to a programmatic, verifiable sanitization model

  • Recognition that many old techniques (e.g. degaussing) no longer apply to modern media

NIST SP 800-88r2 removes all sanitization techniques and instructs organizations to use IEEE 2883-2022 for approved sanitization processes.

Conclusion 

As NIST itself notes, improperly sanitized media can provide a rich illicit source of information. Organizations must ensure that when devices leave their control – whether for reuse, resale, or destruction – they do not jeopardize data privacy, security, or regulatory compliance.

Getting it wrong is not only financially costly but also harmful to your brand’s most important asset: its reputation.

SK Tes is also uniquely positioned to offer a full suite of services encompassing the entire lifecycle of technology assets, including managed deployment, IT asset disposition, data center decommissioning, and electronics recycling. These services are delivered through our own infrastructure and operated by our own staff, offering a secure chain of custody and peace of mind for your organization.

FAQs about NIST 800-88 Data Sanitization Guidelines

Is NIST 800-88 mandatory?

NIST 800-88 is mandatory for many U.S. federal agencies and is widely used by commercial organizations as a best-practice framework for secure media sanitization.

Which NIST 800-88 method is recommended?

NIST Revision 2 states that organizations should use Purge instead of Clear whenever feasible, as it provides stronger protection against data recovery.

Does NIST 800-88 apply to SSDs?

Yes, NIST 800-88 applies to modern storage technologies, including SSDs, flash storage, mobile devices, cloud environments, and virtualized storage systems.

What changed in NIST SP 800-88 Revision 2?

Revision 2 introduces a more programatic approach to sanitization techniques.

What is the difference between NIST 800-88 and IEEE 2883?

NIST 800-88 provides the governance framework and sanitization outcomes, while IEEE 2993 specifies approved sanitization techniques used to achieve those outcomes.

See how SK Tes can help you with your NIST data destruction.

Explore Data Destruction Services